Mailchimp & GDPR

Last updated:
06.05.2021
The newsletter management provider Mailchimp is used by startups and large corporations alike. However, because the practical tool is operated by a US company, ensuring GDPR compliance can be challenging for businesses.
Mailchimp & GDPR
Key Takeaways
  • Mailchimp is a US-based newsletter management tool with problematic GDPR compliance.
  • In 2020, the ECJ declared the EU-US Privacy Shield invalid due to insufficient protection against US intelligence agencies.
  • The Bavarian Data Protection Authority demanded enhanced measures from Mailchimp for data processing in accordance with EU standard contractual clauses.
  • Companies must ensure that Mailchimp data is not accessible to US authorities, including through the use of SCCs.
  • Newsletters must offer a double opt-in process, a transparent privacy policy, and an easy way to unsubscribe.

Newsletter marketing has become an indispensable part of modern business. However, even when using tools like Mailchimp you must ensure compliance with the GDPR.

Email marketing with Mailchimp

Mailchimp is a tool for newsletter managementthat allows companies to create, manage, and send mailings. It provides templates for creating newsletters, and you can also import your own. Mailchimp also allows you to embed dynamic content in your mailings, such as forms, and import contacts. Using the double opt-in process , you can integrate subscription and unsubscription functions for your newsletter.

Based in Atlanta, USA, the service provider Mailchimp offers intuitive handling and various subscription plans alongside these useful features. With a free membership, you can send up to 12,000 emails to 2,000 recipients per month. For a monthly fee of 10–25 USD, you can send an unlimited number of newsletters.

Despite all its advantages, this cloud-based tool has some weaknesses, as using Mailchimp requires companies to hand over personal data, such as their customers' email addresses. Since many European companies work with this US-based provider, the question arises: Is it possible to use Mailchimp in a GDPR-compliant manner?

Mailchimp & GDPR: How secure is user data in Mailchimp?

As a US company, Mailchimp is not fundamentally required to comply with the GDPR. However, according to Article 44 of the GDPR, personal data such as names or email addresses may only be processed in so-called third countries if it has been verified that data protection standards meet European requirements. From 2016 to mid-2020, this was regulated by the EU-US Privacy Shield. This included a list of companies registered with the U.S. Department of Commerce that had received certification to process data from Europe. Although Mailchimp was covered by the Privacy Shield, the effectiveness of this protection was questionable, as no official body ensured compliance with the guidelines.

These doubts were confirmed in 2020 by the CJEU's Schrems II ruling, which declared the Privacy Shield invalid and non-compliant with EU data protection law. The court based its decision on the fact that the Privacy Shield did not protect against access by US intelligence services.

While data protection via Mailchimp could be described as inadequate prior to this ruling, the situation did not fundamentally improve afterward, as the Privacy Shield had at least provided a minimal level of oversight.

Data protection ruling: Unauthorized transfer of email addresses to Mailchimp

The legal situation, which remained ambiguous despite the Schrems II ruling, was further clarified that same year by a successful lawsuit filed by a private individual. The individual's email address had been used by Mailchimp to send a newsletter despite the Privacy Shield being declared invalid. The Bavarian Data Protection Authority ruled that, in addition to a privacy policy containing standard EU contractual clauses, Mailchimp should have implemented additional measures to ensure data-compliant processing. Only in this way could potential access by U.S. intelligence services be prevented.

A general ban on Mailchimp while not representing this, it is a trendsetting decision for future legislative adjustments. It is up to European companies to ensure compliance with the level of data protection – otherwise, transferring email addresses to Mailchimp would not be permissible.

What companies should keep in mind for email marketing

Since many companies use this provider and switching to another newsletter management system would involve effort and additional costs, it is good to know how one might potentially handle Mailchimp. The BayLDA recommends finding out from the company before transferring data to Mailchimp to what extent user data stored there can be accessed by US authorities. It is helpful to inquire whether Mailchimp falls under FISA Sect. 702 or whether US intelligence services can access user data based on Executive Order 12.333. You should find out:

  • where personal data is processed,
  • whether this is transferred to other third countries,
  • what measures are taken to ensure the level of protection,
  • which sub-processors are used,
  • potentially which national regulations apply, and
  • what legal remedies are available.

In addition, advanced measures such as the conclusion of so-called Standard Contractual Clauses (SCCs) should be implemented between your European company and Mailchimp.

For the data-compliant design of your newsletter itself, you should also consider the following:

  • Use of the double opt-in (DOI) procedure and storage of the time of customer registration for newsletter subscription;
  • Reference to the full privacy policy;
  • The email address is the only mandatory field. Any use of data other than email addresses for personalization purposes should be justified.
  • Option for customers to withdraw consent;
  • Information regarding the use of Mailchimp.

As a business owner, there is a lot you can do yourself to ensure your mailings meet GDPR requirements. Nevertheless, you should keep yourself consistently updated until the legal situation is clarified in more detail.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in