Italy’s Data Protection Authority has issued new guidelines on tracking pixels used in email communications, requiring organisations to inform users and obtain consent before deploying the hidden monitoring tools.
Published on 17 April 2026, the Garante per la Protezione dei Dati Personali guidelines address the invasive nature of tracking pixels, which silently monitor whether recipients open and read emails without their knowledge.
Tracking pixels are tiny, often invisible images embedded in emails that automatically send information back to the sender when recipients open the message. The pixels can collect data, including device type, IP address, and exact time of access.
The Authority identified limited exceptions to the consent requirement, including statistical measurements of email open rates, security protocols during user authentication, and mandatory institutional communications such as fraud alerts or contractual notifications.
The guidelines allow organisations six months from publication to achieve compliance with the new standards. Users in Italy must be able to revoke consent easily and granularly, meaning they can withdraw permission for tracking whilst continuing to receive emails.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
