The Garante's Provision No. 284 of April 2026 treats open-rate pixels as cookies — here is what every foreign e-commerce operator and SaaS company selling into Italy must change before 28 October 2026.
LANG: English (en) · AREA: Product Compliance, Liability & Consumer Law · TYPE: Case note (court decision) · MODEL: Sonnet 5 · SEO 84/100 · Flesch Reading Ease 38 · QA acceptable
ABSTRACT: Italy's data protection authority (the <i>Garante per la Protezione dei Dati Personali</i>, the Garante) adopted Provision No. 284 on 17 April 2026, classifying email tracking pixels as a form of access to a recipient's terminal device and requiring prior opt-in consent whenever they are used for open-rate measurement or behavioural analysis in promotional campaigns. The rules were published in the Official Gazette (<i>Gazzetta Ufficiale</i> No. 98) on 29 April 2026, and organisations that send marketing emails to recipients in Italy have until 28 October 2026 to comply — regardless of where the sender is incorporated. Foreign e-commerce businesses and SaaS companies are squarely in scope.
Nemo censetur ignorare legem — no one is presumed ignorant of the law. A principle blunt enough in domestic commerce; far sharper when the law in question is Italian and your servers are in Dublin, Toronto or Austin.
Your email marketing platform is almost certainly firing a tracking pixel on every open. Until April 2026 that was a grey area in Italy. It no longer is. The Garante has moved, the fine-level precedent is set, and the window to fix your consent flows is shrinking.
What is Italy's Garante Provision 284 of 2026?On 17 April 2026, the Italian Data Protection Authority — the
Garante per la Protezione dei Dati Personali — adopted its first dedicated guidelines on the use of email tracking pixels, published as
Provvedimento n. 284. The rules appeared in the
Gazzetta Ufficiale No. 98 on 29 April 2026 and give organisations six months to adjust, with the deadline falling on 28 October 2026.
Tracking pixels are tiny one-pixel transparent images — which are not directly contained within the email but are hosted on remote servers. When a recipient opens the email, their device silently requests that image, and the request tells the sender's platform that the email was opened, often along with the device type, operating system, approximate location, and time. Tracking pixels are commonly used to measure email open rates and to enable marketing automation tools. Until now many businesses used them without a second thought. The Garante has now classified tracking pixels as a form of access to users' terminal devices, subject to the same rules that govern cookies, requiring prior, free, specific, and informed consent from the recipient in most situations.
The legal basis is Article 122 of the Italian Privacy Code (
Codice Privacy, Legislative Decree 196/2003 as amended), implementing Article 5(3) of the EU ePrivacy Directive (Directive 2002/58/EC) — the so-called "cookie law". On 16 October 2024, the European Data Protection Board (EDPB) published the final version of Guidelines 2/2023 on the Technical Scope of Article 5(3) of the ePrivacy Directive, addressing the applicability of that provision to different technical solutions, particularly tracking technologies beyond cookies. The Guidelines contain details on certain use cases related specifically to URL and pixel tracking, extending the reach of the ePrivacy Directive to address the increasing use of non-cookie tracking technology. The Garante's Provision No. 284 is Italy's domestic implementation of that EU-level reading: a pixel loading is "gaining access" to the terminal, full stop.
Do I need consent for email tracking pixels in Italy?The answer is yes, in most situations — but the Provision makes important distinctions.
Open tracking used to measure campaign performance, build recipient profiles, or feed any kind of behavioural analysis requires explicit, granular, purpose-specific consent. That covers the overwhelming majority of what commercial email marketing platforms do by default: open-rate dashboards, A/B testing, automated re-engagement sequences, and lead-scoring integrations all typically rely on identifying individual recipients.
Open tracking used purely to manage list hygiene — suppressing inactive recipients or adjusting sending frequency — may not require consent, so long as data collection is limited to what is strictly necessary. Authentication-related signals, fraud detection, and mandatory institutional notices also fall outside the consent requirement in certain conditions. So a purely anonymised aggregate pixel that cannot be tied back to an individual recipient may be exempt. But that is a narrow carve-out, not a loophole: the moment the pixel resolves to a unique identifier in your CRM, the exemption disappears.
Unlike in most common-law countries — where email marketing is governed primarily by opt-out anti-spam statutes (the UK's Privacy and Electronic Communications Regulations, Canada's CASL, or the US CAN-SPAM Act) and where open-rate tracking is generally not regulated at all — Italy now applies an
opt-in standard to the pixel itself, separately from the email's commercial content. A subscriber who opted in under CASL or PECR has not by that act consented to being tracked in Italy's eyes. The consent must be distinct, informed, and granular.
What exactly does granular consent mean here?Users must be able to withdraw consent easily and selectively: they can choose to stop the pixel tracking while continuing to receive emails normally, or stop all tracking-based communications entirely. The Garante therefore separates two things that most marketers bundle together: the right to send an email, and the right to know whether it was opened. Removing tracking consent cannot mean removing the subscriber from the list.
