emailmarketing.net

France — CNIL Email Prospecting Rules and the Tracking-Pixel Recommendation

CNIL's rules for commercial email (B2C opt-in, existing-customer exception, B2B professional-relevance test) and the 2026 recommendation requiring consent for most email tracking pixels — including the deliverability-measurement exemption every ESP needs to know.

Referencecompliancesender

France transposes the ePrivacy Directive's email-marketing rule through Article L.34-5 of the Code des postes et des communications électroniques (CPCE) and its terminal-equipment rule (cookies/pixels) through Article 82 of the Loi Informatique et Libertés (the Data Protection Act). The regulator is the CNIL. Like UK PECR and CASL, France is an opt-in regime for consumers — but with a distinctive B2B "professional relevance" test instead of the UK's corporate-subscriber exemption, and, since 2026, a headline rule for ESPs: most email open-tracking pixels require the recipient's consent.

Not legal advice — verify thresholds and deadlines against the primary sources (below) and counsel before relying on them. See compliance/README.md.

Message taxonomy

The CNIL distinguishes three message types; the classification determines which rules apply:

Type Definition Legal basis
Commercial prospecting Promotes products, services, or the company's image Consent (B2C), with exceptions below
Transactional Necessary for managing the contract/service — confirmations, alerts, password resets Contract performance / legitimate interest
Relational Follow-up without direct promotional purpose — usage guidance, account management Legitimate interest

Transactional and relational messages must not contain significant promotional content; mixing in commercial content re-classifies the message as prospecting and triggers the consent rules. (Same principle as CAN-SPAM's primary-purpose test, but with an opt-in consequence.)

B2C: prior consent required

Sending commercial prospecting by email or SMS to individuals requires prior consent (Art. L.34-5 CPCE), meeting the GDPR Art. 4(11) standard: free, specific, informed, unambiguous, expressed by a positive and specific action.

  • Pre-ticked boxes are forbidden; an unchecked-by-default checkbox is the recommended mechanism.
  • Acceptance of general terms and conditions cannot substitute for consent.
  • Consent is withdrawable at any time.
  • Legal references: GDPR Art. 4(11) (definition), Art. 6 (lawful bases), Art. 7 (conditions of consent), Art. 21 (right to object); CPCE Art. L.32 and L.34-5.

Exception 1 — existing customers, similar products/services

No prior consent is needed when prospecting an existing customer about similar products or services supplied by the same company, provided:

  1. the person was informed at the time their address was collected that it would be used for prospecting of similar products/services; and
  2. they could object, simply and free of charge, at collection and in every subsequent message.

Boundary rulings the CNIL highlights:

  • A completed sale or service delivery is required — "the exception cannot be mobilised where no sale or service provision has taken place." Mere account creation (e.g., opening an e-commerce account without ordering) does not establish customer status; consent is required.
  • CJEU, 13 November 2025 (Inteligo Media): a holder of a free account on a news site who receives a newsletter promoting paid subscriptions may qualify under the existing-customer exception — a free service that initiates a customer relationship can count.
  • Similar-products examples: a train-ticket buyer receiving offers for similar transport services → exception applies (with opt-out offered); a hotel booking used to send partner airline offers → exception does not apply (different company/products), consent required.

Exception 2 — non-commercial prospecting (charities and similar)

Charities and comparable organisations may prospect on the basis of legitimate interest rather than consent, provided the person was told at collection that their details would be used for "non-commercial prospecting" and has a simple, free way to object both at collection and with each message.

B2B: the professional-relevance test

Prospecting professionals by email does not systematically require consent. The legal basis is legitimate interest, subject to three conditions:

  1. the message relates to the recipient's profession ("en rapport avec la profession de la personne démarchée") — the CNIL's example: pitching software to a company's IT director qualifies;
  2. the person was informed (at collection, or — for data already held or acquired from third parties — verifiably informed) that their details could be used for prospecting, and of the origin of the data and the purpose of the message;
  3. a simple, free objection mechanism is provided.

Generic organisation addresses (info@company.fr, contact@company.fr, commande@company.fr), which relate to legal persons rather than natural persons, fall outside these consent/objection rules entirely. Contrast with UK PECR, where role addresses at corporate subscribers are also exempt from the consent rule but the identity/opt-out duties still apply — see Netherlands & the B2B question for the cross-country comparison.

Universal requirements (all prospecting)

  • Clearly identify the sending organisation.
  • Provide a simple unsubscribe mechanism in every message.
  • Honor objections permanently — the CNIL recommends a suppression list ("liste repoussoir") to prevent re-solicitation (the same architecture as GDPR and suppression lists).
  • Answer data-subject rights requests (access, rectification, objection, erasure) within one month maximum.
  • Provide GDPR transparency information at collection.
  • Non-compliance can be reported to the CNIL as a complaint; unwanted SMS can be reported to platform 33700.

