Insights

Email Tracking Consent: What Event Marketers Need To Fix Before October 2026

By Cameron Korb, sr. email & automation manager

Nothing in Europe’s privacy law changed this year. What changed is that regulators spelled out how it applies. France and Italy have both confirmed that tracking whether someone opens or clicks an email counts as accessing their device, the same as a cookie. So the consent rule you already follow on your website now applies to email too. 

France’s requirement is already in effect, and its grace period for older contacts closed in July. Italy’s deadline follows this fall. Other EU regulators are expected to take the same view, since they all read from the same EU rulebook. If your association or event emails anyone in Europe, whether members, event prospects, or lapsed renewals, this is worth 20 minutes this week.

Compliance Rests on Two Things 

First is a real opt-in to what you collect, and second is a privacy policy that documents it accurately. One without the other doesn’t hold. Most associations have a policy. The gap is usually one of two things:  

  1. The opt-in was never clearly asked for. 
  2. The policy has drifted out of date while the systems behind it kept changing. 

A policy that no longer matches what you actually do is treated as misleading, and regulators view that as worse than having no policy at all.

How a Good Policy Goes Stale 

  • It hasn’t been updated in over a year (California requires an annual review). 
  • You switched email or CRM platforms, but the policy still names the old setup. 
  • The website was redesigned and the old policy never made the move. 
  • New tracking or ad tools were added, with no opt-in and no mention in the policy. 
  • It promises to delete data on request but ignores what you’re legally required to keep.

What Gets Missed Isn’t Malicious. It’s Just Overlooked.

Most associations aren’t cutting corners on purpose. Consent and policy accuracy sit in different departments, get set up once and rarely get revisited unless something forces the question. Email open and click tracking in particular is easy to miss because it feels like basic marketing measurement rather than a data collection practice that requires consent. 

That consent must live somewhere concrete: a checkbox at sign-up for email, a cookie banner for the website, sometimes both if your tools blend the two. And it can’t be prechecked. A compliant opt-in gives a clear, unchecked box describing what’s being collected, links to the policy right where someone says yes, and an easy way to change their mind later. 

What Gets Missed Downstream: Blacklisting 

Most associations that get this wrong won’t necessarily face a lawsuit, but they will get blocked. Add people to a list without a clear “yes,” and your database fills with contacts who never wanted to hear from you. They mark messages as spam, they stop engaging and that pattern is exactly what gets a sender blacklisted. Once that happens, inbox reach for that sender drops to near zero, regardless of subject line or send time. 

Blacklisting isn’t a separate deliverability problem to troubleshoot. It’s a missing opt-in showing up downstream. Fix the consent at the source, and list health tends to follow.

What It Costs To Get Wrong

Real settlements typically land well below these ceilings, but even a fraction of them is enough to end a small organization. 

  • United States: Up to $53,088 per email – B2B not exempt. 
  • Canada: Up to $10 million per violation, with leaders personally liable in some cases. 
  • Europe: Up to €20 million or 4% of worldwide revenue, whichever is larger. 

U.S. law does not require opt-in, but it does require a working unsubscribe, a real mailing address and honest subject lines. Miss any of those and the fine applies per message.

Two Questions To Ask About Your Own Program

  1. Did people actually opt in to what you collect, including email tracking, cookies and ad tools? 
  2. Is the privacy policy current, and does it match the tools you use today? 

If either answer is no, or you’re not sure, that’s your starting point. Confirm the specifics with your legal or privacy contact before making changes, since the right fix depends on your systems and your data. .

Where To Start

  1. Pull up your privacy policy and your email sign-up form side by side.  
  2. Check whether the opt-in language matches what the policy describes and whether both reflect the tools you’re using right now, not the ones in place when the policy was last written.  
  3. If your association runs member communications or event marketing with an outside partner, ask them to walk through this with you.  

Confirming the gap is quick. The fixes rarely are, so give yourself runway before Italy’s deadline arrives.