The Garante takes a pragmatic line on how consent is initially gathered: tracking consent may be combined with newsletter or marketing consent, provided the recipient is clearly informed — a wholly separate checkbox is not necessarily required. But withdrawal must be granular: a recipient must be able to opt out of tracking while continuing to receive the newsletter. Tracking and content are separable on the way out, even if they were bundled on the way in.
In practice, this means that your unsubscribe footer — or a dedicated preference centre — must offer a clearly labelled option to stop pixel tracking independently. A single "unsubscribe from all" link does not satisfy this requirement.
The Garante accepts that consent to tracking pixels can be bundled into a broader consent for promotional communications, as long as it is presented in a neutral, non-coercive way. Pre-ticked boxes, dark patterns that obscure the tracking option, or consent bundled as a condition of service all remain unlawful under the GDPR's Article 7(4) standard, which the Provision applies by reference.
The Poste Italiane fine: why it matters to youThe Provision did not arrive in isolation. On the same day — 17 April 2026 — the Garante fined Poste Italiane S.p.A. €6,624,000 and its payments subsidiary PostePay S.p.A. €5,877,000 for GDPR violations. The investigation, launched in April 2024 following numerous complaints, examined the BancoPosta and Postepay mobile apps, which required users to authorise monitoring of device data — including installed and running applications — to detect malicious software. The authority determined that this intrusive surveillance was not strictly necessary for fraud prevention.
The PSD2 fraud-prevention defence failed the GDPR necessity test. That matters beyond banking apps. The structural argument — "we track you for operational or security reasons, so we do not need consent" — was rejected in clear terms. The Poste Italiane case confirms that security or fraud prevention cannot serve as a blank cheque for data collection. Any foreign operator tempted to reclassify its open-rate pixel as a "deliverability metric" or a "bounce-detection tool" should note that the Garante has just demonstrated it will examine substance over label.
The Garante's jurisdiction over foreign operators is not a theoretical concern. Under the GDPR's territorial rules (Article 3(2)), processing the personal data of individuals in Italy triggers compliance obligations regardless of where the controller is established. A New York SaaS company, a London e-commerce retailer, or a Sydney subscription service that sends tracked promotional emails to Italian recipients is squarely within scope.
How do I make my email marketing compliant in Italy?The following is a sequenced action list, not a commentary.
First, audit your stack. Identify every pixel your email service provider fires and whether its output is tied to individually identifiable records. Most platforms — Mailchimp, Klaviyo, HubSpot, ActiveCampaign — enable open tracking by default and link opens to contact records. That is the scenario Provision No. 284 regulates.
Second, segment your Italian contacts. You need a separate consent field for pixel tracking, distinct from marketing consent, for every contact whose email address you associate with Italian residence. Whether you do this by top-level domain (.it addresses), by country field, or by IP-based sign-up data will depend on how your CRM is structured, but the obligation runs to recipients in Italy, not just Italian citizens.
Third, update your sign-up flows immediately. Compliance for newly collected addresses is expected immediately from the date the rules came into force. If you have not already updated your opt-in forms to include a transparent, granular disclosure of pixel tracking, every Italian address you collect from 29 April 2026 onwards carries non-compliant consent.
Fourth, re-consent your existing Italian list or switch off tracking for it. For existing addresses, the Garante's Provision No. 284 grants a six-month transitional period from publication in the Official Gazette — 29 April 2026 — running to 28 October 2026. You may continue using pixels during this window for pre-existing contacts while you implement compliant re-consent, but the window is not unlimited.
Fifth, build the withdrawal mechanism. Add a clearly labelled "manage tracking preferences" link to your email footer — distinct from your unsubscribe link — that enables a recipient to opt out of the pixel without leaving your mailing list. Log the timestamp and channel for every consent change: if the Garante investigates, consent records are the first thing auditors request.
Sixth, review your data processor agreements. If your email platform processes open data on your behalf, your data processing agreement (DPA) must accurately describe the tracking activity and restrict the platform's use of the data to what you have authorised. Gaps in processor designation were among the violations identified in the Poste Italiane investigation, signalling that the Garante treats processor chain oversight as part of the compliance picture, not a back-office detail.
What is the deadline for Italy's email pixel consent rule?Published in
Gazzetta Ufficiale No. 98 on 29 April 2026, the guidance triggers a six-month compliance window that expires on 28 October 2026. Every organisation that sends emails containing tracking pixels to recipients in Italy — whether a multinational retailer, a mid-size B2B supplier, an email service provider, or a local SME running a newsletter — must decide how to modify consent flows, update privacy notices, renegotiate vendor contracts, and, where necessary, disable pixel tracking entirely before the deadline.
For organisations that cannot complete a full compliance programme in time, the minimum viable position is to disable all tracking pixels in marketing emails by 28 October 2026 and re-enable them only after compliant consent has been collected. This "pixel-off-first" approach eliminates the highest-risk exposure while the full programme is completed.
