Data protection regulators in France and Italy have issued guidance on the use of tracking pixels in marketing emails. Because Wunderkind emails use pixel-based open tracking, this may affect how you send to recipients in these countries. This article explains what the guidance says, what it means for you as a sender, and how Wunderkind can help you put your chosen approach into practice.
What the guidance says
A tracking pixel is a small, invisible image that loads when a recipient opens an email, letting the sender record that the message was opened. France's CNIL and Italy's Garante have both concluded that these pixels should be treated much like cookies under the EU ePrivacy framework. The shared core principle is that using tracking pixels for most marketing purposes requires the recipient's prior consent, that this consent is separate from a recipient's consent to receive email, and that recipients must be able to withdraw it as easily as they gave it.
France (CNIL). The recommendation is grounded in Article 82 of the French Data Protection Act. Marketing tracking pixels generally require prior consent unless a narrow exemption applies. The CNIL also set transitional arrangements for recipients whose details were collected before the recommendation took effect; your privacy team can advise on how those apply to your existing contacts.
Italy (Garante). The guidance (Provision No. 284) applies the same underlying principle and provides a transition period for bringing existing practices into line.
Both sets of guidance stem from the same EU ePrivacy foundation, so if you send across Europe it is worth treating the underlying principles as broader than these two countries alone, even though the specific rules and timelines differ by country.
What this means for you
When you send marketing emails, you are the data controller. You decide your compliance approach, and you are responsible for having a lawful basis — in most cases, consent — for both your marketing and your pixel tracking. Wunderkind acts as a processor on your instructions. In practice, that means the compliance decisions are yours to make with your privacy or legal team; Wunderkind's role is to give you the tools to carry out whatever approach you choose.
Working with your privacy team, the main questions to resolve are:
- Which of your pixel uses need consent. The regulators distinguish uses that generally require consent — such as analyzing open rates to optimize campaigns, or building profiles for cross-channel targeting — from a narrower set that may be exempt, such as security and authentication or strictly limited deliverability measurement. Which bucket your use falls into is for your privacy team to decide.
- Which of your recipients are in scope, and how they should be handled. Both regulators treat recipients differently depending on when their details were collected, and both provide transition arrangements for existing contacts. Mapping your contacts to the right approach is something to settle with your privacy team. For existing recipients, some senders take the position that it is enough to inform them about the tracking — for example, through their cookie or privacy policy — and to offer a clear way to opt out; whether that approach is appropriate for you is a question for your privacy team. The clearest starting point is the regulators' own texts — the CNIL recommendation (an official English translation is available) and the Garante's Provision No. 284.
- How recipients can withdraw. Both regulators expect withdrawing tracking consent to be as simple as giving it.
Two distinctions are worth keeping in mind as you plan. First, consent is tied to a specific purpose, so "we have consent" is not monolithic — it needs to map to what the tracking actually does. Second, tracking consent is separate from consent to receive the email: even a message you may be permitted to send without marketing consent can contain a pixel that requires its own consent. Your privacy team can confirm how both points apply to your program.
How Wunderkind supports your approach
Whatever approach you and your privacy team decide on, Wunderkind can help you operationalize it:
- Honor the consent you already collect. If you maintain tracking-consent status for your contacts, you can pass that information to Wunderkind — the same way you already distinguish audiences today — so that pixel-tracked emails go only to recipients who have consented.
- Capture consent at the point of email sign-up. The regulators recommend collecting tracking consent when the email address is collected. Wunderkind's email capture products are a natural place to add this, and your team can work with us to design the flow.
What to do next
- Share the regulators' own texts with your privacy or legal team and decide together how they apply to your France and Italy sending.
- Work out which recipients are affected and how each group should be treated — that mapping sits with your privacy team.
- If your team calls for a notice or a renewed consent request, plan how you'll deliver it and how you'll capture and act on the replies.
- Once your approach is set, your Wunderkind CSM can configure consent handling and/or sign-up capture to match.
This article explains the regulators' guidance and what Wunderkind's platform can do. It is not legal advice and does not determine whether your program is compliant. Decisions about your legal obligations and the level of risk you are comfortable with rest with you and your legal or privacy team.
Comments
0 comments
Article is closed for comments.