Contact us

E-mail Tracking 2026: the shift toward more transparent communication

By Riccardo Sozzi, Head of Digital Data

There came a point, in recent years, when we started asking ourselves how thin the line really is between an effective e-mail and an intrusion into the privacy of the person receiving it. If you manage e-mail communications for work, you have probably heard about the measure issued by the Italian Data Protection Authority on 17 April: a kind of turning point that brought greater clarity to the use of so-called tracking pixels.

Often, when privacy regulations are discussed, the first reaction is to rush into damage-control mode, fearing sanctions or sudden blocks. But if we look beyond the purely bureaucratic side, what is happening is a natural evolution of digital communication. Think of the tracking pixel as an invisible “return receipt”: a tiny piece of code which, once inserted into an e-mail, notifies the sender when the recipient opens the message. It is a tool we have all used to understand whether content was interesting or to optimise campaigns. The issue, however, is that until now this has often happened in a hidden way, without users being truly aware of what was taking place on their devices.

The Italian Data Protection Authority is asking us to take a step forward toward transparency. It is not telling us to stop communicating, but to do so with greater awareness. Think about it: today, trust is the real currency of marketing. If users know that their interest is being measured correctly and, above all, if they have the power to choose, their relationship with your brand can only become stronger.

We are not facing an emergency that needs to be solved in panic mode, but rather a “maintenance” project for your digital ecosystem. There are six months to align with the new requirements: more than enough time to integrate these changes without overturning the work done so far. The goal of this article is precisely to help you understand that there is nothing frightening here. It is simply a matter of moving from an “all-out” tracking model to one that is more modern, solid and, ultimately, more effective.

Where things stand: what the Authority is really saying and the timeline

To avoid creative interpretations or unnecessary alarmism, it is worth clearly setting out what the discussion is about. With the Guidelines published in April 2026, the Italian Data Protection Authority has not “banned” e-mail marketing, but has drawn a clear line around how technical data is managed.

These are the key pillars of the measure and the adjustment timeline.

  • The pixel is no longer “invisible”: the Authority has officially classified the tracking pixel as a tracker falling within the scope of Article 122 of the Italian Privacy Code. This means it can no longer be considered an accessory or “taken-for-granted” activity. It must be handled with the same level of transparency required for the cookies we accept every day on websites.
  • The distinction between purposes: this is the most important point. The Authority recognises that certain processing activities are necessary: technical, transactional or service e-mails, such as those confirming an operation, are excluded from the requirement for prior consent. The regulatory threshold is raised only when we enter the area of profiling and behavioural analysis for marketing purposes.
  • Privacy by Design: the Authority encourages companies to move beyond old habits, such as inserting the e-mail address in plain text within tracking strings. The aim is to push businesses toward the adoption of unintelligible IDs, which make it possible to measure performance anonymously, separating technical data from the user’s identity.
  • The adjustment period: the Authority has acknowledged the technical complexity of these changes and, for this reason, has granted a six-month adjustment period from the date of publication in the Official Gazette, which took place on 29 April 2026. This means companies have until the end of October 2026 to become fully compliant.

In short, the Authority is not asking us to stop measuring. It is asking us to do so openly, giving companies a clear and reasonable timeframe to align without rushing.

Behind the scenes of tracking and the most common doubts

To understand what is happening, let’s look under the hood. When you send a newsletter, a tracking pixel is often inserted into the HTML code: a tiny, transparent image, as small as a single point on the screen. It is invisible, but for the server it acts as a signal: as soon as the recipient opens the e-mail, this “signal” is activated and sends a notification to the sender.

It is a useful tool, of course. It tells us whether the message reached its destination, whether it was read and helps us understand which content performs best. But, as the Authority rightly points out in its recent Guidelines, this mechanism has one key limitation: it is hidden.

The recipient does not know they are being “observed” and has no way of saying: “I like the newsletter, but I would rather read it without my device sending technical data every time I open it.”

And this is where many people start asking the most difficult questions. Let’s summarise the doubts we hear most often, because we know there are many unfounded concerns circulating.

  • “Do I need to add a banner or ask for consent on every single e-mail?” Absolutely not. The Authority makes a very clear distinction. If you send a service e-mail, such as an order confirmation, a password recovery message or an important notice related to an account, no prior consent is required. In those cases, tracking is considered a technical necessity for the proper functioning of the service requested by the user. The red light appears only when the goal is behavioural profiling or more aggressive marketing activity.
  • “My sending platform handles everything, so am I covered?” Be careful with this point: under the GDPR, responsibility always remains with the party that decides to send the communication, namely you. The platform is only the tool. Being “covered” does not mean ignoring the matter, but making sure the tool has been configured correctly. The Authority suggests, for example, using anonymous identifiers, the so-called unintelligible IDs, instead of directly associating the user’s e-mail address with the tracking activity. This is a common-sense practice, the one we call Privacy by Design, and it immediately makes your work more solid and transparent.
  • “Are we not risking making the user experience too complicated?” Many companies fear overwhelming customers with consent requests. But technology, when properly guided, helps us avoid precisely that. We can integrate the choice at the sign-up stage or offer readers a link in the footer where they can decide, in a granular way, whether they want to receive the “plain and simple” newsletter or the more personalised version. This is not a forced step: it is an act of respect toward your audience.

The action plan: turning compliance into value

At this point, the question many people ask us is: “Okay, I understand. But where do I start?” The answer is less complex than it may seem. You do not need an army of lawyers or to overhaul your IT infrastructure overnight. The Authority’s measure gives us a six-month horizon, which is more than enough time to proceed in an orderly way.

Our approach, built over years of working side by side with companies, is based on three simple directions.

  • The transparency audit: the first step is mapping. We need to understand which e-mails you are sending, which ones actually use tracking pixels and for what purposes. Often, during this phase, we discover that many e-mails do not even need tracking, or that they can be managed through aggregated and anonymous statistics. Streamlining the flow is already an excellent way to reduce risk.
  • The technical update: this is where we enter the field of Privacy by Design. Configuring the sending platform to use unintelligible identifiers, instead of the e-mail address in plain text, is the step that helps secure your technical compliance. It is invisible to the user, but fundamental for your peace of mind.
  • The trust pact with the user: finally, the privacy notice. Instead of hiding everything inside the usual endless texts that nobody reads, we can use this opportunity to speak clearly to your users. A well-designed footer, granular consent management and clear language are not just “legal obligations”: they are a signal that your brand takes its relationship with e-mail readers seriously.

We are not talking about an emergency “fix”, but about a necessary modernisation. The market is changing: tolerance for “in-the-dark” tracking is at an all-time low, and users reward those who choose transparency.

Seeing this adjustment as an opportunity to improve the quality of your communications is, in our view, the best way to turn a regulatory obligation into a competitive advantage.

Navla supports you step by step throughout this process: from the audit phase to technical and legal validation, alongside SAPG Legal, we help secure your communications and strengthen the trust of your users. Contact us today for a consultation.

If you want to learn more about it