# France — CNIL Email Prospecting Rules and the Tracking-Pixel Recommendation

> CNIL's rules for commercial email (B2C opt-in, existing-customer exception, B2B professional-relevance test) and the 2026 recommendation requiring consent for most email tracking pixels — including the deliverability-measurement exemption every ESP needs to know.

Source: emailmarketing.net — https://emailmarketing.net/learn/compliance/france-cnil-email

If you send commercial email to people in France, or track opens on mail to French recipients, the rules you must follow come from French law and its regulator. France transposes the email marketing rule of the ePrivacy Directive through **Article L.34-5 of the Code des postes et des communications électroniques (CPCE)**, and its rule on terminal equipment (cookies and pixels) through **Article 82 of the Loi Informatique et Libertés** (the Data Protection Act). The regulator is the **CNIL**.

Like [UK PECR](https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing) and [CASL](https://emailmarketing.net/learn/compliance/casl), France is an **opt-in** regime for consumers. But it has a distinctive "professional relevance" test for business-to-business (B2B) mail instead of the UK's exemption for corporate subscribers. Since 2026, it also has a headline rule for email service providers (ESPs): **most email open-tracking pixels require the recipient's consent**.

**Not legal advice.** Verify thresholds and deadlines against the primary sources (below) and with counsel before relying on them. See the [compliance overview](https://emailmarketing.net/learn/compliance).

## Message taxonomy

The CNIL distinguishes three types of message, and the classification determines which rules apply:

| Type | Definition | Legal basis |
|---|---|---|
| **Commercial prospecting** | Promotes products, services, or the company's image | Consent (B2C), with exceptions below |
| **Transactional** | Necessary to manage the contract or service: confirmations, alerts, password resets | Performance of a contract, or legitimate interest |
| **Relational** | Follow-up without a direct promotional purpose: guidance on use, account management | Legitimate interest |

Transactional and relational messages must **not contain significant promotional content**. Adding commercial content reclassifies the message as prospecting and triggers the consent rules. (This is the same principle as the primary-purpose test of CAN-SPAM, but with an opt-in consequence.)

## B2C: prior consent required

Sending commercial prospecting by email or SMS to individuals (business-to-consumer, or B2C) requires **prior consent** (Art. L.34-5 CPCE) that meets the standard of GDPR Art. 4(11): free, specific, informed, unambiguous, and expressed by a **positive and specific action**.

- **Pre-ticked boxes are forbidden.** The recommended mechanism is a checkbox that is unchecked by default.
- Accepting the general terms and conditions cannot replace consent.
- Consent can be withdrawn at any time.
- Legal references: GDPR Art. 4(11) (definition), Art. 6 (lawful bases), Art. 7 (conditions of consent), Art. 21 (right to object); CPCE Art. L.32 and L.34-5.

### Exception 1: existing customers and similar products or services

No prior consent is needed to prospect an **existing customer** about **similar products or services supplied by the same company**, provided that:

1. the person was told **when their address was collected** that it would be used for prospecting about similar products or services; and
2. they could object, simply and free of charge, **at collection and in every later message**.

Boundary rulings the CNIL highlights:

- **A completed sale or delivery of a service is required**: "the exception cannot be mobilised where no sale or service provision has taken place." Simply creating an account (for example, opening an e-commerce account without ordering) does **not** make someone a customer, so consent is required.
- **Court of Justice of the European Union (CJEU), 13 November 2025 (Inteligo Media)**: the holder of a free account on a news site who receives a newsletter promoting paid subscriptions may qualify under the existing-customer exception. A free service that starts a customer relationship can count.
- **Examples of similar products**: a buyer of train tickets who receives offers for similar transport services falls under the exception (with an opt-out offered). A hotel booking used to send offers from a **partner airline** does **not** fall under it (a different company and different products), so consent is required.

### Exception 2: non-commercial prospecting (charities and similar)

Charities and comparable organisations may prospect on the basis of **legitimate interest** rather than consent, provided that the person was told at collection that their details would be used for "non-commercial prospecting", and has a simple, free way to object, both at collection and in each message.

