Hi, {{first_name|friend}}. 👋
Welcome to Issue #254 of All About Email!
Last week, my guest author Travis Hazlewood stole the headlines as my most popular newsletter of the last ten weeks! So, if you missed it, check it out.
This week, I'm back with Part Two of my deep dive into the CNIL, asking: “Should we just turn open tracking off?”
Let’s go! 👇
Build Income on Both Sides of the Link.
Upgrade your daily content with fresh career opportunities curated for your community. Whether it is a "Day in the Life" or a weekly roundup, Jobstream™ lets you share real jobs, help your audience earn, and get paid when they apply. Join Jobstream™ and apply to become part of the Career Creator Network™.
⚠️ Before we get stuck in, I am not a legal professional or a privacy expert (although I am a big privacy advocate, and cover topics like this often), so the below is not legal advice; check with your organisation’s legal support.
🚨 If you missed Part One in Issue #252, you might want to check that out, as I looked at why simply identifying your “French and Italian contacts” and disabling open tracking for them isn't the neat compliance solution it first appears to be.
That leaves us with a tough question:
If recipient-level tracking consent is still difficult or impossible on many ESPs, should we just turn open tracking off altogether?
It sounds drastic. But given how unreliable open data has already become, maybe it's a conversation we should be having anyway.
The Case for Just Turning It All Off
🤔 Given all of this, what about the option that most compliance guides mention briefly and then skip past: turning off open tracking globally, for everyone, full stop.
If no recipient-specific tracking pixel, or any equivalent open-tracking resource, is included, there is no open-tracking consent to obtain in France or Italy and no separate open-tracking consent signal to maintain for each contact.
🧠 That does not remove the need to document permission to send the email, or address any other tracking you still use.
🚨 One important caveat: a setting labelled “open tracking off” does not necessarily mean the tracking pixel is removed.
Customer[dot]io says it excludes the pixel when tracking is withheld. Klaviyo says its pixel still loads, but the open is not recorded, while HubSpot says it may continue collecting anonymous open data to support its sending infrastructure.
💡 Before treating a global switch as the complete answer, check exactly what your ESP disables: the pixel itself, individual recording, or merely the reporting attached to it.
A Note on the Data You Are Losing
🚨 A recorded open doesn't necessarily mean someone read your email. It means the tracking image was requested. That request may have resulted from:
A recipient displaying the email with images enabled, without necessarily reading it.
Apple Mail Privacy Protection downloading its remote content in the background, whether the recipient engages with the email or not.
Gmail retrieving and caching the image through its proxy, obscuring some of the information that would otherwise accompany the request.
A security, privacy or other automated system fetching the image.
And the reverse is also true: someone can read an email without triggering an open at all if remote images are blocked.
💡 Open rate has not reliably measured "people who read the email" for years. I covered this in Issue #238. Removing it and rebuilding your measurement around better signals isn't just a compliance workaround; it's better practice:
Clicks, replies, registrations, purchases, downloads, preference updates, subscriber retention.
The things that actually tell you whether your email programme is working.
The Disadvantages Are Real Too
I'd be doing you a disservice if I didn't tell you about what switching it off could actually cost you (and this isn’t an exclusive list):
Subject line testing becomes harder without open rate as the primary signal.
Send-time optimisation loses an input.
Re-engagement programmes built around “hasn't opened in 90 days” need to be rethought:
If you use selective tracking, this creates the ghost reader problem I mentioned in Issue #239: someone can keep reading every email, but because they've opted out of open tracking, your ESP may classify them as inactive.
If you switch open tracking off globally, the problem changes. You no longer have a hidden subset of ghost readers; you can't use opens as an inactivity signal for anyone, so you have to rebuild your sunset and re-engagement logic around other behaviour.
Publishers reporting open-derived estimated impressions to sponsors lose that number.
Historical campaign comparisons break.
🚨 Those are real trade-offs. But they don't make unreliable or potentially unlawful tracking acceptable.
They show how much of the email marketing ecosystem has been built around a metric that stopped being dependable a while ago. The regulation may simply be forcing email marketing to admit it.
Don't Just Blindly Replace Opens with Clicks
This feels like the obvious answer. And as you know from Issue #237, my epic mess-up with click-based triggers, it comes with its own problems. Two of them, actually:
An Operational Problem
💡 As I discovered the hard way, some of your most engaged readers may never click a thing:
The privacy-conscious ones who already block open tracking are often the same people stripping tracked links before they click.
I do it myself: copy the URL, strip the parameters, paste it into a browser. The click never registers, but the content gets consumed.
A Legal Problem
🚨 Tracked clicks are not automatically outside privacy scrutiny either.
The EDPB's own Guidelines 2/2023, which CNIL explicitly cites, cover tracking links as well as pixels.
