YOUR
Search

    17.06.2026

    Tracking pixels in e-mails: the Data Protection Authority's new rules


    1. Introduction

    By Order No. 284 of 17 April 2026, published in the Official Gazette on 29 April 2026, the Data Protection Authority (Authority) adopted the first Guidelines specifically dedicated to the use of tracking pixels in electronic mail communications (“Guidelines”).

    This measure comes at a time of growing attention to tools for monitoring users’ online behaviour and aims to provide a uniform interpretative framework regarding the application of Article 122 of Legislative Decree No. 196/2003 (“Privacy Code) and the provisions of Regulation (EU) 2016/679 (“GDPR”) to tracking systems embedded in emails.

    According to the Authority, tracking pixels are particularly intrusive tools as they operate without the data subject’s knowledge. The Guidelines are based on the observation that such technologies enable the sender to determine whether a message has been opened, the number of views, the device used and, in some cases, further technical data relating to the recipient.

     

    2. Key points of the measure

    2.1 The classification of tracking pixels as tools subject to Article 122 of the Privacy Code

    One of the main clarifications provided by the Authority concerns the legal nature of tracking pixels.

    The Authority states that the insertion of the pixel and the subsequent collection of information generated by its activation constitute operations falling within the scope of Article 122 of the Privacy Code, as they involve both a form of “storage of information on the terminal equipment of a data subject or user” and subsequent “access to information already stored”.

    Of particular significance is the passage in which the Authority states that tracking pixels must be regarded as covert tracking tools, as their presence is not normally detectable by the user and they operate automatically and invisibly.

    The Guidelines also identify a number of parties that may be involved in the use of tracking pixels, including the sender of the message, the email service provider, the provider of mailing list rental services, the provider of tracking technology and the content creator. The Authority specifies that each of these parties is required, on a case-by-case basis and in accordance with the principle of accountability, to define their respective roles for the purposes of the legislation on the protection of personal data.

    The measure also distinguishes between different types of email messages relevant for the purposes of

    the application of the regulations: (i) newsletters, i.e. periodic communications of an informative nature; (ii) DEM (Direct Email Marketing), communications of a predominantly promotional or commercial nature; (iii) transactional emails and automated messages, sent in connection with specific user actions or ongoing transactions; and (iv) service emails, characterised by content designed to meet the specific needs of individuals or the community. This classification is relevant for the purposes of identifying the legal basis applicable to the processing associated with the use of tracking pixels.

     

    2.2 The obligation to provide prior information

    The Guidelines attach particular importance to transparency.

    Indeed, according to the Authority, the use of tracking pixels in emails must be disclosed in advance to the email recipient, regardless of the purpose of the communication or the type of sender.

    The Authority also emphasises that the use of tracking pixels requires all data controllers who already use them or intend to use them to adequately inform the data subjects, in accordance with the principles of fairness and transparency set out in the GDPR.

    At an operational level, the measure allows for simplified, layered information procedures, allowing, for example, the use of summary notices accompanied by links to detailed documentation, as well as the use of digital tools such as chatbots, pop-ups, virtual assistants or other communication channels.

     

    2.3 When consent is required

    A central aspect of the Guidelines concerns identifying the cases in which the use of tracking pixels requires the user’s consent.

    The Data Protection Authority reiterates that Article 122, paragraph 2-bis, of the Privacy Code introduces a general prohibition on accessing information stored on a user’s terminal equipment, storing information, or monitoring user activity through electronic communications networks; such prohibition may only be subject to derogation where the conditions set out in paragraph 1 of the same Article are met.

    The main scenarios in which consent may not be required include:

    • processing carried out solely for the purpose of aggregated statistical analysis of email opens, provided that appropriate anonymisation techniques are used;
    • activities necessary to ensure the security of authentication or account management processes;
    • service or institutional communications where the sender has a legal obligation to send them or where there are specific requirements to protect users. By way of example, the Data Protection Authority refers to messages containing useful guidance on how to prevent phishing or fraud, communications regarding contractual or logistical/organisational changes, notifications relating to security incidents, official information campaigns, as well as reminders regarding deadlines and contractual or social security obligations.

