Research guide

Email newsletter privacy policy requirements

If you collect email addresses for a newsletter, your privacy policy should explain what you collect at sign-up, which email service provider sends the messages, whether opens and clicks are tracked, how people unsubscribe, and how long you keep subscriber data. Email platforms such as Mailchimp make a publicly accessible privacy notice and valid consent contractual conditions, and anti-spam laws add rules for every marketing message.

What Mailchimp's terms require

Section 21 of the Intuit Mailchimp Standard Terms of Use requires members to clearly post, maintain, and abide by a publicly accessible privacy notice that describes their use of Mailchimp and links to Intuit Mailchimp's Global Privacy Statement. Members must obtain all necessary permissions and valid consents from contacts, including consent for Mailchimp's tracking cookies and pixels where required. Other providers have comparable clauses; check your provider's terms.

Consent evidence and list sources

Mailchimp's Acceptable Use Policy states that you must be able to point to an opt-in form or show other evidence of consent for every contact, and it prohibits purchased, rented, or third-party lists. Keep records of when and where each subscriber signed up, the wording shown, and any double opt-in confirmation. The privacy policy should describe the sign-up sources, such as website forms, checkout opt-ins, or event registrations.

Rules for marketing messages in the United States

The FTC's CAN-SPAM compliance guide requires commercial email to use accurate header information and non-deceptive subject lines, identify the message as an advertisement where applicable, include your valid physical postal address, and give a clear way to opt out. Opt-out requests must be honored within 10 business days, and you cannot charge a fee or require more than an email address and a simple reply or single page visit. Each separate email in violation can bring penalties of up to 53,088 US dollars.

Consent in the EU and UK

In the EU and UK, national rules implementing the ePrivacy Directive generally require prior consent for marketing email to individuals, with narrower exceptions in some countries for existing customers who bought similar products and were given a chance to refuse. Under the GDPR, consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give. Your policy should state the legal basis for newsletters, typically consent, and for transactional emails, typically contract.

Open and click tracking

Most email platforms embed tracking pixels and rewrite links to record opens, clicks, device type, and approximate location. Disclose this engagement tracking, the purposes such as measuring newsletter performance, and any choices available, such as turning off tracking where your provider allows it. Mailchimp's terms specifically mention obtaining consent for its tracking technologies where required.

Retention, transfers, and unsubscribing

State how long subscriber data is kept after unsubscribing, for example keeping a suppression record so the address is not emailed again. Explain that the email provider may process data in other countries and the safeguard used. Describe how to unsubscribe, through the link in each email or by contacting you, and how quickly requests are processed.

Transactional versus marketing email

Order confirmations, password resets, and service notices are transactional and usually rely on contract or legitimate interests; newsletters and promotions are marketing and need consent or an opt-out depending on the law. Keep the two clearly separated in the policy and in your sending tools so an unsubscribe from marketing does not stop essential service messages.

Sign-up form checklist

Place a short notice next to the sign-up field that says what subscribers will receive, how often, who sends it, and that they can unsubscribe at any time, with a link to the privacy policy. Do not pre-tick consent boxes, and keep a separate checkbox when you combine newsletter consent with an order or account form.

Generating a newsletter-ready policy

In the questionnaire choose marketing or both for communications, name the email provider, describe the unsubscribe method, and confirm whether opens or clicks are tracked. The generator will not produce a marketing clause without an unsubscribe method. The website sample shows the resulting communications section for a fictional publisher with a newsletter.

Official sources checked for this guide

Platform rules and legislation can change. Verify the current text before publishing or making a high-risk decision.

Common questions

Do I need a privacy policy for a small newsletter?

Yes. Email providers require a publicly accessible privacy notice, and privacy laws require information at the point of collection regardless of list size.

Is double opt-in required?

It is not universally required by law, but it provides strong consent evidence and some providers and countries expect it.

Important: Generated wording reflects supplied facts and is not legal advice or a guarantee of compliance or enforceability.