Insights
Email Tracking Consent: What Event Marketers Need To Fix Before October 2026
By Cameron Korb, sr. email & automation manager
Nothing in Europe’s privacy law changed this year. What changed is that regulators spelled out how it applies. France and Italy have both confirmed that tracking whether someone opens or clicks an email counts as accessing their device, the same as a cookie. So the consent rule you already follow on your website now applies to email too.
France’s requirement is already in effect, and its grace period for older contacts closed in July. Italy’s deadline follows this fall. Other EU regulators are expected to take the same view, since they all read from the same EU rulebook. If your association or event emails anyone in Europe, whether members, event prospects, or lapsed renewals, this is worth 20 minutes this week.
Compliance Rests on Two Things
First is a real opt-in to what you collect, and second is a privacy policy that documents it accurately. One without the other doesn’t hold. Most associations have a policy. The gap is usually one of two things:
- The opt-in was never clearly asked for.
- The policy has drifted out of date while the systems behind it kept changing.
A policy that no longer matches what you actually do is treated as misleading, and regulators view that as worse than having no policy at all.
How a Good Policy Goes Stale
- It hasn’t been updated in over a year (California requires an annual review).
- You switched email or CRM platforms, but the policy still names the old setup.
- The website was redesigned and the old policy never made the move.
- New tracking or ad tools were added, with no opt-in and no mention in the policy.
- It promises to delete data on request but ignores what you’re legally required to keep.
What Gets Missed Isn’t Malicious. It’s Just Overlooked.
Most associations aren’t cutting corners on purpose. Consent and policy accuracy sit in different departments, get set up once and rarely get revisited unless something forces the question. Email open and click tracking in particular is easy to miss because it feels like basic marketing measurement rather than a data collection practice that requires consent.
That consent must live somewhere concrete: a checkbox at sign-up for email, a cookie banner for the website, sometimes both if your tools blend the two. And it can’t be prechecked. A compliant opt-in gives a clear, unchecked box describing what’s being collected, links to the policy right where someone says yes, and an easy way to change their mind later.
What Gets Missed Downstream: Blacklisting
Most associations that get this wrong won’t necessarily face a lawsuit, but they will get blocked. Add people to a list without a clear “yes,” and your database fills with contacts who never wanted to hear from you. They mark messages as spam, they stop engaging and that pattern is exactly what gets a sender blacklisted. Once that happens, inbox reach for that sender drops to near zero, regardless of subject line or send time.
Blacklisting isn’t a separate deliverability problem to troubleshoot. It’s a missing opt-in showing up downstream. Fix the consent at the source, and list health tends to follow.
What It Costs To Get Wrong
Real settlements typically land well below these ceilings, but even a fraction of them is enough to end a small organization.
- United States: Up to $53,088 per email – B2B not exempt.
- Canada: Up to $10 million per violation, with leaders personally liable in some cases.
- Europe: Up to €20 million or 4% of worldwide revenue, whichever is larger.
U.S. law does not require opt-in, but it does require a working unsubscribe, a real mailing address and honest subject lines. Miss any of those and the fine applies per message.
Two Questions To Ask About Your Own Program
- Did people actually opt in to what you collect, including email tracking, cookies and ad tools?
- Is the privacy policy current, and does it match the tools you use today?
If either answer is no, or you’re not sure, that’s your starting point. Confirm the specifics with your legal or privacy contact before making changes, since the right fix depends on your systems and your data. .
Where To Start
- Pull up your privacy policy and your email sign-up form side by side.
- Check whether the opt-in language matches what the policy describes and whether both reflect the tools you’re using right now, not the ones in place when the policy was last written.
- If your association runs member communications or event marketing with an outside partner, ask them to walk through this with you.
Confirming the gap is quick. The fixes rarely are, so give yourself runway before Italy’s deadline arrives.

Cameron Korb is senior email & automation manager at mdg.
Strategy. Ideas. Proof.
Delivered Monthly.
Get insights from real event and association marketing work — not just theory.
"*" indicates required fields
Email Marketing Questions & Answers
Email tracking refers to open and click data collected when a recipient interacts with a message, typically through tracking pixels or wrapped links. French and Italian regulators have confirmed this data collection is equivalent to accessing a device, placing it under the same consent rules as cookies. That means associations need explicit opt-in before collecting open or click data from EU recipients, not just a general privacy policy disclosure. This applies regardless of whether the recipient is a member, event prospect or lapsed renewal, and regardless of whether the association classifies its email as marketing or member communication.
Italy’s deadline for email tracking consent compliance is October 28, 2026. France’s equivalent requirement is already in effect, with the grace period for existing contacts having closed in July 2026. Both countries’ data protection authorities have interpreted email open and click tracking as falling under the same consent standard as website cookies. Other EU regulators are expected to adopt the same interpretation since they draw from the same underlying EU privacy framework, so associations emailing contacts anywhere in Europe should treat this as a near-term compliance issue rather than one limited to France or Italy.
A valid opt-in requires an unchecked box that clearly describes what data will be collected, presented at the point of sign-up rather than buried in a separate policy. It must link directly to the privacy policy where someone provides consent, and it must include an accessible way to withdraw consent later. A prechecked box or a general acceptance of terms does not meet this standard. The opt-in language also needs to match what the privacy policy actually describes, since a mismatch between the two is treated as a compliance gap even if each document is technically present.
Contacts added without a clear opt-in are more likely to mark messages as spam or stop engaging, and that pattern is what triggers sender blacklisting. Once a sending domain is blacklisted, inbox placement for that sender drops sharply across all recipients, not just the unconsented ones, regardless of subject line or send time quality. Blacklisting is typically a downstream symptom of a consent problem rather than a separate deliverability issue to troubleshoot independently. Associations that fix opt-in practices at sign-up tend to see list health and inbox placement recover as a result.
Related Insights
