Tracking

Read time : 

13
 mins

Surviving Signal Erosion: Building Cookieless Tracking with First-Party data for B2B marketers

With news that email open tracking just got stricter in France and Italy, calling for user consent to see open metrics, we wanted to remind teams that the best tracking system is the one built upon the infrastructure you own and the first-party data you collect. See how it all comes together for B2B marketers with server-side tracking, and explicit consent that left behind third-party cookies, fingerprinting and other tracking methods that put user privacy at risk.

By

Maxime RAT

Co-founder

July 23, 2026

TL;DR: Engagement is getting harder to track as the browsers and operating systems we use every day become more privacy-forward and regulators pass new restrictions on the use of cookies and tracking pixels. France and Italy's latest decision to treat email pixels like cookies that need consent further eroded the marketing and sales engagement teams can measure along the buyer journey.

For years, privacy regulators and browsers have been stripping away the third-party cookies and tracking pixels that GTM teams rely on for measurement. While only limited to two countries for the moment, email opens joined the list in 2026.

This article gives you:

  • A timeline of that erosion and where it may be heading,
  • What the first-party data and cookieless server-side tracking alternative is in practice,
  • Why workarounds like fingerprinting create more privacy risks than they're worth,
  • A closer look at the measurement stack worth building instead.

The best place to start explaining the need for cookieless tracking isn't a breakdown of regulation, though. It's with a live demo.

Showing you what we do and don't track

We open demos in a way that used to puzzle prospects.

Before we go into attribution dashboards or analyst agents, we share the screen and spend the opening minute on everything our cookieless tracking collects and what it doesn't. We make a point of showing that there are no stored IDs or fingerprinting.

We subscribe to the idea that interaction data from the journey should land in the customer's own CRM, on the lead and opportunity record, and nowhere else. The attribution dashboards, the part people book the demo for, wait their turn. Why? Because without the tracking, there's no way to attribute credit across channels.

That may seem like a tactic to calm European leads in the market for a marketing attribution tool, but April 14, 2026, was another reminder of why cookieless tracking and privacy-forward methods you own matter. That day, France's data protection authority, CNIL, published its final recommendation on email tracking pixels, and it became another tracking pixel that B2B teams need consent for. Three days later, Italy's Garante adopted its own email pixel guidelines.

There’s no need to be alarmist. Open rates in France and Italy aren't going to disappear entirely. It’s just the latest squeeze on tracking that has been tightening since 2018, each one removing another tracking signal that GTM teams rented rather than owned. That's the case this article makes: cookieless tracking, built on first-party data and server-side delivery, is not just a compliance project for B2B marketing teams. It's the only measurement layer left that improves with age instead of eroding with new regulation.

The metrics and tools affected by the latest email pixel ruling

France's CNIL and Italy's Garante both treat email tracking pixels like cookies: using them to measure who opened a message, optimize send times, or segment objects all now requires prior opt-in consent.

France's window to get consent from existing lists closed on 14 July 2026. Italy's runs until October 28, 2026.

Companies now require consent for most metrics email marketing and outreach tools do by default:

  • Measuring open rates to evaluate or optimize campaigns
  • Send-time optimization based on when individuals open
  • Segmenting openers versus non-openers, and open-triggered nurture branches
  • Building preference or engagement profiles from reading behaviour

Exemptions are limited to delivery authentication and list hygiene in France, plus anonymized aggregate open counts, security flows, and legally mandated messages in Italy; for anything beyond what’s listed, consent comes first.

Getting future consent differs in the two markets. France’s CNIL states consent must be given separately from the opt-in to receive email, ideally at signup, with a box and a phrase explaining each purpose. They also want a separate link to withdraw consent in every message that is distinct from the unsubscribe. In Italy, the Garante accepts bundling tracking consent into the general promotional consent, provided the wording is neutral, and the options to withdraw consent remain separate.

The detail in the regulation that hurts outreach campaigns for marketing and sales teams is that this affects more than just newsletters. The CNIL's position is that pixel consent applies even where the email itself can be sent lawfully without consent, which in France includes B2B prospecting based on legitimate interest. Your sales engagement platform tracks opens with the same pixel mechanism your marketing automation or newsletter tool uses. This means your SDR sequences for French and Italian prospects are in scope too.

