GDPR Email Marketing in 2026: A Compliance Checklist
Short answer. For B2C, email prospecting requires prior consent that is freely given, specific, informed, and unambiguous, except under the soft opt-in for an existing customer contacted about similar products or services, informed at the point of collection and given a simple, free way to object in every message. The tracking pixel falls under a separate regime from the send itself: the CNIL recommendation published in France's Official Journal on 14 April 2026 ties it to article 82 of the French Data Protection Act, so to consent, with two narrow exemptions. For contacts already on your list, the three-month information window closed on 14 July 2026, absent a documented extension. The full checklist is at the end of this article.
2026 reshuffled email compliance in France. The CNIL, the French data protection authority, published a recommendation on tracking pixels in emails (deliberation no. 2026-042 of 12 March 2026, published in the Official Journal on 14 April 2026), followed by a FAQ that settles the concrete cases. The CNIL says so itself: the text is neither regulatory nor exhaustive. The binding constraint sits in article 82 of the French Data Protection Act, which the recommendation simply spells out. For an ecommerce brand running daily flows and campaigns, the practical effect is the same either way: part of your open measurement now rests on a consent you probably did not ask for.
This guide covers the framework that applies to email marketing in 2026: consent, tracking pixels, data retention, DNS authentication, and the operational work of getting compliant, on Klaviyo or on any other tool. None of this is legal advice.
Consent for email prospecting: what the CNIL requires
For B2C, the substance of the rule has not changed, but the CNIL keeps restating it: consent must be prior, freely given, specific, informed, and unambiguous, collected through a positive action. In practice, an unticked checkbox dedicated to commercial prospecting. Accepting terms and conditions is not enough.
What that means for your signup forms:
- A separate checkbox for marketing consent (newsletter, promotional offers).
- An unticked box by default, since a purchase on its own does not constitute consent, subject to the similar products or services exception covered below.
- Clear wording stating the purpose, the approximate frequency, and the channel (email, SMS where applicable).
The B2B exception
For B2B, email prospecting can rely on legitimate interest, provided recipients are informed at the point of collection and can object simply and free of charge. The subject of the message has to relate to the recipient's professional role.
The similar products exception in B2C
If someone has already bought from you, you can send them prospecting messages about similar products or services without collecting fresh consent. Two conditions: inform them when you collect their address, and give them a simple way to object in every email. One caveat: this exception covers the right to send the message, not the right to track it (see the next section).
Tracking pixels: the CNIL's 2026 recommendation
This is the year's major change. The CNIL treats a tracking pixel in an email as a read operation on the recipient's device, and therefore as a tracker under article 82, on the same footing as a cookie: prior, specific consent.
Our dedicated guide to tracking pixels and the CNIL walks through the legal analysis purpose by purpose. What follows is the operational summary.
The three requirements for tracking consent
Consent to pixel tracking has to be:
- Specific to each purpose: to preserve the freely given character of consent, the CNIL recommends collecting it independently and specifically for each distinct purpose. It accepts a single consent only where commercial prospecting and pixels pursue related purposes, for instance prospecting expressly presented as personalised. As soon as the purposes are not related, two separate checkboxes remain the most demonstrable route. Klaviyo reads the French position as requiring tracking consent separate from prospecting consent, a stricter reading than the recommendation itself.
- Collected before any tracked email goes out, with the CNIL recommending you ask for it at the point you collect the address.
- Requested without disproportionate pressure: the consent prompt must not prevent or hinder reading the emails. A contact who refuses tracking can keep receiving your campaigns, since sending and pixel tracking fall under two separate regimes.
The practical consequence runs against intuition: an email you have every right to send may still require consent before you can track it.
Contacts collected before April 2026
For contacts already on your list, the CNIL allows operations to continue under two conditions: clear, accessible information sent within a window that should not in principle exceed three months from 14 April 2026, with an extension possible where the difficulties are documented, and no objection from recipients. That information has a precise purpose: to put the recipient in a position to object to tracking for future emails, in the event their consent was not collected under the terms of the recommendation. Anyone who objects comes out of tracking; keeping the pixel only holds for the rest.
