GDPR Mailchimp
In an indie stack, Mailchimp is used for Marketing emails and audiences. Entity cited: The Rocket Science Group LLC d/b/a Mailchimp. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Mailchimp
Yes. Public Data Processing Addendum.
Stated role
Processor of customer data on the customer's instruction. The DPA does not apply when Mailchimp is itself the controller, except the annex specific to certain jurisdictions.
Personal data
The DPA cites, on the members' side, name, address, title, identifier, and contact details, payment, and account; on the contacts' side, name, email, address, demographic data, purchase history, marketing preferences, IP address, usage data, cookies, browser, location, and payment information.
Sub-processors of Mailchimp
Public list.
Transfers outside the EU
Hosting / location
Customer Data may be transferred and processed in the United States and anywhere Mailchimp, its affiliates, or its sub-processors operate.
EU–United States Data Privacy Framework
Intuit is registered, EU-U.S. Data Privacy Framework status: Active. The Rocket Science Group d/b/a Mailchimp is listed as a covered entity.
Cookies
Essential, performance and functionality, analytics and personalization, and advertising cookies, plus pixels and beacons in members' emails.
Typical use, written by StackLégal and not by the vendor: Marketing emails and audiences.
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Mailchimp a processor within the meaning of the GDPR?
Processor of customer data on the customer's instruction. The DPA does not apply when Mailchimp is itself the controller, except the annex specific to certain jurisdictions.
What DPA does Mailchimp publish?
Yes. Public Data Processing Addendum. https://mailchimp.com/legal/data-processing-addendum/
Which further sub-processors does Mailchimp publish?
Public list. https://mailchimp.com/legal/subprocessors/
Where does Mailchimp state that it processes data, including outside the EU?
Customer Data may be transferred and processed in the United States and anywhere Mailchimp, its affiliates, or its sub-processors operate.
Is Mailchimp registered under the EU–United States Data Privacy Framework?
Intuit is registered, EU-U.S. Data Privacy Framework status: Active. The Rocket Science Group d/b/a Mailchimp is listed as a covered entity. https://www.dataprivacyframework.gov/participant/7693
Which personal data does Mailchimp mention?
The DPA cites, on the members' side, name, address, title, identifier, and contact details, payment, and account; on the contacts' side, name, email, address, demographic data, purchase history, marketing preferences, IP address, usage data, cookies, browser, location, and payment information.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.