## B2B: the professional-relevance test

Prospecting professionals by email does **not** systematically require consent. The legal basis is **legitimate interest**, subject to three conditions:

1. the message **relates to the recipient's profession** ("en rapport avec la profession de la personne démarchée"). In the CNIL's example, pitching software to a company's IT director qualifies;
2. the person was **informed** that their details could be used for prospecting, and of the origin of the data and the purpose of the message. This happens at collection or, for data already held or acquired from third parties, in a verifiable way;
3. a **simple, free way to object** is provided.

**Generic organisation addresses** (info@company.fr, contact@company.fr, commande@company.fr) relate to legal persons rather than natural persons, and fall entirely **outside** these rules on consent and objection. Under UK PECR, by contrast, role addresses at corporate subscribers are also exempt from the consent rule, but the duties to identify the sender and offer an opt-out still apply. See [Netherlands and the B2B question](https://emailmarketing.net/learn/compliance/netherlands-and-b2b-rules) for the comparison across countries.

## Universal requirements (all prospecting)

- Clearly identify the sending organisation.
- Provide a simple unsubscribe mechanism in every message.
- Honor objections **permanently**. The CNIL recommends a **suppression list ("liste repoussoir")** to prevent further solicitation (the same architecture as in [GDPR and suppression lists](https://emailmarketing.net/learn/compliance/gdpr-and-suppression-lists)).
- Answer requests from data subjects to exercise their rights (access, rectification, objection, erasure) within **one month at most**.
- Provide GDPR transparency information at collection.
- Non-compliance can be reported to the CNIL as a complaint, and unwanted SMS can be reported to the platform **33700**.

The CNIL's compliance checklist for senders: classify the message type; check that transactional and relational messages contain no significant promotion; determine the legal basis; inform people at collection; validate consent where it is required; offer objection at collection and in every message; keep the suppression list up to date; supervise service providers; secure the data; define retention periods; and document everything.

---

# The CNIL Tracking-Pixel Recommendation (2026)

**Deliberation n° 2026-042, adopted 12 March 2026, published 14 April 2026** (the public consultation ran from 12 June to 24 July 2025). It is the first operational rulebook from a regulator for email open-tracking pixels, and it directly governs how ESPs that serve French recipients may run open tracking. It applies Article 82 of the Data Protection Act (the French transposition of ePrivacy Art. 5(3)), following the European Data Protection Board's **EDPB Guidelines 2/2023** on the technical scope of the ePrivacy Directive, which confirmed that those provisions apply to pixels in emails.

**Why pixels are covered**: the pixel is a remotely hosted image whose URL carries individual parameters. Displaying it makes the recipient's terminal send targeted information (the pixel identifier, the IP address and so on) back to the actor that placed it. That collection is a **reading operation on the user's terminal**, which is what triggers Article 82. The recommendation covers email only; closed messaging systems such as bank inboxes use other protocols and are out of scope. It is guidance, not regulation, but the CNIL has announced webinars and **enforcement through audits**.

## Who is responsible (GDPR roles)

| Actor | Qualification |
|---|---|
| **Email sender** (the brand that decided to send) | **Controller**, even when tracking is outsourced. In principle it is **jointly responsible** for the reading and writing operations by third parties that it accepts in its emails under contract |
| **Emailing service provider** (the ESP: the technical sending solution, which usually offers the pixel feature) | **Processor**, acting on the controller's instructions |
| **Provider of list rental and sending** ("turnkey" campaigns to rented lists) | Decided case by case: a **processor in principle**. If it also uses pixels for its own purposes (improving the relevance of its lists, or its own deliverability with mailbox providers) and the customer agrees in the contract, **joint controllership** applies (GDPR Art. 26, which requires a clear division of duties for information and rights) |
| **Supplier of tracking technology** (a third-party pixel vendor) | A **processor** if it works only for the sender; **co-responsible** if it also uses the data for its own purposes (for example, product improvement) with the customer's agreement in the contract |
| **Mailbox provider** (receives and displays the mail, and may block image loading) | **Neither controller nor processor**, because it does not use the pixel data |

This is one of the few texts from a regulator that names the role of the ESP explicitly. An ESP that reuses its customers' open data for its own optimization becomes a joint controller.

