Blog · July 20, 2026
The new EU and UK email tracking rules, in plain English
In 2026, regulators in France, Italy, and the UK each confirmed that the invisible pixel most marketing emails use to count opens needs the recipient’s permission first, the same rule that already governs website cookies. If your customers are all in North America, this almost certainly doesn’t reach you yet. Here’s who it does reach, and why the whole idea of an open rate is shakier than it looks.
The headline that probably worried you
You may have seen it phrased as “Europe now bans email tracking” or “you need consent to send email.” Both are wrong, and the second one is the kind of thing that makes a busy owner close six tabs in a panic. Nothing here stops you sending email, and nobody decided this at the level of “the EU.” Three separate national regulators clarified an existing rule, and they did it in slightly different ways. That distinction matters, so let’s take it in plain terms.
What actually changed
Almost every email marketing tool drops a tiny invisible image into your messages. When the reader’s email app loads that image, the tool logs an “open.” That image is the tracking pixel.
For years, businesses treated it as harmless plumbing. The legal view is different: to load that pixel, your email reaches into the reader’s device and pulls information back out (roughly when they read it, and from where). European privacy law has long said that reaching into someone’s device, whether with a cookie on a website or a pixel in an email, needs their permission unless it’s strictly necessary to deliver what they asked for. Counting opens to measure your campaign is not strictly necessary, so it needs consent. And crucially, opening your email is not consent. The usual “we have a legitimate business reason” justification doesn’t cover this either; for this kind of tracking, permission is the route regulators point to.
The Europe-wide privacy board spelled this out in guidance adopted in late 2024. What made 2026 the year it got real is that individual countries started putting deadlines on it.
Who decided what
Three regulators, three flavors. This is where the “the EU banned it” shorthand falls apart.
| Who | Is it binding? | What it asks for | When it bites |
|---|---|---|---|
| France (CNIL) | Guidance, not law | Ask permission before tracking opens; tell existing contacts and give them a way to opt out | 14 July 2026 for contacts you already had |
| Italy (Garante) | Yes, a binding order | Tell recipients up front; get consent for open tracking and profiling | Around 28 October 2026 |
| UK (ICO) | Yes, PECR is law | Same consent rule that already applies to cookies | In force now |
| United States | No equivalent rule | No permission requirement to track opens | Not applicable |
France’s data protection authority, the CNIL, issued a recommendation: strong guidance, but not a law in itself. Its deadline for informing existing contacts landed on 14 July 2026, which has just passed. Italy’s regulator, the Garante, went further with a binding order and a six-month clock running to late October 2026. In the UK, the ICO folded email pixels into the same cookie rules that were already on the books.
Does any of this touch a North American business?
For most readers of this blog, the honest answer is: not directly, and not yet.
These are EU and UK rules. They apply when you are marketing to people in those regions. If your list is customers in Ohio, Alberta, and Texas, a French recommendation about tracking pixels is not your problem. And as of early 2026, no European or UK regulator had actually penalized anyone specifically over an email tracking pixel. The rules are new and the enforcement is still ahead, not behind. Those 2026 deadlines are the point where that could start to change, so this is worth watching if you sell into Europe, not something to lose a weekend over if you don’t.
The United States runs on a completely different track. There is no American law that says you must get permission before tracking an open. Instead, the fights happen in court, where people have tried to aim decades-old wiretapping and privacy statutes at modern tracking. Judges have often been unconvinced: in late 2025 a federal appeals court threw out one such case, reasoning that a company receiving data sent from your own browser is a participant in the conversation, not a secret eavesdropper. If you run an online store and email customers, that is the landscape you’re actually in, and it looks nothing like Europe’s permission-first model.
Open rates were already broken
This part matters wherever you send email. Set the law aside, and the open rate has stopped meaning what you think it means.
Since 2021, Apple’s Mail Privacy Protection loads that tracking pixel automatically for people who turn it on, whether or not they ever opened your email. Apple Mail is a huge share of how the world reads email, well over half of tracked opens by 2025, so a meaningful chunk of your “opens” are now a machine fetching an image, not a human reading your message. The industry has been backing away from open rates as a result. So the metric the new rules are about is one you can no longer fully trust anyway.
