Email Marketing Compliance

Privacy Policy for Mailchimp: What Email Marketers Must Disclose

Using Mailchimp for email marketing? Your privacy policy must disclose subscriber data collection, email tracking, audience segmentation, and GDPR consent mechanisms.

Ideal for email marketers, newsletter creators, and small business owners.

Quick answer: Yes, you need a privacy policy if you use Mailchimp. Mailchimp collects subscriber emails, tracks opens and clicks, logs IP addresses, and stores audience data on your behalf. GDPR, CAN-SPAM, and Mailchimp's own Terms of Use all require you to disclose these data practices to your subscribers.
AK
Written by Anupam Kumar
Last updated: March 2026
12 min read
Reviewed for compliance
1

Why Mailchimp Users Need a Privacy Policy

Mailchimp is one of the most popular email marketing platforms, used by millions of businesses to manage subscriber lists, send campaigns, and track engagement. Every time a subscriber joins your list, Mailchimp collects personal data on your behalf. This makes you the data controller, and you are legally required to disclose what data is collected and how it is used.

Three separate requirements mandate a privacy policy for Mailchimp users:

Mailchimp's Terms of Use: Mailchimp requires all users to maintain a privacy policy that discloses the use of their platform

GDPR (EU subscribers): You must disclose the legal basis for processing, data retention, and subscriber rights

CAN-SPAM Act (US): Requires a physical address, clear unsubscribe mechanism, and honest subject lines

Did you know? Mailchimp can suspend your account if you do not have a privacy policy. Their Standard Terms of Use explicitly require compliance with applicable privacy laws, and accounts found in violation may be permanently terminated.

Can I just link to Mailchimp's privacy policy instead of writing my own?

No. Mailchimp's privacy policy covers how they handle data as a company. As the data controller, you need your own policy explaining what data you collect from subscribers, why you collect it, and how you use Mailchimp to process it. Linking to Mailchimp's policy does not fulfill your legal obligation.


2

What Mailchimp Collects From Your Subscribers

Every data point Mailchimp gathers on your behalf must be disclosed in your privacy policy.

Data TypeWhen CollectedPurpose
Subscriber emailSignupDeliver email campaigns
Name (first/last)Signup formPersonalize emails
IP addressForm submissionRecord consent proof, geolocation
Open trackingEmail opensMeasure engagement rates
Click trackingLink clicksTrack content performance
Location (approximate)Email opensGeographic segmentation
Device and browserEmail opensOptimize email rendering
Purchase historyE-commerce syncProduct recommendations, segmentation
TagsManual or automatedAudience organization
SegmentsRule-based filteringTargeted campaign delivery
Did you know? Mailchimp's open tracking works by embedding a tiny invisible image (tracking pixel) in each email. When the image loads, Mailchimp records the subscriber's IP address, approximate location, device type, and the exact time of the open. This counts as personal data collection under GDPR.

3

Mailchimp Features and Their Data Implications

Each Mailchimp feature you use creates additional privacy disclosure requirements.

FeatureData CollectedDisclosure Required
Email CampaignsOpens, clicks, bounces, unsubscribesTracking methods, data retention
AutomationsTrigger events, behavioral data, timestampsAutomated decision-making, profiling
Landing PagesForm submissions, page views, conversionsCookie usage, data collection forms
Signup FormsEmail, name, consent records, IP addressConsent mechanism, data storage
Customer JourneyMulti-step behavioral trackingProfiling, automated processing
Audience DashboardDemographics, engagement scores, predicted dataData analysis, profiling practices
Transactional EmailOrder details, shipping info, purchase dataE-commerce data processing
WebsitesPage views, visitor tracking, form dataWebsite cookies, analytics tracking

If you use Mailchimp's newsletter features, landing pages, or website builder, each feature adds distinct data collection points that require separate disclosures in your privacy policy.



5

CAN-SPAM Compliance With Mailchimp

The CAN-SPAM Act applies to all commercial emails sent to US recipients. Mailchimp helps with compliance, but your privacy policy must still document these practices.

Physical mailing address: Mailchimp requires you to add a physical address to every email. Your privacy policy should reference this address

Unsubscribe mechanism: Every Mailchimp email includes an unsubscribe link. You must honor opt-out requests within 10 business days

Accurate header information: Your 'From' name, reply-to address, and subject lines must be truthful and not misleading

Commercial content identification: If your email is primarily an advertisement, it must be clearly identified as such

Did you know? CAN-SPAM violations can result in penalties of up to $51,744 per email. Even if Mailchimp provides the unsubscribe mechanism, you as the sender are ultimately responsible for compliance. Your privacy policy is a key part of demonstrating that compliance.

6

Mailchimp's Data Processing Addendum

Mailchimp offers a Data Processing Addendum (DPA) that formalizes the relationship between you (the data controller) and Mailchimp (the data processor). This document is essential for GDPR compliance and should be referenced in your privacy policy.

Automatic inclusion: Mailchimp's DPA is automatically included in their Standard Terms of Use for all accounts

Sub-processors: The DPA lists Mailchimp's sub-processors (AWS, Google Cloud, etc.) and commits to notifying you of changes

International transfers: The DPA includes Standard Contractual Clauses (SCCs) for transferring data outside the EU/EEA

Security measures: Mailchimp commits to technical and organizational security measures including encryption, access controls, and regular audits

Your privacy policy should mention that Mailchimp processes subscriber data under a DPA and that appropriate safeguards are in place for international data transfers. For more on GDPR requirements, see our GDPR privacy policy template.


