From email pixels to layered consent: Where does it end?
Email marketing remains one of the most trusted, established and consumer-friendly forms of (marketing) communication. Unlike many other digital channels, email is built on a direct relationship between an organisation and an individual. Consumers choose to subscribe, can easily unsubscribe, and receive communications in an environment they control. For instance, 70% of French consumers expect online advertising to correspond to their personal interests, while 85 % of European consumers understand and accept the value exchange, through which data helps businesses provide more relevant and personalised experiences. For decades, this balance between organisations and consumers has worked remarkably well.
However, that balance risks being undermined by an increasingly fragmented interpretation and enforcement of privacy rules by European Data Protection Authorities (DPAs), for instance regarding email open tracking pixel. Email pixels are a long-established and lightweight technical mechanism used to understand whether communications are reaching and engaging audiences, assess campaign performance, maintain effective databases and improve future communications. Basic first-party email measurement should not be equated with persistent behavioural surveillance merely because the same technical mechanism can also be used for more extensive forms of tracking. In 2026, both the French CNIL and the Italian Garante published national interpretations addressing email tracking pixels, reaching materially different conclusions on a number of operational questions and exemptions. This followed the EDPB’s Guidelines 2/2023, which address the technical scope of Article 5(3) ePrivacy but expressly leave the application of the consent exemptions to case-by-case assessment. The ICO provides a useful comparator, showing that a different regulatory treatment is possible. With only two EU Member States having developed detailed national positions so far, businesses are left to anticipate how the remaining national authorities may interpret the same European framework.
These recommendations matter because they signal enforcement policy, but they should not be confused with legislation or case law. DPAs cannot amend Article 5(3) ePrivacy through guidance, and the EDPB Guidelines themselves do not determine when consent exemptions apply. Those questions remain questions of law, to be interpreted from the Directive, national implementing legislation and, ultimately, authoritative judicial interpretation.
At the heart of the debate lies a simple question: when an individual consents to receive an email, what exactly are they consenting to? The issue is not whether email measurement should be accountable and transparent. It is whether basic first-party measurement should be made dependent on an additional consent requirement regardless of its purpose, scope, duration and actual impact on individuals.
The answer has traditionally been straightforward. Consent to receive an email encompasses the normal and expected functionalities required to send, deliver, measure and improve that communication. An email is not simply the content that appears on a screen. It is a communication tool that includes technical mechanisms enabling senders to understand whether messages are being delivered, opened, engaged with, or ignored. These insights help organisations improve relevance, reduce unnecessary communications, prevent over-messaging and ensure that recipients receive content that is genuinely useful. Simply put, consumers receive less but more relevant communication.
The CNIL and Garante’s interpretations do not only categorise email open tracking as a distinct processing activity. More significantly, their interpretations assume that such processing activity requires a separate (and additional) layer of consent, based on their interpretations of Article 5(3) ePrivacy. This departs from the GDPR’s risk-based approach, under which profiling and analytics are not subject to a mandatory consent but can rely on other legal bases. As with any European legislation, the aim should always be to have only one, pan-European institution being the voice on privacy regulation matters. Data Protection Authorities (DPAs) should only apply those rules, not add their own of which they are then the enforcers.
It also introduces a new source of legal uncertainty, raising a fundamental Single Market problem. The ePrivacy Directive was adopted both to ensure an equivalent level of protection and to support the free movement of electronic communications services and data across Europe. As we have experienced more often than not, a position adopted by one DPA does not automatically bind other national authorities, many of which may reach different conclusions when interpreting the same legal framework. The result is the fragmented enforcement of a communication channel that is inherently cross-border. Email does not stop at national frontiers, yet organisations could find themselves facing different and potentially conflicting compliance expectations depending on where a sender is located. The recent recommendations on tracking pixels primarily apply to the sending client, so a German Email Service Provider (ESP), which isn’t technically under the scope of the CNIL, having a French client could likely be liable. And while ESPs are affected as technical enablers that must support compliance, the core regulatory duty falls on the sender. Such fragmentation undermines legal certainty, increases compliance costs, and makes it harder for businesses, charities and civil society organisations to communicate consistently with audiences across the EU.
Unsurprisingly, public authorities are exempted from collecting pixel consent in both national approaches, which recognises that certain institutional, transactional, security or service communications may justify different treatment. This confirms the underlying principle that the legal consequence cannot sensibly depend on the pixel alone. Function and necessity matter. Private-sector communications deserve the same functional assessment rather than a presumption that measurement becomes objectionable merely because the communication has a commercial purpose.
How many layers of consent are too many?
Furthermore, it risks opening the door to additional layers of consents within the same marketing channel. Consumers do not benefit from a situation where every element of a communication requires its own consent box. Such an approach may not result in increased transparency or more meaningful control. Instead, it risks creating fatigue, confusion and an increasing number of interruptions that ultimately weaken meaningful choice. Europe has spent years reflecting on the lessons of the GDPR and ePrivacy era. One lesson stands out clearly: more consent requests do not automatically result in better privacy outcomes for data subjects; on the contrary, excessive fragmentation of consent may contribute to consent fatigue and reduce the ability of data subjects to make an informed and meaningful choice.
