Mailchimp and Data Protection in Switzerland 2026: Is Mailchimp revDSG Compliant? The 9-Point Checklist for SMEs
Mailchimp stores data in the United States. Can a Swiss SME still use it? What the revDSG, the Unfair Competition Act and the Swiss-U.S. Data Privacy Framework require, which consent a newsletter needs, and the 9 settings that make a Mailchimp account compliant.
Mailchimp belongs to Intuit, its servers are in the United States, and thousands of Swiss SMEs still use it for their newsletter. That is permitted, provided nine points are in place. Most of them are account settings that take an hour. The rest are texts written once: the privacy policy, the sign-up form, the deletion process. This article walks through the legal questions in the order they come up in our Mailchimp training and ends with the checklist.
Two clarifications first. One: this is a guide from implementation practice, not legal advice. Anyone processing health data, financial data or data about minors talks to a lawyer. Two: the legal basis is the revised Federal Act on Data Protection (revDSG), in force since 1 September 2023, and the Unfair Competition Act (UWG), which has regulated since 2007 who may receive marketing emails.
Is Mailchimp allowed in Switzerland? The short answer
Yes. No Swiss law prohibits a provider with servers in the United States. The revDSG requires that personal data only leaves the country where adequate protection exists or where contractual guarantees ensure the recipient treats it as Swiss law demands. Both can be established for Mailchimp. What the law does not allow is the typical state of many accounts: imported addresses without consent, default tracking without notice, a privacy policy that does not mention Mailchimp, and no process for when someone wants their data deleted.
Where does Mailchimp store the data, and what does the revDSG say?
Mailchimp stores contacts, campaigns and activity data on servers in the United States; there is no choice of server location. Every import is therefore a cross-border transfer under Article 16 of the Data Protection Act. The Federal Council keeps a list of countries with adequate data protection. The United States has been on it since 15 September 2024, but only for companies certified under the Swiss-U.S. Data Privacy Framework (DPF).
For you that means: check the entry for Intuit Inc. on the DPF list at dataprivacyframework.gov and record the date of the check. Should the certification lapse or a court strike down the agreement, as happened in 2020 with its predecessor Privacy Shield, the second safeguard applies: the standard contractual clauses in Mailchimp's Data Processing Addendum. Both together are what a supervisory authority expects today.
Which consent does a newsletter need in Switzerland?
The Unfair Competition Act is stricter here than many assume. Article 3 paragraph 1 letter o requires three things for mass advertising by email: the recipient's prior consent, correct sender information, and a free, straightforward unsubscribe option in every email. The only exception is the customer exception: anyone who obtained the address in the course of a sale may advertise their own similar products, as long as every email offers an unsubscribe.
In practice: contacts from business cards, trade fair lists, LinkedIn exports or purchased databases must not go into a Mailchimp campaign. Existing customers may, with an unsubscribe link. Everyone else needs documented consent, and documented means double opt-in. The law does not require the second click, but anyone who cannot prove in a dispute that the person behind the address agreed will lose. Mailchimp writes the time, source and IP address of the confirmation into the contact profile; that entry is the proof.
What must the privacy policy say about Mailchimp?
Article 19 of the Data Protection Act obliges you to inform people about the collection of personal data, and paragraph 4 explicitly requires you to name the country the data goes to and the guarantees that secure the transfer. A privacy policy that does not mention Mailchimp is therefore not just incomplete; it breaches a specific duty. The section needs five statements: that you use Mailchimp by Intuit Inc. to send the newsletter; that the data is stored in the United States; on what basis the transfer takes place (DPF certification and standard contractual clauses); which data Mailchimp receives (email address, name, sign-up time, IP address, open and click behaviour if tracking is on); and how to unsubscribe and request deletion.
The 9-point checklist: setting up Mailchimp in line with the revDSG
The points are ordered by where they sit in the account, not by importance. One person can complete the first five in an afternoon; the remaining four need some text once and one decision by management.
1. Enable double opt-in in the audience settings
Under "Audience", "Settings", "Audience name and defaults", tick "Enable double opt-in". Mailchimp then sends a confirmation email and only creates the contact as "Subscribed" after the click. The confirmation email can be translated under "Signup forms", "Form builder"; no Swiss SME should send the English default version.
2. Consent wording and a link to the privacy policy in the form
The sign-up form needs one sentence saying what the person will receive and how often, plus a link to the privacy policy. A pre-ticked box is not consent. Under "Form builder", Mailchimp offers "GDPR fields" that work just as well for Switzerland; the advantage is that consent then appears as an attribute in the contact profile and can be segmented.
3. Review existing contacts: customer, consent, or out
Every imported address falls into one of three categories: customer with a purchase relationship (stays, tagged "Customer"), person with documented consent (stays, tagged "Opt-in" with date), or neither (is not emailed). There is no trick for the third group. A "please confirm your subscription" email to addresses without consent is itself a marketing email without consent.
4. Sender with name and postal address in the footer
Mailchimp automatically inserts the address from the account settings into the footer of every campaign; it has to be correct and current. Add a sender name that identifies the company; first-name-only senders do not belong on company emails. The Unfair Competition Act requires correct sender information, and recipients report unknown senders as spam faster.
5. Set open and click tracking deliberately
Mailchimp enables open and click tracking by default for every campaign. Both are permitted if the privacy policy says so, and both have been of limited value since Apple's Mail Privacy Protection. Decide once: tracking on and disclosed in the policy, or tracking off. What does not work is tracking on and nothing said. Also check the Google Analytics link under "Campaign settings", which appends additional parameters to links.