## Purposes requiring consent

Prior consent that is free, specific, informed and unambiguous is required for pixels used for:

- **Analysis of open rates to measure and optimise campaign performance**: personalising content, adapting sending frequency, or switching channel (email, SMS, push). This includes reliability procedures such as fighting ad fraud;
- **Building recipient profiles** from observed preferences and interests, to target recipients **outside email** (websites, mobile apps, other channels);
- **Detection and analysis of suspected fraud** (for example, unusual or massive opens that indicate automation: mass contest entries, exfiltration attempts);
- **Measurement of individual open rates for deliverability** when it is carried out **outside the exempted scope below**.

## Purposes exempt from consent

Pixels used **exclusively** for the following purposes may operate without consent:

1. **Security measures in user authentication**: for example, confirming that an email carrying an authentication code was opened on a terminal known to belong to the intended user.
2. **Measurement of individual open rates for deliverability.** The CNIL accepts that managing a mailing list "almost systematically requires" opening statistics to identify deliverability issues. But the controller must show that the operations are limited to what is strictly necessary to **adjust the frequency of sends to "inactive" recipients, or stop them (database cleaning)**. Within that limit, the pixel data may also serve to:
   - assess and adapt the communication channel (choose other ways of contacting the person);
   - help demonstrate compliance with a legal obligation to transmit information (proof that information required by law before or after the contract was delivered).

**Data minimisation constraint**: in principle, only the **date of the last known opening should be kept, as a day with no time, overwritten at each new opening, with the previous date deleted**.

**Scope limit on the exemptions**: because the exemption in Article 82 depends on the user's "express request", the exemptions apply only to emails **requested by the recipient or related to a requested service**, that is, **transactional emails** or emails the recipient consented to receive. The recommendation defines transactional emails as messages triggered by a user action or event, that are informative or functional and necessary for the contractual relationship: welcome emails, account alerts, shipping notifications, order confirmations and invoices, reminders and password resets, replies from customer service, reminders of appointments or reservations, payment notifications, and breach notifications tied to the requested service. Pixels in **public administration** emails sent as part of a public service mission (including proactive information about rights) also fall within the exemptions.

**Anonymised reuse**: once data collected through a pixel is effectively anonymised, reusing it requires no consent (the anonymisation processing itself remains subject to the GDPR).

**Practical consequence for ESPs**: blanket open tracking of each recipient for engagement dashboards, send-time optimization or automation triggers requires consent for French recipients. Open tracking whose only retained output is a single last-open date, used to run [sunset and inactivity policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies), can be exempt on transactional and consented mail. The **consent regime for pixels is independent of the consent regime for the email itself**: pixel consent may be needed in emails that need no consent themselves (order confirmations, marketing of similar products, charity marketing, B2B professional prospecting).

