Skip to content
← BlogComplianceAnalysis7 min read

France just made 'did they open it' illegal to track without asking

France's CNIL closed its July 14 transition window for email tracking pixels — senders now need real consent to know who opened a message.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

Diagram comparing the old email open-tracking flow, where a pixel fires silently on every send, against the new flow, where the pixel only fires after the recipient has been informed and given a way to object.

Before, the tracking pixel was invisible plumbing. Under the CNIL’s rules, it needs a visible on-ramp: tell the recipient it’s there, and let them say no.

On July 14, 2026, a deadline most cold-email senders outside France never heard of quietly closed. France’s data protection authority, the CNIL, had given companies until that date to inform their existing email contacts that messages sent to them contain tracking pixels — the invisible 1x1 image that fires the moment someone opens an email — and to give those contacts an easy way to object. Miss the window and you lose the transitional grace period entirely, which means going back to collecting fresh, opt-in consent for tracking from your whole existing list rather than relying on an opt-out notice. The CNIL has said it will start checking compliance with the information obligation from mid-July.

If you don’t send to France, this can look like someone else’s problem. It isn’t, for two reasons: France is where this rule started, not where it ends, and the underlying question — do you need consent to know if someone opened your message — is one every mailbox provider and regulator is circling right now, France is just the first to write it down as a formal rule with teeth.

What the CNIL actually requires

The recommendation, adopted in March 2026 and published that April, treats the open-tracking pixel the way most privacy law already treats a website cookie: as a piece of tracking technology that needs a lawful basis before it runs, not after. In practice, that breaks into two buckets:

  • Contacts collected before April 14, 2026 get a transitional, opt-out-based regime. You had until July 14 to tell them tracking is happening and give them a simple way to object — miss it, and the transitional allowance is gone.
  • Contacts collected after April 14, 2026 never had that grace period. Affirmative opt-in consent is required before their opens can be tracked at all.

There are carve-outs — a handful of purposes the CNIL treats as legitimate without separate consent, mostly narrow operational uses rather than general engagement tracking — but “measure my open rate” and “trigger a follow-up sequence because someone opened” both sit squarely inside the part that now needs a lawful basis.

Why this is bigger than one French regulator

Tracking pixels have quietly been the backbone of cold-email measurement for two decades — “did they open it” is the first signal most sequences act on, whether that’s a human checking a dashboard or an automated step deciding whether to send a follow-up. The CNIL’s move formalizes something that’s been building for a while: open tracking already produces noisy, largely unreliable data thanks to Apple’s Mail Privacy Protection prefetching pixels for roughly 58% of tracked opens regardless of whether a human ever looked, and now a major regulator is layering a consent requirement on top of a signal that was already mostly noise.

That combination — unreliable and now legally encumbered in at least one major market — is a strong signal that open tracking’s status as the default measurement layer for cold email is eroding from two directions at once. Italy’s Garante has moved on a related timeline for pixel consent, and trade coverage of the CNIL decision has repeatedly framed it as the first of several similar EU moves rather than a one-off. Expect more DPAs to publish their own version of this over the next year rather than treating France’s rule as an outlier.

The irony regulators are pointing at

Here’s the part that should sting a little: the CNIL isn’t inventing a new category of surveillance out of nowhere. It’s applying the same logic it already applies to web cookies — a technology requiring consent before it can run, with narrow exceptions for genuinely necessary, non-tracking purposes — to a technology that functions almost identically but has, for two decades, escaped that scrutiny purely because it lives inside an email client instead of a browser. A pixel and a cookie do the same job: they let someone outside your control observe your behavior without your explicit awareness that it’s happening. Cookie consent banners became universal because regulators decided that gap was unacceptable on the web. The CNIL’s pixel rule is the same argument, applied to the medium that had, until now, quietly avoided it.

That’s also why this rule is unlikely to stay a French peculiarity. Once one major EU regulator has published a workable, enforceable framework for pixel consent — with a defined transitional period, a clear line between existing and new contacts, and a stated inspection posture — the legal and technical template exists for every other DPA to adopt something similar without having to build the reasoning from scratch. The hard intellectual work of “how do we regulate this” is done; what’s left is other regulators deciding when, not whether, to follow.

What to actually do about it

A practical response, not a legal opinion

  1. Separate delivery tracking from open tracking

    Bounce and delivery signals are operational, not behavioral — you need them to run a mailbox safely. Open tracking is the part that increasingly needs a consent story, so don't let the two get treated as one system when you're deciding what to disclose.

  2. Put the disclosure where people actually see it

    A line buried in a privacy policy three clicks away is a weak position with any regulator working through this issue. A short, plain note in the message itself — or a one-time notice to existing contacts — is the version that survives an inspection.

  3. Build the opt-out path before you need it

    The recipient's ability to say 'don't track my opens' should be a real, working control, not a hypothetical one you'd build if someone complained. Pair it with the same one-click unsubscribe machinery you already run for RFC 8058 compliance.

  4. Stop treating open rate as ground truth for send decisions

    If a step in your sequence exists purely because someone did or didn't open the previous email, that's exactly the kind of profiling-adjacent use a regulator will look at hardest. Reply-based and click-based signals are both more reliable and less exposed than pixel opens.

Where Norbelys fits

This is exactly the gap between “a tool that tracks opens because it always has” and a platform built for a world where that tracking needs a defensible basis. Norbelys already treats raw open-pixel data as untrustworthy by design — we count opens differently, filtering out the prefetch noise instead of reporting a vanity number — and every list in Norbelys carries suppression and unsubscribe state automatically, so the opt-out mechanism this rule requires isn’t a project you have to build, it’s the default behavior of the audience management system you’re already using.

If you’re running outreach into the EU and want a platform where consent state, suppression, and delivery tracking are first-class instead of bolted on, see Norbelys’s plans or read how pricing breaks down — every tier includes the same compliance-grade audience handling, not just the top one. Start a campaign on infrastructure that was built assuming regulators would eventually ask these questions, because they now are.