Italy Italy Garante GDPR AI enforcement

Italy's Tracking-Pixel Deadline Is Fair on Consent, but the Garante's Own Newsletter Shows Where Enforcement Effort Belongs

Italy's Garante gives email marketers until 29 October 2026 to get consent for tracking pixels, while its recent fines target far more concrete harms.

Garante's October 2026 Newsletter in Numbers People of Internet Research · Italy €8,000 Rome Technopole fine Fine over data of scholarship winn… 480 Scholarship winners exposed Records included tax IDs, IBANs an… €4,000 Arvier CCTV fine Camera captured a resident's windo… 6 months Pixel adaptation period Transition period from gazette pub… peopleofinternet.com
Garante's October 2026 Newsletter in N… People of Internet Research · Italy €8,000 Rome Technopole fine 480 Scholarship winners exposed €4,000 Arvier CCTV fine 6 months Pixel adaptation period peopleofinternet.com

Key Takeaways

On 8 October 2026, Italy's data protection authority, the Garante, used its newsletter to remind email marketers that a compliance deadline is close. Tracking pixels, the tiny transparent images that reveal when an email is opened and track recipient behaviour, now require prior, free, specific and informed consent. The same issue reported two small fines: €8,000 on the Rome Technopole Foundation and €4,000 on the Municipality of Arvier. Read together, the items show both what is reasonable in Italy's approach and where it risks losing proportion.

The strongest case for the rule

The Garante's argument deserves a fair hearing. A tracking pixel works without the recipient doing anything. Opening a message can disclose an IP address, device type, time of reading and the number of reopenings, usually without the reader knowing. In its guidelines, the Garante describes this practice as particularly invasive because it often happens without the recipient's full awareness. The Garante treats the practice as falling under Article 122 of the Italian Privacy Code, the national transposition of the ePrivacy rules on accessing or monitoring information on a user's device. On that reading, a pixel is functionally the same as a cookie, and cookies have required consent for years. Consistency is a legitimate regulatory value.

What the guidelines actually require

The guidelines, adopted on 17 April 2026 as Provision No. 284, are narrower than the headline suggests. Consent is the default, but the text carves out three situations:

The Garante also asks for something many consent regimes lack: granular revocation. A recipient must be able to refuse tracking and still receive the email, for example through a footer link or icon. Controllers may fold the pixel consent into the request for marketing consent if the request is neutral, clear and non-coercive. The Garante's press release set a six-month adaptation period, and the October newsletter fixes the end date at 29 October 2026. Some law-firm summaries give 28 October, so businesses should treat the earlier date as the safe one.

These choices are sensible. The aggregate-measurement carve-out means a newsletter publisher can still learn that roughly a third of its audience opens each issue without profiling any individual. The line the Garante draws is between measuring a campaign and watching a person, which is where a proportionate regime should draw it.

Where the burden lands

The pro-innovation concern is not with the principle but with the compliance cost for small senders. A large platform can rebuild its consent flows; an independent publisher or a local business using an off-the-shelf mailing tool depends on its vendor's settings. The guidelines are addressed to a wide group: information society service providers, platform operators, email service providers and bulk senders. Smaller senders are most likely to find out about the deadline from a newsletter reminder, not from months of preparation.

There is also a practical measurement problem. Open rates were already unreliable after mail clients began prefetching images, and a consent-gated pixel will undercount opens even further. Marketers who lean on open rates to judge campaigns will need to shift to clicks and conversions, which are measured with the user's own action. That shift is healthy, but it is a real cost, and regulators should say so plainly instead of assuming the cost is zero.

Audits are the second pressure point. The newsletter signals that checks are planned for the second half of 2026. Audits that start right after the deadline are reasonable, provided they begin with the clearest cases: undisclosed individual-level tracking, no revocation path, or consent bundled so tightly that refusal means losing the email. An audit programme that punishes a missing footer link on a hobbyist newsletter would waste regulator effort and erode goodwill for the rule.

What the two fines show

The fines in the same newsletter are a useful benchmark for proportionality. The Rome Technopole Foundation was fined €8,000 on 23 September 2026 after publishing personal data of 480 scholarship winners online. The data included addresses, tax IDs, birthdates, emails, identity document details and bank information including IBANs. The data was taken down about twelve hours later. The Garante found that transparency duties do not justify disclosing that much, citing breaches of lawfulness and data minimisation. This is the harm data protection law exists to prevent: sensitive financial and identity data that fraudsters can use.

The €4,000 fine on Arvier, a Valle d'Aosta municipality of about 800 residents, concerned a CCTV camera that captured a citizen's home, including windows and balconies. The Garante also found gaps in the legal basis documentation, privacy masking and transparency. The penalty is modest and the finding is concrete: a camera pointed at someone's bedroom window.

Both cases involve identifiable people exposed to real risk. A tracking pixel in a marketing email is a lower-stakes privacy intrusion, even if a genuine one. The Garante is right to regulate it, and the exceptions suggest it knows the difference. Enforcement should keep that ordering: first the leaks, then the cameras on homes, then the pixels that profile individuals, and only afterwards technical non-compliance with no evident harm.

A workable standard

The test for the audits is whether they reward good-faith compliance. Senders who use only aggregate measurement should be told clearly that they need no consent banner. Senders who profile should get a consent flow that is as easy to refuse as to accept. The Garante has built a framework that can do both. Whether it delivers will be visible in who gets fined after 29 October, and in how small the penalties are for first-time offenders.

Sources & Citations

  1. Garante Privacy newsletter, 8 October 2026
  2. Garante Privacy: Guidelines on tracking pixels in emails (Provision of 17 April 2026)
  3. Covington Inside Privacy: Italian DPA publishes guidelines on email tracking pixels
  4. iubenda: Garante email tracking pixel rules