Skip to main content

EU Tracking Pixel Guidance and What It Means for Your Event Emails

Understand the new CNIL and Garante guidance on email tracking pixels, and what it changes (and doesn't change) for tracking in zkipster.

Written by Murilo Aguiar

Please note: this article is for general information only and isn't legal advice. Data protection law depends on your specific circumstances, including where your guests are based and how your lists were built. If you're unsure how this applies to your organization, please speak with your own legal advisor.

What changed

In spring 2026, France's CNIL and Italy's Garante published guidance clarifying how the ePrivacy Directive and GDPR apply to email tracking pixels, the small tracking image that loads when a guest opens an email. zkipster uses this to show whether an invitation or reminder has been opened.

You don't need to stop tracking opens, but French and Italian regulators now expect open tracking to have a clear purpose, to be limited in scope and, in many cases, require consent.

Where France and Italy differ

Both regulators treat a tracking pixel like a cookie: consent is required unless a narrow “deliverability exemption” applies, and each draws that line differently.

France (CNIL): allows per-recipient tracking without consent, but only to identify inactive guests, manage suppression lists, and clean bad addresses.

Italy (Garante): stricter. The consent-free allowance only covers aggregate, anonymized statistics, meaning one shared pixel per send rather than one per recipient. Tracking individual opens typically requires consent.

Two things worth knowing

Consent to email a guest isn't consent to track their email activity, even for transactional emails, so both should be requested separately. And, if you’re working on guest lists with partners, confirmation from them that consent was collected isn't sufficient; CNIL expects you to be able to show individual consent for any guests who didn't come through your own registration flow.

Consent and tracking in zkipster

zkipster is the data processor here. As the event organizer, you are the data controller, and obtaining guest consent, for both sending and tracking emails, is your responsibility. zkipster does not ask your guests for consent on your behalf, and we are unable to manage that process for you. It's up to you to decide how to collect consent, and to make sure it's in place.

zkipster tracks email opens by default; this is core platform functionality and isn't something we can switch off per guest or region. The only guest-level control today is a full unsubscribe: there's no separate opt-out just for pixel tracking. If a guest wants to receive your emails but not to be tracked, that has to be handled outside zkipster.

What to do now

  • Gather consent that explicitly covers tracking, not just receiving emails.

  • Check that your registration flow and privacy notice mention tracking, and confirm you can demonstrate consent for any guests from outside your own sign-up flow.

  • Prioritize reviewing guest lists with attendees from France and Italy.

We'll update this article as the guidance develops.

Helpful Links

Did this answer your question?