Skip to main content

Email Tracking Consent

warning

This article is not legal advice. It describes what Paminga can do; which contacts the rules apply to, and what your consent language should say, is a decision for you and your counsel.

Email open tracking works by placing an invisible image in each email. When the recipient's mail client loads that image, the sender learns the email was opened, when, and from which device. In April 2026 France's data protection authority, the CNIL, published its recommendation treating that image the way it treats cookies: for marketing purposes, it requires the recipient's prior, specific consent. In most cases that consent has to be asked for separately from the consent to receive the email; the CNIL allows a single consent only where the pixel serves the same purpose as the emails it sits in, so treat "separate" as the safe default. Recipients must be able to withdraw that consent as easily as they gave it, from a link in every email. Italy's Garante adopted a similar position the same month.

Paminga lets you record that consent per contact, honors it automatically wherever emails go out, and gives every recipient their own page to grant or withdraw. You keep sending; what changes is whether the open pixel is in the email.

Every contact carries an Email Tracking Consent field with one of three values:

  • Granted — the contact gave a positive answer. Their opens are tracked.
  • Denied — the contact refused, or granted and later withdrew. Their opens are never tracked, whatever your settings say.
  • Unknown — you have not asked, or they did not answer. What happens next is up to your policy.

This is a separate field from the long-standing GDPR Consent field, because the CNIL requires the two consents to be collected separately.

Every change to the field is recorded with when it happened, how it reached Paminga (a form, an import, the consent page, a user editing the contact), and the IP address and browser when the contact acted themselves. That is the proof of consent the regulation asks you to be able to produce. You will find each change in the contact's activity stream under Privacy/GDPR & Email Tracking Consent.

In a Form

Map a checkbox element to the Email Tracking Consent field. A checked box records a grant. An unchecked box records nothing: leaving the box empty is not a refusal, and the box must not be pre-checked.

Keep the checkbox separate from your marketing opt-in, and say plainly who is tracking and what for. Something like: "[Your company name] may track when I open its emails, on any device I use to read them, so it can measure and improve its campaigns." Name every organization that will rely on the consent; a placeholder left in is not a consent.

On the Contact Record

Set the field directly under Miscellaneous on the contact details page, for consent you collected elsewhere. The activity stream records who set it.

Through the API

email_tracking_consent accepts GRANTED, DENIED, or UNKNOWN on the contact create, update, and upsert mutations.

From the Email Itself

Every recipient gets their own email tracking preferences page, reached from the footer link in your emails. Nothing happens when the page is opened; the recipient chooses Allow open tracking or Do not track my opens and the choice is recorded with the conditions it was made under. A contact who withdraws stays untracked even when they reopen an email you sent before they withdrew.

Choosing a Policy for Unknown

Granted is always tracked and Denied is never tracked. The only decision left is what to do with contacts you have not asked.

Account Setting

Under Account Settings → Automation Settings, turn on Require Consent to Track Email Opens. Every automation you create from then on starts with the matching checkbox selected, and any email Paminga sends outside an automation (a form autoresponder, an action set) follows this setting directly.

Per Automation

On an automation's Settings step, under Misc, the checkbox Only track email opens for Contacts who have granted Email Tracking Consent applies the policy to that automation alone. Use it when only some of your audience is affected: turn it on for the automations that reach French contacts and leave the rest alone.

The neighboring Disable Tracking of Email Opens and Clicks in this Automation checkbox is the blanket switch. When it is on, nobody in that automation is tracked, opens or clicks, regardless of consent.

What Happens at Send Time

When an email goes out, Paminga sorts the recipients by whether their opens may be tracked and sends the untracked group without the open pixel. The email itself is identical; only the invisible image is missing. Bounces and unsubscribes are unaffected, and so are clicks unless you turn on Also apply to click tracking under the account setting: then the same contacts also get plain, untracked links. Links still work; the clicks are not recorded or attributed.

Each recipient's send is recorded with whether the pixel was included. Untracked sends still count as sends in your reports, so open rates read lower for an audience with many untracked contacts, just as they would with any recipient whose mail client blocks images. The number of untracked sends per automation is available through the API.

The CNIL asks for a withdrawal link in the footer of every email that carries a pixel. In the Email Builder, the Footer element now includes a Manage email tracking preferences link, and the same link is available on its own as the Tracking Preferences element. Each recipient's copy links to their own preferences page.

Add it to transactional emails too. Consent applies to every email you send, so the link belongs in every email, including the ones that go out without a pixel.

Product

PricingFAQPaminga vs. MarketoMarketo to Paminga TranslatorMarketo Alternative
Paminga Logo
LinkedInFacebookXYouTube
ISO 27001 CompliantSOC 2 Compliant

Built with pride in Denver, Colorado, USA

Copyright © Paminga, Inc. 2026
All rights reserved. Various trademarks held by their respective owners.