EUQR

Tracking links consent: the EDPB guidelines explained

Tracking links consent sounds like a niche legal topic until you notice that most email tools and many link shorteners add an identifier per recipient by default. The EDPB's Guidelines 2/2023 say that design falls under the ePrivacy consent rule. This article explains the reasoning, the CNIL's 2026 position, and where a plain QR redirect sits.

Two links can look identical on a flyer and be very different in law. One sends every reader to the same address and counts how many arrived. The other carries a code that names the recipient, so the sender learns who clicked, when and from what device. European regulators have now said clearly which of the two needs consent. This article walks through the European Data Protection Board's Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive, the French CNIL's 2026 recommendation on email pixels, and what both mean for short links, QR code redirects and retargeting. It is not legal advice; it is a technical reading of official texts, with paragraph numbers so you can check them. The legal checklist for QR codes in general is in the GDPR checklist for QR codes; this piece is only about the link itself.

Two designs that look the same on paper

Design A is a campaign link: qreu.eu/autumn-offer, printed on ten thousand flyers, identical on every copy. The redirect server counts requests and notes country, device type, browser and language in aggregate. Nobody is identified, no cookie is set, nothing is written to the phone. Design B is a tracked link: every newsletter recipient gets qreu.eu/autumn-offer?r=71c2e, where 71c2e is that person's record in the mailing tool. When the link is opened, the tool logs that this particular person clicked. Design B is the default in most email platforms and in many affiliate systems. It is also what the EDPB calls a tracking link.

What the EDPB guidelines say about tracking links consent

Article 5(3) of the ePrivacy Directive is the rule behind cookie banners: storing information on, or gaining access to information already stored in, a user's terminal equipment requires consent, unless it is strictly necessary for a service the user asked for. The EDPB's Guidelines 2/2023, version 2.0 adopted on 7 October 2024, set out when a technique falls under that rule. Paragraph 6 lists the criteria: the operation must concern information (criterion A), involve the terminal equipment of a subscriber or user (criterion B) and amount to storage or to gaining access (criterion C). The guidelines then apply those criteria to concrete cases. Paragraphs 47 and 48 describe tracking pixels, which the EDPB defines as a hyperlink to a resource, usually an image file, embedded in a website or an email so that a request is sent automatically when the content is displayed. Paragraph 49 turns to tracking links and describes them as links where an identifier is appended to the website address, so that the visited site can tell where the traffic came from, a technique the guidelines associate with affiliate marketing. All quotes and paragraph numbers are from the EDPB's version 2.0 PDF, fetched from edpb.europa.eu on 30 September 2026.

Storage, access and why caching counts

The interesting part is how the EDPB gets from a link to terminal equipment. Paragraph 50 says that distributing tracking pixels and tracking links to the user's device amounts to storage, because the content is cached on the device, and that Article 5(3) applies even when that storage is temporary. Paragraph 51 adds that appending tracking information to a URL or an image is in effect an instruction to the terminal equipment to send that information back, which the guidelines qualify as gaining access. Both criteria are met, so the technique falls within Article 5(3), and consent is needed unless one of the exemptions applies. Notice that the reasoning does not depend on cookies at all. A tracked link with no cookie anywhere still counts, because the identifier travels through the user's device and comes back.

Worked example: a regional energy cooperative sends a paper newsletter with one QR code to 20,000 households and an email newsletter with per-recipient links to 8,000 subscribers. The paper code is design A: one URL, aggregate counts. The email links are design B: each carries the subscriber's identifier. Under the EDPB's reading, the second campaign is a tracking-link operation that needs consent, while the first is a count of visits to one address.

The CNIL on pixels and tracking links

France's regulator took the pixel half of this a step further. On 14 April 2026 the CNIL published its recommendation on tracking pixels in emails, adopted as deliberation 2026-042 on 12 March 2026. It defines a pixel as a one-by-one image, invisible to the user, whose file name contains an identifier, so that loading it reveals that this user opened the email, and it separates the cases that require consent from a small set of exemptions, such as measuring deliverability for a service the recipient requested (CNIL, recommandation pixels de suivi, checked 30 September 2026). Tracked links are handled in the accompanying FAQ. The CNIL states that tracking links are not directly covered by the recommendation, but that they involve read and write operations on the user's terminal and therefore fall under Article 82 of the French data protection act, the national transposition of Article 5(3). Whether consent is needed depends on whether the operation is necessary for the service requested; the FAQ's own example of an exempt tracked link is one that lets a reader withdraw consent simply and securely (CNIL FAQ on the pixel recommendation). The Dutch regulator's page on tracking pixels was not reachable when this article was written, so it is not cited here.