The CNIL's compliance checklist for senders: classify the message type; verify transactional/relational messages lack significant promotion; determine the legal basis; inform at collection; validate consent where required; provide objection at collection and in every message; maintain a current suppression list; supervise service providers; secure the data; define retention periods; document everything.


The CNIL Tracking-Pixel Recommendation (2026)

Deliberation n° 2026-042, adopted 12 March 2026, published 14 April 2026 (public consultation ran 12 June – 24 July 2025). This is the first regulator-issued operational rulebook for email open-tracking pixels and directly governs how ESPs serving French recipients may run open tracking. It applies Article 82 of the Data Protection Act (the French transposition of ePrivacy Art. 5(3)), following EDPB Guidelines 2/2023 on the technical scope of the ePrivacy Directive, which confirmed those provisions apply to pixels in emails.

Why pixels are covered: the pixel is a remotely-hosted image whose URL carries individualised parameters; displaying it makes the recipient's terminal return targeted information (pixel identifier, IP address, etc.) to the depositing actor. That collection constitutes a reading operation on the user's terminal — the trigger for Article 82. The recommendation covers email only (captive messaging systems like bank inboxes use other protocols and are out of scope). It is guidance, not regulation, but the CNIL has announced webinars and enforcement through audits.

Who is responsible (GDPR roles)

Actor Qualification
Email sender (the brand that decided to send) Controller, even when tracking is outsourced; in principle jointly responsible for reading/writing operations it contractually accepts from third parties in its emails
Emailing service provider (the ESP — technical sending solution, usually offers the pixel feature) Processor, acting on the controller's instructions
List-rental + sending provider ("turnkey" campaigns to rented lists) Case-by-case: processor in principle; if it also uses pixels for its own purposes (improving list relevance or its own deliverability with mailbox providers) and the customer contractually agrees, joint controllership (GDPR Art. 26 — requires a clear division of duties for information and rights)
Tracking-technology supplier (third-party pixel vendor) Processor if operating solely for the sender; co-responsible if it also uses the data for its own purposes (e.g., product improvement) with the customer's contractual agreement
Mailbox provider (receives/displays the mail; may block image loading) Neither controller nor processor — it does not use the pixel data

This is one of the few regulator texts that names the ESP's role explicitly — an ESP that repurposes customers' open data for its own optimization steps into joint controllership.

Purposes requiring consent

Prior free, specific, informed, unambiguous consent is required for pixels used for:

  • Open-rate analysis to measure and optimise campaign performance — personalising content, adapting sending frequency, or switching channel (email/SMS/push); includes reliability procedures such as ad-fraud fighting;
  • Building recipient profiles from observed preferences/interests to target them outside email (websites, mobile apps, other channels);
  • Detection and analysis of suspected fraud (e.g., unusual/massive opens indicating automation — mass contest entries, exfiltration attempts);
  • Individual open-rate measurement for deliverability when performed outside the exempted scope below.

Purposes exempt from consent

Pixels used exclusively for the following may operate without consent:

  1. Security measures in user authentication — e.g., confirming that an email carrying an authentication code was opened on a terminal known to belong to the intended user.
  2. Individual open-rate measurement for deliverability purposes. The CNIL accepts that managing a mailing list "almost systematically requires" opening statistics to identify deliverability issues — but the controller must demonstrate the operations are limited to what is strictly necessary to adjust the frequency of, or stop, sends to "inactive" recipients (database cleaning). Within that limit, the pixel data may also serve to:
    • assess and adapt the communication channel (choose alternative contact methods);
    • help demonstrate compliance with a legal obligation to transmit information (proof that legally-required pre-/post-contract information was delivered).

Data-minimisation constraint: in principle only the date of the last known opening — day only, no time — overwritten at each new opening with deletion of the previous one should be kept.

Scope limit on the exemptions: because Article 82's exemption keys on the user's "express request," the exemptions apply only to emails requested by the recipient or relating to a requested service — i.e., transactional emails or emails the recipient consented to receive. The recommendation defines transactional emails as messages triggered by a user action/event, informative or functional and necessary for the contractual relationship: welcome emails, account alerts, shipping notifications, order confirmations and invoices, reminders and password resets, customer-service replies, appointment/reservation reminders, payment notifications, breach notifications tied to the requested service. Pixels in public administration emails sent within a public-service mission (including proactive rights information) are also within the exemptions.

Anonymised re-use: once data collected via a pixel is effectively anonymised, its re-use requires no consent (the anonymisation processing itself remains subject to GDPR).