Please note that this is, for the moment, a CNIL recommendation and not a new law passed by parliament. It's the regulator's formal interpretation of ePrivacy and GDPR rules that already existed, published after a public consultation, and it defines the standard the CNIL will use when they audit.

The lesson here is not to wait and see if it sticks. Email platforms will change their EU defaults whether or not enforcement ever reaches you. The data will thin out either way.

How have privacy standards been eroding third-party tracking?

Steadily, for almost a decade. Since 2018, regulators and browser makers have restricted third-party cookies, cross-app identifiers, and tracking pixels in wave after wave. No restriction has ever been reversed, and for good reason; it's in the consumer's interest. The April 2026 email pixel rules in France and Italy are the newest wave, not the last one.

Here’s a timeline of the erosion:

May 2018: GDPR takes effect in the EU, turning the older ePrivacy cookie-consent recommendations into something that can be fined.

2017 to 2019: Safari's Intelligent Tracking Prevention hardens: script-set cookies capped at seven days, sometimes 24 hours. A multi-month B2B buying journey can't be followed client-side in Safari at all.

January 2020: The CCPA takes effect in California. Roughly twenty US states have passed comprehensive privacy laws since. This stopped being a European story years ago.

April 2021: Apple's App Tracking Transparency makes cross-app tracking opt-in on iOS. Most people decline.

September 2021: Apple Mail Privacy Protection starts preloading tracking pixels, marking emails "opened" whether or not a human read them. Litmus puts Apple Mail above half of all email opens, which means open rates have been part fiction for nearly five years.

January 2022: The CNIL in France fines Google 150 million euros and Facebook 60 million over cookie banners that made refusing harder than accepting.

July 2024: Google announces Chrome will keep third-party cookies after four years of deprecation theatre. In April 2025 it scraps even the planned opt-out prompt.

April 2026: The CNIL in France and the Garante in Italy bring email pixels under cookie-grade consent rules, three days apart.

The one line in the timeline every marketer was preparing for, Google’s deprecation of third-party cookies in Chrome, never happened. And it didn't matter. The cookieless future arrived on schedule everywhere except the place everyone was staring, because the squeeze was never really about Chrome. It's regulators and Apple, moving independently toward the same destination, with the EU writing the template and US states copying it.

Looking at the last point in the timeline, France and Italy moved three days apart on pixels; other European authorities read the same directive and tend to draft their own version.

The message is clear: click-tracking redirects, and whatever identifier the ad-tech industry invents next will each get the same treatment when their turn comes. You don't need to predict which signal dies next. You just need to stop building on the category of signals that keeps dying: the ones collected without asking, on infrastructure you don't own.

Timeline of privacy restrictions eroding third-party cookies and tracking pixels, 2018 to 2026.

Why does the erosion hit B2B marketing hardest?

The B2B buying journey is long, multi-channel, and email-heavy, exactly the type of journey that rented signals measure worst. A seven-day cookie cap is an inconvenience for e-commerce. For a nine-month enterprise deal with six stakeholders, it erases the story.

Open rates have been an unreliable engagement signal that teams have relied on for years, even before France and Italy required consent for email tracking. Relying on open-based scoring or segmenting by email openers just means you’re basing decisions on shrinking and inaccurate data. Nurture emails and re-engagement campaigns all keep using these faulty signals to judge who seems "engaged," but these systems keep running on bad data. A supposed email open is not a reply.

Surface metrics were always the weak foundation under B2B growth reporting. Now the surface itself is cracking.

Here's what the alternative looks like in practice, and it's best shown by highlighting a pattern we see in most B2B pipelines:

  • The SDR sequence goes out, and the buyer never replies.
  • The sequence report reads as nine emails sent, two of them opened, but never answered.
  • Meanwhile, the same buyer is on the website, reading feature pages and pricing on their own schedule, until one day they fill the demo form.

Judged solely by opens and replies, the lead seemed uninterested. Judged by the first-party journey recorded on the company's own domain, the sequence did its job: it started a research process that ended in pipeline: same prospect, opposite conclusion. Only one of those two data sources is legal to collect in France without asking. It happens to be the honest one.

You didn't make bad decisions by trusting engagement data. It was the best signal available. But so is the cookieless alternative.

The cookieless tracking alternative that shines a light on the B2B journey

Verty quickly, what exactly is cookieless tracking?

