Pixel tracking explained: how tracking pixels work on websites and in emails, common ad pixels, and when GDPR, ePrivacy and CCPA require consent or an opt-out.
Pixel tracking is a way to record what people do on a website or in an email by loading a tiny, usually invisible resource from a third-party server. When the page or email loads, the tracking pixel sends a request with data such as the page URL, time, IP address, device details and an identifier, so the advertiser or analytics provider can count visits, measure conversions and build audiences. Because a tracking pixel reads and sends information from the user's device, EU law treats it like a cookie: in most cases it needs prior consent.
A tracking pixel (also called a pixel tag, web beacon, spy pixel or conversion pixel) started life as a 1x1 transparent image placed in the HTML of a page or email. Nobody sees it, but the browser or email app has to fetch it, and that fetch is the signal.
Today the word "pixel" usually means a small JavaScript tag provided by an ad platform, such as the Meta Pixel or the TikTok Pixel. The script still sends requests to the platform's server, but it can do much more than a plain image: read and set cookies, record events like "AddToCart" or "Purchase", and attach hashed customer data for matching.
| Type | Where it runs | What it can collect |
|---|---|---|
| Image pixel (1x1 GIF/PNG) | Web pages and HTML emails | Open or page view, time, IP address, user agent, any IDs in the URL |
| JavaScript pixel | Web pages | Page views, custom events, cookie IDs, click IDs, form and purchase data sent by the site |
| Server-side conversions API | Your server to the ad platform | Events your server chooses to send, often with hashed email or phone and the browser's cookie ID |
_fbp cookie) and read click IDs added to ad landing page URLs, so later visits and purchases can be tied back to the ad.Many platforms now recommend sending the same events from your server as well, through tools such as the Meta Conversions API, the TikTok Events API, the LinkedIn Conversions API or Google Ads enhanced conversions. Server-side tracking is not a way around privacy rules: the data still describes a person and is still sent to an advertising platform, so the same consent or opt-out choice has to apply.
| Pixel | Platform | Typical use | Server-side counterpart |
|---|---|---|---|
| Meta Pixel | Facebook and Instagram ads | Conversions, retargeting, lookalike audiences | Conversions API |
| TikTok Pixel | TikTok ads | Conversions, retargeting, optimization | Events API |
| Google tag (Google Ads) | Google Ads | Conversion tracking, remarketing | Enhanced conversions |
| LinkedIn Insight Tag | LinkedIn ads | Conversions, retargeting, B2B audience insights | Conversions API |
| Microsoft UET tag | Microsoft Advertising | Conversions, remarketing lists | Offline conversion imports |
| Pinterest Tag | Pinterest ads | Conversions, retargeting | Conversions API |
All of these tags send data about visitors to the ad platform, so all of them fall under the same consent and opt-out rules described below.
Pixels and cookies are different tools that usually work together.
| Tracking pixel | Cookie | |
|---|---|---|
| What it is | A request to a third-party server, triggered by an image or script | A small text file stored in the browser |
| Main job | Sends data out of the browser | Stores an identifier or setting on the device |
| Works in email | Yes, when images load | No, most email apps do not keep cookies |
| Blocked by clearing cookies | No | Yes |
| EU consent rule | ePrivacy Article 5(3) | ePrivacy Article 5(3) |
A JavaScript pixel normally sets its own cookies, which is why a cookie scanner is a good way to find pixels you did not know were on your site. For the basics on cookies, see All About Cookies.
Most email marketing tools add a tracking pixel to each message by default to measure open rates. Each image URL is unique to the recipient, so the sender learns who opened the email, when, how many times, and roughly where and on which device.
On 14 April 2026 the French regulator CNIL published its recommendation on email tracking pixels (adopted on 12 March 2026). The main points are:
Read our full analysis in CNIL email tracking pixels recommendation.
Some email apps also limit pixels on the user's side. Apple Mail Privacy Protection, for example, downloads remote content privately in the background and hides the recipient's IP address, which makes open rates less reliable.
Pixel tracking is legal when you follow the privacy rules of the places where your visitors and subscribers live. The rules differ a lot between the EU and the US.
Article 5(3) of the ePrivacy Directive requires consent before storing or accessing information on a user's device, unless it is strictly necessary for a service the user asked for. In its Guidelines 2/2023 on the technical scope of Article 5(3), adopted in final form on 7 October 2024, the European Data Protection Board confirms that the rule is not limited to cookies and covers URL and pixel tracking. Advertising and analytics pixels are not strictly necessary, so they need prior, opt-in consent.
The data the pixel collects (IP address, cookie IDs, browsing events) is personal data under the GDPR, so you also need a lawful basis, a clear privacy notice, and a way for users to withdraw consent as easily as they gave it. The UK applies the same approach through PECR and the UK GDPR.
Under the CCPA, giving personal information to a third party for cross-context behavioral advertising is "sharing", even when no money changes hands. Most retargeting and conversion pixels from ad platforms fall into this category. The CCPA is an opt-out law, so you must:
Several other US state privacy laws have similar opt-out rights for targeted advertising, and many require opt-in consent for sensitive data such as health information.
Pixels are also a major source of class actions in the US:
Regulators are strict when pixels reveal health information. In 2023 the US Federal Trade Commission ordered BetterHelp to pay $7.8 million over claims that it shared sensitive health data with advertising platforms without consent, and took action against GoodRx under the Health Breach Notification Rule for sharing health data with platforms including Facebook and Google. If your pages reveal health conditions, appointments or medications, keep advertising pixels off those pages or get explicit consent first. Read more in the BetterHelp FTC settlement.
Pixel tracking is the use of a small image or script, called a tracking pixel, that sends data to a third-party server when a web page or email loads. Advertisers and analytics providers use it to measure visits, email opens and conversions, and to build retargeting audiences.
When a page or email loads, the browser or email app requests the pixel from the provider's server. The request carries data such as the IP address, device, page URL, time and an identifier, and JavaScript pixels can also read and set cookies and send events like purchases.
Yes, if you follow the privacy rules that apply to your users. In the EU, EEA and UK, advertising and analytics pixels need prior consent under the ePrivacy rules and the GDPR. Under the CCPA and other US state laws, you must give notice and stop pixels that share data for targeted advertising when a user opts out, including through Global Privacy Control.
Yes, in most cases. The European Data Protection Board confirms that Article 5(3) of the ePrivacy Directive covers pixel tracking, not only cookies, so pixels that are not strictly necessary for a service the user requested need prior consent.
A cookie is a small file stored in the browser that keeps an identifier or setting. A tracking pixel is a request to a third-party server that sends data out. JavaScript pixels usually set cookies too, and pixels also work in emails, where cookies generally do not.
Set your email app to ask before loading remote images, or use a privacy feature such as Apple Mail Privacy Protection, which loads remote content privately in the background and hides your IP address. Senders in the EU should ask for consent before using email tracking pixels at all.
UniConsent is a Google-certified, IAB TCF-registered consent management platform built for sites that run advertising pixels:
Learn more about consent for ad tags on our Advertisers page, or create a free UniConsent account and start managing your pixels today.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up