Hi, {{first_name|friend}}. 👋
Welcome to Issue #252 of All About Email!
Last week, we were back with another summer guest author. Robert Brandl has built this awesome Chrome Extension (I use it), and that comes with a serious amount of data, as we looked at what the email platforms behind 16,655 brands can tell us.
This week, I'm returning to the CNIL and Garante tracking pixel story from Issues #238 and #239. The response to those two issues was fantastic, and a lot of what's been written publicly since has left me with a nagging feeling that something important is being missed.
Let’s go! 👇
That lead in your CRM? Gone.
Over 3.5 billion people open WhatsApp, Instagram, or Facebook Messenger every day. Your customers are already there, asking questions and comparing options.
Wati puts your business across WhatsApp, Instagram DM, Facebook Messenger, SMS, RCS, and web chat in one AI-powered inbox.
Automations instantly respond, route conversations, and keep every interaction tracked in one place.
Meet customers where they already are, before your competitor does.
⚠️ Before we get stuck in, I am not a legal professional or a privacy expert (although I am a big privacy advocate, and cover topics like this often), so the below is not legal advice; check with your organisation’s legal support.
If you are not familiar with this topic and you haven’t read Issues #238 and #239, start there before going any further.
The General July 14th Deadline has Passed
🚨 Some important things to note:
If you didn't notify existing subscribers by July 14th, you can no longer normally rely on the transitional arrangement, although the CNIL allows a reasonably justified extension in limited, documented circumstances.
Missing it doesn't mean you give up; you've lost the benefit of the transitional arrangement.
Italy's deadline, October 28th, 2026, is still live. So for those subscribers, there's time. But not as much as it looks.
"Just Identify Your French and Italian Contacts and Disable Tracking"
Since Issues #238 and #239, a common piece of advice has been appearing in articles and social posts:
Segment your French and Italian subscribers. Disable open tracking for them.
🚨 It sounds practical and actionable. But it rests on a false premise that most articles never actually examine; let me explain:
A French citizen living in the UK isn't automatically covered because they're French.
A UK tourist in Paris doesn't need to be French for French law potentially to apply when they open your email.
💡 Nationality, residence, current location, and what's in your CRM are not interchangeable legal tests:
An @orange[dot]fr address doesn't prove where someone lives, where they are when they open an email, or which law applies to the tracking.
A Gmail address tells you even less.
And CRM country fields? They may reflect a billing address, a company headquarters, a sign-up location, or something entered several years ago.
People move. People travel.
The dependency is on other things, which are much harder to segment:
Where the sender or controller is established.
Whether it has a relevant EU establishment.
Which audience it deliberately targets.
Where the user is located / where the person's behaviour is being monitored.
The CNIL actually made this clearer in its July FAQ. It says French law can apply to a non-EU organisation where pixels are used to monitor the behaviour of people located in France. Article 82 also specifically refers to its competence regarding users located in France.
🚨 Notice the wording: users located in France, not French citizens.
That doesn't mean someone's physical location automatically answers every territorial-scope question. Still, it does reinforce why identifying “French people” by nationality, email domain, or a CRM country field is the wrong starting point.
💡 Domain matching (@orange[dot]fr, @laposte[dot]net) and CRM country fields are useful proxies for identifying who is “likely” in France.
The advice isn't completely wrong. But you're making an educated guess, not achieving legal certainty, and you should frame it as such rather than present it as a complete compliance solution.
This is exactly the point Lauren Meyer raised back in April: determining who is "French" at the time of interaction isn't straightforward.
🤔 It's one reason a single global standard starts to look more defensible than segmenting by geography.
IP Geolocation Doesn't Solve It Either
The obvious response is: "use IP data to work out where someone is when they open."
Here's the problem with that:
The IP address is received when the remote image is requested. The tracking pixel has already fired before you can use the IP to estimate where the recipient might be.
🤔 You can't use data collected through a tracking operation to decide retrospectively whether that tracking operation should have happened.
And even setting that aside, IP geolocation in email is increasingly unreliable:
Apple Mail Privacy Protection, Gmail image proxying, security scanners, VPNs, corporate networks, and mobile carrier routing can all obscure the real location.
For Apple Mail users with MPP enabled, a significant chunk of most newsletter audiences, the IP your ESP logs is Apple's proxy server, not the user's IP address.
🚨 As I mentioned in Issue #238, MPP already compromised open rate.
The same problem that broke your open rate is now breaking your compliance location signal.
Where the ESPs Are, And Where Some Aren't
This isn't just me arguing that ESPs need to build better controls. In its July FAQ, the CNIL specifically tells service providers that their products should make it easier for customers to comply.
It says providers should offer functionality that supports:
Disabling trackers.
Treating recipients differently within the same mailing list.
Managing mailing lists based on a consent signal where consent is required
And Privacy by design and by default.
💡 The CNIL also says providers may offer functionality to collect that consent.
Since Issues #238 and #239, I've been watching which platforms have actually moved on this, although the below is not an exhaustive list:
Klaviyo
Per-recipient open-tracking controls and account-wide disabling are live, although recipient-level consent currently has to be populated via data import/sync or API
Native collection of open-tracking consent through Klaviyo sign-up forms is still listed as part of its next phase of work.
Customer[dot]io
Supports workspace-level tracking defaults, plus a per-contact consent attribute that can override those defaults.
That consent status can be updated via the API or imports, and recipients can manage their tracking preferences through a hosted consent page linked in the email footer.
Customer[dot]o also supports disabling tracking at the individual message level.
💡 That gives it a reasonably complete consent-management model: a default policy, recipient-level overrides, and a way for subscribers to change their preference themselves.