Personalised redirect URLs, the kind most ESPs use to track clicks, can identify individual recipients and raise ePrivacy questions.
Connecting a click to subsequent website activity can involve cookies, CRM matching, and further profiling.
Turning off open tracking doesn't give you a free pass to make click tracking more invasive. The goal is better measurement, not just different invisible tracking.
🧠 Clicks are a better signal than opens. But swap one for the other and call it done? That's not a strategy. We need to start building a broader, more defensible signal mix of engagement that’s relevant to our audiences and brands.
Where This Leaves Marketers
I’ve talked about this before in Issue 239, but here’s a little refresher of what I’ve come up with, and bearing in mind this isn't legal advice, and your DPO should be involved before anything structural changes.
💡 Some of the things I'm suggesting you might not be able to do with your ESP right now, and for me, that's the case:
Ask Your ESP
Can your ESP prevent consent-requiring open tracking for a recipient who hasn't consented?
You could then ask separately how that is technically achieved.
Audit What Depends on Opens
Map every flow that uses individual open data.
Automations, engagement segments, lead scores, sunset policies, resend-to-non-openers.
Separate deliverability management (suppression, sunset logic) from marketing optimisation (segmentation, personalisation, send-time testing).
🚨 These now have different rules and different consent requirements/exemption analyses.
Stop Using Open Data for Profiling and Sales Activity
Where you don't have valid consent, stop. Those uses are hard to fit within either regulator's narrow exemptions, and they're the highest-risk use cases if enforcement comes.
Add a Tracking Consent Withdrawal Link to Your Footer
💡 This is separate from a normal unsubscribe. No re-entry of the email address, effective immediately, and it needs to work for emails already in the inbox, not just future sends.
🤔 Beehiiv still can’t do this. Brevo and Customer[dot]io provide recipient-facing withdrawal mechanisms, while Klaviyo says a consent-status change stops it recording opens even from emails already in the inbox.
But I still haven’t found public documentation confirming that any of them natively provide all three elements together: a one-click withdrawal link, immediate effect, and explicit neutralisation of tracking from previously delivered emails.
Check Your Open Data Storage
Under the CNIL's individual deliverability exemption, you should retain only the “date”, not the timestamp of the last known open, overwritten with each new interaction.
If your ESP is storing a full engagement history, you cannot rely on that narrow exemption to justify a full individual open history.
💡 For now, I'd guess that's outside of most ESP users' control.
If Your ESP Can't Do Recipient-Level Controls, Consider Disabling Globally
A conservative global switch removes the guessing game entirely.
A France-and-Italy-only segment based on email domains may reduce risk, but it shouldn't be presented as a complete compliance solution. (It isn't.)
And Talk to Your Legal Team
🚨 Before making any compliance decisions, a "recommendation" from a regulator has a way of becoming something else entirely when enforcement starts, which it has for the CNIL.
Before You Go
🤔 Maybe the real mistake is treating open tracking as something we have to save?
We’ve spent years building subject-line tests, sunset policies, engagement scores and sponsor reporting around a signal that no longer reliably tells us whether someone actually read the email.
💡 The CNIL and Garante may be forcing a conversation about compliance, but perhaps the more useful question is whether this is the push we needed to build better measurement in the first place.
For more information on this topic, check out Issues 252, 238, and 239.
That's it for this week, {{first_name|friend}}. 👋
Simon
All About Email - Playlist 🎧
Every week, as I write this newsletter, I'll share the track of the moment to create an unbelievably eclectic playlist just for your inbox.
Sponsorship Opportunities
🚨 If you’re interested in sponsoring the “All About Email” newsletter, you can find all the details in this Google Doc.
One idea shouldn't take six rewrites to post.
Posting everywhere means rewriting one idea six times, so you post to one, or none. SureThing turns one idea into native posts for every platform.
Email Marketing News & Tips
This week's excellent and insightful email news & tips:
🎉 My Favourite Email of Last Year - How We Built a Personalised Wrapped Email. (Multiplied Media x Action Rocket)
Verified, not invited - What Gmail’s political sender program actually says about deliverability. (Mailgun & Alison Gootee)
😬 This Makes Me Nervous - Claude Can Now Press Send, Reply and FWD in Gmail Too. (Emailexpert)
Deliverability Analysis - Gmail Will Now Tell You, in Plain Language, Whether Users Want Your Email. (Emailtooltester)
U-Turn - Apple Not Changing "Hide My Email" Addresses After All. (Spam Resource)
An Opportunity - Use Surveys or Petitions to Grow. (Inbox Collective)
🐴 The Deliverab-Iliad, Chapter Nine - Troy, the Transactional Trojan Horse. (Alison Gootee)
If you have any questions about this email or email marketing, please reply, and I will get back to you as soon as possible.
I hope you have a great week! 👋




