Decoding the world of cybersecurity

Italy sets deadline for email tracking pixel compliance

Italy’s privacy regulator says organisations using tracking pixels in email have until 29 October to bring notices, consent and withdrawal mechanisms into line with its guidance.

Italy sets deadline for email tracking pixel compliance
Summary
  • Italy’s Garante has set 29 October as the end of the adjustment period for its email tracking pixel guidance.
  • Prior consent is generally required, with limited exceptions for necessary technical or security functions.
  • Compliance with the guidance is included in the regulator’s inspection programme for the second half of 2026.

Companies using invisible tracking pixels in email have until 29 October to bring their consent, privacy notices and withdrawal mechanisms into line with guidance issued by Italy’s data protection regulator.

The Garante said the six-month adjustment period attached to its guidance is approaching its end, after which organisations using the technology can expect compliance to form part of regulatory inspection activity.

Tracking pixels are small transparent images embedded in email messages. When a recipient’s device requests the image from a remote server, the sender can determine that the message has been opened and may collect associated technical or behavioural information.

Although the underlying request is technically simple, the Garante considers the technology potentially intrusive because monitoring can take place without a recipient clearly realising that opening an email is being recorded.

Its guidance places tracking pixels within Article 122 of Italy’s Privacy Code, which covers technologies capable of accessing information on a user’s device or monitoring online behaviour. GDPR requirements around transparency, consent, accountability and privacy by design apply alongside those national rules.

Prior consent will generally be required where the pixel is used to measure engagement or support marketing and profiling. Limited exceptions can apply where processing is strictly necessary for a technical function, security or certain service communications, but the purpose and scope have to support that exemption.

Organisations therefore need to distinguish between different uses rather than treating every pixel as equivalent. A request required to deliver a service or protect a system has a different legal basis from a mechanism designed to tell a marketing team who opened a promotional email.

Recipients must also receive transparent information about the processing and be able to withdraw consent through a practical mechanism. Where several tracking purposes exist, the regulator expects organisations to consider whether users can exercise meaningful choices rather than being forced into a single bundled decision.

Privacy by design creates another requirement beyond disclosure. Companies are expected to reduce identifiability and limit unnecessary circulation of personal information, which can include reconsidering what the pixel collects, how long the resulting data is retained and which external providers receive it.

Email engagement information often feeds into larger marketing systems. An open signal can be combined with CRM records, website behaviour, lead scoring and advertising data, turning one apparently minor request into part of a broader profile of an individual’s activity.

That wider processing explains why regulators have increasingly treated pixels in much the same way as other tracking technologies. The relevant question is not the physical size of the image but what happens after the request is generated and how the resulting information is linked with other data.

The compliance deadline can therefore affect email platforms, newsletter operators and organisations that rely on third-party marketing systems without necessarily operating the underlying tracking technology themselves. Responsibility still depends on the organisation’s role in determining how and why the information is processed.

Compliance with the guidelines is included in the Garante’s inspection programme for the second half of 2026, turning the 29 October date into an enforcement milestone rather than an advisory target.

Before that deadline, organisations using email pixels need an accurate view of where they are deployed, whether consent is required and whether current privacy notices describe the resulting data flows. Systems introduced through marketing platforms or templates can otherwise remain active without being visible to the teams responsible for privacy governance.

The Italian rules do not prohibit tracking pixels outright. They require organisations to treat them as data processing technologies whose legality depends on purpose, transparency, user choice and minimisation rather than as an invisible feature of email delivery.

×