English
consentglass · GDPR scanner for websites

HomeGuides › Service

Using Mailchimp in a GDPR-compliant way

Mailchimp (Intuit Inc., USA) processes email addresses, open and click behaviour and embeds a tracking pixel in emails. The service needs clean consent and a documented US transfer.

Double opt-in is not the default in Mailchimp but a setting per audience: under Settings → Audience name and defaults, “Enable double opt-in” must be active. Without this setting, every address entered via a form lands in the list immediately — a single opt-in that is hard to prove in a dispute and that German courts regularly consider insufficient for advertising emails.

The second building block is the data processing agreement. Intuit provides a Data Processing Addendum that applies once the terms of use are accepted; the standard contractual clauses it contains or Intuit's DPF certification are the transfer basis for processing in the USA. Both should be documented and mentioned in the privacy policy.

The tracking active by default in Mailchimp campaigns (email opens via a tracking pixel, clicks via rewritten links) creates usage profiles. The clean approach is to either switch this tracking off or include it in the consent and disclose it in the privacy policy. A blanket note “we use Mailchimp” is not enough.

Is this a risk?

For sending the newsletter, the legal basis is generally consent (Art. 6 (1)(a) GDPR), evidenced via a double opt-in. Without a confirmed sign-up, without a data processing agreement with Intuit, or without a named transfer basis, there is no legal basis. The tracking of opens and clicks common in newsletters requires separate consent or must be made transparent.

What you can do

Häufige Fragen

Is a single opt-in allowed for newsletters?
For advertising newsletters, German case law practically always requires a double opt-in, because only then is it provable that the sign-up came from the owner of the address. A single opt-in is barely defensible in a dispute.
Do I need a DPA for Mailchimp?
Yes. Mailchimp processes the email addresses on your behalf. Intuit's Data Processing Addendum applies once the terms are accepted; you should archive it.
May I use open tracking in newsletters?
Only transparently and ideally based on consent. The tracking pixel and click tracking create behavioural profiles; recipients must be informed, and many data protection experts consider separate consent necessary.
Is the US transfer to Mailchimp unproblematic after the DPF?
The transfer is generally covered by the EU-US Data Privacy Framework as long as Intuit stays certified. The consent and evidence obligations for the newsletter itself apply regardless.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.