Email tracking is under the CNIL's radar. In June 2025, the National Commission for Information Technology and Freedoms published a draft recommendation on the request for consent for tracking pixels (and in particular for email open pixels), the final version of which was published on April 14, 2026.
This request for consent, which is currently ignored by most shippers, could revolutionize the way they do business. emailing practices. The CNIL's approach is logical: under the RGPD, tracking data is considered personal data requiring explicit consent. Let's take a look.
The final version of the recommendation, which was published on April 14, 2026, can be viewed here: https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels
Since then, the CNIL has completed the mechanism: a second webinar (this time intended for solution providers) and a 27-question FAQ published on July 22, 2026, which lift several ambiguities, notably regarding anonymization and tracking links. This article has been updated to incorporate these clarifications.
Live! CNIL and tracking pixels: our field feedback
Tuesday, June 23rd at 11 AM, online, on YouTube
After several experiences in the field (in insurance, the press, B2B...), we have accumulated learnings that we want to share.
What types of consent are brands moving towards? What are good questions to ask depending on your industry, structure, and collection methods? How to balance marketing, legal, and operational risks? A practical livestream, with no beating around the bush.
The link to the live site is : https://www.youtube.com/watch?v=fDT-VDGW8C8
Replay of our Youtube live stream from Thursday, May 7, 2026
We have dissected, read, and reread the 11 pages of the CNIL recommendation. In detail. Without skipping anything.
In this live stream, we are clarifying in black and white what is still allowed without consent and what is no longer allowed. What this changes for your deliverability and the management of your inactive contacts. We are also giving you a concrete action plan to be compliant before the deadline.
The link to the live site is : https://www.youtube.com/watch?v=Q8xWSwyojvE
Table of contents
- Live! CNIL and tracking pixels: our field feedback
- Replay of our Youtube live stream from Thursday, May 7, 2026
- The CNIL is concerned about email tracking pixels
- Important points to remember
- No need for tracking pixel consent in a deliverability context
- What impact does B2B have?
- Complying: 11-Step Action Plan
- FAQ: Frequently Asked Questions About Email Tracking Consent
- Conclusion – Is this really the end of the world?
The CNIL is concerned about email tracking pixels
As stated in its preamble, the CNIL initiated this clarification initiative following reports and complaints from individuals who felt they were being spied on via emails. Through this document, the CNIL wishes to clarify the provisions of the GDPR that have been misinterpreted by organizations since 2018.
In reality, in recent years, CNIL lawyers have informed several audited brands that their open and click tracking measures were not legal without prior consent. Surprised, email marketers asked the CNIL for clarification on their lawyers' positions. And this recommendation followed.
Important points to remember
- In its recommendation, CNIL primarily targets the email open pixel. And more specifically, the ability to track opens by name.
- Click tracking falls under the same legal framework: it is no longer a hypothesis, The CNIL explicitly confirmed this during its second webinar. We might as well become compliant right now by applying the same principles to opens and clicks. Even though the CNIL probably won't audit this issue before publishing an official recommendation.
- For addresses already in your database, You have 3 months as of the publication of the recommendation to inform your recipients about the use of the pixel and allow them to object to it, no later than July 14, 2026 (if you are late, you will have to justify yourself with technical constraints. For addresses collected after April 14, 2026, on the other hand, there is no transition period: they fall directly under the consent regime.
This article is freely available.
It took time and expertise!
This month, thanks to our customer-sponsors: Actito, BPI France, Cardif, Citeo, Clarins, CMI France, Editis, Engie, France Télévisions, Le Parisien, Les Echos, Les Furets, Pierre Fabre, UMR, Voyageurs du monde... Thanks to the missions they entrust to us, we can write and share free content. They support our educational work to promote more responsible email. Become a customer and benefit from our expertise while supporting the production of open knowledge.
What you can always do without consent ✅
- Statistics : measure the overall open rates of your campaigns. The July 22 FAQ confirms this (question 6): reuse data from an exempted pixel (or consented) establishing overall statistics per campaign does not require consent, provided that the anonymization is effective (through aggregation). Please note: being «anonymized by your sending platform» is not sufficient if the data can still, in reality, be traced back to an individual. See our dedicated article on’anonymization of email open tracking without consent.
