FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. Brevo

Brevo

MarketingWebsite

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Brevo do?

Brevo (formerly Sendinblue) is a French marketing platform providing email campaigns, transactional email, SMS marketing, WhatsApp campaigns, marketing automation, CRM, landing pages, and web push notifications. As a French company with EU infrastructure, Brevo is one of the most GDPR-compliant marketing platforms available — no US data transfers, direct CNIL oversight, and EU data processing as the default. Brevo is the leading European alternative to US platforms like Mailchimp, Klaviyo, and HubSpot.

What is Brevo?

Brevo (formerly Sendinblue) is a French marketing technology company founded in Paris. It provides email campaigns, transactional email (SMTP API), SMS marketing, WhatsApp marketing, marketing automation, a CRM, landing pages, web push notifications, and Facebook ads integration. Brevo serves over 500,000 businesses globally and is the leading European alternative to US-based marketing platforms like Mailchimp, Klaviyo, and HubSpot. As a French company, Brevo is subject to GDPR and CNIL oversight directly.

The EU advantage: no third-country transfers

Brevo''s most significant GDPR advantage is its EU infrastructure. All email, contact, and campaign data is processed and stored within the EU. No Standard Contractual Clauses are required. No Transfer Impact Assessments are needed for the primary data flows. This makes Brevo significantly simpler to use compliantly than US-based alternatives, particularly for organisations with strict data residency requirements.

Consent requirements

Despite being EU-based, Brevo email marketing still requires valid GDPR consent for marketing emails to EU contacts. Being EU-hosted does not change the consent requirement for placing emails in inboxes — it only eliminates the transfer complexity. Implement double opt-in, use explicit consent checkboxes, and record consent timestamps. Brevo provides GDPR-compliant signup form features and double opt-in confirmation flows.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Transactional email and legitimate interest

Transactional emails sent via Brevo (password resets, order confirmations, account notifications) can rely on legitimate interest or contract performance without separate marketing consent. The key distinction is purpose: emails triggered by user actions to fulfil the service are transactional; emails sent to promote products or re-engage users are marketing and require consent.

Practical compliance steps

Sign the Brevo DPA. Implement double opt-in for marketing lists. Use GDPR-compliant subscription forms with explicit consent checkboxes. Distinguish transactional from marketing emails in your Brevo account. Configure unsubscribe handling and honour opt-outs promptly. Use Brevo''s contact deletion API for erasure requests. Add Brevo to your privacy policy as an EU-based processor.

GDPR consent category

Marketing

Websites using Brevo must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) required for email marketing campaigns. Legitimate interest (Art. 6(1)(f)) for transactional emails triggered by user actions. Contract performance (Art. 6(1)(b)) for service-related communications. Brevo's EU infrastructure removes the transfer complexity present with US-based alternatives.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidelines. No SCCs required for standard deployments.

DPIA considerations

A DPIA is generally not required for standard Brevo email marketing deployments. It may become relevant for large-scale multi-channel marketing automation combining email, SMS, and WhatsApp data across many EU contacts.

Sample consent text

I agree to receive marketing communications from [Brand] via email and SMS. I understand I can unsubscribe at any time. My data is processed by Brevo, a French company, in accordance with our privacy policy.

Technical details

Tracking methodEmail marketing, SMS, transactional email API, marketing automation, CRM, first-party tracking script, landing pages
Server locationEuropean Union (Brevo is a French company with EU infrastructure)

Third-party domains contacted

brevo.comsibautomation.comsendinblue.com

Cookies placed

NameTypeDurationPurpose
sib_cuidpersistent13 monthsBrevo visitor identifier for website analytics and contact identification via the Tracker feature

Brevo places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Brevo require GDPR consent?

Yes for marketing emails, SMS, and WhatsApp campaigns. EU infrastructure does not exempt Brevo from consent requirements for marketing communications. Implement double opt-in and use explicit consent checkboxes. Transactional emails may rely on legitimate interest or contract performance.

Is Brevo (Sendinblue) GDPR compliant?

Yes. Brevo is a French company under CNIL jurisdiction with EU infrastructure. It provides a GDPR-compliant DPA, processes all data within the EU, and does not require SCCs for standard deployments. It is one of the most GDPR-friendly marketing platforms available.

Does Brevo transfer data outside the EU?

No for standard deployments. All Brevo email, SMS, and contact data is processed and stored within the EU. No Standard Contractual Clauses are required. This is Brevo's primary GDPR advantage over US-based alternatives.

What legal basis applies to Brevo?

Consent for marketing emails, SMS, WhatsApp campaigns, and push notifications. Legitimate interest for transactional emails triggered by user actions. Contract performance for service-essential communications. The EU infrastructure simplifies compliance but does not change the fundamental consent requirement for marketing.

How do I implement double opt-in in Brevo?

Create a subscription form in Brevo, enable double opt-in in the form settings, and configure the confirmation email template. Brevo sends a confirmation email; only contacts who click the confirmation link are added to the active list. Brevo records the confirmation timestamp automatically.

Does Brevo set tracking cookies?

Brevo's Tracker feature (for website analytics and contact identification) sets first-party cookies. If enabled, this requires consent under the ePrivacy Directive. Transactional email delivery itself does not require cookies.

How do I handle erasure requests in Brevo?

Delete the contact in the Brevo contacts database. This removes their email address, attributes, and subscription history. For erasure from transactional email logs, use the Brevo API. Respond to requests within 30 days and document all deletions.

Why choose Brevo over Mailchimp for GDPR compliance?

Brevo's EU infrastructure eliminates SCCs, Transfer Impact Assessments, and US transfer disclosure requirements that apply to Mailchimp. Both require consent for marketing emails, but Brevo's French jurisdiction means CNIL guidance applies directly, providing clearer regulatory clarity for French and EU organisations.