What Is Pixel Tracking?

Pixel tracking explained: how tracking pixels work on websites and in emails, common ad pixels, and when GDPR, ePrivacy and CCPA require consent or an opt-out.

What Is Pixel Tracking?

Pixel tracking is a way to record what people do on a website or in an email by loading a tiny, usually invisible resource from a third-party server. When the page or email loads, the tracking pixel sends a request with data such as the page URL, time, IP address, device details and an identifier, so the advertiser or analytics provider can count visits, measure conversions and build audiences. Because a tracking pixel reads and sends information from the user's device, EU law treats it like a cookie: in most cases it needs prior consent.

What Is a Tracking Pixel?

A tracking pixel (also called a pixel tag, web beacon, spy pixel or conversion pixel) started life as a 1x1 transparent image placed in the HTML of a page or email. Nobody sees it, but the browser or email app has to fetch it, and that fetch is the signal.

Today the word "pixel" usually means a small JavaScript tag provided by an ad platform, such as the Meta Pixel or the TikTok Pixel. The script still sends requests to the platform's server, but it can do much more than a plain image: read and set cookies, record events like "AddToCart" or "Purchase", and attach hashed customer data for matching.

TypeWhere it runsWhat it can collect
Image pixel (1x1 GIF/PNG)Web pages and HTML emailsOpen or page view, time, IP address, user agent, any IDs in the URL
JavaScript pixelWeb pagesPage views, custom events, cookie IDs, click IDs, form and purchase data sent by the site
Server-side conversions APIYour server to the ad platformEvents your server chooses to send, often with hashed email or phone and the browser's cookie ID

How Does a Tracking Pixel Work?

  1. The pixel is embedded. The site owner adds the platform's base code to every page, or the email tool inserts an image with a unique URL into each message.
  2. The browser or email app loads it. When the page renders or the email is opened, the device requests the image or script from the platform's server.
  3. Data travels with the request. The request carries the IP address, user agent, referring page, timestamp and parameters in the URL, such as a campaign ID or subscriber ID.
  4. Cookies are read or set. JavaScript pixels usually store an identifier in a first-party cookie (for example, the Meta Pixel uses the _fbp cookie) and read click IDs added to ad landing page URLs, so later visits and purchases can be tied back to the ad.
  5. Events are matched and used. The platform matches the events to its users and uses them for conversion reporting, retargeting audiences, lookalike audiences and campaign optimization.

Many platforms now recommend sending the same events from your server as well, through tools such as the Meta Conversions API, the TikTok Events API, the LinkedIn Conversions API or Google Ads enhanced conversions. Server-side tracking is not a way around privacy rules: the data still describes a person and is still sent to an advertising platform, so the same consent or opt-out choice has to apply.

Common Advertising Pixels

PixelPlatformTypical useServer-side counterpart
Meta PixelFacebook and Instagram adsConversions, retargeting, lookalike audiencesConversions API
TikTok PixelTikTok adsConversions, retargeting, optimizationEvents API
Google tag (Google Ads)Google AdsConversion tracking, remarketingEnhanced conversions
LinkedIn Insight TagLinkedIn adsConversions, retargeting, B2B audience insightsConversions API
Microsoft UET tagMicrosoft AdvertisingConversions, remarketing listsOffline conversion imports
Pinterest TagPinterest adsConversions, retargetingConversions API

All of these tags send data about visitors to the ad platform, so all of them fall under the same consent and opt-out rules described below.

Tracking Pixels vs Cookies

Pixels and cookies are different tools that usually work together.

Tracking pixelCookie
What it isA request to a third-party server, triggered by an image or scriptA small text file stored in the browser
Main jobSends data out of the browserStores an identifier or setting on the device
Works in emailYes, when images loadNo, most email apps do not keep cookies
Blocked by clearing cookiesNoYes
EU consent ruleePrivacy Article 5(3)ePrivacy Article 5(3)

A JavaScript pixel normally sets its own cookies, which is why a cookie scanner is a good way to find pixels you did not know were on your site. For the basics on cookies, see All About Cookies.

Email Tracking Pixels

Most email marketing tools add a tracking pixel to each message by default to measure open rates. Each image URL is unique to the recipient, so the sender learns who opened the email, when, how many times, and roughly where and on which device.

On 14 April 2026 the French regulator CNIL published its recommendation on email tracking pixels (adopted on 12 March 2026). The main points are:

  • Prior consent is the rule for tracking pixels in emails, including for measuring open rates.
  • Two narrow exceptions apply only to emails the recipient asked for, such as order confirmations or password resets: pixels used for authentication and security, and pixels used to measure deliverability so inactive addresses can be removed.
  • Consent should be collected when the email address is collected, separately from consent to receive marketing, and every email should offer an easy way to withdraw it.
  • For addresses collected before the recommendation, senders had until 14 July 2026 to inform recipients so they could object.

Read our full analysis in CNIL email tracking pixels recommendation.

Some email apps also limit pixels on the user's side. Apple Mail Privacy Protection, for example, downloads remote content privately in the background and hides the recipient's IP address, which makes open rates less reliable.

Is Pixel Tracking Legal?

Pixel tracking is legal when you follow the privacy rules of the places where your visitors and subscribers live. The rules differ a lot between the EU and the US.

GDPR and ePrivacy (EU, EEA and UK)

Article 5(3) of the ePrivacy Directive requires consent before storing or accessing information on a user's device, unless it is strictly necessary for a service the user asked for. In its Guidelines 2/2023 on the technical scope of Article 5(3), adopted in final form on 7 October 2024, the European Data Protection Board confirms that the rule is not limited to cookies and covers URL and pixel tracking. Advertising and analytics pixels are not strictly necessary, so they need prior, opt-in consent.

