Is Email Tracking Legal? What GDPR, ePrivacy and CAN-SPAM Actually Say
The short version: in most places, tracking opens and clicks in marketing email requires consent, while doing it in genuine one-to-one business correspondence sits in a much greyer area that regulators have largely not pursued. Which of those you are doing matters more than which tool you use.
The EU and UK: GDPR and ePrivacy
Two regimes apply and they are often conflated.
GDPR governs personal data. An email address is personal data, and so is the record that a specific person opened a message at a specific time from a specific device. So you need a lawful basis to process it, you need to disclose it in your privacy notice, and the person has the usual rights of access and erasure.
ePrivacy is the one that bites harder for tracking specifically. It governs storing or accessing information on a user’s device, which is the rule that made cookie banners ubiquitous. Regulators — notably in France and Germany — have taken the view that tracking pixels fall under it, which points toward prior consent rather than legitimate interest for marketing email.
- Marketing email to a list: the safe reading is that you need consent for tracking, obtained separately from consent to receive the mail at all.
- One-to-one business email: genuinely unsettled. A reasonable argument exists for legitimate interest, and enforcement against individual salespeople has been essentially nonexistent. That is not the same as it being clearly permitted.
- Either way: disclose it in your privacy policy, honour deletion requests, and do not retain engagement data longer than you need it.

The United States: CAN-SPAM
CAN-SPAM says nothing about tracking pixels. It regulates commercial email more broadly — you must not use deceptive headers or subject lines, you must identify the message as an advertisement where relevant, you must include a valid physical address, and you must honour opt-outs promptly.
So open tracking in the US is not specifically prohibited. State privacy laws — California’s in particular — add disclosure and deletion obligations around personal data, but none currently ban tracking pixels outright.
Canada: CASL
CASL is strict about consent to send commercial email in the first place, with meaningful penalties. It is less specific about tracking, but if you have valid express consent to send commercial messages, tracking engagement within them is generally treated as part of that relationship. Disclosure remains sensible.
The practical distinction that matters
Regulators, and most people’s intuitions, treat these as different activities even when the underlying technology is identical:
- A campaign to 10,000 addresses, tracked, scored, and fed into automation. Clearly marketing. Consent territory.
- An email to one person you are in a conversation with, where you want to know whether your proposal arrived and was read. Much closer to ordinary correspondence.
The technology does not distinguish them; the context does. If you are doing the second, you are in a defensible position in most jurisdictions. If you are doing the first and calling it the second, you are not.
A defensible practical posture
- Say so in your privacy policy. Explicitly: that you track opens and clicks, what you store, how long, and how to ask for deletion. Cheap, and it is the first thing anyone looks for.
- Get consent for marketing tracking. If it is a campaign, treat tracking as part of what you are getting consent for.
- Do not track sensitive contexts. Health, legal, financial hardship, employment disputes. The downside is disproportionate.
- Answer honestly if asked. "Yes, I use a tool that tells me when emails are opened" costs you nothing. Denying it costs you everything.
- Store less. City-level rather than precise location, no raw IP retention, short retention windows. Less data is less risk.
- Honour deletion requests without argument.
The ethical line, separately from the legal one
Legality is a floor. The behaviour that keeps you trusted is narrower: use tracking for timing, never as leverage. Do not tell someone you can see they opened your email. Do not treat an open as consent to be pursued. Do not infer interest from a number that, as we have argued at length, does not carry that meaning — see an open is not intent.
And recognise the recipient has a straightforward defence: turning off automatic image loading ends open tracking entirely for them. That is covered in how to block email tracking pixels in Gmail, and the fact that it is one setting away is part of what makes the practice defensible.
On our side: MailSenseAI stores city-level location rather than precise coordinates, does not retain raw IP addresses, adds no footer or signature to your emails, and requests no permission to read your mailbox. The details are in the privacy policy and the security overview.
See it in your own inbox
Know what happens after you hit send.
MailSenseAI shows opens, clicks, and replies in real time — right inside Gmail — so you follow up at the moment interest is highest.
Add to Gmail · free