What does Mailchimp do to comply with the GDPR?
- Appointed a Data Protection Officer (DPO) to oversee our compliance program.
- Continuously review our security measures to ensure any personal data we collect and process on our systems is adequately protected.
- Ensure our Privacy Policy clearly explains Mailchimp's commitment to the GDPR, is transparent about how we use personal data, and gives individuals information about how they can exercise their data subject rights.
- Incorporate the EU's Standard Contractual Clauses in our Data Processing Addendum which automatically forms part of our Standard Terms of Use (our contract with you) and applies to customer data protected by EU laws.
- Provide our customers with GDPR-ready terms in our Data Processing Addendum and update our contracts with third party vendors to ensure they are GDPR-compliant.
- Maintain formal processes around data subject rights to ensure we can help customers fulfill requests they receive.
- Respond to and fulfill data subject rights requests in our role as a controller.
- Complete Data Protection Impact Assessments to identify and minimize any risks from our processing activities.
- Maintain accurate records of our processing activities, both as a processor and controller of personal data.
- Pay close attention to regulatory guidance around GDPR compliance and making changes to our product features and contracts when they're needed.
- Certify annually with the EU-U.S./Swiss-U.S. Privacy Shield Frameworks and continue to protect EEA, UK, and Swiss data in compliance with the Privacy Shield Principles. You can view our Privacy Shield certification here.