About the General Data Protection Regulation
The GDPR regulates how organizations process the personal data of EU citizens, including organizations located outside of the EU.
Get the job done with a pro
From training to full-service marketing, our community of partners can help you make things happen.
If your business is based in the European Union (EU), or you process the personal data of EU citizens, the General Data Protection Regulation (GDPR) affects you.
In this article, we'll answer common questions about Mailchimp and the GDPR.
Note
Mailchimp offers tools and information as a resource, but we don’t offer legal advice. We recommend you contact your legal counsel to find out how the GDPR affects you.
Yes. You can edit the suggested language for the GDPR fields of our signup forms to collect consent for processing activities that occur outside of Mailchimp. If you choose to write your own descriptions, make sure you’re explicit about why you’re collecting data.
OPTIN_TIME
and OPTIN_IP
fields in your exported CSV file. These fields contain the date, time, and IP address associated with the signup.CONFIRM_TIME
and CONFIRM_IP
fields in your exported CSV file. These fields contain the date, time, and IP address associated with the confirmation.The GDPR could affect your business outside of Mailchimp. We recommend you contact your legal counsel to find out how the GDPR affects you.
We recommend you enable double opt-in if you are subject to data protection laws that require it.
Double opt-in includes an extra confirmation step that verifies each email address. This confirmation provides additional evidence of consent.
Export your audience and review the OPTIN\_TIME
and CONFIRM\_TIME
fields in your exported CSV file.
OPTIN\_TIME
The time a contact submitted your signup form, if they used it to sign up.
CONFIRM\_TIME
The date and time the contact clicked the link in the opt-in confirmation email.
If the values of the OPTIN\_TIME
and CONFIRM\_TIME
fields are different, it is likely the contact signed up using double opt-in.
If you’ve combined multiple audiences using the built-in combine audiences tool, the OPTIN\_TIME
field won't be included in your exported file. You won’t be able to verify the opt-in status of contacts.
Yes. If you have GDPR-friendly forms enabled for an audience, you can import contacts who have given GDPR-friendly consent for marketing permissions.
Format Guidelines for Your Import File
Yes. If you export a GDPR-enabled audience, one CSV file header will match the GDPR form field label in your segments. This field will display each marketing permission the contact has opted-in to.
Choose the Remove contact option from the Actions menu on the profile page, then choose Permanently delete. To delete more than one contact at the same time, navigate to the contact table to choose each contact you want to delete. Then, click the three vertical dots to choose Delete contacts for steps to permanently delete your contacts. For step-by-step instructions on this process, read Delete Contacts.
This action permanently removes all of a contact’s personal information and anonymizes their data in your reports. After you delete a contact, you won’t be able to add them back to your audience.
If one of your contacts asks us to remove their data from every account in Mailchimp, we'll notify you with an email. You are required to consider whether you have a legal obligation to respond to and address this individual's deletion request in accordance with your obligations under applicable laws.
You can translate any GDPR field except the Privacy Policy and Terms field. You can also translate other parts of your signup form. For more information, check out Translate Signup Forms.
No. The Privacy Policy and Terms field lets your contacts know that you’ll be storing their info in your Mailchimp account. A link to our Global Privacy Statement and Terms is included.
Yes. When you edit the fields on your GDPR-friendly form, check the box next to Require at least one option. If this is enabled for your form, a contact must select at least one marketing permission checkbox before they can submit the form. We suggest making any field related to email marketing a required field or enabling double opt-in. We recommend this so that the contact can’t submit the form and get added as a Subscribed contact to your audience without selecting how they would like to hear from you.
Yes. We've added marketing_permissions
as a field with a boolean value, so you can enable GDPR fields and sync contact marketing permissions using the Marketing API. To learn more about managing your audience with the Mailchimp Marketing API, check out our API documentation.
To comply with requests to fully delete data, you can also permanently delete contacts using the Marketing API. After a contact is permanently deleted, they cannot be re-imported.
You are responsible for determining whether other third-party applications, including integrations and e-commerce stores, meet GDPR requirements.
If you rely on consent to process subscribers' personal data, double check whether the consent that you previously obtained meets the GDPR's standards. For example, check third-party integrations to be sure they don't automatically add people to your Mailchimp audience without an opt-in checkbox that clearly states how you'll use that person's data. You should also review the terms associated with any Mailchimp add-ons or third-party integrations you use.
Mailchimp's Data Processing Addendum which incorporates the EU’s Standard Contractual Clauses (“SCCs”), forms part of our Standard Terms of Use, which is our contract with you. By using Mailchimp or signing up for an account, you’re agreeing to these Terms.
Chapter 8 of the full text of the GDPR discusses remedies, liability, and penalties.
Mailchimp is headquartered in and has offices in the United States. Our servers are also located in the United States. This means data we process may be transferred to, stored, or processed in the United States.
If you’re located in the EU or use Mailchimp to market to anyone in the EU, please review Section 20 of our Standard Terms of Use. These sections include important information about how Mailchimp treats EU data and what you should do if you’re keeping EU data in your Mailchimp account. For more information, read Mailchimp and European Data Transfers.
Technical Support
Have a question?
Paid users can log in to access email and chat support.
The GDPR regulates how organizations process the personal data of EU citizens, including organizations located outside of the EU.
Learn how to use Mailchimp's GDPR-friendly tools to collect consent from new and existing contacts.