Summary
In March 2026, the CNIL (the French data protection authority) published a recommendation clarifying how existing GDPR and ePrivacy rules apply to email tracking pixels.
It isn't a new law, it's the regulator's interpretation of existing requirements, but it changes what's considered acceptable practice.
Here's what you need to know:
Post-purchase notifications sent via Shipup by ZigZag (shipment updates, delivery confirmations, carrier incident management) are service communications, not marketing communications. They fall under exemptions recognised by the CNIL.
You remain the Data Controller for your communications; Shipup by ZigZag acts as your Data Processor and provides the tools you need to meet your obligations.
If you embed marketing content in transactional notifications (product recommendations, loyalty programme promotions, promotional banners), that content may require separate consent, this is the main area to review.
What did the CNIL publish?
On 12 March 2026, the CNIL published a recommendation explaining how existing GDPR and ePrivacy rules apply to email tracking pixels.
It doesn't create new legislation, it clarifies when a pixel can be used without consent, and when prior consent is expected, depending on the purpose of the tracking.
Core principle: tracking pixels generally require prior consent, unless a specific exemption applies.
The CNIL distinguishes in particular between:
Tracking that serves an exempt purpose: security/authentication, deliverability management (e.g. cleaning inactive contacts, provided only the date, not the time, of last open is stored, overwritten each time), service communications explicitly requested by the customer (order confirmations, shipment/delivery updates), and anonymised, aggregated statistics (provided the anonymisation is effective at the storage level, not just at display).
Tracking used for marketing purposes: campaign performance measurement, behavioural personalisation, profiling, cross-channel targeting, which requires prior consent.
Key nuance: what matters is the purpose of the tracking, not the type of email. A delivery email's tracking pixel can still require consent if it's used for marketing or profiling purposes, not just deliverability.
Who's responsible for what
You (the retailer) | Shipup by ZigZag | |
GDPR role | Data Controller | Data Processor |
Decides | Which communications are sent to your customers, the purpose of tracking, the content displayed, the appropriate legal basis | How to implement your instructions technically |
Responsible for | Collecting and managing your customers' consent, determining the legal basis for each processing activity | Providing the tools and documentation needed to support your compliance |
Does not | Validate individual customer consent, communicate directly with your customers on this topic |
Transactional and marketing communications serve different purposes, which may lead to different compliance requirements. Compliance is a shared effort: Shipup by ZigZag provides the tools and documentation; you decide how to use them.
How Shipup helps you stay compliant
Operational post-purchase notifications are covered by two independent exemptions
All notifications sent via Shipup by ZigZag (shipment updates, delivery confirmations, carrier incident management) are transactional/service communications, this alone falls under one CNIL exemption category. When the pixel is additionally used for deliverability purposes (e.g. managing inactive contacts), that's a second, separate exemption. Shipup's core usage is therefore covered twice over, independently.
The area to watch is edge cases: if you embed marketing content in transactional notifications (product recommendations, loyalty programme promotions, promotional banners), or use aggregated metrics for marketing purposes, that content may require separate consent. It's your responsibility to assess whether these communications require consent under the CNIL recommendation.
The same tracking data can serve different purposes
For example, when a customer opens a delivery notification, that event may be used both for deliverability/customer support (covered by the exemption) and to measure marketing performance (which requires consent). Shipup by ZigZag distinguishes these purposes: if a customer hasn't consented to marketing-related tracking, the data continues to be processed for the operational purposes covered by the exemption, but that customer is excluded from marketing analytics, campaign optimisation, and ROI reporting.
You can already request that the tracking pixel be disabled
On request to your Customer Success Manager or our Support team, we can fully disable the tracking pixel on your account. More granular, self-service controls are coming as part of the roadmap below.
