Article · June 17, 2026
Mailchimp and PDPL Email Marketing: What to Do?
Mailchimp stores email in the US—do opt-in and open tracking trigger PDPL duties? See a practical checklist for businesses.
Quick answer
What does PDPL mean for Mailchimp email marketing?
Mailchimp doesn’t automatically “have a problem” under the PDPL, but how you use it can create legal obligations. When you import email lists, tag behavior, track email opens, or transfer data to servers in the US, your business is processing personal data and must comply with current regulations.
Under the Personal Data Protection Law (Law 91/2025/QH15), expected to take effect from 01/01/2026 and to replace Decree 13/2023/ND-CP. The enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and Prevention of High-Tech Crime (A05).
The key for marketing and engineering teams is: don’t just ask “can we use Mailchimp,” ask “what data is being sent, who can access it, where is it stored, how long is it kept, and where is the proof of consent.”
What should you watch for under the PDPL when Mailchimp stores email in the US?
Yes. When email lists, names, company information, or open/click behavior are stored on infrastructure outside Vietnam, you are processing data involving cross-border transfer under the rules. This typically entails risk assessments, vendor management, and preparing appropriate documentation/safeguards.
In practice for SMEs, common risks include:
- Importing legacy customer lists into Mailchimp without knowing whether the original consent source was sufficiently clear.
- Enabling tracking to measure open rates without transparent information in the privacy notice.
- Allowing agencies or overseas staff to access the audience list without access controls.
- Using automations to pull data from the CRM into Mailchimp without mapping the processing purpose.
If you’re unsure whether your data falls into sensitive categories, or whether cross-border transfer is involved, review with counsel before wider rollout.
| Item | Common risk | What to do | |
|---|---|---|---|
| Storing email in the US | Data outside Vietnam, harder to control access | Review vendor, access controls, retention period | |
| Importing legacy lists | No clear evidence of consent | Keep opt-in logs, collection source, timestamp | |
| Email open tracking | Recipients not fully informed | Update the privacy notice/cookie notice if web tracking is used | |
| Sharing with an agency | Customer data exposure | Sign a data processing agreement, limit access rights |
How should opt-in be understood for email marketing under the PDPL?
Opt-in should be understood as the recipient having been fully informed and having explicitly agreed to receive marketing emails. Under the PDPL, businesses should keep evidence of the time, collection source, notice content, and how the user confirmed.
A practical pattern should include:
- An unticked checkbox.
- Language clearly stating they will receive marketing emails.
- A link to the privacy policy.
- Logs of time, IP, form source, campaign source.
- A working unsubscribe mechanism that doesn’t burden users.
If you use “purchased data,” scraped lists, or imports from sources that cannot prove consent, that is a major risk area. Under the rules, send only when you have a legal basis and supporting documentation.
Identify the data source:
specify whether the email came from a signup form, order, event, or internal CRM; avoid “mixed lists.”
Standardize the opt-in language:
use a separate checkbox for marketing, separate from purchase terms; do not pre-tick.
Keep proof of consent:
store timestamp, form content, source page, user ID, and unsubscribed status if applicable.
Attach transparent policies:
specify the email provider, where data is stored, the purpose of sending emails, and how to withdraw consent.
Check automations:
ensure workflows do not automatically add users to newsletters if they have not agreed.
Set up deletion and filtering:
periodically remove bounces, unsubscribes, and data with no remaining processing purpose.
Is tracking email opens in Mailchimp an issue under the PDPL?
It can trigger obligations, because open tracking typically uses a pixel or behavioral measurement to know who opened, when, and on which device. This data helps optimize campaigns but is also personal behavioral data if it can be linked to a specific recipient.
Businesses should do three things:
- Clearly disclose it in the privacy policy or the notice accompanying the form.
- Enable tracking only with a clear purpose—avoid turning it on by default for all campaigns if unnecessary.
- Separate internal reporting from identifiable data where possible, e.g., keep only aggregate stats.
Note: do not outright label trackers as “illegal.” The issue is whether you have provided notice, have a legal basis, control the data, and can account for it under the rules.
What should you do if email data leaks from Mailchimp?
If you discover exposure of an email list, a mistaken audience, or unauthorized access, your business must respond quickly. Under the rules, a data breach notification must be made within 72 hours of discovery.
Contain the incident:
lock down access, change passwords, pause suspicious integrations.
Determine scope:
who is affected, what data was exposed, when, and from which source.
Preserve evidence:
export logs, screenshots, activity history, webhooks, API keys.
Notify within 72 hours:
prepare content per the rules and prioritize timely submission.
Remediate and monitor:
revoke tokens, reset integrations, review consent and retention processes.
Quick checklist for marketing and dev teams
You can use this checklist before moving Mailchimp to production:
- Have a privacy notice that states data is sent to a US provider.
- Have a separate opt-in checkbox for marketing.
- Have consent logs and unsubscribe logs.
- Have role-based access for staff/agencies.
- Have a process for handling access/erasure requests.
- Have an incident response and breach notification process within 72 hours.
- Reassess trackers if you use open/click tracking for measurement.
If you need to deploy a cookie banner, store consent evidence, or set up a DSAR workflow for landing pages, consent.vn can help standardize this for easier operations.
- Three key points are valid consent, where data is stored (e.g., the US), and clearly disclosed open/click tracking.
- Only if you can prove the data source and the legal basis for sending marketing under the rules; lists with unclear sources are a major risk.
- It usually requires transparent notice and a specific processing purpose; review with counsel if you use deep tracking.
- Under the rules, data breach notification must be within 72 hours of discovery.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP; A05 — thuvienphapluat.vn, bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?