That open pixel? It's personal data.Here's the part most senders miss. When you track opens and clicks, you're not just counting numbers. In a lot of the world, you're processing someone's personal data, and there are laws about that. Let's walk through what actually applies to your email tracking.
⬡ talking-stat, big "4 frameworks", then four pills fade in: GDPR · CCPA/CPRA · ePrivacy · CAN-SPAMStart with the why. An open pixel and a wrapped click link don't just record "someone opened." They can log an IP address, a device type, a timestamp, tied to a real subscriber. That combination points at an identifiable person, and once it does, most privacy laws say you're processing personal data. That's the whole reason these rules touch email at all.
⬡ dissect, label a tracked-open record: IP · device · timestamp · subscriber, then a tag "= personal data"GDPR: you need a lawful basis.In the European Union, GDPR is the strictest of the bunch. If your engagement data ties to an identifiable person, you need a lawful basis to process it. For plain analytics, most senders lean on something called legitimate interest. For ad targeting, you generally need explicit consent. Either way, your privacy policy has to say what you collect, why, and for how long. And subscribers get rights: to see their data, to delete it, to take it with them. Legitimate interest is its own video, linked below.
⬡ split-compare, LEFT "Analytics → legitimate interest" vs RIGHT "Ad targeting → explicit consent"If this is clearing up the privacy fog, subscribe. We go through the whole measurement and compliance playbook, one question at a time.
⬡ title-card, on-screen "Subscribe · one email question at a time"California's CCPA, and its update CPRA, are less prescriptive than GDPR, but they're growing. The big trigger: if you sell or share email engagement data with third parties, think ad platforms or data brokers, you have to disclose that and offer people a way to opt out. Keep it inside your own systems for your own analytics, and it's a lighter lift.
⬡ record-cards, two cards: "Internal analytics = lighter" · "Sold/shared with third parties = disclose + opt-out"Two more to know. The EU's ePrivacy Directive covers cookies and tracking tech, and whether it fully covers email pixels is still genuinely debated. The proposed ePrivacy Regulation would spell it out and likely require consent for pixels, but it's not in force yet. Worth watching. And in the US, CAN-SPAM doesn't really regulate tracking at all. It sets the floor: honest headers, a working unsubscribe, no deception. That's the baseline, not the ceiling.
⬡ timeline, ePrivacy Directive (now, debated) → proposed ePrivacy Regulation (future, likely consent); side note card "CAN-SPAM = US floor"So the one habit: treat your tracking like the personal data it often is. Update your privacy policy to describe email tracking, link it from your footer, and check how long you hang onto that event data. Rules differ by region and they shift, so if you're sharing tracking data outside your own walls, get advice for your actual setup.
⬡ checklist, three steps: 1 describe tracking in policy · 2 link it from footer · 3 review retentionNext up: what your tracking-pixel disclosure actually has to say, in plain words. And subscribe, we're answering every email question, one at a time.
⬡ end-card, Subscribe + Next: "What disclosures are required for tracking pixels?" (004.012.002)How do privacy laws affect email tracking? Opens, clicks, IPs, and device data can count as personal data, which is why GDPR, CCPA/CPRA, ePrivacy, and CAN-SPAM all touch your email program. In plain English: why a tracking pixel can be personal data, what lawful basis GDPR expects (legitimate interest for analytics, consent for ad targeting), what CCPA requires when you sell or share engagement data, where ePrivacy stands today, and why CAN-SPAM is only the floor. This is general guidance, not legal advice. Rules differ by region and change, so check your obligations for your own situation.
0:00 That open pixel is personal data
0:20 Why tracking counts as personal data
0:50 GDPR needs a lawful basis
1:30 California: CCPA and CPRA
2:00 ePrivacy and the CAN-SPAM floor
2:45 The one habit to take away
Next: What disclosures are required for tracking pixels? → [link 004.012.002]
Full written guide → reviewmyemails.com/emailalmanac/004/004-012/004-012-001
#email #privacy #GDPR