Our roadmap
Shipup by ZigZag is committed to helping you comply with the CNIL recommendation while preserving the operational value of post-purchase communications. Our roadmap focuses on three priorities:
1. Clarifying the distinction between operational and marketing tracking (July 2026)
We're reviewing all tracking-related functionality to clearly distinguish tracking used to operate and support the delivery experience from tracking used for marketing, campaign optimisation, or performance measurement. This distinction becomes the foundation of how tracking data is processed and reported within Shipup by ZigZag.
2. Improving transparency and compliance support
We're updating our documentation and customer guidance to help you understand the CNIL recommendation, identify use cases that may require consent, configure Shipup by ZigZag accordingly, and document your compliance approach. Our Customer Success and Support teams are equipped to assist you through this transition.
3. Giving you greater control over consent (Objectif Q3 2026, ongoing)
We're building new capabilities so you can:
Import your consent preferences into Shipup by ZigZag: an import module (CSV, with API/FTP/integration options where possible) to send us your customers' opt-out signals.
Export opt-outs recorded by Shipup by ZigZag: an export module so you know which shoppers have opted out of marketing tracking, keeping your own systems in sync.
Automatically exclude opted-out shoppers from marketing analytics, while keeping them in deliverability analytics (a different purpose, not subject to consent).
A new deliverability-focused analytics dashboard, separate from marketing analytics.
What we recommend you do now
The CNIL set a deadline of 14 July 2026: for existing contact databases, retailers were required to inform recipients and give them the opportunity to opt out. If you haven't done this yet, we recommend you:
Identify whether your transactional notifications include marketing content (product recommendations, promotions, banners), this is the segment most exposed under the CNIL recommendation.
Review your consent and transparency mechanisms for any marketing-related tracking, in coordination with your legal counsel.
Does the recommendation ban tracking pixels?
No. The recommendation recognises that certain tracking activities may benefit from existing exemptions, particularly where they are closely connected to the delivery of a service requested by the customer.
Are shipment and delivery notifications still permitted?
Yes. These communications are among the examples explicitly referenced by the CNIL as potentially falling within the exemption framework.
Does Shipup by ZigZag become the Data Controller?
No. You remain the Data Controller. Shipup by ZigZag acts as your Data Processor.
Does Shipup by ZigZag verify customer consent?
No. You remain responsible for determining the appropriate legal basis for each processing activity.
Can I disable tracking?
Yes, on request. Contact your Customer Success Manager or our Support team. This isn't yet something you can do yourself from your account settings, but we're working on more granular, self-service controls.
What if my notifications contain marketing content?
You should assess whether those communications require consent under the CNIL recommendation. Check with your legal counsel if you're unsure.
Can I personalise post-purchase communications?
Yes, provided the personalisation serves the delivery experience rather than a marketing purpose. Adapting a notification based on the delivery journey, or adding extra reassurance for a high-value shipment, generally aligns with the operational framework. Personalisation used to promote products, segment customers based on behaviour, or optimise marketing performance requires consent.
Is this only relevant in France?
No. This recommendation was published by the CNIL and directly reflects its interpretation of French law. However, it's based on existing ePrivacy and GDPR principles that apply across the EU, and we expect it to influence the broader European interpretation of email tracking practices. If you operate across multiple European countries, we recommend applying a consistent approach wherever practical and seeking local legal advice where country-specific requirements may differ.
What Shipup by ZigZag features are affected?
Primarily features that rely on email open and click tracking: operational post-purchase notifications, marketing content embedded in notifications, email performance dashboards (open rates, click rates, CTOR, conversion metrics), and marketing attribution features such as UTM tracking. Other features aren't directly affected by this recommendation, though they remain subject to applicable data protection rules.
Can the same tracking data be used for different purposes?
Yes. For example, when a customer opens a delivery notification, that tracking event may support both operational purposes (customer support, deliverability) and marketing measurement. Shipup distinguishes these purposes: tracking data continues to be processed for operational purposes covered by the exemption, but is not used for marketing analytics, campaign optimisation, or ROI reporting if the customer hasn't consented.
