Search

Privacy: The new Guidelines on Tracking Pixels published by the Italian Data Protection Authority

Privacy: The new Guidelines on Tracking Pixels published by the Italian Data Protection Authority

Edited by Paola Furiosi and Andrea Strippoli

The digital marketing and data economy ecosystem is undergoing deep changes. In this context the Italian Data Protection Authority issued Provision No. 284 of 17 April 2026, containing the Guidelines on the use of tracking pixels in email communications (hereinafter, the “Guidelines”), published in the Official Gazette of the Republic of Italy of 29 April 2026.

Tracking pixels (also known as web beacons, pixel tags, or spy pixels) are small images, typically 1×1 pixels in size and invisible to the human eye, that are embedded into web pages, emails, or digital documents to monitor user behavior. When a user opens a web page or an email containing a tracking pixel, the browser or email client sends a request to the server hosting the image to load it. This request automatically transmits a range of information to the server, including the user’s IP address, the type of browser and device used, the operating system, the date and time the page was opened, and, in some cases, the actions performed on the page. As the image is transparent or the same size as a single pixel, the user is unaware of its presence. It is precisely this hidden nature that makes tracking pixels particularly intrusive and justifies their regulation.

The Guidelines clarify that, unless the user consents or specific exceptions apply, storing and accessing information on the user’s device is forbidden. Data controllers have a period of 6 (six) months from the date of publication in the Official Gazette to comply, i.e. by 29 October 2026.

As concerns its legal basis, the provision falls within the framework already introduced by Directive 2002/58/EC (hereinafter, the “ePrivacy Directive”) and by Regulation (EU) 2016/679 (hereinafter, the “GDPR”). Within this framework, the ePrivacy Directive operates as lex specialis, while the provisions of the GDPR remain applicable to aspects not specifically regulated. Prevalence of the ePrivacy Directive over the GDPR has immediate practical implications for operators, as the primary source for the installation of tracking pixels in emails must be found in Article 5(3) of the ePrivacy Directive, transposed into Italian law under Article 122 of the Privacy Code.

This Article provides a general ban on accessing or storing information on the user’s device, which can only be waived in cases where: (i) the user has given prior, informed, freely given, specific and unambiguous consent or (ii) one of the exceptions set out in Article 122 of the same rule applies – namely, where the processing is necessary, enables, or facilitates the transmission of an electronic communication, or where the operations carried out are necessary for the provision of an online communication service at the users’ request.

This approach is consistent with the position already taken by the Italian Data Protection Authority in its Guidelines on cookiesand other tracking tools (Provision No. 231 of 10 June 2021), which the Guidelines expressly refer to, as well as with the position taken by theEuropean Data Protection Board in Guidelines 2/2023 on Technical Scope of Article 5(3) of ePrivacy Directive.

With regard to exceptions to the consent requirement, the Italian Data Protection Authority has identified certain scenarios in which prior user consent is not required, specifically:

  • The tracking pixel is only used to measure, in an aggregate form, the opening rate of messages. In this case, the information collected (including technical data such as IP addresses and client information) must be anonymized to prevent measurements that can be traced back to individual users, and the pixel must be identical for all recipients of the same campaign;
  • The tracking pixel is used as a security measure in the context of user authentication, account setup, or credential updates. In such cases, the tracking pixel is used to verify that a specific message — such as an account activation confirmation — has actually been opened on a device associated with the user in question; or
  • The data controller is required by law to send an institutional or service message and needs to verify that the recipient has acknowledged its content. This is the case, for example, with communications containing instructions on how to protect from phishing or fraud in the presence of actual threats.

Where it is not possible to rely on one of the exemptions provided for by the applicable law, it is necessary to obtain the user’s prior consent before installing tracking pixelswithin emails.

As for the methods of obtaining consent, given the close correlation between the use of tracking pixels and marketing purposes, the Italian Data Protection Authority considers that consent for the use of such tools may be included within the broader consent to receive marketing communications. In other words, the user may express one single and informed consent that covers both aspects.

With regard to the withdrawal of consent, the Italian Data Protection Authority specifies that this shall take place in a simple manner and, if necessary, also in a granular way. Users may, in fact, withdraw their consent entirely — thereby ceasing to receive further marketing communications – or only in relation to the use of tracking pixels, thereby continuing to receive such communications without the tracking tool. As for the management of granular consent withdrawal requests, the Italian Data Protection Authority suggests embedding in the email a standardized icon or a link positioned in the email footer, which redirects users to a dedicated section for exercising their rights. In this area, the data subject may either request to stop receiving marketing emails (as already happens when users click on unsubscribe links in the footer of marketing emails), or to stop receiving only tracking pixels, meaning they will continue to receive email communications without such pixels.

In terms of roles, the Italian Data Protection Authority identifies a number of parties that may be involved in the tracking process:

  • The sender, which determines the purposes for using the pixels;
  • The email service provider, which provides the platform;
  • The distribution list service provider, which independently manages the sending of marketing emails to the distribution lists;
  • The tracking technology provider;
  • The content creator;
  • The recipient of the message.

In light of the deadline set for 29 October 2026, data controllers, email marketing service providers, bulk messaging platform operators, and any other parties involved in the use of tracking pixels are required to promptly implement an appropriate compliance plan. In particular, it is recommended to:

  • Conduct a review of email communication flows that include tracking pixels;
  • Update privacy policies to include reference to tracking pixels and the related legal basis;
  • Implement consent collection mechanisms or amend those already in place;
  • Implement a mechanism for withdrawing consent in a granular way;
  • Review existing agreements with email platform and technology providers, properly formalizing data protection roles and updating data processing agreements or joint controllership agreements, where necessary;
  • Evaluate the implementation of measures suggested by the Italian Data Protection Authority aimed at reducing the risk of identifying recipients. Among these measures, the Authority indicates, in particular, the generation of unintelligible and non-sequential identifiers to associate with the recipient’s email address, maintaining such correspondence in an internal and separate layer of the platform used. This way, the counting of the message openings occurs via the identifier, without the email address being included in the technical request generated by the pixel upload.

The Guidelines represent a key step in the evolution of the data economy, regulating the use of tracking technologies that have previously been widely unregulated. The main challenge for operators now is to comply with a regulatory framework that requires them to balance marketing needs with full respect for the data subjects’ rights.

Paola Furiosi

Legal Partner | PwC Italy |  + posts