← All topicsMetrics & ReportingPrivacy, Compliance & Ethics in Measurement
Accuracy / correctness · 2
accuracyScript says CCPA 'is growing' and CPRA is 'its update', matching the article. Accurate. Kept the article's hedge that ePrivacy application to email pixels is 'still debated' and the Regulation is 'not in force yet', preserving the article's non-definitive stance. No over-definitive legal claim introduced.
accuracyArticle says legitimate interest is 'usually' the basis for analytics and 'explicit consent for ad targeting'. Script mirrors with 'most senders lean on' and 'generally need', preserving the hedge rather than stating it as universal law. Good, no drift.
Would elevate the video · 1
elevateThe article's closing links to the retention question (004.009.006) and frames retention review as a concrete action. The script keeps 'review retention' in the takeaway checklist, good, but could name the related retention video explicitly in a DEFER-style line since retention is where senders most often trip. Minor add, connections block already carries it.
Considered, left out · 2
skipArticle's sidebar/promo fields (sidebarTitle 'Privacy-Compliant Tracking', CTA to /pricing) dropped rightly. These are page-furniture CTAs, not teaching content, and the spec forbids pushy product CTAs. Correctly left out.
skipDropped the explicit almanac inline-link phrasing ('that guide covers the practical requirements in more detail'). Rightly skipped as prose plumbing; the CONNECTIONS block and NEXT beat carry the same cross-link for a video.
How privacy laws actually treat your email tracking
Question: 004.012.001 · How do privacy laws affect email tracking? · ~3:30 · single-question video
Model note: frames law as "the general rule / what regulators expect," not legal advice. Rules differ by region and change, so the script says "check your obligations" rather than making guarantees.
COLD OPEN
That open pixel? It's personal data.

Here's the part most senders miss. When you track opens and clicks, you're not just counting numbers. In a lot of the world, you're processing someone's personal data, and there are laws about that. Let's walk through what actually applies to your email tracking.

⬡ talking-stat, big "4 frameworks", then four pills fade in: GDPR · CCPA/CPRA · ePrivacy · CAN-SPAM
BEAT 1, why tracking counts as personal data

Start with the why. An open pixel and a wrapped click link don't just record "someone opened." They can log an IP address, a device type, a timestamp, tied to a real subscriber. That combination points at an identifiable person, and once it does, most privacy laws say you're processing personal data. That's the whole reason these rules touch email at all.

⬡ dissect, label a tracked-open record: IP · device · timestamp · subscriber, then a tag "= personal data"
BEAT 2, GDPR is the strict one
GDPR: you need a lawful basis.

In the European Union, GDPR is the strictest of the bunch. If your engagement data ties to an identifiable person, you need a lawful basis to process it. For plain analytics, most senders lean on something called legitimate interest. For ad targeting, you generally need explicit consent. Either way, your privacy policy has to say what you collect, why, and for how long. And subscribers get rights: to see their data, to delete it, to take it with them. Legitimate interest is its own video, linked below.

⬡ split-compare, LEFT "Analytics → legitimate interest" vs RIGHT "Ad targeting → explicit consent"
SUBSCRIBE

If this is clearing up the privacy fog, subscribe. We go through the whole measurement and compliance playbook, one question at a time.

⬡ title-card, on-screen "Subscribe · one email question at a time"
BEAT 3, California is lighter but real

California's CCPA, and its update CPRA, are less prescriptive than GDPR, but they're growing. The big trigger: if you sell or share email engagement data with third parties, think ad platforms or data brokers, you have to disclose that and offer people a way to opt out. Keep it inside your own systems for your own analytics, and it's a lighter lift.

⬡ record-cards, two cards: "Internal analytics = lighter" · "Sold/shared with third parties = disclose + opt-out"
BEAT 4, ePrivacy and the CAN-SPAM floor

Two more to know. The EU's ePrivacy Directive covers cookies and tracking tech, and whether it fully covers email pixels is still genuinely debated. The proposed ePrivacy Regulation would spell it out and likely require consent for pixels, but it's not in force yet. Worth watching. And in the US, CAN-SPAM doesn't really regulate tracking at all. It sets the floor: honest headers, a working unsubscribe, no deception. That's the baseline, not the ceiling.

⬡ timeline, ePrivacy Directive (now, debated) → proposed ePrivacy Regulation (future, likely consent); side note card "CAN-SPAM = US floor"
TAKEAWAY

So the one habit: treat your tracking like the personal data it often is. Update your privacy policy to describe email tracking, link it from your footer, and check how long you hang onto that event data. Rules differ by region and they shift, so if you're sharing tracking data outside your own walls, get advice for your actual setup.

⬡ checklist, three steps: 1 describe tracking in policy · 2 link it from footer · 3 review retention
NEXT / SUBSCRIBE

Next up: what your tracking-pixel disclosure actually has to say, in plain words. And subscribe, we're answering every email question, one at a time.

⬡ end-card, Subscribe + Next: "What disclosures are required for tracking pixels?" (004.012.002)
DESCRIPTION

How do privacy laws affect email tracking? Opens, clicks, IPs, and device data can count as personal data, which is why GDPR, CCPA/CPRA, ePrivacy, and CAN-SPAM all touch your email program. In plain English: why a tracking pixel can be personal data, what lawful basis GDPR expects (legitimate interest for analytics, consent for ad targeting), what CCPA requires when you sell or share engagement data, where ePrivacy stands today, and why CAN-SPAM is only the floor. This is general guidance, not legal advice. Rules differ by region and change, so check your obligations for your own situation.

0:00 That open pixel is personal data

0:20 Why tracking counts as personal data

0:50 GDPR needs a lawful basis

1:30 California: CCPA and CPRA

2:00 ePrivacy and the CAN-SPAM floor

2:45 The one habit to take away

Next: What disclosures are required for tracking pixels? → [link 004.012.002]

Full written guide → reviewmyemails.com/emailalmanac/004/004-012/004-012-001

#email #privacy #GDPR

CONNECTIONS
• next: 004.012.002 What disclosures are required for tracking pixels?
• deeper: 004.012.004 What is "legitimate interest" in analytics?
• related: 004.009.006 What's a typical data retention policy for events?
• vocab: personal data, lawful basis, legitimate interest, consent, GDPR, CCPA/CPRA, ePrivacy, CAN-SPAM