Also emailing recipients in France? The French rule, set by the CNIL, has its own page, translated into English: Tracking pixels in emails: the CNIL rule, explained simply
Tracking pixels in emails: what PECR and the ICO require, explained
The ICO published its final guidance on storage and access technologies on 29 April 2026. It draws a line many marketing teams miss: the rules on email marketing govern the email, and a different rule governs the tracking pixel inside it.
This page explains that line without jargon: what a pixel does, why the soft opt-in does not reach it, what the exceptions introduced by the Data (Use and Access) Act 2025 cover, and where the United States stands.
The short answer
Pixels are not banned.
Where a pixel stores or accesses information on the recipient's device, regulation 6 of PECR applies: consent, unless an exception does.
The soft opt-in covers the email, not the pixel.
Regulation 22 lets you send to existing customers. The ICO places pixels under regulation 6, which has its own exceptions.
The new exceptions are not for tracking people.
The statistical exception is about how a service is used, not who uses it. The ICO has not analysed email opens under any exception.
What a tracking pixel is, in the code
A tracking pixel is a small piece of code, usually a tiny transparent image, embedded in the body of an email. It is not attached: it is fetched from a remote server when the email is displayed.
That request tells the sender the email was opened, when, and by whom — the image address usually carries an identifier unique to each recipient. The ICO lists its other names: web beacon, web bug, 1x1 GIF, spy pixel, clear GIF.
<!-- open tracking -->
<img src="https://mail.exemple-esp.com/o.gif?c=8412&u=a3f9d2e1c7&t=1755400981"
width="1" height="1" alt="" style="display:block;border:0" />
The rule: regulation 6 of PECR
Since 5 February 2026, regulation 6 reads: subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user. That includes instigating the storage or access, and collecting information the device emits automatically.
Unless an exception applies, the ICO's reading is three steps: tell people what the technologies are, explain what they do, and obtain prior consent for their use. Consent means UK GDPR consent.
On email, the ICO's wording is conditional. Most email marketing is governed by regulation 22, it says, but where tracking pixels store information, or gain access to information stored, on a user's device, regulation 6 applies.
The email and the pixel: two separate rules
The ICO says it in its guidance on direct marketing by email: the electronic mail marketing rules in PECR apply to the email itself, not to the tracking pixels. If the email includes tracking pixels, you must comply with the rules on storage and access technologies.
| Rule | What it governs | What it requires |
|---|---|---|
| PECR regulation 22 | Sending marketing emails to individuals. | Prior consent to receive them, unless the soft opt-in applies. |
| Regulation 22(3), soft opt-in | An exception for sending to existing customers. | Details obtained in a sale or negotiation, similar products and services, and a simple way to refuse at collection and in every message. |
| PECR regulation 6 | Storing or accessing information on the device. | Clear and comprehensive information and consent, unless a Schedule A1 exception applies. |
| UK GDPR | Processing the personal data collected. | Where no exception applies, PECR consent means consent is the lawful basis too. |
So does the soft opt-in cover the pixel?
Not on the texts. The soft opt-in is an exception within regulation 22, and regulation 22 says nothing about storing or accessing information on a device. The ICO places the pixel under regulation 6, whose exceptions are listed in Schedule A1 — and the soft opt-in is not one of them.
The ICO does not write that sentence in so many words; it follows directly from its two guidance documents. The same reasoning applies to the new soft opt-in for charities in regulation 22(3A).
The exceptions, and what they are not for
Schedule A1 to PECR, inserted by the Data (Use and Access) Act 2025 and in force since 5 February 2026, lists five exceptions. Two are old — transmission, and strictly necessary. Three are new: statistical purposes, appearance and functionality, and emergency assistance.
Neither the legislation nor the ICO's guidance says whether an email open pixel can fall within any of them. What the ICO does say points away from per-recipient tracking.
Strictly necessary
Storage or access strictly necessary to provide an information society service the user requested. Security, fraud prevention and authentication are examples within it, not separate exceptions.
Conditions
- Judged from the point of view of the subscriber or user, not your own.
