Mailchimp (Intuit Inc., USA) processes email addresses, open and click behaviour and embeds a tracking pixel in emails. The service needs clean consent and a documented US transfer.
Double opt-in is not the default in Mailchimp but a setting per audience: under Settings → Audience name and defaults, “Enable double opt-in” must be active. Without this setting, every address entered via a form lands in the list immediately — a single opt-in that is hard to prove in a dispute and that German courts regularly consider insufficient for advertising emails.
The second building block is the data processing agreement. Intuit provides a Data Processing Addendum that applies once the terms of use are accepted; the standard contractual clauses it contains or Intuit's DPF certification are the transfer basis for processing in the USA. Both should be documented and mentioned in the privacy policy.
The tracking active by default in Mailchimp campaigns (email opens via a tracking pixel, clicks via rewritten links) creates usage profiles. The clean approach is to either switch this tracking off or include it in the consent and disclose it in the privacy policy. A blanket note “we use Mailchimp” is not enough.
For sending the newsletter, the legal basis is generally consent (Art. 6 (1)(a) GDPR), evidenced via a double opt-in. Without a confirmed sign-up, without a data processing agreement with Intuit, or without a named transfer basis, there is no legal basis. The tracking of opens and clicks common in newsletters requires separate consent or must be made transparent.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.