Practical consequence for ESPs: blanket per-recipient open tracking for engagement dashboards, send-time optimization, or automation triggers requires consent for French recipients; open tracking whose retained output is a single last-open date used to run sunset/inactivity policies can be exempt on transactional and consented mail. The consent regime for pixels is independent of the consent regime for the email itself: pixel consent may be needed in emails that themselves need no consent (order confirmations, similar-products marketing, charity marketing, B2B professional prospecting).

Collecting pixel consent

  • Purpose-by-purpose presentation: each purpose should carry a short title plus a brief description. The CNIL supplies model wordings, e.g. — deliverability: "[Sender] and [third parties] use trackers (tracking pixels) to find out if and when you open the emails in order to compile diffusion statistics and take the necessary actions (adaptation of the frequency or stop mailings) to manage the mailing lists"; campaign performance: "…whether you open the emails, the time at which you do so, and information about the device you use to personalise content, adjust the sending frequency or the channel used"; cross-context profiling and fraud detection have analogous templates. Detailed descriptions should be reachable from the consent interface (expand button or hyperlink at the first level).
  • Good practice: disclose even consent-exempt pixels in the privacy policy.
  • Scope clarity: the recipient must be able to identify which email address the pixels will affect, and understand that trackers will operate on all terminals where they read that mailbox.
  • Preferred moment: collect pixel consent at the time the email address itself is collected, integrating the purpose summary (with a link to the trackers policy) into the signup form.
  • Retro-fitting consent: where consent wasn't collected with the address (or the address came from a third party without proof of pixel consent, or was collected orally), send a pixel-free email containing a link to a consent interface. The link must lead to a page requiring a positive action (button click) so that automatic link pre-loading by mailbox providers cannot register a phantom consent — the same defence as for one-click unsubscribe endpoints. Use a per-recipient tracking link so only the address holder can express the choice; such links, serving user security/authentication, are themselves consent-exempt under Article 82.
  • Inactivity = refusal. Non-response to a consent solicitation must be treated as refusal; the solicitation must not pressure recipients or hinder reading. Offer an explicit "refuse" as easy as "accept," record the choice, and don't re-solicit for a period — 6 months of non-solicitation is cited as good practice. (This 6-month figure is a re-solicitation gap specific to pixel consent, not a general consent-freshness rule; for how it compares with other jurisdictions' freshness numbers see Consent Record-Keeping.)
  • Granularity: consent should be asked independently per purpose; a two-level interface (global accept at level one, per-purpose choices at level two) is acceptable. A single consent may bundle electronic direct marketing (Art. L.34-5) with pixels serving related purposes — e.g., marketing expressly presented as personalised plus the pixels that personalise it, or contest emails plus anti-fraud pixels. Unrelated purposes need separate consent, and display advertising and email prospecting are always separate purposes.
  • CMP caution: collecting pixel consent through a web/app consent-management platform is possible but demands care — the person must understand the choice concerns a different environment (their email) and which address is affected.

Withdrawal

  • Offer withdrawal via a tracked link in the footer of every email; withdrawing must be as easy as consenting.
  • If the link opens a web page, withdrawal must complete without further action — in particular without retyping the email address.
  • Withdrawal must be effective: future emails must not trigger the operations, and for already-sent emails the sender may need measures so previously embedded pixels stop being exploited when a message is reopened.

Proof of consent

  • The controller must be able to demonstrate consent at any time (GDPR Art. 7(1)) via individualised records — each person's consent and the conditions under which it was obtained.
  • Where a third party collected the address and the consent, a contract clause obliging the partner to obtain valid consent is not sufficient proof. The contract may instead govern: the consent-collection mechanisms, availability of the evidence to the relying party, evidence-retention conditions preserving probative value, and regular audits of the consent-gathering mechanisms. Contractual commitments do not shield the controller from liability if evidence cannot be produced.

Transition for existing lists

For addresses already collected before publication, tracking may continue only if clear, accessible information is sent to recipients within at most 3 months of publication of the recommendation, enabling anyone whose consent wasn't validly obtained to object to the operations for future emails. Where new consent is needed anyway (e.g., transmitting data to new controllers for prospecting), valid pixel consent must be obtained for non-exempt operations.

Deliverability relevance

France is the first jurisdiction to regulate open-tracking mechanics in detail, and it lands on the position deliverability practitioners already reached for technical reasons: open data is unreliable (Apple Mail Privacy Protection pre-fetches pixels; Gmail proxies images) and its legitimate operational use is list hygiene — exactly the purpose the CNIL exempts. ESPs should treat per-recipient open analytics for French recipients as a consent-gated feature, keep a minimal last-open date for sunset policies, and prefer click and conversion signals for engagement measurement. See also the UK position (PECR): pixels fall under the storage-and-access rules there too, but without (yet) an equivalent operational recommendation.

#compliance#legal#france#cnil#eprivacy#gdpr#consent#tracking-pixels#open-tracking