Blog · July 20, 2026

The new EU and UK email tracking rules, in plain English

In 2026, regulators in France, Italy, and the UK each confirmed that the invisible pixel most marketing emails use to count opens needs the recipient’s permission first, the same rule that already governs website cookies. If your customers are all in North America, this almost certainly doesn’t reach you yet. Here’s who it does reach, and why the whole idea of an open rate is shakier than it looks.

The headline that probably worried you

You may have seen it phrased as “Europe now bans email tracking” or “you need consent to send email.” Both are wrong, and the second one is the kind of thing that makes a busy owner close six tabs in a panic. Nothing here stops you sending email, and nobody decided this at the level of “the EU.” Three separate national regulators clarified an existing rule, and they did it in slightly different ways. That distinction matters, so let’s take it in plain terms.

What actually changed

Almost every email marketing tool drops a tiny invisible image into your messages. When the reader’s email app loads that image, the tool logs an “open.” That image is the tracking pixel.

For years, businesses treated it as harmless plumbing. The legal view is different: to load that pixel, your email reaches into the reader’s device and pulls information back out (roughly when they read it, and from where). European privacy law has long said that reaching into someone’s device, whether with a cookie on a website or a pixel in an email, needs their permission unless it’s strictly necessary to deliver what they asked for. Counting opens to measure your campaign is not strictly necessary, so it needs consent. And crucially, opening your email is not consent. The usual “we have a legitimate business reason” justification doesn’t cover this either; for this kind of tracking, permission is the route regulators point to.

The Europe-wide privacy board spelled this out in guidance adopted in late 2024. What made 2026 the year it got real is that individual countries started putting deadlines on it.

Who decided what

Three regulators, three flavors. This is where the “the EU banned it” shorthand falls apart.

WhoIs it binding?What it asks forWhen it bites
France (CNIL)Guidance, not lawAsk permission before tracking opens; tell existing contacts and give them a way to opt out14 July 2026 for contacts you already had
Italy (Garante)Yes, a binding orderTell recipients up front; get consent for open tracking and profilingAround 28 October 2026
UK (ICO)Yes, PECR is lawSame consent rule that already applies to cookiesIn force now
United StatesNo equivalent ruleNo permission requirement to track opensNot applicable

France’s data protection authority, the CNIL, issued a recommendation: strong guidance, but not a law in itself. Its deadline for informing existing contacts landed on 14 July 2026, which has just passed. Italy’s regulator, the Garante, went further with a binding order and a six-month clock running to late October 2026. In the UK, the ICO folded email pixels into the same cookie rules that were already on the books.

Does any of this touch a North American business?

For most readers of this blog, the honest answer is: not directly, and not yet.

These are EU and UK rules. They apply when you are marketing to people in those regions. If your list is customers in Ohio, Alberta, and Texas, a French recommendation about tracking pixels is not your problem. And as of early 2026, no European or UK regulator had actually penalized anyone specifically over an email tracking pixel. The rules are new and the enforcement is still ahead, not behind. Those 2026 deadlines are the point where that could start to change, so this is worth watching if you sell into Europe, not something to lose a weekend over if you don’t.

The United States runs on a completely different track. There is no American law that says you must get permission before tracking an open. Instead, the fights happen in court, where people have tried to aim decades-old wiretapping and privacy statutes at modern tracking. Judges have often been unconvinced: in late 2025 a federal appeals court threw out one such case, reasoning that a company receiving data sent from your own browser is a participant in the conversation, not a secret eavesdropper. If you run an online store and email customers, that is the landscape you’re actually in, and it looks nothing like Europe’s permission-first model.

Open rates were already broken

This part matters wherever you send email. Set the law aside, and the open rate has stopped meaning what you think it means.

Since 2021, Apple’s Mail Privacy Protection loads that tracking pixel automatically for people who turn it on, whether or not they ever opened your email. Apple Mail is a huge share of how the world reads email, well over half of tracked opens by 2025, so a meaningful chunk of your “opens” are now a machine fetching an image, not a human reading your message. The industry has been backing away from open rates as a result. So the metric the new rules are about is one you can no longer fully trust anyway.

Which raises a better question than “am I allowed to track opens.” It’s “do my emails even arrive?” An open rate, reliable or not, only ever spoke to messages that already landed. It said nothing about the ones that were filtered or bounced before anyone could open them. In a scan of 4,673 small businesses across the US and Canada, more than half were missing at least one of the basic records that decide whether their mail reaches the inbox at all. That is the failure that actually costs you customers, and it hides better than any tracking rule.

Common questions

Do these new rules apply to my US or Canadian business? Only if you send marketing email to people in the EU or UK. If your list is entirely North American, the French, Italian, and UK rules don’t reach you. What can affect you is different: US lawsuits over tracking tend to reuse older wiretap and privacy laws, and courts have often been skeptical of them.

What is an email tracking pixel? A tiny invisible image, often a single dot, that your email tool tucks into a message. When the image loads, the tool records that the email was opened, along with rough details like the time and the reader’s location. You almost never see it, and most email platforms switch it on by default.

Do I have to turn off open tracking? Not automatically. If you email the EU or UK, the safe path is to ask permission before tracking, or simply turn tracking off. If you don’t email those regions, you can leave it on, though it’s worth knowing the number it produces is unreliable anyway.

Is emailing myself a good way to test whether my email works? No. Mail to your own address always arrives, so it tells you nothing about whether a stranger’s inbox accepts you. The same trap now applies to open rates: Apple and others load the tracking pixel automatically, so an open can be a machine, not a person.

Start with what you can actually check

The tracking rules are worth understanding, and if you sell into Europe they’re worth acting on before those autumn deadlines. But for most North American owners the pressing question is the older one hiding underneath: is your email even getting through? The plain-English guide explains what receivers check, and you can run your domain through the free scanner in about thirty seconds to see whether the basics are in place. If something comes back red, you’ve likely found where your missing emails have been going, tracked or not.

This is a plain-English explainer, not legal advice. If you market heavily into the EU or UK, check the specifics with a privacy professional.

Free inspection

Check your domain in 30 seconds

Enter your domain. We read SPF, DKIM, DMARC, and MX from public DNS and explain what's missing in plain English - no signup, no account.

Free · no account · results in ~30 seconds

References

Published July 20, 2026.