Plus ça change, plus c'est la même chose.
"The more it changes, the more it's the same thing."
It's fitting that the French have a phrase for it, because it's the French regulator that just proved it. This spring, France's CNIL ruled that the humble tracking pixel — the invisible 1×1 image that has quietly powered email open rates for over two decades — needs the recipient's prior consent. Italy's Garante reached the same conclusion within weeks. Two regulators, one spring, same verdict. When France and Italy agree on something this quickly, you know it's serious. It normally takes them longer to agree on lunch.
Unlock our insights
Register your email to access all of our case studies and receive exclusive insights.
We have just sent you an email
Please click the link in the email to confirm your identity.
Plus ça change, plus c’est la même chose.
“The more it changes, the more it’s the same thing.”
It’s fitting that the French have a phrase for it, because it’s the French regulator that just proved it. This spring, France’s CNIL ruled that the humble tracking pixel — the invisible 1×1 image that has quietly powered email open rates for over two decades — needs the recipient’s prior consent. Italy’s Garante reached the same conclusion within weeks. Two regulators, one spring, same verdict. When France and Italy agree on something this quickly, you know it’s serious. It normally takes them longer to agree on lunch.
Here’s the twist: neither passed a new law. Both simply pointed out that under rules which have existed since GDPR and the ePrivacy Directive, most email tracking was never really legal in the first place. The pixel didn’t change. The law didn’t change. What changed is that two regulators wrote it down, attached deadlines, and started the clock.
What actually happened
In April 2026, the CNIL published its final recommendation on email tracking pixels, and the Garante adopted Provision No. 284. Both start from the same premise: a pixel that reports whether a specific person opened an email is functionally a cookie, and it needs the same prior consent. Crucially, consent to receive a marketing email and consent to be measured inside it are two different permissions. “Send me your newsletter” and “watch me read your newsletter” are not the same sentence, however much the analytics dashboard wishes they were.
The deadlines are not leisurely. France required existing contact databases to be brought into line by 14 July 2026, with no transitional period at all for contacts collected after mid-April. Italy’s compliance window closes on 28 October 2026.
There are carve-outs, but they’re narrower than most marketers hope. Tracking used purely for deliverability, things like suppressing dead addresses or adjusting send frequency, can run without consent. Italy also exempts genuinely anonymised aggregate counts, where no individual can be identified. But the moment the same pixel feeds behavioural analytics, lead scoring, or automation triggers, you’re back inside the consent requirement. Which, let’s be honest, describes almost every marketing platform’s factory settings.
“It’s only two countries” is the wrong read
Formally, these are national measures. Practically, every EU data protection authority is reading from the same ePrivacy and GDPR text, and regulators in this space have a long habit of arriving at the same conclusions, fashionably late, but they do arrive. If your distribution lists include recipients in France or Italy today, the deadlines already apply to you. If you have other EU-based contacts, consider Paris and Rome your weather forecast.
For financial services marketers, there’s a second-order effect worth taking seriously: your compliance team is going to ask about this, if they haven’t already. Investment firms don’t get to shrug at regulatory guidance. Shrugging is not an approved control. The question “can our email platform distinguish a consented contact from a non-consented one?” is about to start appearing in due-diligence questionnaires, vendor reviews and RFPs. For most platforms, the honest answer is no, followed by a meaningful glance at the roadmap.
Why most platforms can’t cope
The standard architecture of email marketing is one pixel, embedded in every message, feeding one analytics pipeline. Opens and clicks flow into the same reports, the same lead scores, the same automated journeys, for every recipient identically. There is no dial. Your choices are tracking everyone or tracking no one: compliance risk or flying blind. Neither looks great in the board pack.
The road we took in 2018
When GDPR arrived, our clients asked us how they could keep measuring campaigns when some recipients couldn’t be individually tracked. So we built the answer, and it’s been quietly doing its job ever since. So quietly, in fact, that until recently we hadn’t put a page about it on our own website. Cobbler’s children, shoes, etc. That’s fixed, and this year we’ve given it a name that says what it does: StoneShot ConsentTrack.
ConsentTrack offers four tracking levels, from no tracking at all, through anonymous campaign totals and privacy-preserving unique counts, up to full individual tracking. The level is set as an instance default, and then individual contacts are elevated to full tracking through consent: a flag synced from your CRM, an opt-in on a preference form, or a list import marked as consented.

The part that matters is what happens at send time. One campaign, one send: consented contacts are fully tracked; everyone else is measured anonymously. Your French recipients are handled to the CNIL’s standard, your Italian recipients to the Garante’s, your consented contacts everywhere else exactly as before — and your campaign-level reporting stays whole across all of them, because anonymous recipients still count in your totals. No split sends, no parallel lists, no all-hands meeting about The New Process.
It also covers clicks, not just opens. The 2026 guidance concentrated on pixels, but per-recipient link tracking raises precisely the same principles, and betting that regulators won’t notice redirect links seems a bold strategy. ConsentTrack’s levels govern both together.
What to do this quarter
Wherever your email program runs, the checklist looks the same:
- Audit what you’re actually embedding. Find out what your platform puts in each message and where that data flows. The answer may surprise you, and not in the birthday sense.
- Ask the differentiation question. Can your platform vary tracking by recipient, consent status, and purpose? Not in a roadmap deck, in production today.
- Split your consents. Separate tracking consent from marketing consent in your sign-up flows.
- Uncouple tracking from unsubscribe. Italy explicitly requires that recipients can decline the surveillance while keeping the newsletter, which seems only fair.
- Talk to your compliance team before they talk to you. It’s a much nicer meeting in that order.
If the answer to the platform question is no, we should talk. ConsentTrack has been doing this for eight years, not built in a rush for a deadline but built for clients who never had the luxury of ignoring one.
We’re always sharing fresh case studies and blogs packed with insights. Sign up now and be the first to know!
Subscribe