7

Intuit Acquisition: What Changed for Privacy

Intuit acquired Mailchimp in November 2021 for approximately $12 billion. This acquisition has privacy implications that Mailchimp users should address in their privacy policies.

Expanded data ecosystem: Subscriber data may now be subject to Intuit's broader privacy framework, which also covers TurboTax, QuickBooks, and Credit Karma

Updated entity name: Mailchimp is now officially 'The Rocket Science Group LLC d/b/a Mailchimp, an Intuit company.' Your policy should reference the current entity

Cross-product data sharing: Intuit's privacy statement allows data sharing across their product family for purposes like product improvement and personalization

Updated DPA: The Data Processing Addendum has been updated to reflect Intuit's corporate structure and sub-processor list

Important: If your privacy policy still references "Mailchimp" without mentioning Intuit, it may be outdated. Update your policy to reference "Intuit Mailchimp" and note that data may be processed within the Intuit corporate family.

8

Common Mistakes in Mailchimp Privacy Policies

Not disclosing email tracking

Many Mailchimp users fail to mention that open tracking and click tracking collect personal data like IP addresses and device information. This is a GDPR violation.

Missing Mailchimp as a third-party processor

Your privacy policy must name Mailchimp (Intuit) as a third-party data processor. Simply saying 'email marketing service' is insufficient under GDPR.

No mention of international data transfers

Mailchimp stores data on US servers. If you have EU subscribers, you must disclose this cross-border transfer and reference the legal mechanisms (SCCs) that authorize it.

Ignoring landing page and website data

If you use Mailchimp's landing pages or website builder, these collect additional data (cookies, page views) that require separate disclosure beyond email-related data.

Outdated entity references

Policies that reference 'The Rocket Science Group' without mentioning Intuit are outdated. After the 2021 acquisition, your policy should reflect the current corporate structure.

Wondering what happens if your privacy policy is missing or incomplete? See our guide on what happens without a privacy policy.


9

How to Write a Privacy Policy for Mailchimp

Follow these six steps to create a compliant privacy policy for your Mailchimp email marketing.

1

Audit your Mailchimp data collection

List every type of data Mailchimp collects on your behalf: subscriber emails, names, IP addresses, open tracking, click tracking, location data, and purchase history. Check your audience fields and merge tags for custom data points.

2

Document all Mailchimp features you use

Identify which features you actively use: email campaigns, automations, landing pages, signup forms, customer journeys, audience dashboard, transactional email, or websites. Each feature has different data implications.

3

Disclose tracking and analytics

Explain that Mailchimp tracks email opens, link clicks, subscriber location, device type, and engagement metrics. Specify how this data is used for campaign optimization and whether subscribers can opt out of tracking.

4

Add GDPR consent mechanisms

If you have EU subscribers, enable Mailchimp GDPR consent fields in your signup forms and document consent collection in your privacy policy. Include details on how subscribers can withdraw consent at any time.

5

Include CAN-SPAM compliance details

Document your unsubscribe process, physical mailing address, and how you honor opt-out requests within the required 10-business-day window. Reference the automatic unsubscribe links Mailchimp includes in every email.

6

Reference Mailchimp as a data processor

Name Intuit Mailchimp as a third-party data processor, link to their privacy policy, and reference the Data Processing Addendum (DPA) for legal basis. Note that data is stored on US servers with appropriate safeguards.

For a comparison with other email marketing platforms, see our guide on privacy policy for HubSpot. If you run a small business, our small business privacy policy guide covers additional requirements.


10

Frequently Asked Questions

Do I need a privacy policy if I use Mailchimp?

Yes. Mailchimp's Terms of Use require all users to have a privacy policy. Additionally, laws like GDPR and CAN-SPAM require you to disclose how you collect, use, and store subscriber data. Without a privacy policy, Mailchimp can suspend your account.

What data does Mailchimp collect from my subscribers?

Mailchimp collects subscriber email addresses, names, IP addresses at signup, email open tracking data, click tracking data, approximate location, device and browser information, purchase history (if connected), and any custom tags or segments you create.

Does Mailchimp comply with GDPR?

Mailchimp offers GDPR-compliant features including consent checkboxes for signup forms, a Data Processing Addendum (DPA), data export and deletion tools, and lawful basis tracking. However, you as the data controller are responsible for implementing these features correctly and disclosing them in your privacy policy.

How do I enable GDPR fields in Mailchimp?

In Mailchimp, go to your audience settings and enable GDPR fields. This adds consent checkboxes to your signup forms that let subscribers opt in to specific types of communication. You must document this consent mechanism in your privacy policy.

Is Mailchimp a data processor or data controller?

Mailchimp acts as a data processor on your behalf. You are the data controller responsible for determining how and why subscriber data is processed. Mailchimp provides a Data Processing Addendum (DPA) that formalizes this relationship under GDPR.

What changed after Intuit acquired Mailchimp?

After Intuit acquired Mailchimp in 2021, the privacy landscape expanded. Subscriber data may now be subject to Intuit's broader privacy practices. Your privacy policy should reference Intuit Mailchimp and note that data may be shared within the Intuit family of companies for product improvement and analytics.

Can I use Mailchimp without tracking email opens?

Yes. Mailchimp allows you to disable open tracking and click tracking for individual campaigns. However, if you keep tracking enabled (the default), you must disclose this in your privacy policy as it involves collecting personal data like IP addresses and device information.


Generate My Mailchimp Privacy Policy

Create a customized, legally compliant privacy policy that covers your Mailchimp email marketing in under 60 seconds.

Free previewOne-time paymentMailchimp-ready

Structured around widely accepted GDPR and CAN-SPAM requirements. Not legal advice.


Related Resources