|
/ Documentation /General/ SureContact Email Tracking Pixel Regulations

SureContact Email Tracking Pixel Regulations

Email Tracking Pixel Regulations (CNIL, Garante, and Beyond): Managing Your Open Tracking Settings

You will learn

  • What data SureContact’s tracking pixel records
  • How to determine which of your recipients these regulations may apply to
  • How to send a transitional email to existing recipients, and record responses once your privacy team has them
  • What to consider for deliverability with a large send
  • Where to turn on SureContact’s open tracking controls

Some regulators in the EU, including France’s data protection authority (the CNIL) and Italy’s data protection authority (the Garante), have issued guidance regarding consent for using tracking pixels in emails. Whether and how this guidance applies to your program is a determination for you and your privacy team. This article covers what SureContact’s tracking pixel records, and how to use SureContact to help act on whatever your privacy team decides.

What SureContact’s Tracking Pixel Records

When a message is sent, SureContact inserts an invisible 1×1 pixel image into the email. The pixel’s URL contains a unique ID tied to a record SureContact creates on its servers at send time, linking that ID to your account, the message, and the recipient the email was sent to. That record doesn’t know whether the message is ever opened. 

When the recipient’s email app (such as Gmail, Outlook, or Apple Mail) loads the pixel, it sends a web request to SureContact’s servers. Like any web request, this includes the IP address, as well as the device or browser information (user agent) the request came from. Receiving that request isn’t the same as tracking the open; whether it’s recorded as one depends on your open tracking setup.

Open tracking on (the default, for your account and that recipient, unless you’ve turned it off or that recipient’s tracking consent has been set to denied): SureContact matches the request back to your account, the message, and the recipient using the record created at send time, and records an “Email Opened” event that stores the account, recipient, message, timestamp, and device or browser information (user agent). The IP address included in the pixel request is not stored or retained. This is the event that shows up in your reporting and recipient activity, and feeds attribution, segmentation, and automation triggers.

Open tracking off, either for that specific campaign (via the campaign’s Track Opens setting) or for that specific recipient (tracking consent set to denied): the pixel is still present in the email, and when the recipient’s email app loads it, the request still reaches SureContact’s servers. SureContact checks the request against your settings before recording anything. If tracking is off, the request is not logged, not stored, and not associated with the recipient’s profile. The request is discarded there: no “Email Opened” event is created, and nothing is added to your reporting or recipient activity. This server-side check is what allows SureContact to honor the campaign and recipient’s current tracking settings at the moment the email is opened, rather than relying on a status that may have changed since the email was sent.

Open tracking consent is tracked independently of a recipient’s subscription status. Setting a recipient’s tracking consent to denied only stops the “Email Opened” event from being recorded for them; it does not unsubscribe them or stop future sends. These are two separate fields, and updating one does not affect the other.

Identifying Recipients Who May Be Affected

Which recipients these rules apply to, and what that means for each of them, is a determination you make with your privacy team, not one SureContact can make for you. The CNIL and Garante’s guidance differ by country, and within each country, by when a recipient’s consent was originally collected. See the article above for a breakdown by country.

You can use profile data such as location to help build a starting audience, then work with your privacy team to confirm who’s in scope and how each group should be handled.

How to Send a Transitional Email to Existing Recipients

If your privacy team advises sending existing recipients a notice about tracking pixels, and a way to respond, here’s how to do that in SureContact.

To send a specific email without recording opens, you have two options:

  • Turn off open tracking on the specific campaign before sending. In the campaign settings, set Track Opens to off. This means no “Email Opened” events will be recorded for any recipient of that campaign, regardless of their individual tracking consent setting.
  • Add the {{tracking_preferences_url}} merge tag to the email’s footer so recipients can opt out of open tracking (set their own tracking consent to denied) themselves, without being unsubscribed from your emails. This link is already included in the starter template footer.

If your privacy team determines that the opt-out approach applies to your recipients (i.e., open tracking remains on unless a recipient objects), the {{tracking_preferences_url}} link is the native, recipient-facing mechanism for that: recipients click it, land on a preference page, and can opt out of (or back into) open tracking on their own, independent of their email subscription status.

How to Record Recipients’ Responses

Recipients can manage their open tracking preference directly using the {{tracking_preferences_url}} merge tag. Add this link to your email footer; when a recipient clicks it, they are taken to a preference page where they can opt out of (or back into) open tracking without unsubscribing from your emails.

If you need to update tracking consent in bulk, for example, to record objections collected through a separate channel, use the API (PATCH /contacts/{uuid} with tracking_consent: denied). Tracking consent is not currently exposed in CSV import or SFTP/data warehouse sync, so those aren’t available as a mechanism for this today.

Once consent is set, you can filter contacts by their tracking consent status to see who has opted out.

Deliverability Guidance for a Large Send

A transitional email is often a one-time send to most or all of your list at once, which carries the same deliverability considerations as any large send:

  • Try to avoid sending your entire list in a single blast, especially if part of it is unengaged. Sending in batches over a short window is safer for your sender reputation than one very large send.
  • Review your list hygiene before sending. 

Additional Resources

Need Help?

If you need any assistance, please email [email protected], and our support team will be happy to help you.

Was this doc helpful?
What went wrong?

We don't respond to the article feedback, we use it to improve our support content.

Need help? Contact Support
Table of Contents
Scroll to Top