Is Email Tracking Legal Under the GDPR?

Short answer: it can be, and the responsibility is yours, not your tool's. Long answer: it depends on who you write to, why, and what you do with the result.
Table of contents
This is not legal advice. It is a practical summary of how the question is usually framed in the European Union, so you can have an informed conversation with someone qualified if you need one.
What the law is actually about
Recording that a person opened an email, at a given time, from a given device, is processing personal data. The GDPR therefore applies. Two questions follow: do you have a legal basis, and have you been transparent.
For one-to-one business email, the usual basis is legitimate interest: you have a genuine business reason, the processing is proportionate, and it does not override the person's rights. That reasoning holds much better for a quote you send to a client who asked for it than for a cold campaign to a purchased list.
The distinction that matters most
There is a wide gap between two practices that use the same technology:
- Tracking a specific message you have a reason to send. A quote, a proposal, a follow-up in an ongoing conversation. Narrow, purposeful, proportionate.
- Tracking everything, permanently, on everyone. A systematic record of who reads what and when, across all your correspondence. Much harder to justify, and much harder to explain if someone asks.
This is why a per-email toggle is not just an interface preference. It is what makes the first practice possible and the second one a deliberate choice rather than a default.
Transparency
Transparency does not mean announcing a tracking pixel in every signature. It means that if someone asks what data you hold about them, you can answer, and that your privacy policy reflects what you actually do.
If you send commercial email at any volume, your privacy policy should mention that you measure opens, why, and for how long you keep the data.
Rights you have to be able to honour
Under the GDPR, the person you wrote to can ask what you hold, ask for it to be corrected, ask for it to be deleted, and object to the processing. In practice, for open tracking, that means being able to find and delete the records for a given recipient.
Choose tooling that lets you do that. If your data is locked in a platform that cannot delete a single recipient's history, you have a problem that is not technical.
Where the tool's responsibility sits
Your provider is a processor. It has to secure the data, process it only on your instructions, disclose its own subprocessors, and let you export or delete. mailcheck stores the subject, the recipient, the sender and the open events, never the body of your emails, keeps an anonymised fingerprint of the IP rather than the address itself, and processes in the European Union.
But the choice of who to write to and why remains yours. No tool can make an unlawful campaign lawful.
A workable rule of thumb
Before enabling tracking on a message, ask yourself whether you would be comfortable explaining to the recipient, in one sentence, why you are measuring this. "I wanted to know if my quote had reached you before calling" is an answer most people accept. "I log every email I send to everyone" is not.
If you cannot produce the first kind of sentence, turn the toggle off.
Documenting a legitimate interest assessment
Legitimate interest is not a box to tick, it is a reasoning you should be able to produce. In practice it has three parts, and writing them down once for your business covers most situations.
The purpose. What are you actually trying to achieve? "Knowing whether a commercial proposal reached the recipient, in order to time a follow-up appropriately" is a real, specific business purpose. "Understanding our audience" is not.
The necessity. Could you achieve the same result with less data? If a simple reminder after a fixed number of days would do, the case for measuring weakens. If the timing genuinely depends on knowing, it strengthens.
The balance. Would the recipient be surprised or troubled to learn what you do? A client expecting your quote would not be surprised that you know it arrived. A stranger on a purchased list would be, which tells you something about that practice more broadly.
What to put in your privacy policy
If you track opens, your privacy policy should say so in plain language. Four elements are enough:
- That you measure whether emails you send are opened, and why.
- What is recorded: typically the subject, the recipient, the send time and the open events.
- How long you keep it.
- How someone can ask for their data, or ask you to stop.
This is not a formality. It is the document you point at if someone asks, and having it makes the conversation short.
Processor, controller, and who answers for what
The vocabulary matters when something goes wrong. You are the controller: you decide who to write to, why, and what to do with the result. Your tool is the processor: it handles the data on your instructions.
That split means the tool owes you certain things, and you should check that it provides them: security of the data, processing limited to your instructions, disclosure of its own subprocessors, the ability to export and to delete, and a location for the processing that you are comfortable with.
It also means no supplier can absorb your responsibility. A tool hosted in the European Union that never reads the body of your emails makes your position easier to defend, but the decision to write to a given person remains yours.
Outside the European Union
The GDPR travels with the person, not with your office. If you write to someone in the European Union, it applies, regardless of where you are based.
Other regimes have their own logic. Canada's anti-spam law is stricter than the GDPR on consent for commercial messages. Several US states have consumer privacy laws with their own definitions. The United Kingdom applies a near-identical regime under a different name.
The practical conclusion for a small business: apply the strictest standard you are exposed to, which for most European senders means the GDPR, and stop worrying about mapping each recipient to a jurisdiction.
The test that keeps you out of trouble
Before enabling tracking on a message, ask whether you could explain to that specific person, in one sentence, why you measured it. "I wanted to know the quote had arrived before calling you" works. "I record every email I send" does not.
That test is not legal advice, but it correlates remarkably well with the outcome of a proper legitimate interest assessment, and it takes two seconds.
Conclusion
Open tracking is not forbidden, and it is not a free pass either. It is ordinary data processing, which means it needs a purpose, proportionality and the ability to answer for it. Used per message, on correspondence you have a real reason to send, it sits comfortably within normal business practice.
Frequently asked questions
Do I need consent to track email opens?
For one-to-one business email, the usual basis is legitimate interest rather than consent, provided the purpose is specific, the processing is proportionate, and you are transparent about it. Systematic tracking of everyone is much harder to justify.
Do I have to tell recipients that I track opens?
You need your privacy policy to reflect what you actually do, and you need to be able to answer if someone asks. You do not need to announce it in every signature.
Who is responsible if something goes wrong, me or the tool?
You are the controller and you answer for the decision to write to someone and why. The tool is a processor and answers for security, its subprocessors, and giving you the means to export or delete.
Track the emails that matter
Install mailcheck for free and track up to 10 emails per month in Gmail and Zoho Mail.
Add to Chrome, freeNo credit card. Unlimited tracking from 9 EUR per month.
Keep reading
Email tracking