Искусственный интеллект · 1 июня 2025 · 4 мин чтения

Regulation of tracking pixels

In June 2025, France launched a public debate on a draft recommendation regarding the use of tracking pixels in electronic22 communications. Similar guidance has also23 been published in Norway.

Из выпуска мониторинга No. 6 (18), June 2025 · выпуск целиком, PDF · на сайте Института Гайдара

Experience of France and

Norway

In June 2025, France launched a public debate on a draft recommendation regarding the use of tracking pixels in electronic1 communications. Similar guidance has also2 been published in Norway.

A tracking pixel is a special tracking technology representing an image (1x1 pixel in size) that is embedded in emails (as well as advertisements, browsers, etc.) and allows collecting data on user activity (e.g., whether the email was read, time the email was opened, IP address, device and browser from which the email was opened, geolocation, etc.). Pixels are placed not in the email itself, but on remote servers (outside the site where the user is located), which makes it possible to collect user data on a remote server with further processing of such data.

When a user opens an email, an image of the pixel is automatically downloaded, sending a request to the server where the pixel is located. The request contains technical data, including IP address, device and browser information, timestamp, and so on. - at which point the user activity data is received by the server. That is, the pixel itself does not collect any information, but the fact that it is downloaded allows the sender of the email to receive information that a particular email was viewed by a certain user, the time of viewing, geolocation, and so on.

Regulators are focusing on developing rules specifically for this technology due to the rise in lawsuits. For example, in 2022, lawsuits were filed against a one-third of the 100 largest US hospitals that sent sensitive data to Facebook via pixels on their websites.

Technology enables the collection of data about the recipient of the email, so regulators in France and Norway recommend the following:

1. Consider that the sender of the e-mail message becomes the controller of the data collected through the tracking pixels, as it is the sender who decides whether to use the technology to collect the data, as well as determining the goals of data processing.

The email service provider ensures that users' emails are received and displayed, it does not affect senders' use of pixels (although it may block automatic image uploads), so it is neither a data processor nor a data controller.

2. Embedding tracking pixels in emails will require prior consent from the recipient:

− When analyzing the opening of emails. For example, if a sender is evaluating their marketing strategies (how often recipients read emails, how attractive the email headers are, etc.) to improve email readability, adjust the frequency of sending emails, etc.

− When individually analyzing the recipient's interest in emails to personalize content, e.g., customizing the content of emails depending on the identified preferences and interests of the recipient; personalizing the sending channel (email, SMS, push notifications, etc.) depending on which channel the recipient uses more often.

Consent is not required for:

− Using pixels for security and user authentication. A pixel allows you to make ensure that an email with a password reset link is opened on a device that belongs to a specific user.

− When measuring the statistics of opened emails. In this case, you should use pixels for anonymous statistics, without individually tracking individual users.

3. The purpose of using pixels should be disclosed. For example, recipients could be warned to the recipient that when they open the email, information about their actions may be used to display personalized ads or content on other platforms.

4. Consent to use pixels can be requested at the time of consent to send emails, warning that pixel tracking will occur when the email is opened.

5. There should be a simple procedure for withdrawing consent to the use of tracking pixels. For example, it is recommended that a link to withdraw consent be included in every email containing the pixel. This link should lead to a site where consent can be withdrawn without additional steps (e.g., entering an email address).

Russia’s experience

Today in Russia, Roskomnadzor does not issue special guidelines on the use of tracking technologies, including such technologies as cookies. However, behavioral data collected by such tracking technologies fall under the definition of personal data provided for in Federal Law No. 152 “On Personal Data”. In particular, Russian courts qualify cookie data as3 personal data. Thus, data collected through tracking pixels is subject to the same legal protection as other personal data.


From the monitoring issue No. 6 (18), June 2025. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также

Искусственный интеллект

AI under cover

1 мая 2026
Искусственный интеллект

Trust the system

1 марта 2026