- Deliverability : measure open rates aggregated by destination domain (on domains of sufficient size to not allow individual identification. Important nuance: the FAQ explicitly validates the campaign level, but remains silent at the destination domain level. This is a grey area to be secured by truly effective anonymization, we detail this precise case in our article dedicated to the anonymization of openings.
- Inactive push inactive emails out of your mailings or adapt the sending frequency based on your contacts' last open date.
- Security / Authentication : tracking to verify that an authentication email (2FA code, password reset link, etc.) is indeed opened on the recipient's terminal.
- Legal duty to inform tracking to prove the proper transmission of legally required information (pre-contractual information, mandatory disclosures, rate changes, etc.).
- Transactional e-mails insertion of pixels into emails directly related to a service requested by the recipient (welcome, account alert, order confirmation, shipping, appointment reminder, etc.), provided that the pixel itself serves an exempted purpose (deliverability, security, legal obligation).
- A/B Tests conducting A/B tests based on the open rate remains feasible as long as one reasons in terms of the aggregate performance of an audience (non-nominative), in line with the logic of question 6 of the FAQ. Point of caution: the recommendation places «measuring and optimizing campaign performance» on the consent side; therefore, an A/B test can only be defended without consent if it is limited to effectively aggregated and anonymized rates. To be verified with your mailing platform.
This will require explicit consent ❌
- Tracking individually identify who opens your emails.
- Targeting target your contacts based on their open behaviors (for example, non-openers of a previous campaign).
- Profiling determine your contacts' interests based on their open behavior.
- Targeting adapt your sending frequency based on individual behaviors (based on something other than the last open or click date).
- Customization personalize your content based on each contact's open interactions.
And click tracking?
The CNIL recommendation literally concerns open-tracking pixels. But clicks fall under the same legal framework, and this is no longer a mere deduction. In the recommendation (page 8), The CNIL is already reminding that tracking links are subject to Article 82 of the French Data Protection Act (Loi Informatique et Libertés) and refers to the EDPB Guidelines 2/2023 which cover them. Above all, during its second webinar (aimed at solution providers), Benjamin Poilvé (CNIL) was explicit: tracking links are subject to similar obligations, and work is currently underway on the subject.
Our operational reading As there is no specific recommendation on click tracking to date, the CNIL will not carry out checks on it immediately, but it will come. You might as well take advantage of the ongoing project to deal with both subjects at the same time: setting up consent for click tracking will save you from having to redo the work in 12 to 18 months, when the CNIL (or an inspection) comes to formally clarify the matter.
No need for tracking pixel consent in a deliverability context
To maintain a good reputation, it must be possible to exclude inactive contacts from mailings. And the common definition of an inactive contact until now is: «Any contact that has not opened and/or clicked at least one email in the last X months.».
Good news The recommendation explicitly recognizes these uses as exempt from consent. This was one of the most anticipated points by market players. However, be careful, this exemption is only valid for emails explicitly requested by the recipient (so no B2B opt-out prospecting or legitimate interest).
Three uses are exempted (page 5 of the recommendation):
- Identify inactive users to remove them from the database.
- Adjust the sending frequency to inactive users (e.g., moving from several sends per week to one per month).
- Switch to an alternate channel when email no longer functions (SMS, push...).
Beware of a use that might seem legitimate to you: launch a marketing reactivation campaign (super promo, strong editorial content). This is no longer «strictly necessary.» The logic of the exemption is to disengage, not to re-engage better. A commercial reactivations campaign requires consent.
The technical counterpart: minimizing data.
The CNIL mandates that only the date of last opening, without time, overwritten with each new opening. Storing a complete history is no longer compatible with the exemption.
What impact does B2B have?
