Anyone sending newsletters and commercial communications in Italy has until 29 October 2026 to comply with the Garante privacy’s guidelines on tracking pixels in emails. After that date, finding out whether and when you opened a message will no longer be a campaign statistic collected in silence: in many cases it will require your consent.
What a tracking pixel is
It is a tiny image, usually transparent, placed in the body of the email and hosted on a server belonging to the sender. When your email program downloads the images in the message, the server logs the request. From that, the sender can work out whether the email was opened, at what time, from which device and with which IP address.
The Garante considers it a particularly invasive tool precisely because, in most cases, the recipient does not know it exists. That is why it has brought pixels under Article 122 of the Privacy Code, the provision that transposes the e-Privacy directive and covers technologies that access information on a user’s device or monitor their behaviour. The GDPR continues to apply to the rest of the processing.
What changes in practice
The general rule is prior consent, freely given, specific and informed. It is needed above all when open data is used to profile the individual recipient: tailoring later messages according to how often they open them, splitting contacts by level of interest, building a commercial profile.
The guidelines do not ban the pixel outright. Exceptions are provided for:
- overall, anonymous counts, with no pixels traceable to the individual;
- security checks, such as the email confirming a new account or a changed password;
- service or institutional messages, for example a notice about an incident or a change to a contract.
These exemptions, too, must be assessed rigorously and documented by the sender.
For people receiving the emails, the room for choice changes too. Withdrawal must be granular: you will be able to stop being tracked while still receiving the newsletter, or unsubscribe altogether. The link for doing so must be placed in the footer of every message, choices must be recorded, and access to a service cannot depend on accepting tracking. Subscribing and being monitored are therefore two separate decisions.
The Garante also recommends a privacy-by-design approach: an identifier that is non-sequential and cannot be interpreted, linked to the email address only inside the sender’s systems, so that the pixel request does not leak the address.
Timing and who is affected
The text was adopted in April and the deadline for compliance is six months from publication in the Gazzetta Ufficiale, so until 29 October. The Authority cites inspections carried out between October 2025 and February 2026, confirming that the issue is not a theoretical one.
The rules apply to everyone: companies, public bodies, online service providers, email providers and operators of bulk-mailing platforms. The guidelines also distinguish between roles (sender, platform provider, tracking technology provider), who will have to clarify who is the controller and who the processor.
What you can do yourself
Even before companies get their house in order, you can cut down on tracking yourself. Many email programs let you stop remote images from loading automatically: without that download the pixel is never requested and the sender cannot see the open. Some email apps and privacy protection services already do this by default; others need to be configured.
What we think
The most interesting point is the separation between subscribing and being tracked. Today, anyone who wants a newsletter accepts, without knowing it, being measured. If selective withdrawal becomes the norm, we will see a real change in habits: less silent profiling and more messages built on what the user has chosen to share.
There is, however, a practical risk: if consent becomes one more banner to click, many people will accept it without reading, as already happens with cookies. The value of the rules will depend on how email marketing platforms implement withdrawal in the footer and on how visible the Garante’s checks remain after the deadline. For readers, meanwhile, blocking remote images remains the simplest defence. If you are interested in personal data online, you will find a recent case in Express 2026: dati clienti esposti.
Written by the SpazioiTech newsroom with the help of AI tools, from facts verified across at least two independent outlets, and checked before publication. Spotted a mistake? Tell us.
Translated from the Italian original. Read in Italian



