Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Embed newsletter signup forms and pop ups on your site with MailerLite. Subscriber data is processed primarily in the EU with some US subprocessors, requiring consent and double opt in.
The MailerLite Plugin embeds newsletter signup forms and pop ups directly on your website and connects them to your MailerLite account. When a visitor submits a form their name and email address are sent to the MailerLite API and stored in your MailerLite subscriber list. MailerLite is operated by a company registered in Lithuania and processes data primarily in the European Union, but it relies on certain subprocessors located in the United States.
The plugin collects the subscriber email address and name when a form is submitted. Embedded forms and pop ups set cookies to control how often a pop up is shown to a visitor, to track whether a visitor has already signed up, and to attribute a signup to a particular campaign or source. These cookies are non essential and require prior consent under the ePrivacy Directive.
Processing subscriber personal data for email marketing requires a legal basis. Consent under Article 6(1)(a) GDPR is the standard basis for marketing newsletters. Because MailerLite uses US based subprocessors, you must inform subscribers of international transfers and ensure a Data Processing Agreement is in place with MailerLite. The non essential cookies set by forms and pop ups require separate cookie consent before they are placed.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Visitors must give freely given, specific, informed and unambiguous consent before their data is added to your mailing list, and again before non essential cookies are placed. MailerLite supports double opt in, which is strongly recommended to document consent and reduce the risk of spam complaints. Your consent mechanism must clearly state who processes the data, the purpose and the right to withdraw.
Primary processing takes place in the European Union, which is a compliance advantage. However MailerLite's subprocessor list includes vendors based in the United States. Transfers to those subprocessors rely on standard contractual clauses. You must disclose these transfers in your privacy policy and list the subprocessors in your record of processing activities.
Sign the Data Processing Agreement in your MailerLite account settings. Enable double opt in for all signup forms. Block non essential MailerLite cookies until cookie consent is given. Update your privacy policy to name MailerLite, describe EU primary processing and disclose US subprocessors under standard contractual clauses. Add MailerLite cookies to your cookie policy. Review MailerLite's subprocessor list regularly for changes.
Websites using MailerLite Plugin must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is unlikely to be required for standard newsletter signup forms using MailerLite, given EU primary processing and double opt in. However, consider a DPIA if you collect special category data via forms or use pop ups with behavioural targeting. Document the legal basis for each form, ensure DPA with MailerLite is signed, and list all US subprocessors in your record of processing activities.
Sample consent text
I agree to receive the newsletter and accept that my name and email address will be stored by MailerLite and processed in the EU. Some data may be transferred to US subprocessors under standard contractual clauses. I can unsubscribe at any time.
Third-party domains contacted
assets.mailerlite.comconnect.mailerlite.comstatic.mailerlite.comforms.mailerlite.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| mailerlite:popups | Functional | Several months | Stores whether a visitor has already seen or dismissed a MailerLite pop up to control display frequency |
| ml_subscriber | Functional | Session | Webform session cookie that manages the MailerLite signup flow and prevents duplicate submissions |
| ml_attribution | Marketing | Session | Tracks the source or campaign that led to a newsletter signup for attribution reporting in MailerLite |
MailerLite Plugin collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The MailerLite Plugin can set a pop up display frequency cookie (often prefixed ml_ or named mailerlite:popups) to prevent the same pop up appearing too often, a webform session cookie to manage the signup flow, and a signup attribution cookie to link a subscriber to a campaign. These cookies are functional or marketing in nature and are not essential to the core website, so consent is required before they are placed.
Yes. Two separate consents are needed. First, the visitor must consent to receiving your newsletter before their email and name are added to your MailerLite list. This is consent under Article 6(1)(a) GDPR for email marketing. Second, the non essential cookies set by forms and pop ups require prior cookie consent under the ePrivacy Directive. Using double opt in for the newsletter signup is strongly recommended to evidence consent clearly.
The legal basis is consent under Article 6(1)(a) GDPR. Visitors must actively opt in to your newsletter, and that consent must be freely given, specific, informed and unambiguous. Consent for the newsletter signup is separate from consent for non essential cookies. You must keep records of when and how consent was given, and subscribers must be able to withdraw consent at any time by unsubscribing.
MailerLite is based in Lithuania and processes data primarily in the European Union, which is a compliance advantage. However MailerLite uses subprocessors, some of which are located in the United States. Transfers to those subprocessors rely on standard contractual clauses. You must disclose these US subprocessors in your privacy policy and in your record of processing activities. MailerLite publishes a list of its subprocessors in its Data Processing Agreement.
A formal DPIA is unlikely to be required for standard newsletter signup forms using MailerLite, because the processing is not high risk given EU primary processing and the availability of double opt in. However you should consider a DPIA if you collect special category data via forms (for example health or political opinions), if you use pop ups with behavioural targeting, or if you combine MailerLite data with other datasets to profile subscribers in a way that significantly affects them.
Sign the Data Processing Agreement in your MailerLite account settings before collecting any subscriber data. Enable double opt in for all signup forms to document consent. Configure your consent management platform to block MailerLite cookies until cookie consent is given. Add a clear privacy notice to each signup form explaining who processes the data and why. Update your privacy policy to name MailerLite as a processor, describe EU primary processing and disclose US subprocessors under standard contractual clauses. Review MailerLite's subprocessor list for changes at least annually.
MailerLite is already one of the more privacy friendly email marketing tools because it is EU based and offers double opt in. Alternatives include Brevo (formerly Sendinblue, also EU based), Mailchimp (US based, higher transfer risk) and self hosted tools such as Listmonk or Mautic which keep all subscriber data on your own infrastructure. If minimising US data exposure is a priority, EU based providers or self hosted solutions are preferable.
Add a dedicated entry for MailerLite in your cookie policy table. List at minimum the pop up frequency cookie (e.g. ml_... or mailerlite:popups, functional, several months), the webform session cookie (functional, session) and the signup attribution cookie (marketing, session or short term). For each cookie state the name, provider (MailerLite), purpose, type and duration. Link the cookie policy entry to your consent management platform categories so visitors can accept or reject MailerLite cookies independently.