Email read-tracking is not GDPR compliant
blog.ohmysmtp.com
blog.ohmysmtp.com
Nice
You would probably find it really weird that a NYT article archive HTML page you have on your machine still tracks you because you client runs the JS if it wasn't already the norm. But then why does downloading that same document on-demand change your expectation of being tracked? Or if we were in a alternate universe where web pages were hyperlinked PDFs I bet you would find it odd that opening one in Acrobat sends all your interactions to some server somewhere.
It's fine that by convention we have some places where it's not kosher to track people but we at least have to admit that the distinction is arbitrary and that being upset about email tracking but not website tracking is inherently inconsistent. Because sure you can name differences between emails and websites but nothing really fundamental.
For websites I would look as the data in aggregate. Sure that aggregation can be pretty precise but still it is not on the personal level. I suppose technically speaking you could checks the individual use of a website for logged in users but even Google Analytics is very explicit on hat not being OK for instance, and there is no UI for it in any tool that I know.
External (embedded) pictures are deactivated per default, if you want to get at least a tiny chance I see your picture, attach it or gain my trust (and even then, attach it).
JS in mails is completely ignored, it has no business of being there.
It would be nice to live in a world where you could trust sizeable companies not to break the law (or my trust) with every other email they send. It would be nice to have html and css in a mail and not have people abuse it. But as things stand now, not using html is the way to go.
In e-mails it isn't clear at all and unless you're tech-savvy you might not immediately realize that "remote content" means "read receipts".
Also, messenger read receipts don't leak your IP address and what kind of client you're using (via the user-agent header) whereas e-mails do.
Sure, it might be useful for them, but I'd still like to have to opt-in to it.
If my friend embedded a tracking pixel in my email because I didn't have read receipts and they wanted to know if I'd opened their email, I'd be having a real serious conversation about boundaries and privacy with that "friend".
Advertisers that do the same thing are being shitty people, in exactly the same way it'd be shitty if a friend did it.
To be clear, I'm not arguing against read receipts. I'm arguing against _working around_ opt-in read receipts.
They can’t make it seem like I didn’t download it but they can remove most of the usefulness of the information (it reveals whether the Gmail address is valid I suppose)
And even those who do are not warning you about the tracking part, only about loading resources. Most users will just think that they want to see the nice images and accept and have no idea that it means they are tracked.
IIRC gmail doesn't allow any outgoing requests of email stylings. It strips it out or rewrites it to a re-hosted URL.
Tested with regular accounts and google workspace.
No idea where this rumor came.
Oh, wait - you're using gmail? I'm afraid you're beyond help.
A burner email address I gave out exactly once to a vendor at defcon 2 years ago has been "opting into" all sorts of new marketing campaigns from many different companies, and as recently as this February.
Explain to me how tracking pixels in those emails are consistent with GDPR's informed consent.
Also it's generally useful to know if a particular email is read so you can test out different formats and whatnot.
Probably because those email newsletters are spam sent to people who interacted with a form once.
That's because you're spamming them.
> even if they signed up for the emails in the first place
Users can change their mind. Clicking anything in an email leads to susceptibility of phishing. So they shouldn't need to click an unsubscribe link to do so. Reporting you for spam is the safest option from their perspective.
And I would argue that most users didn't sign up for the emails. They were conned into giving their email and usually for a completely different purpose.
> Also it's generally useful to know if a particular email is read so you can test out different formats and whatnot.
That's a very dubious assertion. Formats are in the content of the email. Different formats won't tell you why one email was opened while another was not.
Formats can include different titles and descriptions, which can make a huge difference in how often users open your emails. Also just different kinds of emails you might want to send (maybe you send some users an email with a coupon, and some with a new product notification).
Maybe you don't see the value in having people know whether you read their email, which is fine, but there are clearly tonnes of legitimate use cases for having that kind of information. If I know a segment of users on my email list never open a particular type of email, it is better to just not send them that kind of email, both for the sender and recipient.
Regardless, I think Gmail killed tracking pixels by loading images through their servers anyways.
Google did not kill tracking personalized tracking pixels. All they blocked is the ability to determine the user's IP because you will get a connection from Google's proxy instead of directly from the user.
Those use cases are generally few and far between. They are the exception.
I've had my mail clients (and Gmail) set for years to not load external images, and occasionally get "we notice you haven't been reading our messages so we're going to stop sending them to you" emails from mailing lists that I do actually read.
Indeed it is! Yet messengers like WhatsApp and Telegram always mark the messages that have been read. And I really hate this. Given the fact the actual messengers still are pretty good and very useful, I would pay them a premium if they could hide when have I been online and what messages have I read.