Absent a reasonable extension justified by documented difficulties, that window has now closed: the recommendation's rules apply, including collecting consent where it is required. If no information was ever sent, the FAQ leaves only two ways out: collect people's consent, or stop using consent-based pixels until that consent has been collected.
Cart recovery and transactional emails
The CNIL FAQ handles cases one by one. An abandoned cart reminder is a promotional email: no pixel exemption. A purchase confirmation or a subscription renewal can qualify, provided you do not slip promotional elements into it, which rules out the cross-sell in the transactional emails you were hoping to keep measuring.
The two exemptions
Only two purposes escape consent under the recommendation: security measures contributing to user authentication, and individual open rate measurement for deliverability purposes, meaning adjusting frequency or stopping sends to inactive contacts. These exemptions assume the email was requested by the recipient or attached to a service they requested, and that the data collected stays strictly limited to what is necessary. On minimisation grounds, the recommendation holds that only the date of the last known open should be kept, to the day and without recording the time, updated on each new open with the previous one deleted.
When someone refuses
A refusal has to be respected and recorded. Silence is not agreement, and a consent-based pixel cannot be inserted while you wait for a future consent. Build a durable exclusion segment into your flows rather than re-asking for consent on every campaign, which drains consent of its meaning and shows up immediately in an audit. The CNIL recommends that refusing be as simple as accepting, and that the recipient's choices be recorded so they are not asked again for a certain period, with six months without further solicitation cited as good practice.
Customer data retention: the reference period
In its guidance on customer relationship management, the CNIL sets out the deletion of information relating to customers who have stayed inactive for a prolonged period, three years from the end of the commercial relationship, subject to the data that legal obligations require you to keep for longer (accounting, litigation). That reference covers customer data: it does not set the period applicable to prospects who have not bought.
For an ecommerce business, the end of the relationship corresponds in practice to the last purchase or the last meaningful interaction (account login, email click, promo code redemption).
This lines up with the logic of the sunset flow and list cleaning: once the period is up, the customer data concerned should be deleted or archived, since deactivating a profile in the tool leaves the data sitting in the database.
DNS authentication: the technical foundation
Yahoo's sender best practices require bulk senders to authenticate with SPF and DKIM, publish a DMARC policy, keep the complaint rate under 0.3%, and offer a working one-click unsubscribe through the List-Unsubscribe header, with Yahoo strongly recommending the RFC 8058 POST method. These requirements come from the mailbox providers rather than the GDPR, but they decide whether you land in the inbox at all.
The two workstreams overlap on two points. One-click unsubscribe is both a mailbox provider requirement and the simple means of objection expected in every prospecting message. The complaint rate, meanwhile, is an indirect measure of how good your consent is: a cleanly collected list complains rarely, a bought or pre-ticked list complains fast.
If your DNS setup is not in place, no amount of GDPR compliance will make up for emails that do not arrive.
Getting compliant on Klaviyo
Open tracking
Klaviyo lets you turn off open tracking at the account level and manage each recipient's status through CSV import, SFTP, data warehouse sync, or the API. One thing to know before considering the subject closed: the pixel stays in the email and the request still reaches the tool's servers, it is the recording of the event that gets blocked. The CNIL, for its part, hangs article 82 on the read operation on the device.
Proof of consent
Klaviyo records consent proof properties on each profile: source form, method, form version, and timestamp. That is the individualised trace you would produce in an audit. Where consent is collected by a third party on your behalf, the CNIL FAQ rules out a contractual clause as proof: whoever delegates the collection cannot rely on a clause in the contract to evidence consent, they have to be able to demonstrate that consent was validly collected, through audits for example. The contract then frames the demonstration mechanisms, the provision of evidence, and retention terms, without relieving you of your responsibility as controller if the third party's failure leaves you unable to produce proof. The per-profile trace is what opens the file.
The CNIL has also opened a consultation on proof of consent in marketing. Traceability requirements will most likely tighten: storing each proof properly now costs less than reconstructing a history later.
Double opt-in or single opt-in?