The remaining question I’d still like answered is whether withdrawing consent also neutralises tracking of emails already in the inbox, which the CNIL now expects providers to handle.
HubSpot
HubSpot appears to support disabling tracking at the individual email level. Still, I haven't found clear public documentation showing a native per-contact open-tracking consent control equivalent to what Klaviyo or Brevo now offer.
That means the practical workaround still seems to involve sending separately configured tracked and untracked versions of an email to different audience segments.
The problem, as we've already discussed, is that this pushes the hard part back onto the marketer: how do you reliably determine which contacts should receive the untracked version in the first place?
💡 Until HubSpot documents a true recipient-level tracking-consent mechanism, I'd treat its current position as more of a campaign-level workaround than a complete consent-management solution.
Mailchimp
Has a per-campaign toggle for marketing emails: manual, no global or segment-level kill switch.
Mailchimp Transactional/Mandrill does have global Sending Defaults for open tracking, plus per-message API/SMTP overrides.
Brevo
Per-contact consent for email open and click tracking is now supported, with Yes/No/Unknown consent states stored for each contact.
Consent can be collected through Brevo sign-up forms and update-profile forms, and recipients can withdraw tracking consent through a dedicated link in the email footer.
Brevo also supports API-based consent updates and lets senders decide how to treat contacts with an Unknown tracking status.
Brevo strongly recommends setting the default for Unknown contacts to No, so tracking is not enabled unless a positive consent signal exists.
💡 That puts Brevo much closer to the recipient-level model the regulators are asking ESPs to support, rather than relying on a blanket country segment or account-wide switch-off.
Brevo’s implementation covers both open and click tracking, which is broader than Klaviyo’s current documented recipient-level control, which is specifically focused on open tracking.
🧠 That distinction is useful because it shows different ESPs are interpreting and implementing the regulatory requirements differently.
The Sound of Silence (Love that song!)
🚨 And then there are the platforms that have said nothing, including Beehiiv, my ESP.
There's no documentation of tracking consent controls, no per-contact suppression, no global tracking disable for email opens, and no public statement about CNIL compliance that I can find.
But Beehiiv isn't alone. Several platforms are in the same position, and if you're on one of them, the questions I'm raising here apply just as much to you.
💡 French compliance consultancy Dipeeo goes further in its CNIL guide. It recommends that if your email platform cannot disable tracking pixels or otherwise implement the required controls, you should consider whether the provider remains suitable for your compliance needs.
Dipeeo links that back to Article 28 GDPR, which requires controllers to use processors that provide sufficient guarantees around appropriate technical and organisational measures.
🚨 That does not mean Article 28 automatically says “your ESP has no tracking toggle, therefore you must leave.” The assessment is broader and depends on the processing, available safeguards, and how the service is configured.
But if your ESP cannot technically enable you to comply with a regulatory requirement, processor suitability becomes a legitimate question.
I’m not saying switch… I’m saying it’s a question worth asking.
Before You Go
That’s a lot to take in, and I have even more to say on the topic. 😂
A lot of the compliance guides that have appeared since July 14th are genuinely well-intentioned (like my articles), and some have useful platform-specific detail.
But the “identify your French contacts and segment them” framing that runs through almost everything is not the complete answer; it’s a practical starting point.
💡 The IP chicken-and-egg problem, where the pixel has already fired before you can determine location, is a gap that almost no article addresses.
So, I’ll leave you with this:
The same privacy technologies that destroyed the accuracy of open-rate measurement also undermine IP-based attempts to decide whether somebody should be tracked.
And if identifying the “right” recipients isn’t dependable, and your ESP cannot manage consent properly at the recipient level, there is another option: stop tracking opens altogether.
That comes with consequences of its own, of course.
But maybe the answer to a tracking-consent problem isn’t better geographical tracking. Maybe it’s accepting that open tracking isn’t worth preserving in its current form.
🫠 I’m going to guess this is where some of us are right now:
Making an informed estimate using imperfect tools, given that the CNIL is aware of these technical limitations.
Documenting what you’re doing, reducing the risks you can, and actively trying to close the gaps is clearly better than ignoring the issue altogether. But it still isn’t the same as meeting all applicable requirements.
🤔 Is this where most of us will sit until ESPs catch up?
For some platforms, that’s happening now. For others, including mine, we’re still waiting.
And in a couple of weeks, I’m going to look at the other option properly: what actually happens if we switch off open tracking?
That's it for this week, {{first_name|friend}}. 👋
Simon
All About Email - Playlist 🎧
Every week, as I write this newsletter, I'll share the track of the moment to create an unbelievably eclectic playlist just for your inbox.
Sponsorship Opportunities
🚨 If you’re interested in sponsoring the “All About Email” newsletter, you can find all the details in this Google Doc.
The tool your team adopts next quarter is in today's issue. TLDR AI is curated by Anthropic and ex-Google engineers and read by 1.1M+ people who like being first. Free, daily.
Email Marketing News & Tips
This week's excellent and insightful email news & tips:
It’s not about spam word - What do you think you can change in your email program this week? (Edward Ma)
EVP Update - Food for thought. (Kyle Renfrew)
The Easiest Mistake? - Google Adds New Gmail Warning To Help Prevent BCC Privacy Mistake. (Forbes)
Forced Dark Mode - Confusing, isn’t it? (Mark Robbins)
Gmail Blue Checkmarks - Why Are Major Brands Letting Them Expire? (Emailtooltester)
Visibility - Add a sign-up to your header or nav. (Inbox Collective)
Is it even worth it? - A/B testing...wasted or worth the hype? (Email Advice in Your Inbox)
If you have any questions about this email or email marketing, please reply, and I will get back to you as soon as possible.
I hope you have a great week! 👋




