Skip to main content

The Italian Data Protection Authority ("Garante") has approved the “Guidelines on the use of tracking pixels in email communications” (GPDP, decision of 17 April 2026), which are addressed to any entity, whether private or public, that is involved in any capacity in the use of tracking pixels in emails.

Tracking pixels have been defined as images, generally invisible to the user, hosted on remote servers, downloaded to the recipient’s email client and stored in the memory of their device when the email is opened. Through this process, the sender can obtain information regarding whether a specific user has opened the message, along with other details such as the IP address, the type of device used or the time of access, thereby enabling user tracking.

These tools are used for a variety of purposes, such as sending marketing communications based on profiling, combating spam, measuring the audience and performance of sent communications, or for technical purposes.

In line with long-standing legal doctrine, the Garante has clarified that the use of tracking pixels in emails falls within the scope of the ‘ePrivacy’ regulations applicable to cookies and other tracking tools, as well as the regulations on the protection of personal data, and therefore primarily the GDPR.

With regard to compliance, given the particularly intrusive nature of tracking pixels due to their hidden nature, the Authority has highlighted the need to fully respect the principles of transparency and fairness, as well as the obligations regarding information provision, which may also be fulfilled through simplified methods, to be determined by the data controllers.

It is also essential to ensure an appropriate legal basis for the processing. The DPA has clarified that the use of tracking pixels requires the prior consent of users, specifying certain simplified methods that operators may adopt in this regard. It has also identified exceptional cases in which, subject to certain limits, it is possible to use tracking pixels without requiring the consent of recipients.

The regulation applies to all relevant operators (including providers of email delivery services, mailing list rental and email delivery services, tracking technology providers, and content creators), including those already using these technologies at the time the regulation comes into force, and covers all types of email (newsletters, DEMs, transactional emails and automated messages, service emails).