A practical guide to Italy’s 2026 email tracking pixel rules: consent, anonymous open statistics, exemptions, granular withdrawal, provider duties, and the six-month transition.
Italy’s data protection authority, the Garante, adopted final guidelines for tracking pixels in email on April 17, 2026. They were published in the Italian Official Gazette on April 29, starting a six-month period for affected organizations to bring existing systems into line. The default rule is straightforward: a pixel that reads information from a recipient’s device generally requires prior, informed consent unless a specific Article 122 exemption applies.
The important part is what follows that headline. The Garante recognizes narrow exceptions for genuinely anonymous campaign-level statistics, authentication security, and certain legally required or service communications. It also says tracking consent may, in principle, be included with promotional-email consent—provided the request is neutral and informed and the recipient can later withdraw tracking alone while continuing to receive email.
Italy’s email pixel rules at a glance
PIXEL USE LIKELY TREATMENT UNDER THE GUIDELINES
Individual opens for campaign performance prior consent generally required
Frequency changes based on recipient behavior prior consent generally required
Preference, profiling, or targeted advertising prior consent generally required
Same campaign pixel for anonymous global statistics may qualify for an exemption
Authentication or account-security workflow may qualify when necessary
Required institutional or service communication may qualify when proportionate and necessary
Formatting or decorative remote image still assess access, purpose, and necessity
Provider reuse for its own analytics or products separate role, purpose, and legal analysis
Labels do not decide the result. Actual identifiers, purposes, recipients,
downstream uses, retention, and technical design do.Do not read “may qualify” as a safe harbor. The sender remains accountable for showing why the operation is necessary, proportionate, minimized, transparent, and confined to the claimed exemption. If an exempt event also updates an individual profile, chooses the next campaign, or feeds advertising audiences, that additional use requires its own analysis.
What the Garante means by an email tracking pixel
The guidelines describe a small, often transparent image that is hosted remotely rather than contained in the message. When the email renders, HTML causes the mail client to request the image from a server. That request can disclose that the message was opened along with information such as an identifier, IP address, device or client information, time, and repeat-open activity.
email HTML
-> remote image URL is present in the message
-> client, proxy, scanner, cache, or reader requests the image
-> server receives URL identifiers and request metadata
-> analytics system records an open-like event
-> event may update campaign totals, recipient state, or profiles
A request is not reliable proof that a person read the message.
That measurement limitation does not remove the privacy analysis.Under Article 122 of Italy’s Privacy Code, the Garante treats the operation like other storage-and-access technologies governed by the ePrivacy framework. The rule applies before asking whether later processing has a GDPR lawful basis. Legitimate interests for subsequent analytics do not automatically replace the consent or exemption required for the device-access operation itself.
When prior consent is generally required
Consent is the ordinary path when individual open data measures or improves promotional campaign performance. The guidelines expressly discuss changing subject lines after low open rates, improving relevance or readability, adapting frequency, stopping messages based on observed interest, and inferring preferences for commercial profiles. Those purposes go beyond merely transporting an email.
- Assigning an open or non-open to a named or pseudonymous recipient.
- Using individual behavior to change content, cadence, channel, or eligibility for later messages.
- Scoring leads or triggering sales, lifecycle, advertising, or retargeting workflows.
- Inferring tastes, preferences, intent, or engagement for a customer profile.
- Sharing identifiable open events with an ESP, analytics vendor, advertising platform, or another third party for additional purposes.
- Collecting IP address, client, device, precise time, or repeat opens beyond what an asserted exemption actually needs.
The anonymous campaign-statistics exemption
Italy’s most useful technical distinction is between individualized measurement and genuinely anonymous global statistics. The Garante says a pixel used to count the overall percentage of messages opened may qualify without specific pixel consent when the results are anonymous and cannot produce measurements about individual recipients.
ONE CAMPAIGN
one identical pixel URL for every recipient
no recipient or message-recipient identifier in the URL
IP address and client metadata anonymized
output limited to an anonymous campaign total or percentage
no person-level history, segment, profile, trigger, or export
NOT THE SAME DESIGN
unique pixel per recipient -> raw event stored -> identifier removed later
The second design first creates individualized data. Calling the final dashboard
aggregate does not make the collection anonymous by itself.The authority suggests an identical pixel for every recipient in the same campaign and anonymization of related technical data such as IP address and mail client information. This is materially different from generating a unique tracking URL per recipient and aggregating the events later. Teams relying on this route should test logs, CDNs, observability systems, query strings, cache keys, and warehouse tables—not only the customer-facing report.
Security, service, and institutional exceptions
The guidelines also identify scenarios in which a pixel may be necessary for authentication security or for a communication the sender is legally required to deliver. Examples include account activation, password changes, data-portability workflows, urgent phishing or fraud warnings, security-incident notices, contractual changes, event logistics, privacy notices, and reminders tied to contractual or contribution obligations.
