FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. Mailchimp
M

Mailchimp

MarketingWebsite

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Mailchimp do?

Mailchimp (owned by Intuit) is a US-based email marketing platform used by millions of small businesses and creators. For European audiences, the key GDPR requirement is valid opt-in consent for email marketing — pre-ticked boxes, implied consent, and purchased lists are not compliant. All subscriber data is processed in the US requiring SCCs. Mailchimp provides built-in GDPR features including consent checkboxes, double opt-in, and unsubscribe management to help operators stay compliant.

What is Mailchimp?

Mailchimp is an email marketing and automation platform owned by Intuit. It is one of the most widely used email marketing tools globally, particularly popular with small businesses, creators, and non-profits. Mailchimp provides list management, email campaign creation, marketing automation, audience segmentation, landing pages, and basic CRM features. It integrates with hundreds of e-commerce, CMS, and business platforms.

The GDPR consent requirement for email marketing

Under GDPR, sending marketing emails to EU contacts requires valid consent: freely given, specific, informed, and unambiguous. This means using an unchecked opt-in box, never using pre-ticked checkboxes, not bundling marketing consent with terms of service, and retaining evidence of consent (who, when, how). Mailchimp provides tools to help: GDPR-compliant signup forms, double opt-in, consent timestamp recording, and granular subscription management.

Email tracking and ePrivacy

Mailchimp email tracking pixels (open tracking) and click tracking constitute personal data processing. Open tracking works by embedding a 1x1 pixel image in each email — when loaded, it registers an open event linked to the subscriber. This is widely considered personal data processing under GDPR. Disclose email tracking in your privacy policy. Consider whether open tracking is necessary; many privacy-conscious senders disable it.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

US transfers and DPA

All Mailchimp subscriber data is processed in the US. Sign the Mailchimp Data Processing Agreement (available via Mailchimp account settings under Extras) which includes SCCs for EU-US data transfers. Disclose Mailchimp as an email processor in your privacy policy.

Practical compliance steps

Sign the Mailchimp DPA. Enable double opt-in for all EU lists. Use GDPR-compliant signup forms with explicit unchecked consent checkboxes. Record and retain consent evidence. Never add contacts without consent. Honour unsubscribe and erasure requests promptly. Disclose Mailchimp and email tracking in your privacy policy. Purge inactive subscribers periodically to maintain data minimisation.

GDPR consent category

Marketing

Websites using Mailchimp must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) required for email marketing to EU contacts. GDPR requires a clear affirmative opt-in for marketing emails — pre-ticked boxes, implied consent, or purchased lists are not valid. Legitimate interest applies only in very limited B2B scenarios with existing customer relationships.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive for email tracking pixels and cookies, SCCs for US data transfers

DPIA considerations

A DPIA is generally not required for standard Mailchimp email marketing. It may become relevant for large-scale audience profiling, automated segmentation combining multiple data sources, or for email programmes targeting vulnerable populations.

Sample consent text

Yes, I would like to receive marketing emails from [Brand]. I understand I can unsubscribe at any time using the link in any email. My data will be processed in accordance with the privacy policy.

Technical details

Tracking methodEmail marketing platform, email tracking pixels (opens, clicks), embedded signup forms, landing pages, first-party cookies, audience data enrichment
Server locationUnited States (Mailchimp/Intuit is a US company with US infrastructure)
Data transferred outside the EUMailchimp (owned by Intuit) is a US-based email marketing platform. All subscriber data is processed on US infrastructure. EU personal data transfers require Standard Contractual Clauses. Mailchimp provides a GDPR-compliant DPA.

Third-party domains contacted

mailchimp.comlist-manage.commailchimpapp.net

Cookies placed

NameTypeDurationPurpose
_mc_userpersistent1 yearMailchimp user identifier for tracking email campaign engagement and subscriber analytics

Mailchimp places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Mailchimp require GDPR consent?

Yes. Marketing emails to EU contacts require valid GDPR consent: unchecked opt-in, specific purpose, documented timestamp. Mailchimp provides GDPR-compliant forms with double opt-in.

What does double opt-in mean in Mailchimp?

Double opt-in sends a confirmation email subscribers must click to verify. Enable it for all EU lists via Mailchimp's List Settings.

Can I send marketing emails to existing customers without consent?

In limited B2B scenarios, legitimate interest may apply. This requires a documented LIA and a clear opt-out in every email. For consumer marketing, consent is always required.

Does Mailchimp transfer data outside the EU?

Yes. All subscriber data is processed in the US. Sign the Mailchimp DPA via Account Settings which includes SCCs.

Does Mailchimp email tracking constitute personal data processing?

Yes. Open and click tracking links engagement to subscriber profiles. Disclose this in your privacy policy.

How do I handle erasure requests in Mailchimp?

Permanently delete the contact in Mailchimp. Respond within 30 days and document all actions.

Can I import contacts from a CSV into Mailchimp?

Only if those contacts have valid documented consent. Never import contacts who have not specifically opted in to your marketing.

Are there EU-based alternatives to Mailchimp?

Brevo (France), Mailjet (France), and CleverReach (Germany) provide EU data residency with simpler GDPR transfer compliance.