All posts

Mailchimp and UK GDPR: Data transfers, DPA requirements, and what you need to do

29 June 20266 min read

Mailchimp stores UK subscriber data on US servers. That creates compliance obligations under UK GDPR that many small businesses get wrong.

Mailchimp's servers are located in the United States. When you add UK contacts to your Mailchimp audience, their personal data is transferred to the US. Under UK GDPR, this is a "restricted transfer" that requires appropriate safeguards.

The good news is that Mailchimp has proper transfer mechanisms in place. The potentially expensive news is that using them isn't automatic.

Current transfer status: Data Privacy Framework certification

Good news: Mailchimp is now certified under the UK-US Data Privacy Framework (DPF), including the UK Extension. This means UK businesses can transfer personal data to Mailchimp without needing additional transfer mechanisms like IDTAs or SCCs.

Mailchimp is certified under the EU-US DPF, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework. You can verify this certification by searching for "Intuit" on the official Data Privacy Framework register.

This replaces the previous Privacy Shield framework, which was invalidated in July 2020 following the Schrems II court decision. The new Data Privacy Framework came into effect in July 2023.

The DPA requirement: Not optional

If you have UK or EEA contacts in your Mailchimp audience, you must have a Data Processing Addendum (DPA) in place with Mailchimp. This is required under Mailchimp's terms of use (section 20.5) and UK GDPR.

The DPA is incorporated into Mailchimp's standard terms, so accepting it is straightforward. But make sure you actually do it - having a signed DPA is a compliance requirement, not optional.

The Standard Contractual Clauses ("SCCs") are directly incorporated into our Data Processing Addendum (DPA) which automatically forms part of our Standard Terms of Use (our contract with you) and applies to customer data protected by European data protection laws (including the GDPR). These act as a backup mechanism if the Data Privacy Framework is ever invalidated.

The DPA covers Mailchimp's role as a data processor, your obligations as the data controller, and the technical and organisational measures Mailchimp implements to protect your data.

What the German enforcement action actually means

In March 2021, the Bavarian Data Protection Authority (DPA) ruled on the use of Mailchimp's services by a German publishing company. It's crucial to note that the decision was not about Mailchimp's compliance measures, but focused on the customer's failure to conduct a required data transfer assessment under GDPR.

In light of the Schrems II decision the BayLDA considered that the transfer of the complainant's email address to Mailchimp was unlawful under the GDPR because the publishing company failed to assess whether technical supplementary measures were necessary in addition to the SCCs - and therefore failed to implement any such measures - to ensure the transfer of data satisfied the GDPR requirements.

The BayLDA therefore decided not to impose a fine or take any other enforcement action. However, there is no guarantee the ICO would not impose a fine in similar circumstances.

The key point: the problem was the customer's failure to conduct proper due diligence, not Mailchimp's compliance measures.

Why this matters for UK businesses

The ICO can impose significant penalties for UK GDPR violations. Article 83 UK GDPR and section 157 DPA 2018 provide for two levels of maximum fine, depending on the statutory provision that has been infringed. The standard maximum amount is £8.7 million or, in the case of an undertaking, is the higher of either £8.7 million or 2% of the undertaking's total worldwide annual turnover in the preceding financial year.

For serious violations, the penalties are higher. The maximum fine can reach £17.5 million or 4% of annual global turnover, whichever is higher.

Under PECR (Privacy and Electronic Communications Regulations), the ICO can issue fines of up to £500,000 under PECR for serious contraventions. Where the same conduct also breaches UK GDPR, the ICO can issue GDPR fines of up to £17.5 million or 4% of annual global turnover, whichever is higher.

The common failure: Assuming compliance is automatic

Most small businesses using Mailchimp make the same mistake. They assume that because Mailchimp is a legitimate service with proper certifications, they don't need to do anything.

That's wrong. Here's what typically happens:

1. A business signs up for Mailchimp and starts collecting email addresses 2. They use Mailchimp's standard signup forms without enabling GDPR features 3. They don't review or accept the Data Processing Addendum 4. They collect email addresses without proper consent documentation 5. They assume Mailchimp's compliance covers them completely

Mailchimp explicitly states in Section 20 of their Terms of Use, that you must be compliant with all applicable laws. This usually means your country's privacy laws and those of your users'. You're responsible for determining whether the Service is suitable for you to use in light of your obligations under any regulations like HIPAA, GLB, EU data privacy laws (including the General Data Protection Regulation) (collectively, "EU Data Privacy Laws"), United States export control laws and regulations and economic sanctions laws and regulations.