Confirm an account message opened on a device known to the userUse only when the pixel is necessary to the security workflow; do not treat it as the sole authentication factor.
Warn customers about an active phishing campaignDocument why knowing the notice was accessed is necessary and beneficial to recipients.
Notify a customer of a contractual or scheduled-service changeKeep the event separate from marketing engagement and profiling.
Choose the next promotion from each recipient’s open historyThis is individualized campaign optimization and ordinarily requires prior consent.
An operational label does not make every pixel necessary. A receipt can usually be delivered without recording a named open. A security notice does not justify exporting its open event into a marketing profile. Define the narrow decision the event supports and remove every field and downstream use that does not support it.
Can tracking consent be combined with marketing-email consent?
Yes, in principle—and this is frequently misstated in summaries of the Italian rules. The Garante recognizes that consent to receive promotional email and consent to receive its tracking pixel are conceptually distinct. To reduce repetitive requests and consent fatigue, however, it says the pixel choice may be included in the broader promotional-email consent when the purposes are closely connected and the request is neutral, unforced, and sufficiently informative.
BEFORE THE CHOICE
explain that promotional emails include tracking pixels
describe the data, purposes, and relevant parties clearly
provide layered access to complete information
use a neutral, affirmative control without preselection or pressure
AFTER THE CHOICE
allow withdrawal of all promotional email
allow separate withdrawal of pixel tracking only
continue sending pixel-free email when only tracking is withdrawn
propagate the choice to templates, automations, vendors, and old identifiersThe practical test is not the number of checkboxes. It is whether a person understands what will happen and retains a meaningful way to stop the tracking without being forced to unsubscribe from wanted email. If purposes are materially different—for example, campaign measurement and cross-channel advertising—separate choices may still be needed under ordinary consent principles.
Notice and granular withdrawal
The authority supports layered notices. A concise explanation can appear where the address is collected with a link to fuller information, potentially alongside an existing cookie or privacy policy. What matters is that the hidden nature of the pixel does not remain hidden from the recipient.
- Explain the pixel before consent rather than relying only on a footer notice after collection.
- Identify the purposes, data categories, retention, recipients, and relevant sender or provider roles.
- Make refusing as practical as accepting and preserve evidence of the notice and choice shown.
- Place a recognizable footer link or icon in each message that opens a dedicated rights or preference area.
- Let the recipient stop all email or stop tracking alone while continuing to receive pixel-free messages.
- Synchronize withdrawal across campaigns, automations, transactional renderers, ESP settings, analytics, and profiles.
recipient_id internal identity
email_scope newsletter / promotion / product updates
tracking_purpose campaign measurement / personalization / other
decision accepted / refused / withdrawn
purpose_version exact language and purpose set
notice_version immutable notice snapshot
decided_at timestamp and collection context
tracking_withdrawn_at effective time, if withdrawn
provider_sync pending / complete / failed
render_policy pixel_allowed / aggregate_only / no_pixelThe six-month transition period
APRIL 17, 2026 Garante adopts the final guidelines
APRIL 21, 2026 Garante publishes its announcement
APRIL 29, 2026 Guidelines appear in Official Gazette, Series 98
SIX MONTHS Period provided for affected parties to conform existing systems
The official text measures the period from Gazette publication. Confirm the exact
calendar deadline and applicability with Italian counsel rather than relying on
a third-party countdown.The transition is not a reason to postpone discovery. Consent collection, historical-list treatment, preference synchronization, provider configuration, anonymous aggregation, template changes, and evidence preservation can require coordinated work across marketing, product, data, security, engineering, and legal teams.
Who is responsible: sender, ESP, list provider, or tracking vendor?
The Garante distinguishes the sender that chooses the communication and tracking purposes, the email-sending platform, a provider that rents lists and sends on a client’s behalf, and the vendor supplying the tracking technology. A sender will commonly be a controller. An ESP commonly acts as a processor when it follows documented instructions, but a provider can become a controller or joint controller where it determines purposes or essential means for its own operations.
- Map who decides whether a pixel is used, what it measures, and what happens after an event.
- Document processor instructions, retention, security, sub-processors, international transfers, and deletion behavior.
- Disable provider defaults that insert unique pixels before the required consent state is available.
- Prevent the provider from reusing raw events for benchmarking, product analytics, advertising, or model training without an independently valid role and basis.
- Test whether image hosts, CDNs, security tools, logs, and data warehouses retain identifiers that the reporting layer claims to anonymize.
- Give customers a reliable way to render pixel-free messages and to implement anonymous campaign-level measurement where appropriate.
Privacy by design for pixel identifiers
Where an individualized pixel is lawfully used, the authority recommends reducing direct identifiability. It suggests a non-intelligible, non-sequential identifier whose mapping to the email address remains in a separate internal layer. The email address should not travel inside the image request merely because encoding or hashing makes it less readable.