Where a QR redirect sits in this picture

A QR code scan is an HTTP request from the phone to the redirect server, followed by a redirect to the destination. Whether that falls under Article 5(3) depends on what travels in the request and what the server does with it. If the URL is the same for everyone and the server sets no cookie, the request contains no identifier that the sender placed on the device. The server does receive the IP address, and the guidelines discuss IP-only tracking separately in paragraphs 54 to 56: gaining access to an IP address triggers Article 5(3) only where the address originates from the user's terminal equipment, which the EDPB says can be the case for some static addresses and for IPv6. That nuance is another reason not to keep IP addresses at all. EUQR's redirect never stores the raw IP address; the scan analytics are aggregate counts computed from hashes that rotate daily, and the redirect sets no cookie. The technical detail of what a scan sends and what becomes of it is in QR code analytics without cookies.

Redirects that load pixels before forwarding

Some shorteners insert a step between the click and the destination: an interstitial page that loads advertising pixels and then forwards the visitor. The shortener Cuttly describes this in its own privacy policy, dated 19 May 2026, which states that tracking pixels are loaded only after a shortened link is clicked and before the user is redirected to the target page, and lists the Meta, TikTok, LinkedIn, Pinterest, Quora and X pixels among those that can be triggered (cutt.ly/privacy, checked 30 September 2026). That is a retargeting feature, and it is exactly the kind of storage and access the guidelines describe, performed on the sender's behalf by the shortener. If your redirect provider offers pixels on the redirect, the consent question lands on your desk. EUQR's URL shortener loads no pixels on the redirect and does not offer them.

A practical checklist for marketing teams

  • One link per placement, never one link per recipient, on print and in email alike.
  • No customer numbers, order IDs or hashed email addresses in slugs or query strings.
  • No pixels or scripts on the redirect step; check your shortener's privacy policy for the words interstitial, pixel or retargeting.
  • Aggregate counts only: country, device, browser, language, time, never a visit history per person.
  • If you do need per-recipient tracking, treat it as a consent question, document the basis and give the reader a way to opt out that itself does not track.

What this means on EUQR

EUQR was built for design A. Every dynamic QR code and short link is one URL for everyone, the redirect sets no cookie and stores no raw IP address, analytics are aggregated counts from daily-rotated hashes, and there are no pixels, no retargeting audiences and no per-visitor identifiers anywhere in the product. That is why the GDPR-ready QR code generator needs no cookie banner for the redirect step, and why scan data and short-link data can be hosted in Amsterdam without third-party tracking scripts. It also means EUQR cannot tell you which named person scanned a code; if your campaign depends on that, EUQR is the wrong tool and the consent conversation is the right next step. Plans start at €0.99 per month on the pricing page, checked 30 September 2026, excluding VAT. Again, this is not legal advice. Read the paragraphs cited above, and if you run email campaigns with per-recipient links, take the question to whoever owns privacy in your organisation before the next send.

Frequently asked questions

Does a short link need consent under the ePrivacy Directive?
A plain short link that is the same for every reader and sets no cookie is a request to one address and is counted in aggregate. A tracked link that carries a per-recipient identifier is different: the EDPB's Guidelines 2/2023, paragraphs 49 to 51, treat it as storage on and access to the user's device under Article 5(3), which normally requires consent.
What exactly is a tracking link according to the EDPB?
Paragraph 49 of Guidelines 2/2023 describes a tracking link as a link where an identifier is appended to the website address so that the visited site can tell where the traffic came from, a technique the EDPB associates with affiliate marketing. Paragraphs 50 and 51 explain why distributing such links counts as storage and as gaining access.
Does a QR code scan fall under the same rule?
It depends on what the code encodes and what the server does. A code that encodes one URL for everyone, with no cookie set on the redirect and no identifier in the URL, is a plain request and an aggregate count. A code that encodes a per-recipient identifier or a redirect that loads retargeting pixels is a tracking operation under the EDPB's reasoning.
What did the CNIL say about tracking links in 2026?
The CNIL's recommendation of 14 April 2026, deliberation 2026-042, covers tracking pixels in emails. Its FAQ says tracking links are not directly covered but do involve read and write operations on the terminal and therefore fall under Article 82 of the French data protection act; consent then depends on whether the operation is necessary for the requested service.
How does EUQR count scans without tracking people?
Every EUQR code and short link is one URL for all readers. The redirect sets no cookie, stores no raw IP address and loads no pixels. Scan and click analytics are aggregate counts by country, device, browser and language, computed from hashes that rotate daily and hosted in Amsterdam. EUQR cannot tell you which individual scanned, by design.

Count scans without a consent problem

Create a dynamic QR code or short link that is the same for every reader, with aggregate analytics, no cookies and no pixels on the redirect. Hosted in Amsterdam, from €0.99 per month.

Create a code