This concern is no longer an industry argument alone. The European Commission’s Digital Omnibus proposal expressly identifies the interaction between ePrivacy and the GDPR as a source of legal uncertainty and higher compliance costs and proposes to simplify the framework, expand consent exemptions for low-risk or necessary uses and address consent fatigue. At the very moment when the EU legislature is reconsidering the existing balance, national supervisory authorities should be particularly cautious about creating additional consent architectures through interpretation.
Email marketing is already operating in a technically challenging environment. Measures introduced by major inbox providers, including Apple Mail Privacy Protection in 2021 or Yahoo’s & Google’s joint email authentication and deliverability requirements in 2024, have changed the interpretation and reliability of traditional KPIs. That does not make measurement irrelevant. It makes access to a range of reliable performance indicators more important, including open rates where technically meaningful, click-through rates, click-to-open rates, conversions, unsubscribe rates and deliverability metrics. A market cannot optimise a communication channel if regulation progressively removes the ability to understand whether that channel works.. Deliverability requirements and KPIs such as open rates, click rates, unsubscribe rates, are inevitably evolving, as can be observed in GDMA’s International Email Benchmark, which provides a global independent baseline measurement for email marketers.
Against this backdrop, imposing additional consent requirements on email performance measurement risks making a trusted and direct channel less effective for everyone. And "everyone" truly means everyone:
- Email is not simply a tool used by companies to promote products and services.
- Charities depend on email to engage donors and support important causes.
- NGOs use it to mobilise communities and advocate for social change.
- Consumer organisations rely on email to inform citizens of their rights.
- Governments and public authorities communicate public health information, safety alerts and essential public services through email.
- Universities, hospitals, cultural institutions, sports clubs, trade associations, political parties and elected representatives all use email to reach people who have chosen to hear from them.
Restricting the ability to measure the effectiveness of email communications therefore extends far beyond commercial marketing and falls particularly heavily on SMEs, charities, publishers, membership organisations and specialist European ESPs. Compliance costs are not competitively neutral. A global platform can absorb the cost of multiple national consent architectures, legal teams and preference-management systems across the EU. A small European business cannot do so at equivalent cost. Email gives these organisations an affordable means of maintaining direct relationships with customers, members, donors and supporters without depending on vast cross-service datasets or closed advertising ecosystems.
Prospecting, customer acquisition and business growth also depend on measurement. Organisations need to understand whether communications are reaching audiences, whether campaigns are effective, and whether recipients find their content relevant. Removing the ability to measure basic engagement without introducing practical alternatives risks reducing the efficiency of customer acquisition efforts and making it harder for businesses to reach new audiences.
Protecting privacy without sacrificing proportionality
Consumers justifiably (and legally) deserve transparency about how their information is used. Organisations should clearly explain their practices and offer straightforward ways to manage preferences. Data collection should be proportionate, limited and accountable. But the European legal order also protects the freedom to conduct a business, competition and the functioning of the Internal Market. Proportionality matters.
The appropriate line is therefore not ‘pixel versus no pixel’. It is basic measurement versus materially intrusive behavioural use. Aggregated audience measurement, short-lived first-party analytics, deliverability, database hygiene and security are fundamentally different from persistent profiling, cross-context combination of behavioural data or disclosure to unrelated third parties. A proportionate framework should recognise those differences.
Europe needs privacy rules that are understandable, workable, technologically neutral and capable of operating at scale across the Single Market. Creating additional consent requirements around successive technical components of the same communication risks moving in the opposite direction. Specificity of consent should not be confused with the artificial fragmentation of economically and functionally connected operations. Indeed, the Garante itself recognises that closely related promotional communication and tracking may, in principle, be covered by a single informed consent, expressly acknowledging the problem of consent fatigue. Creating new layers of consent for every technical component of an email risks moving in the opposite direction. Europe needs to draw a line that is clear and proportionate for both individuals and organisations. Protecting email marketing also means protecting European tech sovereignty, as many players are Europe-born and -based organisations, whether the email service provider, the sender or both.
Email marketing has earned its place as one of the most trusted channels in the modern economy. Regulators and Data Protection Authorities should respect the distinction between interpreting and enforcing the law and effectively creating new general obligations through guidance. Supervisory interpretations are important, but they are not legislation and should not become a substitute for choices that belong to the European legislature. Where national interpretations materially increase compliance burdens across a cross-border market, the case for intervention should be supported by evidence of necessity, proportionality and meaningful benefit to individuals.
At a minimum, Europe needs a single and coherent approach to email measurement. The EDPB Guidelines deliberately stop at technical scope and do not determine the application of Article 5(3) exemptions. That open question should not now be filled by 27 different national rulebooks. Any further policy choice of general application should be addressed at European level, transparently and with full consideration of its effects on consumers, competition, innovation and the Single Market.
If Europe wishes to promote innovation, competitiveness and consumer trust simultaneously, the answer cannot be an endless series of permission layers. FEDMA’s position on repealing the ePrivacy Directive as part of the ongoing Digital Omnibus would provide a workable-risk-based approach under the sole umbrella of the GDPR.
The answer is smart regulation that protects individuals while allowing organisations to communicate effectively with the people who want to hear from them.