The recommendation applies to both B2C and B2B! And the CNIL takes care to specify it explicitly (page 10):
«The consent regime for tracking pixels is independent of the one applicable to sending the email in question: consent for tracking pixels may therefore be necessary for emails that do not, in principle, require the recipients» consent (...) prospecting business professionals in a field related to the work of the person being solicited (...)»
In short, inserting a tracking pixel in B2B emails requires specific opt-in.
Some good news, after all Consent exemptions (deliverability, security, legal obligation) also apply in B2B. You can therefore continue to manage your B2B inactives without consent, under the same conditions as in B2C (i.e., with consent to receive emails).
Complying: 11-Step Action Plan
Before diving in! We've chosen a maximalist and exhaustive approach for this action plan (it's long 😉): you'll find both what's strictly necessary to be compliant and what we consider best practices. Not all brands will go all the way with every priority, and that's normal. It's up to your teams to decide where to draw the line based on your context, resources, and strategy. This article is here to inform your decisions, not to impose them.
Priority 1 – Diagnose: Audit Your Current Practices
Before any update, take the time to take an honest photograph of the current situation. This requires collaboration between CRM, IT, legal, and deliverability teams. It's also an opportunity to bring everyone back to the table on a topic that concerns all these professions at once.
Examples of questions to ask me:
- Where are your email addresses currently collected? With which mentions or checkboxes? The goal is to be exhaustive so as not to miss any element (there's more to life than just digital, think about your partners).
- What are the uses of data from tracking Openings (and clicks) in your CRM strategy
- Which consent collection wording would allow you to group this collection? The CNIL authorizes a single consent for commercial prospection and tracking pursuing a purpose directly related to that prospection (see priority 5).
- What types of emails do you send?, do they all fall under the same legal regime and/or do they benefit from exemptions?
- What tools will you need to leverage these consents? (where they are stored)? It's likely that they aren't *only* in your main email sending tool.
If this has not already been done, organize a workshop as soon as possible with the relevant teams. And if you need outside help to facilitate this workshop, do not hesitate to contact Badsender.
Following this diagnosis, you will know which projects to prioritize, which can be simplified, and which require bringing in external providers. Without this initial snapshot, the following steps will be taken blindly.
Priority 2 – Diagnose: Assess Your Shipping Platform's Capabilities
In the concrete actions that will follow, you will be autonomous on one part, but clearly dependent on your email sending platform on others. We recommend that you contact them or read the publications and documentation they have on the subject.
A few essential questions:
- Granular consent Can you handle multiple consent fields (opens, clicks, cross-channel profiling) according to your strategy?
- Minimized storage Are the opening dates retained by day without time, overwritten with each opening (CNIL requirement for deliverability exemption)?
- Pixels differentiated by consent Does the platform generate a different pixel based on the recipient's status? A full pixel for consenting users, and a restricted pixel (last opened date, domain, campaign ID, aggregated A/B version) for others?
- Deletion of history in case of objection When a recipient withdraws their consent, is the behavioral data history concerning them effectively deleted?
- Separation of transactional and marketing flows Is the distinction manageable at the template and workflow level, or only on a case-by-case basis?
- Individualized proof of consent date, context, version of the information...
Badsender has prepared a comparison of implementations of open tracking recommendations in email sending solutions. Feel free to consult this document, which we update regularly.
Co-responsibility: Who is legally responsible for what?
Your router is a subcontractor by default: you remain responsible for the processing and must ensure the legality of the practices (recommendation, page 4). It becomes jointly responsible only if it uses pixels for its own purposes, which then requires a formalized agreement between you.
Beware of the trap: your platform's technical compliance is necessary, but it won't protect you if your collection forms or proof of consent are deficient. You'll remain exposed in case of an audit.
Priority 3 – Decide: Rethink your targeting and personalization strategies
The idea isn't necessarily to implement a complete overhaul. But, with your improved understanding of the legal framework, you'll need to streamline your practices to comply, and also to avoid unnecessary complications. It's important to strike a balance between:
- Continue collecting without scaring your potential contacts.
- Keep offering relevant content to your recipients.