It’s the practice of measuring buyer journeys without third-party cookies or covert device identifiers. It rests on first-party data collected on your own website with consent captured at the point of conversion, and on server-side delivery of journey data into a system you own, usually the CRM. That’s how Heeet tracks customer journeys and stores the data on the record of every lead and opportunity.

Cookieless tracking turns measurement into a property you own across your website, your forms, your CRM, and ties the interaction only to people who consented.

This is all done by placing a first-party script on your own domain that records the touchpoints of a visit: channel, campaign, keyword, content viewed. Nothing is tied to a person yet. When the visitor fills a form and gives consent, the recorded journey attaches to the new lead inside Salesforce or HubSpot. Anonymous visitors stay anonymous. Consented leads arrive with their whole history attached. That trade, losing the ability to spy on strangers in exchange for complete data on everyone who matters, is the entire bet behind cookieless attribution. So far it's paying out, and it’s possible thanks to server-side tracking.

How does server-side tracking work?

Server-side tracking moves data collection and distribution from the visitor's browser to a server you control. Events are captured on your own domain, then forwarded to destinations like the CRM and ad platforms through APIs. It replaces third-party scripts and pixels that browsers and regulators keep restricting.

The differences with the client-side model explain most of its value.

In the setup built on third-party cookies, a B2B site loads a dozen third-party scripts in the visitor's browser: analytics, ad platform pixels, session recorders, enrichment tools. Each one sets its own identifiers, ships data to its own servers, and each is exactly the kind of third-party call that Safari throttles, ad blockers strip, and consent banners suppress. Industry estimates of the resulting blind spot vary widely, but any team that has compared ad-platform conversion counts against CRM reality has seen the gap firsthand.

Server-side flips the “Script”, pun intended, by creating a collection point that records the event and sends the journey data into a single place like a CRM or analytics platform.

Server-side architecture also does a better job at ensuring:

Durability: First-party collection on your own domain is the one measurement channel no browser update is aimed at.

Simplified consent for the user: with a single collection point that collects and stores consent and forwards only what's permitted, compliance stops being a browser-side headache.

Quality data for activation: events get tied to CRM lead and opportunity records. When deals close, you can send ad platforms like Google Ads and LinkedIn Ads the offline conversions that resulted in closed-won revenue instead of form fills. This allows platforms to find buyers rather than leads that stagnate.

Site performance: fewer third-party scripts in the browser means a faster site. It's not a huge difference maker by any means, but it's a nice little benefit.

Very important to note, even though it’s quite obvious at this point. Server-side tracking does not allow you to bypass consent . Moving collection to your server changes nothing about whether consent is required when an individual is identified. The legitimate wins are the four above, plus a cleaner story when a regulator, or an enterprise buyer's security team, asks where prospect data lives.

One build note. Server-side setups (a self-hosted tagging container, for instance) put the collection infrastructure on your plate or in that of another platform to store the data, such as an attribution platform or your own solution. Either way, that means cloud hosting and maintenance. CRM-native implementations fold the server-side layer into the attribution product itself, which is the route we took with Heeet: the tracking is first-party and cookieless, the sync to ad platforms is API-based, and the destination is your Salesforce or HubSpot rather than a warehouse you have to set up.

Comparison of client-side tracking blocked by browsers versus server-side tracking with a consent gate feeding the CRM and ad platforms.

Why not use fingerprinting and other tracking workarounds?

First and foremost, fingerprinting is a privacy nightmare. It happens persistently without the user's consent, and there’s no straightforward way to opt out of it. Accuracy is another issue, since browsers actively degrade them. Discrimination can also be a factor, as targeting, messaging, and even pricing can be altered using the data retrieved from fingerprinting.

For those who don’t know what fingerprinting is, it stitches together device-specific data like screen resolution, browser version, fonts, timezone, and IP address into a statistical identifier that recognizes a returning visitor who never agreed to anything.

Regulators treat it as a tracker requiring prior consent, exactly like a cookie. The real problem is withdrawal. A visitor can delete a cookie. Nobody can delete their screen resolution. A tracking method that offers no meaningful way to say no is the precise behaviour these rules are put in place to stop.

On top of the legal exposure, the identifier itself is decaying: Safari, Firefox, and Brave now randomize or flatten the very attributes fingerprints depend on, so the "same" visitor turns into several.

