The CNIL says tracking pixels require prior consent. Yes, in B2B too.
Every email you send through Mailchimp, HubSpot or Brevo contains something your recipients don't see: a tracking pixel. A transparent 1×1 pixel image that loads automatically when the email is opened. Until now, no one gave it much thought. The CNIL, the French data protection authority, has just changed the equation.
Their position: tracking pixels require prior consent. Yes, in B2B too.
When someone opens an email sent through any email marketing platform, an invisible image loads from a server. The server records that the email was opened, at what time, from which device, from which geographic area, and how many times it was re-viewed.
Every "open rate" in your Mailchimp dashboard comes from here. It is not a cookie, it requires no installation, and it works without the recipient clicking anything. That is precisely the problem.
The CNIL treated tracking pixels as a mechanism for accessing information on the user's device, similar to cookies. Under the ePrivacy Directive (transposed into the legislation of each EU Member State), this type of access requires prior informed consent.
What surprised many people: the rule also applies in B2B. We have already received questions from clients who only send corporate newsletters, to company addresses, and who were convinced this didn't concern them. It does. The exceptions are very limited — only strictly transactional communications, such as an order confirmation or invoice.
The decision comes from France, but the principle is European. Authorities in other countries can reach the same interpretation at any time. Some probably will.
If you send newsletters or email campaigns, there are a few things to check.
The subscription form must explicitly mention that you will track email opens through tracking pixels. Most forms say nothing about this. People subscribe to content and, without knowing it, are being monitored.
The privacy policy must be updated. Many companies have sections about cookies but completely ignore email pixels. It's the same logic, a different channel.
The platform settings matter. Mailchimp, HubSpot, Brevo — they all allow tracking to be disabled at the campaign level. If you don't have valid consent, disabling it is the simplest thing you can do right now.
And document it. In an inspection, you need to be able to show that you informed recipients and that you have their consent.
I hear it constantly: "But they subscribed to the newsletter, so they agree to everything." No. Consent to receive an email and consent to track reading behaviour are two separate things.
I also see companies relying on legitimate interest as the legal basis for tracking pixels. The CNIL was clear: for mechanisms similar to cookies, the basis is consent. Legitimate interest does not work here. The ePrivacy rules take precedence.
The quickest: add a notice to your subscription form. Something like: "We will use tracking pixels to measure email performance. You can opt out at any time." One sentence. That's all.
If you want to go further, also offer the option of receiving a plain-text version, without tracking. Some platforms support this. It's not complicated.
Tracking pixels are not illegal. They are illegal when no one mentions them. And in my experience, the difference between a lawful email marketing campaign and a problematic one comes down to a missing sentence in a form that no one has reviewed in two years.
A tracking pixel is a transparent 1×1 image embedded in the body of an email that loads automatically from a server when the recipient opens the message. The server records that the email was opened, at what time, from which device, from which geographic area, and how many times. Every "open rate" in email marketing platforms such as Mailchimp, HubSpot or Brevo comes from here.
Tracking pixels are not illegal in themselves, but they become a problem when recipients are not informed and have not given consent. The CNIL treats tracking pixels as a mechanism for accessing information on the device, similar to cookies, which requires prior consent under the ePrivacy Directive. The rule applies even in B2B; the exceptions are limited to strictly transactional communications, such as order confirmations or invoices.
Yes. For mechanisms similar to cookies, the legal basis is consent, not legitimate interest — the ePrivacy rules take precedence, and the CNIL was clear on this point. Consent to receive the newsletter and consent to track reading behaviour are two separate things: subscribing to content does not automatically cover tracking.
Explicitly mention in your subscription form that you will track email opens through tracking pixels, update your privacy policy so it also covers email pixels and not just cookies, and document the notice and consent in case of an inspection. If you don't have valid consent, disable tracking at the campaign level in your platform settings and, ideally, offer a plain-text version without tracking.
We check your subscription forms, privacy policy and email platform settings, and tell you exactly what to change.