Three questions to structure this reflection :
1. Do you really need to track openings individually? Many brands track individual opens out of habit, without actually using the data downstream. The advent of recommendations is an opportunity rather than a constraint: disable individual tracking, and you'll gain simplicity and compliance all at once. Caution: it's not enough not to exploit the data; your platform must also not store it (minimization principle).
2. How to redefine your inactive contacts?
The last-opened date is now the only usable signal to identify inactives, if they have not given their consent. If your current definition is based on other indicators, you will need to check whether they comply. Our Reference article on inactive contacts remains valid in its principles, but its operational implementation may vary.
3. Which first-party signals should be strengthened in parallel?
Openings will become a partially blind signal: reduced coverage due to consent, Apple Mail Privacy Protection, and anti-tracking filters. Reducing your reliance on this signal by strengthening other sources is a good sustainable practice: authenticated clicks on your site, purchases, customer service responses, declared preferences, and your own transactional events. These will better withstand future changes.
Priority 4 – Decide: Define your consent strategy
⚠️ Quick reminder: We are experts in email marketing and deliverability, not legal professionals. The following is our operational interpretation of the CNIL's recommendation, informed by our experience with our clients. It does not replace the advice of a DPO, a legal expert, or a lawyer specialized in your specific case. Seek guidance to validate your choices.
This is the legal translation of the choices you made in priority 3.
Three decisions to make:
1. What level of consent?
The CNIL authorizes a single consent for commercial prospecting and tracking pixels that serve a purpose directly related to that prospecting: content personalization, adaptation of sending frequency, fraud detection. Conversely, cross-channel profiling (using opens to then target on the web, mobile, or in display advertising) is not related to email prospecting and requires a separate consent box.
The more distinct use cases you have, the more checkboxes you'll have. Choose the tightest scope that serves your CRM strategy.
2. Which coverage: opens only, or clicks too?
The recommendation literally concerns opening pixels, but the same legal framework applies to tracking links, as the CNIL confirmed during its 2nd webinar. Covering them right now in your consent strategy will save you from having to redo the work in 12 to 18 months, when the CNIL or an inspection formally clarifies the subject.
3. What to do with the existing base?
Your contacts have already given a «simple» opt-in. For them, the recommendation provides for simple information within 3 months with the possibility of opting out (see priority 10). You can also take advantage of this communication to request explicit consent... but the conversion rate is likely to be very low. This needs to be decided in consultation with your DPO and legal team.
Priority 5 – Implement: Update your collection forms
⚠️ Quick reminder (the same as above): we are email marketing and deliverability experts, not lawyers. The following is our operational interpretation of the CNIL recommendation, informed by our experience with our clients. This does not replace the advice of a DPO, legal expert, or specialized lawyer for your specific situation. Make sure to get professional guidance to validate your choices.
You now know what consent to collect (priority 4). Now you just need to phrase it.
The consent must be free, specific, informed, and unambiguous. The simplest way is to add a checkbox (not pre-checked) to your forms, with clear wording about the purposes.
Two examples:
«I agree to [Brand] using tracking pixels to provide me with content tailored to my interests and reduce the number of irrelevant emails I receive.»
«I agree to receive commercial communications by email from [Brand Name], personalized based on my interactions with these emails (opens and clicks). I can withdraw my consent at any time via the link provided in each email.»
The word «personalized» (or an equivalent) is legally decisive: it is what makes it possible to couple opt-in and consent to pixels in a single box. Without this coupling, the CNIL requires finer granularity.
Go beyond formal compliance
A legally correct move is not necessarily an effective move. A job of Plain language writing and UX design is necessary. This is the point that will make the difference between brands that do the bare minimum and those that transform this obligation into a customer relationship lever.
Target all collection points
Web, paper, oral, partners, contests, physical events. The mapping carried out as priority 1 must lead to a systematic update here. A single missing mention can invalidate the proof of consent for all contacts collected on this channel.

Priority 6 – Implement: Distinguish transactional flows from marketing flows in your ESP
Transactional emails (order confirmations, account alerts, package shipments, appointment reminders, password resets, etc.) benefit from a specific regime: they can be sent without consent, and the pixels they contain can be exempted if they serve an exempted purpose (security, deliverability, legal obligation).