What it does not cover
- Advertising: the ICO says no advertising purposes meet the strictly necessary exception, and counts ad measurement and performance as advertising.
Statistical purposes
Collecting statistics about how an information society service or website is used, with a view to improving it.
Conditions
- Clear and comprehensive information about the purpose.
- A simple means of objecting, free of charge — and the person has not objected. Without it, the ICO says, what you are doing is not in line with the exception.
- Data shared only with those helping to improve the service; a third-party analytics provider must be a processor.
What it does not cover
- Identifying, tracking or monitoring people: the ICO says the exception is about how your service is used, not about who uses it.
- Keeping individual-level data once it has been aggregated.
- Online advertising purposes.
Appearance and functionality
Adapting the appearance or functionality of a website to the user's preferences, subject to the same information and objection conditions.
One more rule matters for email, where one pixel often does several jobs: if one purpose falls within an exception and another does not, you must get consent for the storage or access.
Getting and withdrawing consent
Where consent is needed, it is UK GDPR consent: freely given, specific, informed and unambiguous, by a statement or a clear affirmative action. The ICO does not describe a mechanism specific to email; its general requirements are these.
-
1
A clear affirmative action
No pre-ticked boxes, and nothing set off before consent is given.
-
2
Clear and comprehensive information
Which technologies, for what purposes, which third parties store, access or receive the information, and for how long.
-
3
Not buried in terms and conditions
Consent must be specific: agreeing to receive emails is not, by itself, agreeing to be tracked.
-
4
Refusing as easy as accepting
The option to refuse carries the same weight as the option to accept.
-
5
Withdrawal with the same ease
When someone withdraws, stop the storage or access, stop the processing and tell third parties. The ICO says to treat a withdrawal of consent as a request for erasure.
Tracked links
The ICO has no section on email click tracking as such. Its guidance covers link decoration and navigational tracking: regulation 6 applies where these techniques involve storing or accessing information on a device, and the key consideration is the purpose.
In its examples, a link that only carries a campaign source is described as link decoration; a user identifier added to the URL and then stored in a cookie falls under regulation 6. The strictly necessary exception is recognised for link decoration only to authenticate a user.
Who is responsible, and the penalties
The sender
As the service provider, you have the primary responsibility for compliance with PECR, including for third-party technologies you choose to use.
Your email platform
The guidance does not classify email service providers. Roles under UK GDPR — controller, processor, joint controller — are yours to establish.
Up to £17.5 million or 4 % of turnover
For a breach of regulation 6 or 22 committed on or after 5 February 2026, the higher maximum of the Data Protection Act 2018 applies. Earlier breaches stay under the previous regime.
Organisations outside the UK
PECR has no specific rules for organisations based outside the UK; a UK organisation hosted abroad remains covered. UK GDPR can apply to monitoring people in the UK.
As at 15 September 2026, the ICO's own enforcement chapter still says it will be updated once the new regime is in force, while the legislation gives 5 February 2026. We found no ICO penalty or reprimand about pixels in emails; our search of its enforcement records was not exhaustive.
How we got here
-
2003
The regulations
Privacy and Electronic Communications Regulations
Regulation 6 implements Article 5(3) of the ePrivacy Directive; regulation 22 governs email marketing.
-
Dec 2024
Consultation
Draft update of the ICO's cookies guidance
Renamed guidance on storage and access technologies.
-
Jun — Jul 2025
The Act
Data (Use and Access) Act 2025
Royal Assent on 19 June 2025; a second ICO consultation in July on the new exceptions.
-
5 Feb 2026
In force
New regulation 6, Schedule A1 and the new penalty regime
Commenced by S.I. 2026/82.
-
29 Apr 2026
Final guidance
ICO guidance on storage and access technologies
With two additions: the simple means of objecting, and multiple purposes.
-
May 2026
Next
ICO advice to government on online advertising
On possible changes to regulation 6 for lower-risk online advertising. The ICO stresses that nothing has changed at this stage.
And in the United States?