The non-obvious risk that most compliance checklists omit is the SaaS double exposure. If your product sends transactional or lifecycle emails on behalf of your customers — and your platform inserts its own tracking pixel into those emails — you may be a data processor in breach, and your customer (the controller) may be in breach simultaneously. Review the terms under which your platform embeds tracking code and ensure your customers are informed of, and consented to, pixel deployment in emails they send to their Italian users.
October 2026 is close. The consent infrastructure, the list segmentation, the footer mechanics, and the processor contracts all take time to change correctly. The Garante has made clear, through both a binding provision and a nine-figure enforcement action in the same month, that it regards terminal-device access without consent as a serious violation — not a technicality. The question now is not whether to act, but whether to act in time.
Image prompt: A sleek modern home office in northern Europe or North America — a desk with an open laptop showing an email marketing dashboard with open-rate statistics, a small red warning icon visible on the screen. A stack of legal documents sits beside the keyboard. The scene is lit by cool morning light from a wide window, giving a sense of urgency and careful scrutiny. Colour palette: pale grey, white, muted blue, with a single accent of amber-red from the notification icon. Photorealistic, editorial-style composition, no text visible anywhere in the image.
Image file: italy-email-tracking-pixel-consent-2026-garante-cover
HREFLANG BLOCK:
JSON-LD:
LANGUAGE QA: transparent images of an extremely small size — just one pixel -> tiny one-pixel transparent images · the window closing 28 October 2026 -> the deadline falling on 28 October 2026 · The legal foundation sits in Article 122 -> The legal basis is Article 122 · which transposes Article 5(3) of the EU ePrivacy Directive -> implementing Article 5(3) of the EU ePrivacy Directive · a pixel loading is 'gaining access' to the terminal, full stop -> pixel loading constitutes 'gaining access' to the terminal, period · the Provision draws important distinctions -> the Provision makes important distinctions · may not require consent, provided the data collected is limited to what is strictly necessary -> may not require consent, so long as data collection is limited to what is strictly necessary · A subscriber who opted in to receive your newsletter under CASL or PECR has not thereby consented -> A subscriber who opted in under CASL or PECR has not by that act consented
CHECK:
AUTHORITY 1: Garante Provision No. 284 of 17 April 2026, published Gazzetta Ufficiale No. 98, 29 April 2026.
REFERENCES: Full — Provvedimento n. 284 del 17 aprile 2026, Gazzetta Ufficiale n. 98 del 29 aprile 2026.
EXISTS? YES — confirmed across at least eight independent sources including iubenda, globallawexperts, aoshearman, insideprivacy, consentpixel, spotler, gblock.
CONTENT MATCHES what I wrote? YES — pixel-as-terminal-access classification, prior consent requirement, six-month transitional window to 28 October 2026, granularity/withdrawal rules, and exemptions for non-identifying aggregate tracking and institutional messages all confirmed.
AUTHORITY 2: Garante Decision No. 237/2026 (Doc-Web 10241537) of 17 April 2026, fining Poste Italiane €6,624,000 and PostePay €5,877,000.
REFERENCES: Full — Garante per la Protezione dei Dati Personali, Decision No. 237/2026, Doc-Web 10241537, 17 April 2026.
EXISTS? YES — confirmed by DataGuidance, Il Sole 24 Ore, digitalpolicyalert.org, zyphe.com (with Doc-Web reference), changeflow/govping, globalbankingandfinance.
CONTENT MATCHES what I wrote? YES — combined €12.5M fine, mobile app device surveillance, BancoPosta/PostePay apps, fraud-prevention necessity argument rejected, processor/DPIA gaps, coercive consent all confirmed.
AUTHORITY 3: EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) of the ePrivacy Directive, adopted 7 October 2024 / published 16 October 2024.
REFERENCES: Full — European Data Protection Board, Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive (Directive 2002/58/EC), Version 2.0, adopted 7 October 2024.
EXISTS? YES — confirmed by official EDPB PDF (edpb.europa.eu), digitalpolicyalert.org, hunton.com, natlawreview.com, lexisnexis.co.uk, mydata-trust.com.
CONTENT MATCHES what I wrote? YES — Guidelines explicitly address pixel and URL tracking as within scope of Art. 5(3); consent required for access to terminal device; final version adopted October 2024.
OVERALL: GREEN — all three authorities independently confirmed for existence and content match.
LOCAL NOTE:
1. Search intent targeted: transactional — a foreign e-commerce operator or SaaS company that has already received a compliance query, a legal warning, or is preparing for EU market entry and needs to instruct counsel to fix a concrete, imminent regulatory problem with a hard deadline.
2. Local-market framing used: the contrast with UK PECR, Canadian CASL, and US CAN-SPAM (all opt-out regimes that do not regulate the tracking pixel at all) is the central differentiator for this audience; the article foregrounds that existing "compliant" consent under those systems is insufficient in Italy, making this a genuinely new exposure for foreign operators, not a routine GDPR update.
3. Italian terms kept untranslated: <i>
Do you need legal assistance or a free estimate?
Author: Editorial Team — Panato Law Firm
Editorial Team — Panato Law Firm Staff