Cnil

The Loophole CNIL Left Open

The guidance this blog covered earlier in July treats an email tracking pixel like a cookie and requires consent for it in most cases. It also carves out an exemption for one specific use: measuring whether an email was opened, for the narrow purpose of keeping a mailing list’s deliverability healthy. That exemption is real, and read in full it is narrower than most summaries of it suggest. It is also written loosely enough, in one specific place, that a sender inclined to stretch it has room to do so. This post is about that one place, and about how it should eventually be closed.

Continue reading

France and Italy Just Turned Email Tracking Pixels Into a Consent Problem

In the spring of 2026, two of Europe’s most active data protection regulators reached the same conclusion within weeks of each other, without coordinating on it: an invisible pixel that reports when you opened an email is not meaningfully different from a cookie, and it needs the same consent.

The pixel did not change. The law around it did.

Consent risk you didn’t sign up for is still risk. EMail Parrot removes it at the source instead of asking you to manage it.

Continue reading