Still, your platform must clearly distinguish these flows from marketing flows. In practice, many ESPs apply the same tracking rules to all campaigns, which means losing the benefit of the transactional exemption.
Based on the priority 1 diagnosis, two concrete actions:
- Set up distinct tracking rules pixels and tracking links exempt on pure transactional flows, conditional pixels on marketing flows.
- Handle the case of hybrid emails a transactional email that also contains product recommendations, a welcome email with a promotion... These emails mix a transactional part (exempt) and a marketing part (which requires consent). Either you separate the two into distinct emails, or you apply the strictest regime to the whole.
A warning sign to watch out for: if your ESP cannot simply explain how it distinguishes these flows, then it probably doesn't. Investigate further during the meeting scheduled as a priority 2.
Priority 7 – Implement: Integrate a consent withdrawal link in your emails
Just like with opt-in, consent for open tracking must be able to be revoked at any time and in one click. Therefore, a consent withdrawal link must be included next to the unsubscribe link in your footers (and headers if you follow this practice).
Unsubscribe and withdrawal of consent: two different things
Many brands merge the two into an «all or nothing» mechanism, even though they are legally distinct. Our advice: offer both a one-click global withdrawal (to comply with the «as easy to withdraw as to consent» requirement) and granular withdrawals by purpose, for those who want finer control.
Retroactive neutralization
The recommendation requires that the pixels of the emails already sent will no longer be exploited if the recipient reopens them after withdrawing their consent. This is one of the points to explore as a priority 2, and likely one where you will be most dependent on product developments from your email sending platform.
Priority 8 – Implement: Update or create your Preference Center
The multiplication of consent choices (reception, opens, clicks, cross-channel profiling...) makes the preference center more relevant than ever. Well-designed, it can even replace the classic unsubscribe page: the recipient arrives on a single interface where they fine-tune their choices.
If you don't have one, now is a good time to create one. If you already have one, it probably needs to be reviewed to incorporate the new granular withdrawal choices defined in priority 7.
One requirement not to forget: withdrawal must be made without re-entering the email address (recommendation, page 10).
Priority 9 - Implement: Set up a consent proof system
Proof of consent for email tracking must be kept for the entire duration of that consent's validity. Concretely, you must be able to produce at any time, for each recipient individually: the date of consent, the collection context (web form, partner page, dedicated campaign, etc.), the exact version of the information displayed, and the scope of the accepted purposes.
An explicit warning from the CNIL
A contractual clause between you and your provider (ESP, collection partner, list lessor) is not sufficient to transfer proof of consent. The recommendation is very clear on this point (page 11):
«The obligation to prove consent cannot be fulfilled by the mere presence of a contractual clause obligating one party to obtain valid consent on behalf of the other.»
If your addresses are collected by a third party (partner, rental provider, co-organized event, etc.), you must technically receive proof of this, not just contractual assurance. This point directly conditions the validity of all emails sent to these contacts.
Concretely
This is one of the projects most dependent on your sending platform (see priority 2). Questions to explore: what evidence is kept natively? Is it exportable? How are subsequent consent changes managed? How do you connect evidence from multiple sources (web form, preference center, email opt-out, etc.)?
Priority 10 – Regularize and Formalize: Inform your existing recipients
Regarding consent for existing databases, the CNIL does not require collecting consent again. On the other hand, it asks to send a campaign to inform subscribers about the tracking of their opens (and, by extension, their clicks) and to offer them an easy way to opt out for future emails sent.
You have 3 months from the publication of the recommendation to proceed, which is until July 14, 2026, at the latest. (Please note: the CNIL allows limited tolerance if you document a deliverability constraint related to the volume of mailings or a late update to your email sending solution).
