FEDMA_LogoFinal-01FEDMA_LogoFinal-01FEDMA_LogoFinal-01FEDMA_LogoFinal-01
  • Home
  • About us
    • Our Principles
    • National Association Members
    • Corporate Members
    • Governance & team
  • Latest News
  • Policy Area
    • Position Papers
    • Consumer Protection
    • Data Transfers
    • Digital Economy
    • Privacy & Data Protection
  • FASt
  • Projects
    • Unlocking Privacy Enhancing Technologies in marketing and advertising
    • Ethical AI-Powered Marketing Charter
    • AI Policy
    • Educational Hub
    • Sustainability Best Practices Guide
    • Legal Fact pack
  • Contact
Subscribe
✕

From email pixels to layered consent: Where does it end?

2 September 2026

Email marketing remains one of the most trusted, accountable and consumer-friendly forms of (marketing) communication. Unlike many other digital channels, email is built on a direct relationship between an organisation and an individual. Consumers choose to subscribe, can easily unsubscribe, and receive communications in an environment they control. For instance, 70% of French consumers expect online advertising to correspond to their personal interests, whereas 85 % of European consumers understand and accept the value exchange that data collection helps drive personalisation. For decades, this balance between organisations and consumers has worked remarkably well.

However, that balance risks being undermined by an increasingly fragmented interpretation and enforcement of privacy rules by European Data Protection Authorities (DPAs), for instance regarding email open tracking pixel. This harmless technology is key to understanding if and when an email has been opened, reflecting an individual’s interest, enabling organisations to assess the effectiveness of their communications and improve future advertising. In France,the CNIL published in April 2026 a recommendation on the use of email tracking pixel. The Italian Garante published a similar decision while giving organisations more flexibility, while the ICO in the UK does not see pixel tracking as requiring a separate regime. And there is no telling what any of the other 25 European DPAs may do. 

At the heart of the debate lies a simple question: when an individual consents to receive an email, what exactly are they consenting to? The key is not whether email measurement should be subject to privacy safeguards, but whether all forms of measurement should require a separate layer of consent. 

The answer has traditionally been straightforward. Consent to receive an email encompasses the normal and expected functionalities required to send, deliver, measure and improve that communication. An email is not simply the content that appears on a screen. It is a communication tool that includes technical mechanisms enabling senders to understand whether messages are being delivered, opened, engaged with, or ignored. These insights help organisations improve relevance, reduce unnecessary communications, prevent over-messaging and ensure that recipients receive content that is genuinely useful. Simply put, consumers receive less but more relevant communication.

The CNIL and Garante’s interpretations do not only categorise email open tracking as a distinct processing activity. More significantly, their interpretations assume that such processing activity requires a separate (and additional) layer of consent, based on their interpretations of Article 5(3) ePrivacy. This departs from the GDPR’s risk-based approach, under which profiling and analytics are not subject to a mandatory consent but can rely on other legal bases. As with any European legislation, the aim should always be to have only one, pan-European institution being the voice on privacy regulation matters. Data Protection Authorities (DPAs) should only apply those rules, not add their own of which they are then the enforcers. 

It also introduces a new source of legal uncertainty across Europe. As we have experienced more often than not, a position adopted by one DPA does not automatically bind other national authorities, many of which may reach different conclusions when interpreting the same legal framework. The result is the fragmented enforcement of a communication channel that is inherently cross-border. Email does not stop at national frontiers, yet organisations could find themselves facing different and potentially conflicting compliance expectations depending on where a sender is located. The recent recommendations on tracking pixels primarily apply to the sending client, so a German Email Service Provider (ESP), which isn’t technically under the scope of the CNIL, having a French client could likely be liable. And while ESPs are affected as technical enablers that must support compliance, the core regulatory duty falls on the sender. Such fragmentation undermines legal certainty, increases compliance costs, and makes it harder for businesses, charities and civil society organisations to communicate consistently with audiences across the EU. Unsurprisingly, public authorities are exempted from collecting pixel consent.

How many layers of consent are too many?

Furthermore, it opens the door to endless layers of consents within the same marketing channel. Consumers do not benefit from a world where every element of a communication requires its own consent box. Such an approach does not increase transparency or control. Instead, it creates fatigue, confusion and an ever-growing number of interruptions that ultimately weaken meaningful choice. Europe has spent years reflecting on the lessons of the GDPR and ePrivacy era. One lesson stands out clearly: more consent requests do not automatically result in better privacy outcomes for data subjects; instead they contribute to consent fatigue and reduce the ability of data subjects to make an informed and meaningful choice.

