Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Mailchimp for WooCommerce is the official plugin that connects a WooCommerce store to Mailchimp. It syncs orders, products, and customer data to Mailchimp and adds a site tracking script that sets first party cookies for abandoned cart recovery and product retargeting. The data is processed in the United States by Mailchimp, a service of Intuit. Because the tracking cookies are not strictly necessary, prior consent is required under the GDPR and the ePrivacy Directive.
Mailchimp for WooCommerce is the official integration that links a WooCommerce online store to a Mailchimp marketing account. It synchronises orders, products, carts, and customer profiles to Mailchimp and adds a JavaScript site tracking snippet to the storefront. With this data, merchants can send abandoned cart emails, retarget shoppers with product recommendations, build segments, and measure the revenue generated by their campaigns.
The site tracking script sets first party cookies such as _mcid, which stores a Mailchimp visitor identifier for about one year, _mcida, a session cookie, and mailchimp_landing_site, which records the first landing URL for roughly one month. For cart recovery the plugin also stores the shopper email in values such as mailchimp.cart.current_email. Alongside the cookies, Mailchimp receives order details, products viewed, cart contents, names, email addresses, and IP addresses, which constitute personal data under the GDPR.
Because the tracking script writes and reads cookies on the shopper terminal for marketing and retargeting rather than for a strictly necessary function, Article 5(3) of the ePrivacy Directive requires prior consent. The onward processing of names, emails, and purchase behaviour by Mailchimp also qualifies as processing of personal data, so a lawful basis, a clear privacy notice, and a record of processing activities are required, and Mailchimp acts as a processor under a data processing agreement.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The marketing tracking script and its cookies must not load before the shopper has actively accepted the marketing category in your consent banner. Pre ticked boxes, implied consent from continued browsing, and cookie walls do not meet the GDPR standard. Newsletter opt in at checkout must be a separate, unticked choice, and the consent you collect must be freely given, specific, informed, and as easy to withdraw as to give.
Mailchimp processes data in the United States, so you must document the transfer under the EU US Data Privacy Framework and the Standard Contractual Clauses and accept the Mailchimp and Intuit data processing terms. In practice, gate the site tracking script behind your consent management platform, keep the checkout newsletter box unticked, list the Mailchimp cookies and their durations in your cookie policy, and configure data retention and deletion so that shopper data is not kept longer than necessary.
Websites using Mailchimp for WooCommerce must obtain user consent under GDPR regulations.
DPIA considerations
Mailchimp for WooCommerce sets a persistent visitor cookie (_mcid) for about one year, stores shopper emails for cart recovery, and sends names, emails, and full purchase histories to Mailchimp on US infrastructure. A DPIA should assess the scale of ecommerce profiling, the linkage of behavioural and identifiable customer data, the international transfer to the United States, and retention periods, together with mitigations such as consent gating, an unticked checkout opt in, data minimisation, and shortened retention.
Sample consent text
We use Mailchimp for WooCommerce to recognise your visit, recover abandoned carts, and send you relevant product recommendations. Mailchimp places cookies on your device to identify your browser and link your shopping activity to our store records. These cookies load only after you accept the marketing category, and the data may be processed in the United States. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
chimpstatic.comdownloads.mailchimp.com*.list-manage.come.mailchimp.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _mcid | marketing | 1 year | Stores the Mailchimp visitor identifier used to recognise the browser across visits and to link site activity to a Mailchimp contact for retargeting and cart recovery. |
| _mcida | marketing | Session | Short lived session cookie used by the Mailchimp tracking script to manage the current browsing session. |
| mailchimp_landing_site | marketing | 1 month | Stores the first landing URL of the visitor so that the original traffic source can be attributed to later orders. |
| mailchimp.cart.current_email | marketing | Session | Stores the shopper email associated with the current cart so that abandoned cart recovery emails can be triggered. |
| mailchimp_user_email | marketing | 1 month | Stores a known shopper email to associate returning visits with an existing Mailchimp contact for cart recovery and personalisation. |
Mailchimp for WooCommerce uses cookies for user preferences — inform visitors with a consent banner.
The site tracking script sets first party cookies including _mcid, which stores a Mailchimp visitor identifier for about one year, _mcida, a short lived session cookie, and mailchimp_landing_site, which records the first landing URL for around one month. For cart recovery the plugin also stores the shopper email in values such as mailchimp.cart.current_email.
Yes. The tracking and cart cookies are not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before the site tracking script loads. The checkout newsletter box must also be a separate, unticked choice.
The storage and reading of cookies relies on consent under the ePrivacy Directive, and the marketing processing of names, emails, and purchase behaviour relies on consent under Article 6(1)(a) of the GDPR. Legitimate interest is generally not available because consent is already required to place the cookies.
Yes. Mailchimp, a service of Intuit Inc., processes data on infrastructure in the United States. Transfers are covered by the EU US Data Privacy Framework and Standard Contractual Clauses, which you should reference in your privacy notice and cookie policy.
A full DPIA is not always mandatory, but it is strongly recommended because the plugin combines ecommerce behavioural data with identifiable customer records and transfers data internationally. Document the purposes, data categories, retention, and safeguards, and reassess if you enable advanced segmentation or predicted demographics.
Load the site tracking script only after the shopper accepts the marketing category in your consent management platform, and keep the cookies blocked until then. Keep the checkout newsletter box unticked, accept the Mailchimp and Intuit data processing terms, set sensible retention, and document the cookies in your cookie policy.
EU based options such as Brevo, MailPoet, or Sendinblue keep data within the European Union and integrate with WooCommerce for newsletters and cart recovery. The right choice depends on whether you need Mailchimp specific features or prefer to avoid an international transfer to the United States.
List each Mailchimp cookie, its purpose, and its duration, name Mailchimp and Intuit Inc. as recipients, and disclose the transfer to the United States. Keep the entries in sync with a regular cookie scan so that new or renamed Mailchimp cookies are reflected accurately.