On April 17, 2026, the Italian Data Protection Authority adopted decision No. 284, published in the Official Gazette on April 29, 2026, containing the first Italian Guidelines on the use of tracking pixels in email communications. This intervention fills an important regulatory gap in an area that affects virtually every company with a newsletter or marketing email.
What tracking pixels are
Tracking pixels are transparent one-pixel images, not embedded in the email but hosted on remote servers. When the message is opened, HTML code triggers a request to the sender's server that allows collection of information: open event, recipient's IP address, device used, reading time, number of subsequent opens. The DPA qualifies them as 'particularly invasive markers due to their hidden nature'.
When consent is required
Consent is mandatory when the pixel is used to measure the behavior of individual recipients, evaluate the performance of promotional campaigns, modify content and frequency of sends based on demonstrated interest, or build commercial profiles.
- No consent needed for GLOBAL aggregated statistical counts (same pixel for all campaign recipients, anonymized IP)
- No consent needed for strictly necessary technical measures (security, spam fighting)
- No consent needed for mandatory-content messages (data breach notifications, contract deadlines, administrative reminders)
- In all other cases: prior, free, specific, informed, unambiguous consent required
The critical point for DPOs
The preferences management icon/link in the email footer must ALWAYS be present, regardless of consent. Refusing tracking alone cannot result in any service limitation. The Italian DPA goes beyond the French CNIL: consent granularity is an autonomous right, distinct from unsubscription.
The 4 actions to take by October 29, 2026
- Update privacy notices (subscription form + cookie policy) with dedicated tracking pixel section
- Add a separate, NOT pre-selected checkbox for tracking consent (distinct from newsletter subscription)
- Configure the email platform to disable pixels for old subscribers without new consent (privacy by default)
- Implement selective revocation mechanism: footer link in every email leading to preferences management area
Suggested privacy-by-design measures
The DPA suggests an operational indication: the sender should generate an unintelligible, non-sequential identifier for each recipient, to be associated with the email address in an internal, separate platform layer. This way the count of open events passes through the identifier without exposing the email address in the technical request.
In DPO Workspace
We'll soon add to sector templates a 'Email tracking pixel compliance' procedure as a placeholder to customize for clients doing email marketing. The compliance deadline (October 29, 2026) will be tracked as urgency in the client's dashboard.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free