Email marketing is already operating in a technically challenging environment. Inbox providers increasingly limit tracking capabilities, as changes introduced by major platforms (such as Apple Mail Privacy Protection in 2021 or Yahoo’s & Google’s joint email authentication and deliverability requirements introduced in 2024) have reduced the reliability of open rates. Deliverability requirements and KPIs such as open rates, click rates, unsubscribe rates, are inevitably evolving, as can be observed in GDMA’s International Email Benchmark, which provides a global independent baseline measurement for email marketers.

Against this backdrop, imposing additional consent requirements on email performance measurement risks making a trusted channel less effective for everyone. And "everyone" truly means everyone:

  • Email is not simply a tool used by companies to promote products and services. 
  • Charities depend on email to engage donors and support important causes. 
  • NGOs use it to mobilise communities and advocate for social change. 
  • Consumer organisations rely on email to inform citizens of their rights. 
  • Governments and public authorities communicate public health information, safety alerts and essential public services through email. 
  • Universities, hospitals, cultural institutions, sports clubs, trade associations, political parties and elected representatives all use email to reach people who have chosen to hear from them. 

Restricting the ability to measure the effectiveness of email communications therefore extends far beyond commercial marketing. This is even more concerning for small and medium-sized businesses, charities, publishers and membership organisations. These organisations often rely on email as their most affordable and effective communication channel. Unlike large digital platforms, they do not possess vast advertising ecosystems or extensive datasets. Email allows them to maintain relationships with customers, members, donors and supporters in a transparent and cost-effective way.

Prospecting, customer acquisition and business growth may also suffer. Organisations need to understand whether communications are reaching audiences, whether campaigns are effective, and whether recipients find their content relevant. Removing the ability to measure basic engagement without introducing practical alternatives risks reducing the efficiency of customer acquisition efforts and making it harder for businesses to reach new audiences.

Respecting privacy while maintaining proportionality

Consumers justifiably (and legally) deserve transparency about how their information is used. Organisations should clearly explain their practices and offer straightforward ways to manage preferences. Data collection should be proportionate, limited and accountable. High-risk activities should continue to be subject to robust safeguards. But proportionality matters.

Europe needs privacy rules that are understandable, workable and future-proof. Creating new layers of consent for every technical component of an email risks moving in the opposite direction. Europe needs to draw a line that is clear and proportionate for both individuals and organisations. Protecting email marketing also means protecting European tech sovereignty, as many players are Europe-born and -based organisations, whether the email service provider, the sender or both.

Email marketing has earned its place as one of the most trusted channels in the modern economy. Regulators and Data Protection Authorities should not undermine that success through unilateral, inconsistent interpretations that create complexity without delivering meaningful benefits to individuals.

If Europe wishes to promote innovation, competitiveness and consumer trust simultaneously, the answer is not an endless series of permissions. FEDMA’s position on repealing the ePrivacy Directive as part of the ongoing Digital Omnibus would provide a workable-risk-based approach under the sole umbrella of the GDPR. The answer is smart regulation that protects individuals while allowing organisations to communicate effectively with the people who want to hear from them.

Share

RECENT NEWS

  • From email pixels to layered consent: Where does it end?2 September 2026
  • Europe regulates telemarketing in different ways. What can be learnt?5 August 2026
  • EU AI Labeling rules: Transparency Is not the same as Trust3 August 2026
  • FEDMA wins Benelux Enterprise Awards for “Best Data Marketing Advocacy Body 2026”30 June 2026

© Fedma 2026

Made with ❤️ by MFM Digital

Contact us

rue de la Loi, 155
BE-1040 Brussels, Belgium

+32 2 779 4268

info@fedma.org

Follow us


EU Transparency registry number: 39300567160-02

Support

Privacy Policy

Terms and Conditions

Intranet

Subscribe
Subscribe Become a member Intranet

Follow us

Support

Terms and conditionsPrivacy PolicyIntranet –

Become a member now

To discuss FEDMA Membership, please contact rdewouters@fedma.org or book an introductory call via Microsoft Bookings.

SEND EMAIL INTRODUCTORY CALL

Never see this message again.

DO NOT MISS OUR NEWS

Subscribe to our Newsletter