Essential prerequisite
This campaign can only be launched if the entire opt-out system is operational: updated forms and preference center (priorities 5 and 8), opt-out link in emails (priority 7), history nullification in case of objection, technical differentiation between pixels with and without consent (priorities 2 and 6), proof mechanism in place (priority 9). Without these foundations, the information campaign would be useless at best, and counterproductive at worst: a recipient who objects but whose choice is not correctly taken into account puts you in a worse situation than before the campaign.
Priority 11 – Regularize and Formalize: Update your privacy page
This is the least technical step, but it should not be forgotten. Your privacy policy (or «privacy» page) must reflect the new practices implemented in the previous priorities.
To add or update:
- Mentioning the use of tracking pixels and tracking links in your emails.
- The specific objectives pursued (personalization, deliverability, security, etc.), in line with the strategy defined in priority 4.
- The terms and conditions for withdrawing consent and the existence of a preference center, if applicable (priority 8).
- Potential third-party service providers involved in the processing (ESPs, pixel providers, partners).
This step has no direct operational impact, but it plays a legal role: it is on this page that recipients (and, in case of inspection, the CNIL) will look for detailed information. It's better for it to be consistent with what you are actually doing. Work with your legal counsel and/or your DPO.
Example of writing a privacy page: look at the last paragraph

FAQ: Frequently Asked Questions About Email Tracking Consent
How much time do brands have to comply?
0 days. Compliance is required now, and brands should have applied it since May 2018 (the date the GDPR became applicable). Nevertheless, for address databases already collected, the CNIL is granting a 3-month transition period (until July 14, 2026) to inform recipients about the use of pixels and allow them to object to them for future emails. For any new address collection, however, the rules apply immediately.
Does this recommendation concern the click-through rate?
Technically, the recommendation applies only to open-tracking pixels. But the tracking links used to measure clicks fall under the same legal framework. The CNIL explicitly recalls this in its recommendation (page 8) and confirmed it verbally during its second webinar. In practice, the click issue will follow: it is better to prepare for it now by integrating consent for clicks into the same project.
Is there a distinction between transactional emails, service emails, order confirmations... and marketing emails?
Yes. So-called «transactional» emails (order confirmations, shipping notifications, security alerts, 2FA codes, invoices, customer service responses, appointment reminders, Terms of Service updates, etc.) benefit from a specific regime: they are linked to a service expressly requested by the recipient, and the pixels they contain can therefore be exempted from consent. Provided that these pixels themselves have an exempted purpose (security, deliverability, legal obligation).
Watch out for the trap: a transactional email does not allow just any pixel. If the pixel serves a marketing purpose (personalization, performance measurement), consent is still required, even in a welcome or order confirmation email.
Is a welcome email considered a transactional email?
Yes, the CNIL explicitly cites welcome emails among the examples of transactional emails (recommendation, page 6). But be careful: everything depends on the actual content and the purpose of the pixel.
A strictly informative welcome email (registration confirmation, service overview, account access) is transactional. However, if the email leans heavily towards marketing content (promotions, product recommendations, acquisition workflow triggers), its transactional classification becomes questionable. And even in a purely transactional email, a marketing-oriented pixel is still subject to consent.
Does the CNIL make a distinction between using tracking to target openers and using it to exclude inactive users?
Yes, that is even the structuring distinction of the entire recommendation. See the paragraph on deliverability above.
Can a group collect a single, valid consent for tracking across multiple brands or entities?
The subject is more complex than it appears. The CNIL requires that the recipient clearly understands who will use the tracking pixels (recommendation, page 7). As soon as a group comprises several distinct legal entities, each can be responsible for its own processing, which argues for explicit consent per entity.
Broader consent may be possible when all entities are named at the time of collection and their uses are closely linked. However, the exact framework still needs to be specified on a case-by-case basis with your DPO or legal counsel.
Our practical recommendation: When in doubt, prioritize distinct consent per brand. This is more readable for the recipient and more robust in case of an audit.
How can you know an open rate without tracking?
The pixel is not prohibited. Without consent, it remains possible to use an anonymous pixel associated with a campaign identifier (and not an individual contact) to measure an overall open rate (if your email sending solution allows it). This aggregated measurement, which does not allow tracing back to an identifiable recipient, falls outside the scope of consent provided that the anonymization is effective. The July 22 FAQ confirms this in black and white (question 6). We are developing the subject, and its pitfalls, in our article dedicated to the anonymization of openings.