## Collecting pixel consent

- **Present purposes one by one**: each purpose should have a short title and a brief description. The CNIL supplies model wordings. For deliverability: "[Sender] and [third parties] use trackers (tracking pixels) to find out if and when you open the emails in order to compile diffusion statistics and take the necessary actions (adaptation of the frequency or stop mailings) to manage the mailing lists". For campaign performance: "…whether you open the emails, the time at which you do so, and information about the device you use to personalise content, adjust the sending frequency or the channel used". Cross-context profiling and fraud detection have similar templates. Detailed descriptions should be reachable from the consent interface, through an expand button or a hyperlink at the first level.
- Good practice: disclose even the pixels that are exempt from consent in the privacy policy.
- **Clear scope**: the recipient must be able to identify **which email address** the pixels will affect, and understand that the trackers will operate on **all the terminals** where they read that mailbox.
- **Preferred moment**: collect pixel consent **when the email address itself is collected**, by adding the summary of purposes (with a link to the trackers policy) to the signup form.
- **Collecting consent afterwards**: where consent was not collected with the address (or the address came from a third party without proof of pixel consent, or was collected orally), send an **email without pixels** that contains a link to a consent interface. The link must lead to a page that requires a **positive action** (a button click), so that the automatic pre-loading of links by some email clients cannot register a phantom consent. This is the same defence as for [one-click unsubscribe](https://emailmarketing.net/learn/list-management/list-unsubscribe) endpoints. Use a **tracking link unique to each recipient**, so that only the holder of the address can express the choice. Such links serve user security and authentication, and are themselves exempt from consent under Article 82.
- **Inactivity counts as refusal.** Not responding to a request for consent must be treated as a refusal, and the request must not pressure recipients or get in the way of reading. Offer an explicit "refuse" option that is as easy as "accept", record the choice, and do not ask again for a period: **6 months without asking again is cited as good practice**. (This 6-month figure is a gap before asking again that applies specifically to pixel consent, not a general rule on how fresh consent must be. To compare it with the freshness figures of other jurisdictions, see [Consent Record-Keeping](https://emailmarketing.net/learn/compliance/consent-record-keeping#manage-keep-consent-under-review).)
- **Granularity**: consent should be requested separately for each purpose. An interface with two levels (a global accept at the first level, and choices for each purpose at the second) is acceptable. A **single consent** may cover both electronic direct marketing (Art. L.34-5) and pixels that serve **related** purposes: for example, marketing expressly presented as personalised together with the pixels that personalise it, or contest emails together with anti-fraud pixels. Unrelated purposes need separate consent, and **display advertising and email prospecting are always separate purposes**.
- **Caution with consent management platforms (CMPs)**: collecting pixel consent through a CMP on a website or in an app is possible but needs care. The person must understand that the choice concerns a different environment (their email), and which address is affected.

## Withdrawal

- Offer withdrawal through a **tracked link in the footer of every email**. Withdrawing must be as easy as consenting.
- If the link opens a web page, withdrawal must complete **without any further action**, in particular without typing the email address again.
- Withdrawal must be **effective**: future emails must not trigger the operations, and for emails already sent, the sender may need to take measures so that pixels embedded earlier are no longer exploited when a message is opened again.

## Proof of consent

- The controller must be able to demonstrate consent at any time (GDPR Art. 7(1)) through **individual records** of each person's consent and of the conditions under which it was obtained.
- Where a third party collected the address and the consent, a **contract clause that obliges the partner to obtain valid consent is not sufficient proof**. The contract may instead govern the mechanisms for collecting consent, the availability of the evidence to the party relying on it, the conditions for keeping evidence so that it keeps its value as proof, and **regular audits of the mechanisms that collect consent**. Contractual commitments do not protect the controller from liability if the evidence cannot be produced.

## Transition for existing lists

For addresses collected before publication, tracking may continue **only if clear, accessible information is sent to recipients within at most 3 months of the publication of the recommendation**, so that anyone whose consent was not validly obtained can object to the operations for future emails. Where new consent is needed anyway (for example, to transmit data to new controllers for prospecting), valid pixel consent must be obtained for the operations that are not exempt.

## Deliverability relevance

France is the first jurisdiction to regulate the mechanics of open tracking in detail, and it reaches the position that deliverability practitioners had already reached for technical reasons. Open data is unreliable (Apple Mail Privacy Protection pre-fetches pixels, and Gmail proxies images), and its legitimate operational use is **list hygiene**, which is exactly the purpose the CNIL exempts. ESPs should treat open analytics for individual French recipients as a feature that requires consent, keep a minimal last-open date for [sunset policies](https://emailmarketing.net/learn/operations/list-hygiene-and-sunset-policies), and prefer click and conversion signals to measure engagement. For the UK position, see [PECR](https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing): pixels fall under its rules on storage and access too, but there is no equivalent operational recommendation there (yet).