AVOID
/[email protected]&campaign=spring-sale
/open?recipient_sha256=<stable-cross-campaign-hash>
/open/000004219 # enumerable identifier
PREFER WHEN INDIVIDUAL TRACKING IS PERMITTED
/open/<opaque-random-event-token>
token -> short-retention event table -> separate recipient mapping
ALSO CONTROL
access, precision, retention, exports, logs, CDN query capture,
downstream profiles, replay behavior, and withdrawal blockingItaly and France are similar—but not identical
ISSUE ITALY: GARANTE 2026 FRANCE: CNIL 2026
Core framework Article 122 + GDPR Article 82 + GDPR
Marketing optimization consent generally required consent generally required
Aggregate opens anonymous global total may qualify anonymization needs separate analysis
Deliverability global anonymous statistics discussed narrow individual exemption with conditions
Authentication necessary security may qualify participating in authentication may qualify
Consent collection combined promotional choice possible sending and tracking analyzed independently
Withdrawal tracking-only withdrawal required simple withdrawal; stop residual requests
Transition six months from April 29 Gazette date three months from April 14, with FAQ nuance
Do not copy one country’s configuration into the other. Apply the rule governing
each audience, purpose, and processing operation.Both authorities reject the idea that ordinary campaign optimization becomes necessary merely because marketers find open rates useful. But the implementation routes differ. An architecture serving both countries should support jurisdiction-aware policy, explicit consent, pixel-free rendering, granular withdrawal, anonymous campaign measurement, isolated exempt streams, and documented evidence rather than a single global “open tracking” switch.
A practical migration checklist
1 DISCOVER render every template and locate remote images and redirect trackers
2 INVENTORY record data, identifiers, purposes, parties, retention, and destinations
3 CLASSIFY separate individual analytics, anonymous statistics, security, and service uses
4 DISABLE turn nonessential unique pixels off where consent evidence is absent
5 REDESIGN use one campaign pixel only where genuinely anonymous measurement is chosen
6 INFORM publish accurate layered notices before the recipient’s decision
7 COLLECT create neutral consent with versioned evidence
8 WITHDRAW support tracking-only withdrawal and pixel-free continued delivery
9 MINIMIZE use opaque identifiers, separate mappings, limited fields, and short retention
10 VERIFY test ESP defaults, CDNs, logs, warehouses, exports, old messages, and vendorsInclude messages created outside the main campaign editor: abandoned-cart automations, receipts, password resets, sales sequences, support tools, CRM sends, event platforms, list-rental campaigns, and manually uploaded HTML. A single legacy template or provider default can bypass an otherwise correct preference system.
What to measure when individual opens are off
A privacy-aware program does not have to operate without evidence. Provider acceptance, bounces, deferrals, complaints, unsubscribes, replies, and first-party outcomes are usually more actionable than an image request distorted by proxies, scanners, caches, and blocked remote content. Click redirects also require their own privacy analysis; they are not an automatic consent-free substitute for pixels.
Receiving server accepted or rejected the messageOperational evidence, not proof of inbox placement or reading.
Anonymous campaign-level open estimateUse an identical campaign pixel and prevent recipient-level reconstruction.
Recipient initiated an expected conversationA meaningful signal for human workflows with monitored reply handling.
Customer completed the intended first-party actionMeasure the actual product, account, or purchase goal under the appropriate policy.
Bounce, complaint, or unsubscribe occurredUse promptly for suppression, list quality, and expectation review.
Frequently asked questions
Does Italy ban all email tracking pixels?
No. Prior consent is the ordinary requirement for individualized campaign measurement, profiling, and optimization, but the guidelines describe narrow exemptions. These include genuinely anonymous campaign-level statistics, necessary authentication security, and certain required institutional or service messages. Each exemption depends on its real purpose and design.
Can we keep aggregate open rates without consent?
Potentially, when the measurement is genuinely anonymous. The Garante suggests using the same pixel for everyone in a campaign and anonymizing related technical information so no individual measurement is possible. Unique recipient pixels aggregated only in the dashboard are not automatically equivalent.
Do we need a separate checkbox for tracking?
Not necessarily. The Garante says tracking consent may be included in a broader promotional-email consent when the connected purposes are explained neutrally and clearly. The recipient must still be able to withdraw tracking alone and continue receiving email without the pixel.
When does the transition period end?
The official guidelines provide six months from their April 29, 2026 publication in the Italian Official Gazette. Organizations should have Italian counsel confirm the exact deadline calculation and how the transition applies to their existing processing rather than relying solely on a third-party date.
Does hashing the email address make a pixel anonymous?
Usually not by itself. A stable hash can still single out and link the same recipient across events or datasets. The guidelines recommend opaque, non-sequential identifiers and a separate internal mapping where individual tracking is lawful. Genuine anonymous statistics must prevent recipient-level measurement and re-identification in the actual system, including logs and exports.