    Conversely, consent is required when tracking is used for marketing purposes, profiling, or the individual optimisation of promotional campaigns.

    The provision expressly refers to cases where individual measurement and analysis of email open rates are used to assess and improve the performance of promotional campaigns on the basis of observed behaviour, or when the open rate data is used to derive inferred information about the user’s potential tastes, interests and preferences for the purpose of creating commercial profiles.

     

    2.4 Single consent and the right to granular withdrawal

    One of the most innovative aspects of the Guidelines is the attempt to reconcile the need for protection with that for simplification.

    The Data Protection Authority indeed recognises that consent to receive promotional communications and consent to the use of tracking pixels can be obtained through a single expression of consent.

    This simplification is, however, accompanied by an important safeguard for the data subject: the possibility of subsequently withdrawing consent, even on a selective basis.

    The Guidelines stipulate that the user may revoke consent only partially, specifically with regard to tracking associated with the receipt of tracking pixels, while continuing to receive email communications that do not contain tracking tools, if they so wish.

    The Data Protection Authority also draws attention to the data controller’s obligation to duly record all choices made by the data subject, including any partial withdrawals, not least for the purposes of demonstrating consent, which the data controller may be required to do pursuant to Article 7(1) of the GDPR.

     

    2.5 Privacy by design and data minimisation

    The measure also focuses on the technical measures that data controllers should adopt to reduce the risks arising from tracking.

    Among the suggested solutions is the use of pseudonymised and non-sequential identifiers, while keeping the correspondence between these identifiers and the recipients’ email addresses separate.

    According to the Data Protection Authority, these measures help to reduce the exposure of email addresses by minimising the risk of data passing through the network being traceable.

     

    3. Practical implications

    The new Guidelines will have a significant impact on all operators using email campaigns, marketing automation platforms, newsletters and direct email marketing systems.

    In particular, organisations will need to:

    • check whether the tracking pixels used fall within the exemptions identified by the Data Protection Authority or whether they require consent to be obtained;
    • update their personal data processing notices/privacy policies, cookie policies and consent collection procedures;
    • implement mechanisms that allow users to withdraw their consent to tracking in a simple and granular manner;
    • review their contractual relationships with email service providers, marketing automation platforms and tracking technology providers;
    • assess the adoption of technical measures in line with the principles of “privacy by design” and “privacy by default”.

    The transitional arrangements set out in the measure are also particularly significant. The Data Protection Authority has recognised the complexity of the required adjustments, granting operators a period of six months from the date of publication in the Official Gazette. The Guidelines distinguish, in this regard, between new processing operations, for which consent must be obtained in advance at the time the email address is collected, and processing operations already underway, for which the data controller must promptly fulfil their information obligations with the first available communication and implement a mechanism allowing for the withdrawal of consent, even on a granular basis, identifying solutions characterised by maximum recognisability, visibility and ease of use for the benefit of the data subject. The Data Protection Authority specifies that this transitional regime is intended to be gradually phased out as new processing operations are undertaken and become subject to the rule requiring prior consent.

     

    4. Conclusions

    The new Guidelines mark an important step in the evolution of Italian legislation on tracking technologies.

    The Authority confirms a broadly rigorous approach, classifying tracking pixels as tools subject to the special rules set out in Article 122 of the Privacy Code and reaffirming the central importance of the principles of transparency and control by the data subject.

    At the same time, the Authority introduces certain operational simplifications – such as a single consent for promotional communications and tracking – and identifies specific cases of exemption that allow the efficiency of certain services to be maintained.

    For businesses, public bodies, technology providers and digital marketing practitioners, the six-month compliance period provided for by the regulation therefore represents an opportunity to review the processes, tools and legal bases for data processing relating to the sending of electronic communications, in light of a regulatory framework that increasingly prioritises transparency and user awareness.