What you need to do

1. Accept the Data Processing Addendum

Mailchimp's Data Processing Addendum which incorporates the EU's Standard Contractual Clauses ("SCCs"), forms part of our Standard Terms of Use, which is our contract with you. By using Mailchimp or signing up for an account, you're agreeing to these Terms.

While this happens automatically when you sign up, you should review the DPA to understand your obligations.

2. Use GDPR-compliant signup forms

Mailchimp offers GDPR-friendly signup forms with consent checkboxes. Enable these for any audience that includes UK or EU contacts.

Consider enabling double opt-in for additional protection. While not legally required, double opt-in provides stronger evidence of consent if ever challenged.

3. Understand PECR requirements

Under PECR (the Privacy and Electronic Communications Regulations), you need consent to send marketing emails to individuals - with one exception. You can email existing customers without explicit consent if all these conditions are met: You collected their email during a sale or sale negotiation · You're only marketing your own similar products or services · You gave them a clear opportunity to opt out when collecting their details

The soft opt-in does not apply to charities, political parties, or other not-for-profit organisations.

4. Handle tracking appropriately

Mailchimp tracks email opens and link clicks by default. This tracking uses cookies and similar technologies, which has GDPR and PECR implications. Open tracking - A tiny invisible image loads when the email is opened · Click tracking - Links are redirected through Mailchimp's servers · Location data - Approximate location based on IP address · Device information - Email client and device type · This tracking is generally considered legitimate interests processing - you have a genuine business reason to measure campaign performance, and subscribers would reasonably expect it.

If you want to be particularly privacy-conscious, you can disable open tracking in individual campaigns (Campaign → Settings → Tracking). Some organisations disable tracking entirely for sensitive communications.

5. Prepare for data subject rights

Your subscribers have rights under UK GDPR. Here's how to handle them in Mailchimp: Right to access: Export the subscriber's profile and activity data from Audience → All contacts → [Contact] → Export data · Right to erasure: Delete the contact permanently from your audience. Note: this removes all historical data. Right to rectification: Update subscriber details directly in their contact profile. Right to object: Unsubscribe them from marketing. You can keep them in your audience for transactional emails if applicable. Train your team to recognise these requests and respond within 30 days.

6. Update your privacy policy

Update your website's privacy statement or policy to describe your use of Mailchimp. This should explain:

  • That you use Mailchimp for email marketing
  • What data is transferred to Mailchimp
  • The legal basis for the transfer (Data Privacy Framework)
  • How subscribers can exercise their rights

7. Document your compliance

Keep records of:

  • When you accepted the DPA
  • Your consent collection methods
  • Any data subject rights requests and how you handled them
  • Your transfer impact assessment (if you conducted one)

What if you want to avoid US transfers entirely?

If you prefer to avoid US data transfers entirely, several email marketing platforms host data within the UK or EU: Brevo (formerly Sendinblue) - Servers in the European Union. The right choice depends on your features needs, budget, and risk appetite.

But for most small businesses, Mailchimp's Data Privacy Framework certification makes the compliance burden manageable.

The bottom line

Mailchimp can be used compliantly under UK GDPR, but it's not automatic. You need to:

Mailchimp is certified under the UK-US Data Privacy Framework - transfers are lawful · You must sign the Data Processing Addendum if you have UK/EEA contacts · Get proper consent for marketing emails (unless soft opt-in applies)

The German enforcement action was about a business failing to do proper due diligence, not about Mailchimp's compliance measures. Don't make the same mistake.

If you're not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app.

Sources

Mailchimp GDPR Compliance Page https://mailchimp.com/gdpr/

Mailchimp Data Processing Addendum https://mailchimp.com/legal/data-processing-addendum/

Mailchimp European Data Transfers Guide https://mailchimp.com/help/mailchimp-european-data-transfers/

UK GDPR Maximum Penalties - ICO https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/

Bavarian DPA Decision Analysis - Thorntons Law https://www.thorntons-law.co.uk/knowledge/gdpr-violation-for-german-company-using-mailchimp-for-marketing

PECR Enforcement Powers - GDPR Local https://gdprlocal.com/gdpr-newsletter-compliance/

Mailchimp UK GDPR Compliance Guide - Measured Collective https://measuredcollective.com/mailchimp-gdpr-what-you-need-to-know-to-be-gdpr-pecr-compliant/

---

This post is for information only and does not constitute legal advice.

Further reading