The GDPR does not technically mandate double opt-in, but it remains the most solid way to demonstrate unambiguous consent given through a positive action. In agency work, we recommend it by default on European markets, all the more so in the current climate of tightening evidence requirements.
Collecting tracking consent
Treat tracking consent on its own terms. A dedicated collection point, separate from the marketing checkbox, remains the most demonstrable route, since a single consent is only accepted where prospecting and pixels pursue related purposes. As of today, Klaviyo does not expose it in its signup forms: it falls to the sender to set the status through the methods described above. Klaviyo has announced native collection in signup forms and the preference centre, which does not excuse you from collecting consent in the meantime. Your collection wording should explain what the pixel measures (opens) and what a refusal means for the recipient: emails still arrive, statistics are limited on the sender's side.
If you are not on Klaviyo
The principles above do not depend on the tool. Whatever the platform, three checks are worth running in the account, in this order.
- Where the tracking consent status is stored. You need a dedicated contact field or attribute, separate from the marketing subscription status, so you can exclude the profiles concerned at send time.
- What the tracking-off setting actually does. Some settings stop the event from being recorded while leaving the pixel in the message. On article 82 grounds, the read operation on the device is what counts, so the insertion of the pixel itself.
- Where proof of consent is logged. Source form, method, and timestamp, per profile, exportable.
The exact labels and locations of those settings shift with each product's releases: on that specific point, your vendor's help centre is the only authority. The legal analysis, though, lives in the CNIL recommendation and its FAQ, not in a vendor's documentation.
If you run Brevo and want this setup checked, our Brevo agency can audit your account.
GDPR email marketing compliance checklist for 2026
| # | Action | Status |
|---|---|---|
| 1 | B2C marketing consent: dedicated checkbox, unticked, explicit wording | ☐ |
| 2 | Pixel tracking consent: collected on its own terms, dedicated checkbox as soon as the purposes are not related | ☐ |
| 3 | Forms updated with tracking consent and its wording | ☐ |
| 4 | Existing list: information sent, consent collected or objection recorded | ☐ |
| 5 | Tracking refusals honoured durably: exclusion segment, refusing as simple as accepting, no fresh solicitation for six months (CNIL good practice) | ☐ |
| 6 | Consent-based pixel not inserted, not merely not recorded, in emails to profiles without tracking consent | ☐ |
| 7 | Proof of consent stored per profile (form, method, timestamp) | ☐ |
| 8 | SPF, DKIM, and DMARC configured and valid | ☐ |
| 9 | Complaint rate under 0.3% | ☐ |
| 10 | One-click unsubscribe live (working List-Unsubscribe header, RFC 8058 POST method strongly recommended by Yahoo) | ☐ |
| 11 | Sunset flow running to handle inactive customers before the retention period is up | ☐ |
| 12 | Retention policy documented (periods, inactivity criteria, deletion or archiving) | ☐ |
| 13 | Mandatory details current in every email: sender identity, unsubscribe link, simple and free means of objecting | ☐ |
What this changes for your lifecycle strategy
Compliance acts as a filter: it forces you to work with a clean, consenting, engaged list, which serves your results in lifecycle marketing anyway.
Brands that collect tracking consent properly, on top of the consent covering the send, will keep usable metrics on a qualified list. Those that keep tracking without consent stack legal exposure on top of open data already weakened by Apple's image preloading, a subject covered in our Apple MPP guide.
The sensible trade-off comes down to two things. Base your behavioural segmentation on clicks and purchases rather than opens, bearing in mind that tracked links also fall under article 82 and call for a case-by-case analysis of whether they are strictly necessary. And treat compliance as a design constraint, set upstream of implementation rather than patched in afterwards.
If you want a second pair of eyes on your consent setup and your flows, book a Klaviyo and CRM diagnostic.
FAQ
Does the GDPR require double opt-in for email marketing?
No. The GDPR requires consent that is freely given, specific, informed, and unambiguous, given through a positive action, but it does not mention double opt-in. That said, double opt-in remains the most solid way to prove that consent, at a time when the CNIL is working specifically on proof of consent in marketing.
