Skip to Content

CNIL COMPLIANCE

Permission to reach the inbox is not permission to measure it.

A weak subject line shows up as a low open rate. A bad list shows up as bounces. A tracking pixel loading without tracking consent shows up as nothing at all — it renders, the opens come back, the campaign report looks healthy. Nothing on the surface separates a measurement you were entitled to take from one you weren't. You find out at the point where it costs most to find out: a complaint, an audit, a request to produce the exact wording a contact saw at sign-up. And the answer CNIL wants is not whether the recipient agreed to hear from you. It is whether they agreed to be recorded.

2

One checkbox cannot carry both. Neither consent may be derived from the other.

CNIL ebook preview

Why the open rate is now a compliance question, not just a marketing metric

Inside this whitepaper, you will discover:

  1. Where CNIL draws the line between B2C and B2B sending — opt-in by default against opt-out by default, the three conditions of the soft opt-in exception that have to hold together before you can rely on it, and the single embedded offer that turns a transactional message into direct marketing.
  2. The pixel classification matrix — which tracking purposes require prior explicit consent, from campaign optimisation to profiling and mass-open detection, and the narrow set that does not, including the exact condition a deliverability routine has to meet to stay consent-exempt.
  3. How to collect tracking consent that survives a review: timing, transparent information, and granularity — when a single bundled opt-in is permitted, the circumstance that voids it retroactively, and what to do when the address was collected without a tracking consent in the first place.
  4. The architecture underneath both workflows — a unified preference centre holding two independent flags, dynamic pixel injection tied to the recipient record, and dual unsubscribe — plus why withdrawal has to be enforced at the endpoint rather than in the message, and what a nightly batch leaves live overnight.
  5. The four conditions for consent-exempt web analytics under the GDPR and the French Data Protection Act, what cookie-less measurement costs you in return, and the edge cases that catch teams out: security gateways opening mail before the recipient does, purchased lists, and consent requested by email.

The pixel now carries a compliance cost for a metric of declining value

The way out is not to stop measuring. It is to move the primary signal off the inbox — consented pixels where they genuinely earn their place, consent-exempt analytics on the landing page for everything else, and one consent record that the ESP, the website and the analytics layer all honour in real time. Where those systems are separate, the withdrawal flag propagates at the speed of the slowest sync.

If you own the campaign but not the consent record, if you've been told the newsletter opt-in covers the tracking pixel, or if you can't produce the timestamp and form wording for a French contact who signed up eighteen months ago, this whitepaper gives you the standard and the architecture that meets it.

Legal framework, pixel classification, two recipient lifecycle workflows, technical architecture and the edge cases — grounded in CNIL guidance, Article 82 of the French Data Protection Act, and the GDPR.

CNIL ebook cover

Before you download

It depends on who the recipient is. In B2C, opt-in is the default: prior consent must be free, specific, informed and unambiguous, given by an affirmative act before the first commercial message. In B2B, opt-out is the default, on one condition — the offer has to match the recipient's professional role, HR software to an HR director. Where it falls outside that scope, the B2C rules apply.

No. Sending and measuring are separate acts under French law and CNIL assesses them separately. An email that legitimately qualifies for B2B opt-out or B2C soft opt-in still needs a separate opt-in before a consent-mandatory pixel loads. Pixel placement falls under Article 82 of the French Data Protection Act, which transposes the ePrivacy rule on access to terminal equipment — a different track from the sending rules entirely.

Prior explicit consent is required wherever the pixel serves analytics or profiling: reading open rates to optimise a campaign or adjust send frequency, profiling preferences for cross-platform targeting, detecting mass automated opens, or recording open metrics at individual level. A narrow set stays exempt — aggregate deliverability analysis, evidence that mandatory legal information arrived, authentication checks — each with a condition attached. The whitepaper sets out the full classification and the conditions.

No. CNIL treats a pre-ticked box as no consent at all, in B2B exactly as in B2C. Consent requires an affirmative action, logged with a timestamp and the form context. Where the address will be passed to commercial partners, the sender names those partners at the point of capture or links to a list of them, and records a separate opt-in for each.

Yes, with one constraint: the email requesting tracking consent cannot itself carry a tracking pixel. The call to action routes the recipient to a landing page where consent is granted by an affirmative action — clicking a button, not merely arriving on the page. After a refusal, the sender waits before asking again; six months is the working figure.

No. A vendor warranty transfers no liability. The obligation to demonstrate consent sits with the data controller, address by address: timestamp, source URL, and the exact form copy the person saw. Where the vendor cannot produce those records per contact, the sender cannot demonstrate consent, and the mailing is unlawful.

Yes, by moving the measurement off the inbox. Email traffic lands on a site running an analytics configuration CNIL exempts from consent, which measures the engagement that follows the click and carries no consent obligation of its own. The exemption is conditional — four requirements govern purpose, anonymisation, cross-site identifiers and reporting granularity. The whitepaper lists all four, along with what cookie-less measurement gives up.

This page provides general information on CNIL requirements for email marketing and does not constitute legal advice. Specific obligations depend on your data, your recipients and your processing purposes.

Which problem can we solve for you?

JustRelate reviews martech stacks against French privacy requirements: a technical assessment of your current consent workflows, or a demonstration of an architecture that holds sending and tracking permission as independent flags and injects or suppresses the pixel from that record without custom code.

AI chat