The data the pixel collects (IP address, cookie IDs, browsing events) is personal data under the GDPR, so you also need a lawful basis, a clear privacy notice, and a way for users to withdraw consent as easily as they gave it. The UK applies the same approach through PECR and the UK GDPR.

CCPA and US state privacy laws

Under the CCPA, giving personal information to a third party for cross-context behavioral advertising is "sharing", even when no money changes hands. Most retargeting and conversion pixels from ad platforms fall into this category. The CCPA is an opt-out law, so you must:

  • Explain the pixels and the platforms that receive data in your notice at collection and privacy policy.
  • Offer a "Do Not Sell or Share My Personal Information" choice and stop the pixels when a user opts out.
  • Treat a Global Privacy Control signal as a valid opt-out for that browser or device.

Several other US state privacy laws have similar opt-out rights for targeted advertising, and many require opt-in consent for sensitive data such as health information.

US litigation risk: CIPA and VPPA

Pixels are also a major source of class actions in the US:

  • California Invasion of Privacy Act (CIPA). Plaintiffs argue that a third-party pixel that fires without consent "intercepts" the visitor's communication with the website. CIPA allows statutory damages of $5,000 per violation. European Wax Center agreed to a $5 million settlement over Meta, Snap, LinkedIn and other pixels that fired before consent. See CIPA compliance and the European Wax Center settlement.
  • Video Privacy Protection Act (VPPA). Sites that offer video content can face claims when a pixel sends the title of a video a user watched together with an identifier. The VPPA provides liquidated damages of $2,500. See VPPA compliance.
  • CCPA private right of action. In Allison v. PHH Mortgage, a federal court let a CCPA claim based on pixel disclosures go forward. See why CCPA tracking pixels still need a CMP.

Health data and pixels

Regulators are strict when pixels reveal health information. In 2023 the US Federal Trade Commission ordered BetterHelp to pay $7.8 million over claims that it shared sensitive health data with advertising platforms without consent, and took action against GoodRx under the Health Breach Notification Rule for sharing health data with platforms including Facebook and Google. If your pages reveal health conditions, appointments or medications, keep advertising pixels off those pages or get explicit consent first. Read more in the BetterHelp FTC settlement.

How to Make Pixel Tracking Compliant

  1. Find every pixel. Scan your site with a cookie scanner and review your tag manager, theme and plugins. Check your email tool's tracking settings too.
  2. Block pixels until consent. In the EU, EEA and UK, no advertising or analytics pixel should fire before the user agrees. Load the consent banner first and release tags only for the purposes the user accepted.
  3. Use the platforms' consent APIs. Google Consent Mode v2, Microsoft UET Consent Mode, the Meta Pixel consent API and the TikTok Pixel consent functions let the tag wait for a consent signal. Microsoft has required consent signals for users in the EEA, UK and Switzerland since 5 May 2025.
  4. Honor opt-outs in the US. Stop sharing pixels after a "Do Not Sell or Share" request or a Global Privacy Control signal, in the same session.
  5. Apply consent to server-side events. Only send Conversions API or Events API data for users who consented, or who have not opted out where opt-out rules apply.
  6. Update your privacy notice. Name the platforms that receive pixel data, the purposes and how users can change their choice.
  7. Keep records. Store a log of each consent and opt-out so you can prove what the user chose and when.
  8. Get consent for email pixels. Ask at sign-up, separately from marketing consent, and turn off open tracking for contacts who did not agree.

Frequently Asked Questions

What is pixel tracking?

Pixel tracking is the use of a small image or script, called a tracking pixel, that sends data to a third-party server when a web page or email loads. Advertisers and analytics providers use it to measure visits, email opens and conversions, and to build retargeting audiences.

How does a tracking pixel work?

When a page or email loads, the browser or email app requests the pixel from the provider's server. The request carries data such as the IP address, device, page URL, time and an identifier, and JavaScript pixels can also read and set cookies and send events like purchases.

Is pixel tracking legal?

Yes, if you follow the privacy rules that apply to your users. In the EU, EEA and UK, advertising and analytics pixels need prior consent under the ePrivacy rules and the GDPR. Under the CCPA and other US state laws, you must give notice and stop pixels that share data for targeted advertising when a user opts out, including through Global Privacy Control.

Do tracking pixels need consent under GDPR?

Yes, in most cases. The European Data Protection Board confirms that Article 5(3) of the ePrivacy Directive covers pixel tracking, not only cookies, so pixels that are not strictly necessary for a service the user requested need prior consent.

What is the difference between a tracking pixel and a cookie?

A cookie is a small file stored in the browser that keeps an identifier or setting. A tracking pixel is a request to a third-party server that sends data out. JavaScript pixels usually set cookies too, and pixels also work in emails, where cookies generally do not.

How can you block email tracking pixels?

Set your email app to ask before loading remote images, or use a privacy feature such as Apple Mail Privacy Protection, which loads remote content privately in the background and hides your IP address. Senders in the EU should ask for consent before using email tracking pixels at all.

How UniConsent Helps You Manage Pixel Tracking

UniConsent is a Google-certified, IAB TCF-registered consent management platform built for sites that run advertising pixels:

Learn more about consent for ad tags on our Advertisers page, or create a free UniConsent account and start managing your pixels today.

UniConsent Consent Manager for Tracking Pixels


Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up