Which raises a better question than “am I allowed to track opens.” It’s “do my emails even arrive?” An open rate, reliable or not, only ever spoke to messages that already landed. It said nothing about the ones that were filtered or bounced before anyone could open them. In a scan of 4,673 small businesses across the US and Canada, more than half were missing at least one of the basic records that decide whether their mail reaches the inbox at all. That is the failure that actually costs you customers, and it hides better than any tracking rule.
Common questions
Do these new rules apply to my US or Canadian business? Only if you send marketing email to people in the EU or UK. If your list is entirely North American, the French, Italian, and UK rules don’t reach you. What can affect you is different: US lawsuits over tracking tend to reuse older wiretap and privacy laws, and courts have often been skeptical of them.
What is an email tracking pixel? A tiny invisible image, often a single dot, that your email tool tucks into a message. When the image loads, the tool records that the email was opened, along with rough details like the time and the reader’s location. You almost never see it, and most email platforms switch it on by default.
Do I have to turn off open tracking? Not automatically. If you email the EU or UK, the safe path is to ask permission before tracking, or simply turn tracking off. If you don’t email those regions, you can leave it on, though it’s worth knowing the number it produces is unreliable anyway.
Is emailing myself a good way to test whether my email works? No. Mail to your own address always arrives, so it tells you nothing about whether a stranger’s inbox accepts you. The same trap now applies to open rates: Apple and others load the tracking pixel automatically, so an open can be a machine, not a person.
Start with what you can actually check
The tracking rules are worth understanding, and if you sell into Europe they’re worth acting on before those autumn deadlines. But for most North American owners the pressing question is the older one hiding underneath: is your email even getting through? The plain-English guide explains what receivers check, and you can run your domain through the free scanner in about thirty seconds to see whether the basics are in place. If something comes back red, you’ve likely found where your missing emails have been going, tracked or not.
This is a plain-English explainer, not legal advice. If you market heavily into the EU or UK, check the specifics with a privacy professional.
Check your domain in 30 seconds
Enter your domain. We read SPF, DKIM, DMARC, and MX from public DNS and explain what's missing in plain English - no signup, no account.
Free · no account · results in ~30 seconds
References
- EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive The EU-wide guidance confirming that email tracking pixels fall under the same consent rule as cookies (adopted 7 October 2024).
- CNIL: Recommandation pixels de suivi dans les courriels (France) France's official recommendation, adopted 12 March 2026, published 14 April 2026. In French.
- Covington / Inside Privacy: CNIL Publishes Recommendation on Email Tracking Pixels Plain-English analysis of the French recommendation and its 14 July 2026 deadline.
- A&O Shearman: Tracking Pixels in Emails, the Garante's New Guidelines (Italy) Italy's Garante adopted Provision No. 284 on 17 April 2026, binding, with a six-month compliance window.
- Lewis Silkin: Tracking pixels in emails, a comparative analysis of the CNIL and Garante guidance Side-by-side of the French and Italian positions and their differing legal force.
- ICO: Guidance on the use of storage and access technologies (UK) UK guidance treating email tracking pixels the same as cookies under PECR (finalized 2026).
- Pillsbury: Email Tracking Technology Compliance, US and EU Notes that as of March 2026 no EU or UK regulator had enforced specifically against email tracking pixels.
- Squire Patton Boggs (Privacy World): Third Circuit strikes a blow to another pixel case Cole v. Quest Diagnostics, 3d Cir., 13 November 2025 (non-precedential): a US court dismisses a pixel-tracking claim.
- Mailchimp: Apple Mail Privacy Protection FAQ How Apple's Mail Privacy Protection (2021) preloads tracking pixels and inflates open rates.
- State of Small Business Email, US and Canada (June 2026) Our scan of 4,673 firms; source of the more-than-half figure.
Published July 20, 2026.