Gdpr

Italy's Pixel Deadline Is Real. The EU Law Already Was.

Italy’s tracking-pixel deadline lands October 29, 2026, a little under eight weeks from this post. That date gets treated, understandably, as the news. The more useful fact sits underneath it: the consent requirement it enforces was never missing from the rest of Europe or the UK. It was already the law almost everywhere. France and Italy are just the first two regulators to write down exactly what compliance looks like, with a date attached.

Continue reading

The Loophole CNIL Left Open

The guidance this blog covered earlier in July treats an email tracking pixel like a cookie and requires consent for it in most cases. It also carves out an exemption for one specific use: measuring whether an email was opened, for the narrow purpose of keeping a mailing list’s deliverability healthy. That exemption is real, and read in full it is narrower than most summaries of it suggest. It is also written loosely enough, in one specific place, that a sender inclined to stretch it has room to do so. This post is about that one place, and about how it should eventually be closed.

Continue reading

France and Italy Just Turned Email Tracking Pixels Into a Consent Problem

In the spring of 2026, two of Europe’s most active data protection regulators reached the same conclusion within weeks of each other, without coordinating on it: an invisible pixel that reports when you opened an email is not meaningfully different from a cookie, and it needs the same consent.

The pixel did not change. The law around it did.

Consent risk you didn’t sign up for is still risk. EMail Parrot removes it at the source instead of asking you to manage it.

Continue reading