6. Download and file the Data Processing Addendum
Mailchimp provides the Data Processing Addendum among its legal documents; according to Mailchimp it applies automatically as part of the terms of use. Download the current version and file it with your data protection documentation, together with a screenshot of Intuit's DPF entry and the date. If a customer or the Federal Data Protection Commissioner asks, this is the first question.
7. Add the Mailchimp section to the privacy policy
The five statements from the section above, in plain language, without copy-pasting from German GDPR generators that cite articles which do not apply in Switzerland. Anyone revising the policy anyway should add the details on website forms and on any Mailchimp landing pages, which set their own cookies.
8. Define the deletion process: who, how, within what period
Article 32 of the Data Protection Act gives everyone the right to request deletion of their data. In Mailchimp that means "Permanently delete" in the contact profile; "Archive" and "Unsubscribe" leave the data in the account. Decide who handles such requests, that it happens within 30 days, and that the person receives a short confirmation. One sentence in the playbook is enough; what matters is that someone is responsible.
9. Record and responsibility: write it down once
A record of processing activities is only mandatory under the revDSG from 250 employees, or for high-risk processing. One page with points one to eight, the name of the responsible person and the date of the last review is still worthwhile: it is the answer to every enquiry, and it is the document the next person takes over when responsibility changes.
Does a Swiss SME have to move from Mailchimp to an EU provider?
No, not for data protection reasons, as long as the nine points are in place. Providers with servers in the EU or Switzerland simplify the transfer point, because the EU is on the Federal Council's list and no DPF check is needed. They change nothing about consent, privacy policy, tracking and deletion, which is seven of the nine points. A switch is worthwhile for three other reasons: if you process sensitive data, for instance in a medical practice; if your customers in a regulated environment contractually require a Swiss server location; or if Mailchimp's prices from a few thousand contacts upwards clearly exceed the alternatives. Anyone who switches takes the consent evidence along: Mailchimp exports sign-up time, source and IP address per contact.
How are deliverability and data protection connected?
More closely than it seems. Since February 2024, Google and Yahoo have required bulk senders to have an authenticated domain with SPF, DKIM and DMARC, one-click unsubscribe, and a complaint rate below 0.3 percent. Mailchimp sets one-click unsubscribe automatically; domain authentication has to be set up once under "Website", "Domains", which means three DNS records at your hosting provider. The complaint rate is the data protection point: it rises precisely when people receive emails they never agreed to. An account that takes the consent rule seriously has good deliverability almost automatically. An account with imported trade fair lists lands in spam long before any supervisory authority hears of it.
Conclusion
Mailchimp is not a data protection problem for Swiss SMEs; a badly configured Mailchimp account is. The nine points take an afternoon when someone knows them. In our Mailchimp training we go through them in the team's account, together with audience, domain and sign-up form, and build the first automation on that clean foundation. Anyone implementing the points alone will find the settings where named; anyone unsure whether an address list meets the customer exception asks before, not after. How the same rules carry over to ChatGPT and other AI tools is covered in AI and data protection in Switzerland.
Frequently asked questions
- Is Mailchimp GDPR compliant, and does that also apply to Switzerland?
- Mailchimp provides the building blocks for GDPR- and revDSG-compliant operation: a data processing addendum with standard contractual clauses, double opt-in, consent fields in forms, export and deletion of contacts. The account only becomes compliant through the company's own settings and processes. For Switzerland, the Unfair Competition Act (UWG) adds a requirement of prior consent for marketing emails, plus the review of the data transfer to the United States under Article 16 of the Data Protection Act.
- Do I need a data processing agreement for Mailchimp?
- Yes. Mailchimp processes personal data on your behalf, so Article 9 of the Data Protection Act requires a contract. Mailchimp provides a Data Processing Addendum which, according to Mailchimp, forms part of its standard terms and includes standard contractual clauses for the data transfer. Download it and file it with your records; if anyone asks, you have to be able to show it exists.
- Can I import existing customers into Mailchimp without consent?
- For the plain import as a contact, yes; for marketing emails only under the customer exception of the Unfair Competition Act: the address came from a purchase, you advertise your own similar products, and every email offers a free unsubscribe. Anyone who imports and emails contacts from business cards, trade fairs or purchased lists is in breach of Article 3 paragraph 1 letter o UWG.
- Do I have to enable double opt-in in Mailchimp?
- It is not required by law, but the burden of proving consent lies with you. Double opt-in is the only practical evidence that the person behind the address actually agreed. Mailchimp stores the time, IP address and source of the confirmation in the contact profile.
- How do I delete a contact from Mailchimp completely?
- Via 'Permanently delete' in the contact profile, not via 'Archive' or 'Unsubscribe'. Archived contacts remain in the account with all their data, and so do unsubscribed ones. Only permanent deletion removes the profile and activity data. The email address then stays on a suppression list so it cannot be re-imported, which is exactly what an unsubscribe should achieve.
- Can a medical or physiotherapy practice use Mailchimp?
- For appointment reminders and general practice news, yes, under the same conditions as any other company. It becomes delicate as soon as health data can be read from segments or content, such as a segment called 'back patients'. Health data is sensitive personal data, and disclosing it to third parties abroad requires express consent. Practices should segment by interest rather than diagnosis, or keep such content out of Mailchimp altogether.
