Aller au contenu
Audit an email
Guide · United Kingdom Updated 15 September 2026 11 min read

Also emailing recipients in France? The French rule, set by the CNIL, has its own page, translated into English: Tracking pixels in emails: the CNIL rule, explained simply

Tracking pixels in emails: what PECR and the ICO require, explained

The ICO published its final guidance on storage and access technologies on 29 April 2026. It draws a line many marketing teams miss: the rules on email marketing govern the email, and a different rule governs the tracking pixel inside it.

This page explains that line without jargon: what a pixel does, why the soft opt-in does not reach it, what the exceptions introduced by the Data (Use and Access) Act 2025 cover, and where the United States stands.

The short answer

Pixels are not banned.

Where a pixel stores or accesses information on the recipient's device, regulation 6 of PECR applies: consent, unless an exception does.

The soft opt-in covers the email, not the pixel.

Regulation 22 lets you send to existing customers. The ICO places pixels under regulation 6, which has its own exceptions.

The new exceptions are not for tracking people.

The statistical exception is about how a service is used, not who uses it. The ICO has not analysed email opens under any exception.

What a tracking pixel is, in the code

A tracking pixel is a small piece of code, usually a tiny transparent image, embedded in the body of an email. It is not attached: it is fetched from a remote server when the email is displayed.

That request tells the sender the email was opened, when, and by whom — the image address usually carries an identifier unique to each recipient. The ICO lists its other names: web beacon, web bug, 1x1 GIF, spy pixel, clear GIF.

Excerpt from an email's source code — the highlighted value identifies the recipient
<!-- open tracking -->
<img src="https://mail.exemple-esp.com/o.gif?c=8412&u=a3f9d2e1c7&t=1755400981"
     width="1" height="1" alt="" style="display:block;border:0" />

The rule: regulation 6 of PECR

Since 5 February 2026, regulation 6 reads: subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user. That includes instigating the storage or access, and collecting information the device emits automatically.

Unless an exception applies, the ICO's reading is three steps: tell people what the technologies are, explain what they do, and obtain prior consent for their use. Consent means UK GDPR consent.

On email, the ICO's wording is conditional. Most email marketing is governed by regulation 22, it says, but where tracking pixels store information, or gain access to information stored, on a user's device, regulation 6 applies.

The email and the pixel: two separate rules

The ICO says it in its guidance on direct marketing by email: the electronic mail marketing rules in PECR apply to the email itself, not to the tracking pixels. If the email includes tracking pixels, you must comply with the rules on storage and access technologies.

Rule What it governs What it requires
PECR regulation 22 Sending marketing emails to individuals. Prior consent to receive them, unless the soft opt-in applies.
Regulation 22(3), soft opt-in An exception for sending to existing customers. Details obtained in a sale or negotiation, similar products and services, and a simple way to refuse at collection and in every message.
PECR regulation 6 Storing or accessing information on the device. Clear and comprehensive information and consent, unless a Schedule A1 exception applies.
UK GDPR Processing the personal data collected. Where no exception applies, PECR consent means consent is the lawful basis too.

So does the soft opt-in cover the pixel?

Not on the texts. The soft opt-in is an exception within regulation 22, and regulation 22 says nothing about storing or accessing information on a device. The ICO places the pixel under regulation 6, whose exceptions are listed in Schedule A1 — and the soft opt-in is not one of them.

The ICO does not write that sentence in so many words; it follows directly from its two guidance documents. The same reasoning applies to the new soft opt-in for charities in regulation 22(3A).

The exceptions, and what they are not for

Schedule A1 to PECR, inserted by the Data (Use and Access) Act 2025 and in force since 5 February 2026, lists five exceptions. Two are old — transmission, and strictly necessary. Three are new: statistical purposes, appearance and functionality, and emergency assistance.

Neither the legislation nor the ICO's guidance says whether an email open pixel can fall within any of them. What the ICO does say points away from per-recipient tracking.

Strictly necessary

Storage or access strictly necessary to provide an information society service the user requested. Security, fraud prevention and authentication are examples within it, not separate exceptions.

Conditions

  • Judged from the point of view of the subscriber or user, not your own.

What it does not cover

  • Advertising: the ICO says no advertising purposes meet the strictly necessary exception, and counts ad measurement and performance as advertising.

Statistical purposes

Collecting statistics about how an information society service or website is used, with a view to improving it.

Conditions

  • Clear and comprehensive information about the purpose.
  • A simple means of objecting, free of charge — and the person has not objected. Without it, the ICO says, what you are doing is not in line with the exception.
  • Data shared only with those helping to improve the service; a third-party analytics provider must be a processor.

What it does not cover

  • Identifying, tracking or monitoring people: the ICO says the exception is about how your service is used, not about who uses it.
  • Keeping individual-level data once it has been aggregated.
  • Online advertising purposes.

Appearance and functionality

Adapting the appearance or functionality of a website to the user's preferences, subject to the same information and objection conditions.

One more rule matters for email, where one pixel often does several jobs: if one purpose falls within an exception and another does not, you must get consent for the storage or access.

Tracked links

The ICO has no section on email click tracking as such. Its guidance covers link decoration and navigational tracking: regulation 6 applies where these techniques involve storing or accessing information on a device, and the key consideration is the purpose.

In its examples, a link that only carries a campaign source is described as link decoration; a user identifier added to the URL and then stored in a cookie falls under regulation 6. The strictly necessary exception is recognised for link decoration only to authenticate a user.