Fingerprinting is just another workaround that treats privacy rules as an obstacle to route around, which guarantees a rebuild every time the route closes. This may be seen as a tradeoff for some, but it's one we’ll happily take in favour of user privacy at Heeet.

Other data collection tactics that create privacy issues and noise

CNAME cloaking

This disguises a third-party tracker as a subdomain of your own site so it looks first-party to the browser. Safari caught on and capped CNAME-cloaked cookies at seven days back in 2020. Security teams dislike it for their own reasons, since it can expose your visitors' first-party cookies to an outside vendor. This workaround, which browsers have already defeated, shouldn’t be considered, as it’s collecting data without user consent.

Probabilistic identity graphs

Are statistical data systems that match visitors across sessions and devices using IP addresses, timing, and behavioural patterns. The biggest issue here is accuracy, because it relies on making an educated guess. Here’s an example of where it fails. Let’s say an office, or even worse, co-working with different companies full of stakeholders sharing wifi networks and one IP range is used to build a signal for a single company; your chances of making an error increase. What could look like a buying committee of six becomes one blurry "user" in the graph, or even worse, that buying committee could be composed of people from different companies.

The data custody problem

Where you store the data is an issue that comes up when looking at all three alternatives. These methods typically warehouse behavioural profiles of your prospects on the vendor's own servers, which makes your pipeline data someone else's asset and another data breach possibility. Every sub-processor between a touchpoint and your dashboard is one more data processing agreement, one more security questionnaire answer, one more thing an enterprise buyer's legal team can stall a deal over. Contrast that with journey data that lives in your CRM, under your existing Salesforce or HubSpot security model, and nowhere else.

The workarounds provide short-term signals, are illegal in most cases, and are frowned upon. Consent-based first-party measurement is the only approach that gets stronger as enforcement matures. As new regulation and privacy standards kill the workarounds, the accuracy gap favours teams whose data never depended on one.

What does a cookieless GTM measurement stack look like in 2026?

It consists of first-party collection on your own domain with explicit consent captured from the form, server-side delivery of journey and cost data into the CRM, and attribution computed where revenue lives.

Here’s a closer look at the setup that provides you with the most relevant event data from interactions prospects have with your digital properties without third-party cookies or fingerprinting:

First-party collection: Your website is the one property where measurement is fully yours to run. A first-party script records channel, campaign, keyword, ad group, and content engagement across visits: which feature pages and case studies got read, and whether pricing got a look. Yo get all this event data when explicit consent is captured where it should be, from the form. Only then does a journey become a person.

Server-side delivery: Everything from the server-side section above, pointed at revenue. Ad platform spend syncs into the CRM, so cost per acquisition is computed against real pipeline. CRM conversions flow back to Google and LinkedIn through offline conversion uploads, so bidding algorithms optimize on revenue instead of form fills. No step in that circuit depends on a third-party cookie or an email pixel.

CRM-native attribution: Revenue math happens inside Salesforce or HubSpot, where the opportunities and the euros already live. Multi-touch influence across the full journey, pre- and post-acquisition, replaces the engagement proxy layer entirely. Email gets measured by replies and influenced pipeline rather than opens.

This is the architecture Heeet runs. It's why our demo opener doubles as a compliance summary: no stored IDs, no fingerprinting, journey data held anonymously until a form is submitted with consent, everything delivered into the customer's CRM rather than our servers.

Ringover rebuilt its paid and SEO attribution on this stack and reported a 24% improvement in the accuracy of its marketing-generated revenue attribution. Their SEO lead, Fátima Muñoz Peribáñez, can point inside Salesforce to a quarter where organic search drove 25% of pipeline. Neither number required a single third-party cookie or open pixel.

Cookieless tracking architecture: first-party collection, server-side tracking, CRM-native attribution.

The teams that move first get cleaner data, not just cleaner compliance

Regulation set the deadline. The prize was always accuracy. A GTM motion measured on first-party journeys and CRM revenue doesn't lose fidelity when the next platform changes a default or the next regulator publishes a recommendation.

Ready to build future-proof cookieless tracking?

If you want to see what your funnel looks like when every number in it is one you're allowed to keep

Book a demo

Ready to track prospects from lead to close with Heeet?

Heeet gives marketers and sales professionals at IT & Security firms turn geuss work intro informed decisions that drive revenue while meeting the same secruity technical standards you provide your clients.

Talk to us