FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. SendGrid
S

SendGrid

Marketing

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SendGrid do?

SendGrid (owned by Twilio) is a US-based cloud email delivery service used for transactional and marketing emails. Developers use SendGrid's API or SMTP relay to send password resets, order confirmations, newsletters, and automated campaigns at scale. For GDPR compliance, the key distinctions are: transactional emails may rely on legitimate interest or contract performance, while marketing emails require consent. All data is processed in the US requiring SCCs.

What is SendGrid?

SendGrid (owned by Twilio since 2019) is a cloud-based email delivery service providing an API and SMTP relay for sending transactional and marketing emails at scale. It is one of the most widely used email infrastructure platforms, processing billions of emails monthly for developers, SaaS products, e-commerce platforms, and enterprise marketing teams. SendGrid provides email analytics (opens, clicks, bounces, spam reports), email validation, and marketing campaign tools.

Transactional vs marketing email: the key GDPR distinction

SendGrid is used for both transactional emails (password resets, order confirmations, account alerts) and marketing emails (newsletters, promotional campaigns). The GDPR legal basis differs: transactional emails may rely on contract performance or legitimate interest, while marketing emails require explicit consent from EU recipients. Configure your SendGrid integration to ensure marketing and transactional emails are clearly separated and routed through appropriate verification flows.

Email tracking pixels under GDPR

SendGrid''s open tracking (1x1 pixel image) and click tracking (link wrapping through SendGrid''s servers) constitute personal data processing by linking engagement to individual email addresses. For marketing emails, this tracking is justified by the same consent as the email itself. For transactional emails, tracking should be disclosed in your privacy policy. Consider disabling open tracking for privacy-conscious implementations — it is increasingly blocked by email clients anyway.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

US transfers and DPA

All SendGrid data is processed in the US. SCCs are required. Sign the Twilio/SendGrid Data Processing Addendum available from the Twilio Trust Hub. Note that as a Twilio company, the DPA covers SendGrid under the broader Twilio DPA framework.

Practical compliance steps

Sign the Twilio DPA covering SendGrid. Separate transactional and marketing email streams. Obtain and record valid consent for marketing email recipients before adding to SendGrid. Disclose email tracking in your privacy policy. Implement unsubscribe handling with list unsubscribe headers. Use SendGrid''s suppression list management to honour opt-outs. Process erasure requests by removing contacts from SendGrid''s contact database.

GDPR consent category

Marketing

Websites using SendGrid must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for marketing emails to EU contacts. Legitimate interest (Art. 6(1)(f)) for transactional emails triggered by user actions (password resets, order confirmations). Contract performance (Art. 6(1)(b)) for service-essential notifications. Separate consent required for email open and click tracking analytics.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, SCCs for US data transfers

DPIA considerations

A DPIA is generally not required for standard SendGrid transactional email use. It may become relevant for large-scale email marketing programmes combining SendGrid with extensive behavioural tracking and personalisation at individual level.

Sample consent text

Emails from this service are delivered via SendGrid (Twilio), a US email delivery platform. Transactional emails (account notifications, order confirmations) are sent based on your service relationship. Marketing emails are sent only with your consent. See our privacy policy for details.

Technical details

Tracking methodTransactional and marketing email API, email open and click tracking pixels, SMTP relay, email analytics dashboard
Server locationUnited States (SendGrid/Twilio is a US company with US infrastructure)
Cookieless tracking availableYes
Data transferred outside the EUSendGrid (owned by Twilio) is a US-based email delivery platform. All email processing, delivery infrastructure, and analytics data are processed on US infrastructure. EU personal data transfers require Standard Contractual Clauses. SendGrid provides a GDPR-compliant DPA.

Third-party domains contacted

sendgrid.comsendgrid.netapi.sendgrid.com

Cookies placed

NameTypeDurationPurpose
__sg_persistent1 yearSendGrid email engagement tracking cookie linking email clicks to recipient identities for campaign analytics

SendGrid places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does SendGrid require GDPR consent for email marketing?

Yes. Marketing emails sent via SendGrid to EU contacts require valid consent: freely given, specific, informed, unambiguous. Ensure recipients opted in through a GDPR-compliant process before adding them to SendGrid marketing lists.

Does SendGrid require consent for transactional emails?

Generally no. Transactional emails triggered by user actions (password resets, order confirmations, account alerts) may rely on contract performance or legitimate interest. Disclose SendGrid in your privacy policy as the email delivery processor.

Does SendGrid transfer EU data outside the EU?

Yes. All SendGrid processing occurs on US infrastructure. SCCs are required. Sign the Twilio Data Processing Addendum covering SendGrid, available from the Twilio Trust Hub at twilio.com/en-us/legal/privacy/gdpr.

Does SendGrid email tracking require consent?

Open tracking (pixel image) and click tracking (link wrapping) for marketing emails are covered by the marketing consent. For transactional emails, tracking should be disclosed in your privacy policy. Consider disabling open tracking as it is increasingly blocked by email clients.

How do I implement unsubscribe handling in SendGrid?

Use SendGrid's Unsubscribe Group feature to manage subscription preferences. Include a List-Unsubscribe header in all marketing emails. Process unsubscribe requests from SendGrid webhooks and update your contact database to honour opt-outs within 10 business days.

What legal basis applies to SendGrid?

Contract performance for transactional emails. Legitimate interest for service notifications. Consent for marketing emails and newsletters. The legal basis follows the purpose of the email, not the delivery platform.

How do I handle erasure requests for SendGrid contacts?

Delete the contact from SendGrid Marketing Campaigns contact lists. Add the email address to SendGrid's global suppression list to prevent future emails. For transactional email logs, use the SendGrid API to delete email activity records. Respond within 30 days.

Are there EU-based alternatives to SendGrid?

Brevo (formerly Sendinblue, France) provides transactional email API and marketing email with EU data residency. Mailjet (France) provides a comparable transactional and marketing email API with EU infrastructure. Both are strong GDPR-compliant SendGrid alternatives.