Is email marketing doomed to die?
Clearly not. The recommendation does not call email marketing into question; it frames it.
The challenge isn't to abandon email, but to shift towards more first-party data-driven management (authenticated clicks, purchases, declared preferences) and be less dependent solely on open and click signals. Brands that anticipate this shift will gain resilience against future regulatory changes as well as increasing protections from email clients (notably Apple Mail Privacy Protection).
Will this consent be able to thwart AMPP or Google Image Caching?
No. Consent obtained from your recipient has no effect on the protections put in place by email providers. If a user has enabled Apple Mail Privacy Protection, Apple will continue to pre-load the pixel and obscure open data, regardless of your consent mechanism. The CNIL also confirms this in its recommendation: the email service provider is neither a data processor nor a data controller (page 4). It acts according to its own rules, which are binding on you and your recipient.
Should the email open pixel be included in the list of cookies on your website?
No, the open pixel is not a cookie: it is not a web browsing tracker, and therefore it is not intended to be included in your site's cookie banner.
The CNIL itself urges caution on this point (recommendation, page 10): using a CMP designed for web cookies to collect consent for email pixels is technically possible but legally tricky. The recipient may not understand that their choice also applies to an environment (their inbox) separate from the one where they express it (your website).
Which countries does this regulation concern?
The legal framework is European. The recommendation published on March 12, 2026 and published in the Official Journal on April 14, 2026, emanates from the CNIL and represents the French interpretation of this common framework. The authorities of other countries may adopt slightly different interpretations. If you operate in several European countries, you must check the stance of each national supervisory authority. Also worth noting (a point raised during the 2nd webinar): a non-European email service provider operating for French clients must also apply the recommendation. A provider's non-compliance may even constitute a defect capable of justifying the cancellation of the contract.
If I only have one checkbox for consent to receive personalized commercial emails, as well as tracking of opens and clicks, can I have separate opt-out checkboxes for this consent?
The CNIL does not explicitly rule on this question (page 10 of the recommendation), but specifies that «withdrawing consent must be as simple as giving it.» Concretely, in this case, we advise you to do both: offer a one-click withdrawal AND individual withdrawals. Be careful, however: if a recipient unticks tracking but continues to receive emails, you must be able to send them non-personalized emails. Your platform must be able to handle this.
Should I re-collect consent from all my contacts already in the database?
No. The CNIL provides a transitional application method for existing databases (recommendation, page 11): tracking operations can continue provided that clear information is sent within 3 months and recipients are allowed to opt out for future emails.
Be careful not to confuse this method with consent by silence, which the CNIL explicitly excludes (page 7). This is a distinct legal regime, specific to the transition period.
However, some legal experts consider this method to be fragile in the long term and recommend explicit re-consent. This is more legally protective but operationally complex (the re-consent rate is historically very low). It's a decision to be made based on your risk profile.
Conclusion – Is this really the end of the world?
Honestly, no. And that's maybe part of the problem.
Compared to the initial project submitted for public consultation in June 2025, it is evident that market lobbies have had an impact. The exemptions granted on deliverability seem balanced to us, and serious players will be able to continue their work. However, other concessions appear more questionable to us.
The mechanism planned to bring existing databases into compliance is particularly problematic: a simple information campaign with a right to object, without collecting explicit consent. This is convenient for brands, but offers no protection whatsoever to recipients! A brand with a poorly engaged database will mechanically end up with a database deemed «not opposed,» simply because the informational email was not opened. Not really an incentive to do better!
That's why we made the choice of reading maximalist In this article. Minimal compliance is a starting point, not a horizon. Taking advantage of this period to rethink your relationship with your recipients, simplify your forms, and switch to more robust first-party signals is an investment that will pay off far beyond the CNIL compliance issue.
And if you need an outside perspective to help you place that slider, you know where to find us.
Leave a Reply