I really really enjoy having them. They make me feel less anxious about messages.
It costs money to send out emails. If 50% of your users aren't reading them, you can trim the list of those who don't open the email.
Staying on the good side of spam blockers is a much bigger deal.
Spam reduction is definitely a big consideration. However at the last place I worked we would get notifications when people marked the emails as spam, and so we could specifically remove those people from the email list. I don't even know how that part is done - we used one of the big emailer/newsletter websites.
No.
TMTP also specifies Markdown formatting (not HTML), fwiw.
[1] https://hey.com
The EU has absolutely zero authority to tell business located outside of the EU what to do. The fact that someone reading a blog post happens to be in Europe does not all of a sudden put the owner of that blog under EU jurisdiction.
Yes, the first version of cookie banners was awful and pointless. This latest iteration (of compliant banners) is wonderful, though.
They actually give me functionality that I _really want_. I click the "manage preferences" option on every single one for every site that offers it. I opt out of everything except for strictly necessary cookies for site functionality.
I am genuinely thankful for the GDPR era of cookie banners.
Also you should be able to click on the GIANT button on the popup and never see it again.
I bet you also complain that thx to some other bureaucrats now all your marketing emails must include an Unsubscribe link.
As a reminder, I don't believe the majority of consent flows on the web are compliant with the regulation. As per the ICO's guidelines (the UK data protection regulator) https://ico.org.uk/for-organisations/guide-to-data-protectio...:
> Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent.
> Keep your consent requests separate from other terms and conditions.
> Make it easy for people to withdraw consent and tell them how.
> Avoid making consent to processing a precondition of a service.
The majority of consent flows out there don't comply with at least one of these points, so the fact they're still out there 3 years after the regulation went into effect suggests enforcement is indeed lacking.
I installed a game that had a bug (opt-in to tracking wasn't working so tracking was always on). Lots and lots of users complained in the game developers forum but nothing happened. Not even a reply. I and a few others wrote emails to the support mail and nothing. Then I threatened with GDPR months later and two days later support was on my case and my data was deleted from both their system and the third party they used for tracking.
Here in Denmark businesses aren't allowed to receive updates from the CPR registry (like SSN) if you aren't a customer anymore. It's used for stuff like banks automatically getting your new address if you move. Historically sending mails to those that didn't remove you from their updates didn't do anything. Now they run quickly as soon as they read "GDPR".
There are big businesses that get away with things they shouldn't but by far the most problems can now be resolved, even small stuff that big businesses before didn't lift a finger to fix where the little man had no chance in hell. Now they (we!) do.
No it doesn't and yes it is.
Nowhere in the GDPR or in the UK implementation does it say that recipients need to be informed of pixels in and of themselves.
What it does say is that when you obtain the recipients' personal details you must provide them with a privacy notice setting out what data you collect and what you do with it. The privacy notice needs to be provided on collection of their data (when directly collected) or within 30 days of collection if from a third party.
There is no reason to not obtain consent to tracking but to suggest it's the only lawful basis on which to process the data is not correct. Subject to completion of an impact assessment, one could make a case that it falls under legitimate interests depending on the degree of processing of the tracking data e.g. the more that such data is used to inform further targeting of the individual vs. say aggregation of data for improving engagement.
I agree with your underlying point though - I turned off tracking (I use Postmark for transactional emails) because I don't really care about open rate and click rate etc. If my customers want to ignore the emails from the service it's up to them.
The French CNIL, for example, has already fined Google and Amazon $100M+ for this very issue: https://www.huntonprivacyblog.com/2020/12/14/cnil-fines-goog...
GDPR is a nightmare and a case study in how regulations can terrorize entire industries or the abilities of individuals to innovate freely. Just read the chronology of events in that link above and try playing devils advocate that the CNIL did not amend those laws to specifically target these two companies. It's scary.
The decision to overrule an earlier revision by the Counseil D'etat alludes to the guidelines themselves as a measure of "Soft law".
Regardless, making an argument on the semantics of a word instead of the glaring arrogance on display where Government agencies or lawmakers can retroactively change the rules to seemingly target individual companies is ridiculous.
[...]
4. When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.“
An email address is always personal and tracking if the email was opened ties it to that personal data.
So yes, the user has to consent.
Whether it's a header image or a "spy pixel", both of these things can be used to track you. Therefore the solution is to disable it entirely if you do not like being tracked.
No it isn't.
What if I want to see the images in an email newsletter, but don't want to be tracked? The client can't give me a button "open images except tracking pixels" because it doesn't have enough information to know the difference.
That would be nice, but as I already wrote, it's not possible. The only way to have images (or any form of remote resource) in emails, and at the same time avoid tracking, is attaching them.