“Is email tracking legal?” is a fair question with an unsatisfying answer: it depends where you and your recipient are, and what you are sending. The short version is that in the United States open tracking is broadly permitted and barely regulated by name, while in the EU and UK regulators treat tracking pixels much like cookies, with expectations around transparency and, often, consent.
This article is general information, not legal advice. Rules change, they vary by jurisdiction, and your situation may have specifics that change the answer. If your business depends on the answer, ask a qualified lawyer in your jurisdiction.
What a tracking pixel does, in legal terms
A tracking pixel is a small, usually invisible image in the email body. When the recipient’s mail app loads it, the server learns that the message was opened, roughly when, the IP address that fetched it, and often the mail client. That is the whole of it: no access to the mailbox, no reading of other messages, no software installed. The mechanics are explained in how email tracking pixels work.
Two things attract regulatory attention: the IP address, generally treated as personal data in Europe, and the fact that the image is cached on the recipient’s device at all.
The United States
There is no federal statute in the US that names email open tracking and prohibits it. The FTC’s own CAN-SPAM Act compliance guide sets out the rules for commercial email: no false or misleading header information, no deceptive subject lines, identify the message as an advertisement, include a valid physical postal address, explain how to opt out, honor opt out requests within ten business days, and monitor what others do on your behalf. Tracking pixels, open tracking and read receipts do not appear in the guide.
That does not mean anything goes. Two areas are worth knowing about.
State privacy laws. A growing number of US states have comprehensive privacy statutes with their own disclosure and opt out requirements. If you collect open data about consumers at scale, that is a question for counsel.
Wiretapping style claims. There has been active US litigation about tracking technologies under federal and state wiretap statutes, particularly two party consent laws in states such as California and Pennsylvania. Most of it concerns website tracking rather than email pixels, but it is worth watching if you track at volume.
For an individual wanting to know whether a proposal was opened, the US position is permissive.
The EU and the UK
Europe approaches this from a different direction. The question is not “is tracking allowed” but “are you allowed to place and read something on someone’s device”, and the answer starts from consent.
The ePrivacy rule
Article 5(3) of the ePrivacy Directive, widely known as the cookie rule, requires consent before storing information on, or gaining access to information stored on, a user’s device. It is technology neutral, so it was never only about cookies.
The European Data Protection Board settled the application to email in its Guidelines 2/2023 on the technical scope of Article 5(3), adopted in October 2024. The guidelines note that in the case of an email, the sender may include a tracking pixel to detect when the receiver reads the email. The EDPB concludes that distributing such pixels to the user’s terminal equipment does constitute storage, at the very least through the caching mechanism of the client software, and that Article 5(3) is therefore applicable even if the storage is not permanent. It also treats the collection of the identifier that comes back as gaining access under the same article.
In plain terms: Europe’s regulators consider email tracking pixels to be in scope.
The UK position
The UK Information Commissioner’s Office reaches the same place through PECR. Its guidance on direct marketing using electronic mail states that the electronic mail marketing rules in PECR apply to the email itself, not to the tracking pixels, and that tracking pixels are instead covered by PECR’s separate rules on storage and access technologies. Its guidance on those technologies describes tracking pixels as small pieces of code, usually an image file, embedded into a website or an email, and confirms that where they store or access information on a user’s device, regulation 6 applies.
Regulation 6 is the consent and information rule. So a UK sender running marketing email with open tracking needs to think about both telling people and, in most cases, asking them.
France, and a concrete example
France’s data protection authority, the CNIL, published a specific recommendation on tracking pixels in emails on 14 April 2026. Its position is that consent is generally required for pixels used to measure open rates for advertising performance, to build recipient profiles, and for similar analytical purposes. It sets out narrow exemptions, including transactional emails such as order confirmations and password resets, and individual deliverability measurement limited to identifying inactive recipients. It also gave organizations a transition period to inform existing recipients and offer an easy way to opt out.
The CNIL makes one distinction that is easy to miss and important: consent to receive marketing email is not the same as consent to be tracked. They are separate questions.
Marketing email and one to one email are not the same thing
Most of the rules above were written with mass mailing in mind: campaigns aimed at thousands of people whose behavior is then profiled. That is a different activity from a salesperson wanting to know whether a single proposal reached a single client, even though the underlying image is identical.
The honest position is that the ePrivacy rules on pixels are not limited to marketing, so a European recipient’s rights do not evaporate because you only sent one email. What changes is the proportionate response. For one to one business email, transparency is the proportionate step. For campaigns to a list, you need a proper consent mechanism and a privacy notice describing what you collect.
Practical good manners
Rules aside, a simple standard keeps you comfortable in almost every situation. Start from the fact that a pixel shows an image was loaded, not that a person read anything.
Say so if you are in any doubt. A single line in your signature, something like “I use a tool that tells me when my emails are opened”, removes the element of concealment entirely. It costs you almost nothing and it is very hard to object to.
Have a privacy notice if you send at scale. Describe what is collected, why, and how to opt out. This is a requirement in Europe and good practice everywhere.
Use it to time your follow ups, not to judge people. An open is a weak signal about attention, not a statement of interest. When to follow up after an email is opened covers using it well.
Never mention the tracking in the follow up. “I saw you opened my email twice” makes people feel watched, and it is the fastest way to lose a relationship you were trying to build.
Never use it to locate or monitor a person. Do not track someone you have no business reason to contact. Do not use open locations to work out where an individual is. Beyond being unpleasant, this is the kind of use that can engage harassment and stalking laws that have nothing to do with pixels. And as a practical matter it does not even work, because IP based location is approximate at best, as explained in how accurate email open location is.
What this means for a typical sender
If you are in the US tracking business email you actually sent to people you actually know, you are on solid ground, and a disclosure line makes it considerate as well. If you email people in the EU or UK, especially for marketing, treat open tracking as a consent and transparency question and set it up properly. If you are unsure which bucket you are in, ask a lawyer rather than a website.
Where Email Tracker fits
Email Tracker is an iPhone app for tracking emails you compose through it, using Apple Mail’s own compose sheet. It is designed for one to one email rather than bulk campaigns, and it is conservative about what it reports: it ignores Apple Mail’s automatic pre-fetch instead of counting it as an open, and it shows no location rather than a proxy’s location.
On the data side: to show you an open, the service stores the tracked email’s subject and the open events, which include IP address, approximate location and user agent. It does not sign in to, read, or access your mailbox. For the alternative built into most mail systems, see read receipts versus email tracking.
This article provides general information only and does not constitute legal advice. Consult a qualified lawyer about your specific situation and jurisdiction.
Stop wondering whether your email landed
Download Email Tracker free on the App Store and get a notification the next time one of your emails is opened.
iPhone, iOS 17 or later. Free download with an optional subscription.