DPE-2026-0030

Openen van een bericht wordt gemeten

Een bericht meldt terug wanneer het geopend is, via een bron die bij het weergeven wordt opgehaald en de ontvanger aanwijst.

Familie
Gegevens
Status
actief
Geldt voor
web, mobile-app, desktop

Wat er gebeurt

The message body references a remote resource: a one-pixel image, a background image, a font, a stylesheet. Its address carries a value unique to the recipient. Displaying the message makes the client fetch it, which tells the measuring party the time of opening, the client, the operating system and the network the reader was on, and it repeats on every later opening. The resource is chosen so that nothing appears on screen, so the reader has no cue that anything happened.

Waarom het ertoe doet

Reading is not an act the reader performs towards the sender. Here it becomes one: the sender learns when a message was read, how often, from where and on which device, and from a series of those the reader's daily rhythm, time zone, holidays and whether a message was forwarded. The reader learns none of it and was asked nothing, because there is no moment in a message at which anything can be asked.

Veelvoorkomende oorzaken

  • open measurement enabled by default per campaign in the sending platform
  • a decorative remote image whose address carries the recipient token anyway
  • a read receipt implemented as an image fetch because the protocol offers no other route
  • a template inherited between campaigns, with the measurement in it

Dit is het níet

A resource loaded by a web page is Third-party resource loading; there the fetch belongs to a page and the address is the same for everyone. What distinguishes this entry is that rendering a message triggers the fetch and that the address singles out one recipient. A visible image with an address identical for every recipient is not this entry.

Hoe je het vaststelt

Indicator

The same mailing, received at two addresses under your control, contains remote resource references whose path or query differs between the two copies while the message is otherwise identical. The per-recipient difference in the address is the fault. An address identical in both copies is not.

Methode

differential

Kwaliteit van de detectie

95 van 100

De grenzen van deze bevinding

Wat dit patroon zou weerleggen

  • The remote resource addresses are identical in both copies, so nothing in them singles out a recipient.machinaal te toetsende bevinding vervalt
  • The differing value varies per send rather than per recipient, shown by the second mailing to the same two addresses.machinaal te toetsende bevinding vervalt
  • The resource is served from the sender's own domain and no other party receives the fetch.met de hand te toetsende bevinding krijgt een ander patroonStill open tracking, but only the sender learns it. The number of parties changes, the mechanism does not.
  • The recipient asked for a delivery or read confirmation and can see the same record.met de hand te toetsende bevinding vervalt
  • The client fetches every remote resource in advance through a proxy, for every message, whether opened or not.met de hand te toetsende bevinding wordt zwakkerThe address still identifies the recipient; what it reports about the moment of reading becomes unreliable. That is a limit on the inference, not on the finding.

Wat dit patroon níet vaststelt

  • harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
  • severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
  • unlawfulness; that is for a supervisory authority or a court
  • intent; a fault is usually a build decision, not a plan
  • absence: not finding it in one capture is not evidence that it is not there

Reproduceren

  • manualMETHOD.mdno dedicated reproduction exists yet; follow the general method and the indicator above

Juridisch kader

Bepalingen

nl-tw-11-7aeu-gdpr-6-1-aeu-gdpr-13

Veelgehoorde tegenwerpingen

We only look at aggregate open rates.

The address fetched is unique per recipient, which is what makes the aggregate possible in the first place. Which rows are looked at is a choice made after the fact and can change tomorrow; the record is there either way.

The recipient subscribed.

Subscribing is agreement to receive the message, not to being observed while reading it. The two are separately askable, and a platform can send without measuring.

We need it for deliverability.

Deliverability is measured from bounces and complaints, which the mail protocol reports without touching the reader. Whether a message was opened adds nothing to it.

Most clients block images anyway.

Then the measurement fails for those readers and works for the rest. What the message was built to do is the finding, not the success rate.

Geldt wanneer

to-processing

Verwante patronen

← alle patronen