The CNIL recommendation of 14 April 2026 (deliberation no. 2026-042) went off like a grenade inside CRM teams. Three months to become compliant on a topic nobody had put in a roadmap. A topic that touches marketing, legal, product and development all at once. And platforms, Adobe Campaign and Salesforce, that do strictly nothing natively to help you.
A tracking pixel is an invisible 1×1 pixel image embedded in the body of an email. When the recipient opens the message, their mail client loads that image from a remote server. The load is logged: date, time, device, IP address. That mechanism is what feeds the open rates shown in your dashboards, engagement based segmentation, automation scenarios triggered by opens and CRM scoring.
The mechanism is not banned. It is now regulated. The CNIL treats it as a tracker, exactly like a cookie: any use for marketing purposes requires prior consent that is freely given, specific and informed.
A point that is often misunderstood: an email opt-in is not consent to tracking. Agreeing to receive your emails and agreeing to be tracked on open are two distinct purposes. Each one needs its own consent, and the box must not be pre-checked.
This exchange, or some variant of it, has played out in almost every organization running an emailing tool with native tracking. That is where the real issue sits.
Adobe Campaign Classic and Campaign v8 handle email, SMS and push opt-ins. They store preferences and consents. But there is no native "tracking pixel consent" field, no native logic to make pixel insertion conditional in templates, and no prebuilt automation to handle tracking opt-out.
Salesforce Marketing Cloud turns on open tracking by default for every send. Its documentation names France and points out that responsibility lies with the sender, not with the platform. The vendors publish blog posts and FAQs. Not one of them ships a "become compliant" button.
Compliance is a CRM development and architecture project that your technical teams have to run. As the sender, it is your responsibility, not the platform's.
This gap between how the business sees it and the technical reality is the heart of the problem. No tool will close it. It closes with a structured conversation and a two stage plan.
Do not play down the technical complexity to keep the business calm. A timeline you underestimate, and that proves unrealistic two weeks later, damages trust far more than an honest estimate given up front.
Offer a two stage plan, not a monolithic project. A minimal compliance "quick win" in two weeks (informing the existing databases, making objection possible) to cut immediate exposure, then the full project over 6 to 8 weeks. That split gives the business an early win and the developers a realistic scope.
Quantify the business impact, not just the technical cost. "Six weeks of development" means nothing to an IT director. "Six weeks during which we expose the organization to regulatory risk, with an intermediate milestone at two weeks that cuts that risk by 80%" is a decision, not an estimate.
The first question to ask in the scoping meeting: "Of our automation scenarios and segmentations, which ones actually use open data?" The answer maps the real exposure. It is often smaller than the business imagines, which opens a window for a realistic plan.
pixel_tracking_consent and a date pixel_tracking_consent_date in the recipient schema. On Adobe Campaign Classic, an extension of the nmsRecipient schema. On Salesforce MC, a contact attribute in the subscriber profile. Proof of consent (date, source, channel) has to be retained.pixel_tracking_consent = false.The organizations that got through this transition without a major crisis were the ones that already had a clean consent data model, an up to date preference center and documented workflows. Not because they had anticipated the CNIL, but because those foundations serve everything: GDPR, a change of channel, a change of platform.
The organizations caught off guard are the ones that had built up architecture debt without seeing it: poorly documented consents, cascading automations built on fragile engagement criteria, templates never revisited since the day they were created. The regulation did not create these problems. It made them visible.
The deliverability exemption is still usable without consent: you can keep identifying inactive contacts and cleaning your database. It is the only window left open. As soon as open data feeds a segmentation, a scoring or an automation, consent is mandatory.
Exposure mapping, a two stage plan, support for CRM teams on Adobe Campaign or Salesforce. Free scoping, no commitment.
Contact →