Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Mailchimp for WordPress adds newsletter signup forms to a WordPress site and connects them to Mailchimp. When a visitor submits a form their email and name are sent to Mailchimp. If Mailchimp site tracking is enabled, it can set tracking cookies and follow visitors across pages.
Mailchimp for WordPress (MC4WP) is a popular plugin that adds customisable newsletter signup forms to WordPress sites and connects them to a Mailchimp audience. When a visitor submits a form, their email address, name and any other collected fields are transmitted to Mailchimp via the Mailchimp API. If Mailchimp site tracking or connected sites is enabled in the Mailchimp account, Mailchimp can set tracking cookies and follow visitors across the site.
The signup form itself works without any cookies. Cookies only appear when Mailchimp site tracking is enabled, in which case Mailchimp may set mailchimp_landing_site (stores the landing page, lasting 1 month), _mcid (a persistent Mailchimp visitor identifier) and a form session cookie. Without site tracking, no cookies are set in the visitor browser. Regardless of tracking, subscriber email and name are always sent to Mailchimp servers in the United States upon form submission.
GDPR requires a lawful basis for collecting and transferring subscriber data to Mailchimp. For newsletter marketing, this must be explicit consent with a clear opt in. If Mailchimp site tracking is enabled, the ePrivacy Directive also requires prior consent before setting tracking cookies. Double opt in is strongly recommended as it creates an auditable record of consent and is considered best practice under GDPR for email marketing.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Explicit marketing consent is required before adding a subscriber to a Mailchimp list. Use a clear, unticked opt in checkbox on the signup form. Enable double opt in in Mailchimp so subscribers confirm their address by email before being added to your audience. If site tracking cookies are enabled, obtain separate prior consent for those through your consent management platform. Never bundle marketing consent with terms of service acceptance.
Mailchimp is operated by Intuit Inc. and stores subscriber data in the United States. Every form submission results in a transfer of the subscriber email, name and IP address to the United States. Mailchimp relies on the EU US Data Privacy Framework and standard contractual clauses as transfer mechanisms. Ensure you have a signed data processing agreement with Mailchimp and document this transfer in your records of processing activities.
To use Mailchimp for WordPress compliantly: enable double opt in in your Mailchimp audience settings; add an explicit, unticked marketing consent checkbox to every signup form; disable Mailchimp site tracking unless you have a separate cookie consent mechanism; sign the Mailchimp data processing agreement; document the US data transfer and the EU US Data Privacy Framework reliance in your records; include Mailchimp in your privacy policy and cookie policy; and review your consent records regularly to ensure they remain valid.
Websites using Mailchimp for WordPress must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended if Mailchimp site tracking is enabled, as this involves setting persistent tracking cookies and building visitor profiles across pages, which constitutes systematic monitoring. Key risks include processing subscriber personal data in the United States, potential use of tracking cookies without prior consent, and the need for explicit marketing consent. Mitigations include disabling site tracking, implementing double opt in, using granular consent checkboxes and documenting the Mailchimp data processing agreement and transfer mechanism.
Sample consent text
I agree to subscribe to the newsletter. My email address and name will be sent to Mailchimp and stored in the United States. I can unsubscribe at any time. I have read the privacy policy and consent to receiving marketing emails.
Third-party domains contacted
*.list-manage.commailchimp.comchimpstatic.comdownloads.mailchimp.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| mailchimp_landing_site | Analytics | 1 month | Stores the landing page URL for attribution purposes when Mailchimp site tracking is enabled |
| _mcid | Tracking | Persistent | Persistent Mailchimp visitor identifier set when Mailchimp site tracking is enabled to track visitors across sessions |
| mc_session | Functional | Session | Form session cookie used by Mailchimp for WordPress to manage the signup form submission state |
Mailchimp for WordPress collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The signup form itself works without any cookies. Cookies are only set when Mailchimp site tracking is enabled in the connected Mailchimp account. In that case Mailchimp may set mailchimp_landing_site (stores the landing page for attribution, lasting 1 month), _mcid (a persistent Mailchimp visitor identifier) and a form session cookie. Disabling Mailchimp site tracking results in a fully cookieless signup flow.
Yes, in two ways. First, explicit marketing consent is required before adding a subscriber to a Mailchimp list. Use an unticked opt in checkbox on the form. Second, if Mailchimp site tracking is enabled, prior consent for tracking cookies is also required before those cookies can be set. Double opt in is strongly recommended for marketing consent.
The legal basis for newsletter signup and for sending marketing emails is consent under Article 6(1)(a) GDPR. This must be specific, informed and unambiguous marketing consent obtained via an unticked checkbox. If site tracking cookies are used, Article 5(3) ePrivacy also applies. Legitimate interest is not an appropriate basis for email marketing.
Yes. Every form submission sends the subscriber email, name and IP address to Intuit Mailchimp servers in the United States. Mailchimp relies on the EU US Data Privacy Framework and standard contractual clauses as transfer mechanisms. Ensure you have signed the Mailchimp data processing agreement and document this transfer in your records of processing activities.
A DPIA is recommended if Mailchimp site tracking is enabled, because this involves systematic monitoring of visitor behaviour through persistent tracking cookies and building visitor profiles. Key risks include processing subscriber data in the United States and cookie tracking without prior consent. Mitigations include disabling site tracking, implementing double opt in and using granular consent.
Enable double opt in in your Mailchimp audience settings. Add an explicit, unticked marketing consent checkbox to every signup form. Disable Mailchimp site tracking unless you have a separate cookie consent gate. Sign the Mailchimp data processing agreement. Document the US data transfer in your records. Include Mailchimp in your privacy policy and cookie policy. Never bundle marketing consent with terms acceptance.
For a more privacy friendly option, consider a self hosted email marketing platform such as Mautic or Sendy, which keeps subscriber data on your own server in the EU. These avoid the US data transfer entirely. If you stay with Mailchimp, disabling site tracking and using double opt in are the two most effective privacy improvements.
If Mailchimp site tracking is disabled, note in your cookie policy that the signup form works without cookies and no Mailchimp cookies are set. If site tracking is enabled, list mailchimp_landing_site (1 month, landing page attribution), _mcid (persistent visitor identifier) and the form session cookie. State that subscriber data is transferred to Mailchimp in the United States under the EU US Data Privacy Framework.