Can you still use tracking pixels in emails in France?
Yes, with the recipient's prior, specific consent, except for the two exempt purposes (authentication security and deliverability measurement kept to what is strictly necessary). Tracking falls under a regime independent of the send: the CNIL recommends independent, specific consent per distinct purpose, and accepts a single consent where prospecting and pixels pursue related purposes. The obligation also applies to contacts collected before the CNIL recommendation.
What happens if a contact refuses tracking?
You can keep emailing them: sending and tracking fall under two separate regimes. No consent-based pixel should go into those messages, though. Only the exempt, minimised deliverability measurement stays available, where the email was requested by the recipient or attached to a service they requested. Their opens will not be usable for your marketing statistics. The refusal has to be kept on record and respected over time, campaign after campaign.
How long can you keep an inactive customer's data?
The CNIL's guidance on customer relationship management points to the duration of the commercial relationship, then three years from its end, subject to the data that legal obligations require you to keep for longer (accounting, litigation). Put a sunset flow in place to disengage inactive contacts gradually, and document your retention policy.
Does the CNIL pixel recommendation apply to transactional emails?
The pixel regime is independent of the send regime, so yes, the question arises for them too. A purchase confirmation or a subscription renewal can fall under an exemption as long as it carries no promotional elements. An abandoned cart reminder, on the other hand, is treated as a promotional email: consent required for the pixel.
Provenance and verification
Sources reopened on 2026-08-19: the CNIL page presenting the tracking pixel recommendation, the PDF of the recommendation, its FAQ, the CNIL pages on email prospecting, on customer relationship management and on the consultation opened on proof of consent, the Legifrance record of the deliberation, the Klaviyo blog and help centre, and Yahoo's sender best practices. Values checked in the text: deliberation no. 2026-042, its adoption on 12 March 2026 and its publication in the Official Journal on 14 April 2026, the two exemptions from consent (authentication security and individual open rate measurement for deliverability), the minimisation rule limiting retention to the date of the last open, to the day and without the time, the good practice of six months without further solicitation after a refusal (FAQ, question 24), the three-month window for informing an existing list, the FAQ rule ruling out a contractual clause as proof where collection is delegated to a third party, the three years from the end of the commercial relationship set out on the customer relationship page along with its own reservation for data covered by legal retention obligations, and the Yahoo requirements (SPF and DKIM, published DMARC, complaint rate under 0.3%, working one-click unsubscribe through the List-Unsubscribe header, with Yahoo strongly recommending the RFC 8058 POST method). The Brevo help centre returns HTTP 403 to page retrieval: since its content could not be read, it is neither declared as a source nor linked in the body, and no figure or legal analysis rests on it. The legal analysis is referred to the CNIL recommendation and its FAQ.
- Sources checked on
- Reviewed by
- Claude (CLI local) counter-check against the CNIL recommendation, its FAQ, the CNIL pages on email prospecting, on customer relationship management and on the consultation on proof of consent, Legifrance, Klaviyo documentation and Yahoo's sender best practices
- AI assistance
- Yes
- Sources
-
- www.cnil.fr/fr/recommandation-pixel-suivi-courriels
- www.cnil.fr/sites/default/files/2026-04/recommandation-pixels_de_suivi.pdf
- www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques
- www.cnil.fr/fr/la-prospection-commerciale-par-courrier-electronique-sms-mms-et-automate-dappel
- www.cnil.fr/fr/rgpd-en-pratique-maitrisez-votre-relation-client
- www.cnil.fr/fr/marketing-la-cnil-ouvre-une-concertation-sur-la-preuve-du-consentement
- www.legifrance.gouv.fr/jorf/id/JORFTEXT000053876850
- www.klaviyo.com/blog/eu-email-tracking-pixels
- help.klaviyo.com/hc/en-us/articles/53113350637083
- help.klaviyo.com/hc/en-us/articles/360003536031
- senders.yahooinc.com/best-practices
Want to apply this to your stack?
Spend 30 minutes with Charlotte to review your CRM setup, size the opportunity and leave with a practical action plan.
Book a 30-minute call →