Who is responsible, and the penalties

The sender

As the service provider, you have the primary responsibility for compliance with PECR, including for third-party technologies you choose to use.

Your email platform

The guidance does not classify email service providers. Roles under UK GDPR — controller, processor, joint controller — are yours to establish.

Up to £17.5 million or 4 % of turnover

For a breach of regulation 6 or 22 committed on or after 5 February 2026, the higher maximum of the Data Protection Act 2018 applies. Earlier breaches stay under the previous regime.

Organisations outside the UK

PECR has no specific rules for organisations based outside the UK; a UK organisation hosted abroad remains covered. UK GDPR can apply to monitoring people in the UK.

As at 15 September 2026, the ICO's own enforcement chapter still says it will be updated once the new regime is in force, while the legislation gives 5 February 2026. We found no ICO penalty or reprimand about pixels in emails; our search of its enforcement records was not exhaustive.

How we got here

  1. 2003

    The regulations

    Privacy and Electronic Communications Regulations

    Regulation 6 implements Article 5(3) of the ePrivacy Directive; regulation 22 governs email marketing.

  2. Dec 2024

    Consultation

    Draft update of the ICO's cookies guidance

    Renamed guidance on storage and access technologies.

  3. Jun — Jul 2025

    The Act

    Data (Use and Access) Act 2025

    Royal Assent on 19 June 2025; a second ICO consultation in July on the new exceptions.

  4. 5 Feb 2026

    In force

    New regulation 6, Schedule A1 and the new penalty regime

    Commenced by S.I. 2026/82.

  5. 29 Apr 2026

    Final guidance

    ICO guidance on storage and access technologies

    With two additions: the simple means of objecting, and multiple purposes.

  6. May 2026

    Next

    ICO advice to government on online advertising

    On possible changes to regulation 6 for lower-risk online advertising. The ICO stresses that nothing has changed at this stage.

And in the United States?

There is no US federal rule on tracking pixels in emails. The CAN-SPAM Act governs sending — honest headers, identification, opt-out — and does not mention pixels.

The exposure is litigation under state laws. Plaintiffs have brought class actions under Arizona's Telephone, Utility and Communication Service Records Act and California's Invasion of Privacy Act. Every decision we found on email pixels has dismissed the claims.

Case Court and date Outcome
Carbajal v. Home Depot D. Ariz., 16 December 2024 Dismissed: marketing emails and pixels are not covered by the Arizona statute.
Williams v. Pacific Sunwear D. Ariz., 16 April 2025 Judgment on the pleadings for the defendant, on the same ground.
Ramos v. The Gap N.D. Cal., 29 July 2025 Dismissed without leave to amend: the court held that email open rates are not content under CIPA section 631.
Smith v. Target Arizona Court of Appeals, 13 November 2025 Dismissal affirmed, the first appellate ruling: retailer email metrics are not communication service records.

What the headlines mix up

The $10 million Forbes settlement, preliminarily approved on 11 June 2026, and the Wayfair ruling concern trackers on websites, not pixels in emails.

California's CCPA names pixel tags in its definition of a unique identifier, so data from an email pixel can be personal information under that law. We found no enforcement action on email pixels.

The risk in the US today is the cost of defending class actions on theories that have so far failed for email — not an established line of judgments against senders.

What do your emails actually contain?

The free audit reads one of your sends as a recipient receives it and shows the tracking pixels and tracked links it contains, each with the code excerpt that evidences it. It makes no legal assessment: it shows what is there.

Frequently asked questions

The questions we are asked most, with the answer as it follows from the texts. Where the texts are silent, we say so.

Are tracking pixels in emails banned in the UK?

No. Where a pixel stores or accesses information on the recipient's device, regulation 6 of PECR requires information and consent unless an exception applies.

Does the soft opt-in cover tracking pixels?

Not on the texts. The soft opt-in is an exception to regulation 22, which governs sending the email; the ICO says those rules apply to the email itself, not to the tracking pixels, which fall under regulation 6.

Does consent to the newsletter cover the pixel?

The ICO does not say so for email. Consent must be specific and informed, and consent to receive emails is not, by itself, consent to be tracked.

Does the new statistical exception cover open rates?

The ICO has not analysed email opens under it. It describes the exception as being about how a service is used, not who uses it, and not for identifying, tracking or monitoring people — which excludes per-recipient open tracking.

What if one pixel serves several purposes?

If one purpose falls within an exception and another does not, the ICO says you must get consent for the storage or access.

Are tracked links covered?

There is no ICO guidance on email click tracking as such. Regulation 6 applies where link tracking involves storing or accessing information on a device, and the ICO's key test is the purpose.

What about transactional emails?

Regulation 22 only concerns direct marketing; regulation 6 concerns any technology, whatever the email. The ICO has not published an analysis specific to transactional emails.

What is the maximum fine?

For a breach of regulation 6 or 22 on or after 5 February 2026, £17.5 million or 4 % of total annual worldwide turnover, whichever is higher.

Are US companies being fined for email pixels?

There is no federal rule on them. Class actions have been brought under Arizona and California laws, and every decision we found on email pixels dismissed the claims. Settlements reported in the press concern website trackers.

The same question, in other countries

The pixel is the same everywhere; the texts that govern it are not. Each page is written in the language of its country, from the texts of its own regulator.

Sources

Everything above is drawn from the texts below. The links go to the original publications, so you can read them yourself rather than take our word for it.

This page is an explanatory summary written from the texts cited. It is not legal advice and not a statement by the ICO. For how it applies to you, speak to your data protection officer or adviser.