There is no US federal rule on tracking pixels in emails. The CAN-SPAM Act governs sending — honest headers, identification, opt-out — and does not mention pixels.
The exposure is litigation under state laws. Plaintiffs have brought class actions under Arizona's Telephone, Utility and Communication Service Records Act and California's Invasion of Privacy Act. Every decision we found on email pixels has dismissed the claims.
| Case | Court and date | Outcome |
|---|---|---|
| Carbajal v. Home Depot | D. Ariz., 16 December 2024 | Dismissed: marketing emails and pixels are not covered by the Arizona statute. |
| Williams v. Pacific Sunwear | D. Ariz., 16 April 2025 | Judgment on the pleadings for the defendant, on the same ground. |
| Ramos v. The Gap | N.D. Cal., 29 July 2025 | Dismissed without leave to amend: the court held that email open rates are not content under CIPA section 631. |
| Smith v. Target | Arizona Court of Appeals, 13 November 2025 | Dismissal affirmed, the first appellate ruling: retailer email metrics are not communication service records. |
What the headlines mix up
The $10 million Forbes settlement, preliminarily approved on 11 June 2026, and the Wayfair ruling concern trackers on websites, not pixels in emails.
California's CCPA names pixel tags in its definition of a unique identifier, so data from an email pixel can be personal information under that law. We found no enforcement action on email pixels.
The risk in the US today is the cost of defending class actions on theories that have so far failed for email — not an established line of judgments against senders.
What do your emails actually contain?
The free audit reads one of your sends as a recipient receives it and shows the tracking pixels and tracked links it contains, each with the code excerpt that evidences it. It makes no legal assessment: it shows what is there.
Frequently asked questions
The questions we are asked most, with the answer as it follows from the texts. Where the texts are silent, we say so.
Are tracking pixels in emails banned in the UK?
Does the soft opt-in cover tracking pixels?
Does consent to the newsletter cover the pixel?
Does the new statistical exception cover open rates?
What if one pixel serves several purposes?
Are tracked links covered?
What about transactional emails?
What is the maximum fine?
Are US companies being fined for email pixels?
The same question, in other countries
The pixel is the same everywhere; the texts that govern it are not. Each page is written in the language of its country, from the texts of its own regulator.
-
France · CNIL
Pixels de suivi dans les emails : la règle CNIL, expliquée simplement -
Deutschland · § 25 TDDDG
Zählpixel in E-Mails: Was § 25 TDDDG verlangt, verständlich erklärt -
España · AEPD
Píxeles de seguimiento en el correo electrónico: lo que exigen la LSSI y la AEPD -
Italia · Garante privacy
Pixel di tracciamento nelle email: le linee guida del Garante, spiegate
Sources
Everything above is drawn from the texts below. The links go to the original publications, so you can read them yourself rather than take our word for it.
-
Guidance on the use of storage and access technologies
Information Commissioner's Office, final guidance, 29 April 2026.
-
What are storage and access technologies? — Tracking pixels
ICO: regulation 22 and regulation 6 for pixels in marketing emails.
-
What are the exceptions?
ICO: strictly necessary, statistical purposes, appearance and functionality.
-
Guidance on direct marketing using electronic mail — What else do we need to consider?
ICO: the email marketing rules apply to the email itself, not to the tracking pixels.
-
The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 6
As substituted by the Data (Use and Access) Act 2025, in force 5 February 2026.
-
PECR, Schedule A1 — exceptions
Inserted by the Data (Use and Access) Act 2025.
-
PECR, regulation 22 — use of electronic mail for direct marketing
Including the soft opt-in, regulation 22(3).
-
The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
S.I. 2026/82.
-
Smith v. Target Corp.
Arizona Court of Appeals, Division One, No. 1 CA-CV 25-0120, 13 November 2025. Copy published on CourtListener.
-
Ramos v. The Gap, Inc.
U.S. District Court, N.D. California, No. 4:23-cv-04715-HSG, order of 29 July 2025.
This page is an explanatory summary written from the texts cited. It is not legal advice and not a statement by the ICO. For how it applies to you, speak to your data protection officer or adviser.