← All news
7 October 2026

Invisible trackers in your Inbox: Italian Data Protection Authority issues binding Guidelines on email tracking pixels

On 17 April 2026, the Italian Data Protection Authority issued binding Guidelines on tracking pixels in emails: mandatory disclosure, specific legal bases, and a granular consent regime. Controllers have until 29 October 2026 to achieve full compliance.

1. Introduction: invisible trackers in the inbox
On 17 April 2026, the Italian Data Protection Authority ("Italian DPA") adopted Guidelines on the use of tracking pixels in email communications. The document follows a growing number of complaints and two rounds of inspections (October 2025 and February 2026) at an email service provider and a marketing automation platform.
Tracking pixels are tiny, typically transparent, one-pixel images embedded in the HTML code of an email. Hosted on remote servers, they trigger an automatic request to the sender’s server each time the email is opened, enabling collection of data such as: open frequency, the recipient’s IP address, device type, and time of consultation.
The Italian DPA stresses that tracking pixels' invasiveness is compounded by their hidden nature: recipients are generally unaware of their presence. The only technical safeguard currently available — disabling image download altogether — is a blunt instrument that removes all images indiscriminately.
2. The applicable legal framework
The Guidelines are grounded in Article 122 of the Italian Privacy Code (Legislative Decree no. 196/2003, as amended by Legislative Decree no. 101/2018), which transposes the e-Privacy Directive (2002/58/EC), read together with the GDPR. The Italian DPA concludes that embedding a tracking pixel constitutes both "storage of information on the terminal" and "access to information already stored" under Article 122, triggering a default prohibition subject to statutory exceptions. The GDPR applies in parallel: transparency obligations (Articles 12 ff.), data minimisation, and the accountability principle (Article 5(2) GDPR) remain fully operative.
3. Parties covered by the Guidelines
The Guidelines address all parties involved in the deployment of tracking pixels:
- the email sender, who decides whether to use tracking pixels and for what purposes;
- email sending service providers (ESPs), operating marketing automation platforms on behalf of senders;
- mailing list rental and distribution providers, who send emails on behalf of third-party clients from their own subscriber databases;
- tracking technology providers, who supply the technical infrastructure for the pixel;
- content creators who design the promotional message; and
- the email recipient, on whose device the tracking element is installed.
Each party must determine its role (controller, processor, or joint controller) on a case-by-case basis, in line with the accountability principle.
4. Disclosure obligations
Regardless of the purpose or legal basis relied upon, use of tracking pixels must always be disclosed in advance. Failure to do so violates fairness and transparency under Article 5(1)(a) and Articles 12 GDPR and the following.
The Italian DPA endorses a simplified, multi-layered notice approach:
- a short-form disclosure at the point of email address collection, with a link to fuller information (which may be integrated into or linked from the cookie policy);
- multichannel delivery of the notice (e.g. via video, pop-up, chatbot, voice assistant); and
- for already-ongoing campaigns, the information may be provided in the first available email sent after the Guidelines come into force.

5. Legal bases for processing: consent and its exceptions
Article 122 of the Italian Privacy Code imposes a general prohibition on accessing or storing information on a user’s terminal without consent, subject to three exceptions: (a) prior, freely given, specific, informed and unambiguous consent; (b) processing strictly necessary for the transmission of an electronic communication; or (c) processing strictly necessary for the provision of a service explicitly requested by the user.
The Italian DPA identifies three scenarios where controllers may rely on an exception without separate consent:
- aggregate statistical measurement: identical, non-individualised pixels used to measure overall open rates, with full anonymisation of technical data (IP address, email client) meeting the WP29/EDPB Opinion 05/2014 threshold;
- security and authentication: where the pixel verifies that a specific message (e.g. password reset, account activation, or data portability response) has been received by the intended user, ancillary to the provision of the requested service;
- institutional or legally mandated service messages: where the pixel confirms receipt of a legally required communication (e.g. anti-phishing alerts, security incident notifications, contractual change notices, or institutional public-interest campaigns).
In all other cases — in particular where individual open rates are used for profiling, personalising content or subject lines, or building commercial profiles — prior consent is required.

6. Acquiring and managing consent
Where consent is the applicable legal basis, the Guidelines establish the following regime:
- new processing activities: consent must be collected — preferably at the point of acquiring the email address — after due information. Consent to tracking pixels may be bundled with consent to commercial communications, provided the request is neutral and free from pressure or consent fatigue;
- withdrawal: users must be able to withdraw consent easily and in a granular manner — either stopping all emails or continuing to receive emails without tracking pixels. Withdrawal may be implemented via a standardised icon or link in the email footer leading to a preference centre;
- ongoing campaigns: controllers must (i) fulfil disclosure obligations with the first available email send; and (ii) implement and communicate a granular withdrawal mechanism. Users who decline tracking must retain full access to the service without any reduction in quality or functionality.

Lessons learned

Conclusion
The Italian DPA has granted a six-month compliance period from 29 April 2026. Controllers must achieve full compliance with the Guidelines by 29 October 2026.
For privacy practitioners and email marketers alike, the practical implications are substantial: privacy notices must be updated to cover tracking pixels specifically, consent flows must be reviewed or built from scratch, and granular withdrawal mechanisms must be embedded into every email programme.

Article provided by INPLP member: Chiara Agostini (RPLegal&Tax Associazione Professionale, Italy)

By Dr. Tobias Höllwarth