Where your email list really is — seven privacy policies side by side
The common assumption is that email tools are American and the list goes across the Atlantic. We read seven services’ own privacy policies on 3 September 2026, and five of seven store the list data in the EU.
When choosing an email tool, data location is either not considered at all or assumed settled in the wrong direction. The most common assumption is that the industry’s tools are American. We went through seven services’ own privacy policies on 3 September 2026 — not directories or other comparison sites’ tables — and the result is different: five of seven store the list data in the EU.
The short answer
In the EU: Brevo, GetResponse, Systeme.io, MailerLite and EmailOctopus. Outside the EU: Mailchimp and ActiveCampaign. Using either is lawful, but it requires a transfer basis and an entry in your own privacy policy.
Seven services side by side
First the same comparison table as on our other pages. The column Data in the EU is the most relevant for this page, and it comes straight from the same data as the prices — it is not written by hand on any page.
| Tool | Free plan | 500 contacts | 2,500 | 10,000 | GDPR settings | Data in the EU | English interface | |
|---|---|---|---|---|---|---|---|---|
| Brevo Our pickSee prices | 300 emails/day | €7 | €21 | €28 | Yes | Yes | Yes | Try |
| GetResponseSee prices | No free plan (14-day trial) | €16 | €27 | €69 | Yes | Yes | Yes | Try |
| Systeme.ioSee prices | 2,000 contacts, unlimited sending | $17 | $17 | $47 | Yes | Yes | Yes | Try (ad) |
| MailerLiteSee prices | 250 subscribers, 2,500 emails/month | €11 | €29 | €79 | Yes | Yes | Yes | Try |
| EmailOctopusSee prices | 2,500 subscribers, 10,000 emails/month (EmailOctopus branding in the emails) | €9 | €16 | €36 | Yes | Yes | Yes | Try (ad) |
| MailchimpSee prices | 250 contacts, 500 emails/month (daily limit 250) | €11.30 | €39.11 | €95.59 | Yes | No | Yes | Try |
| ActiveCampaignSee prices | No free plan (14-day trial) | €15 | €39 | €149 | Yes | Partly | Yes | Try |
← scroll →
Prices exclude VAT, billed monthly unless stated otherwise.(ad) = ad link
- The price is the monthly price of the cheapest paid plan at that list size. The Free plan column shows when you do not have to pay.
- EmailOctopus and ActiveCampaign: the price list only shows the monthly price on annual billing. Monthly billing costs more.
- GetResponse and ActiveCampaign: the smallest list sold is 1,000 contacts, so the 500-contact column shows that price.
What the policies say about the contracting party
The yes or no above does not tell the whole story. Below is who you contract with and where the data is according to the policy — the part a comparison table cannot condense.
| Tool | Company and home country | What the policy says |
|---|---|---|
| Brevo | France | EU company, servers in the EU. |
| GetResponse | Poland | EU company, servers in the EU. |
| Systeme.io | ITACWT Limited, Ireland | Data in AWS’s Irish data centre; according to the policy it is not transferred outside the EU. |
| MailerLite | MailerLite Limited, Ireland (EEA customers) | The contracting party for EEA customers is an Irish company, data centre in the EU (ISO 27001). A separate US company for other customers. |
| EmailOctopus | Three Hearts Digital Ltd, London | Company outside the EU, but the lists are in AWS’s Irish data centre inside the EEA. |
| Mailchimp | Intuit group, United States | Transfer outside the EU; relies on the Data Privacy Framework and standard clauses. |
| ActiveCampaign | United States | Its own policy lists transfers to the United States, Australia, Ireland, Brazil and Costa Rica. |
← scroll →
Read from the services’ own privacy policies on 3 September 2026: MailerLite, Systeme.io, EmailOctopus and ActiveCampaign. For Brevo (France), GetResponse (Poland) and Mailchimp (Intuit, United States) the information was read the same day from the services’ own policies. The check is repeated every 90 days.
The company’s home country is not the same thing as the data location
This is the most important row in the table and the one most comparisons skip. Two questions are different questions:
- Who do you contract with? That decides which country’s company is the processor of the personal data and which country’s authorities it answers to.
- Where are the servers? That decides whether the data physically moves outside the EU.
In our comparison these differ at two services. EmailOctopus is operated by London-based Three Hearts Digital Ltd, which since Brexit is a non-EU company — but the lists are in AWS’s Irish data centre inside the EEA. MailerLite has a dedicated Irish contracting party for EEA customers, MailerLite Limited, and a separate US company for other customers. So ask both questions, not just one.
What you have to record in your own policy
An email tool is a processor of personal data, and it is recorded in your own privacy policy. If the tool transfers data outside the EU, there is more to record — and the obligation comes straight from the regulation.
Article 13(1)(f) of the GDPR obliges you to tell the data subject three things: that you intend to transfer data to a third country, whether the Commission has adopted an adequacy decision for it, and, if the transfer rests on Article 46 safeguards, a reference to them and to where a copy is available. The original wording requires information on the transfer and “the existence or absence of an adequacy decision by the Commission”.
In practice this is a few lines. The difference between an EU provider and a non-EU one is therefore not that one is prohibited — it is that one requires an entry from you that has to be correct and up to date. The regulation’s general principle points the same way: under Article 44 any transfer to a third country “shall take place only if … the conditions laid down in this Chapter are complied with”, and the level of protection guaranteed by the regulation must not be undermined. Read 14 September 2026.
Those transferring to the United States: what the adequacy decision covers
At two of the tools we compare the data goes to the United States. For them the decisive question is whether the Commission’s adequacy decision covers that specific company — and the answer is not “yes, because the United States”.
Commission Implementing Decision (EU) 2023/1795 was adopted on 10 July 2023, and its Article 1 limits adequacy precisely: the level of protection is adequate for transfers “to organisations in the United States that are included in the ‘Data Privacy Framework List’, maintained and made publicly available by the U.S. Department of Commerce”. Adequacy therefore does not apply to the United States as a country but to the individual organisations that have joined the list.
The list is public at dataprivacyframework.gov. We do not publish individual services’ list status on this page, and the reason is methodological: the status can change in a day, and our 90-day cycle does not guarantee it is current. Check it yourself and use the company’s official name — the service may be listed under its parent company, in which case a search by product name finds nothing. If the company is not on the list, the transfer needs an Article 46 safeguard under the GDPR — in practice the Commission’s standard clauses and the assessment made to support them. Why that is so and what the standard clauses require: Schrems II and moving an email list.
When this matters in practice
Data location is not equally important to everyone, and that is worth saying plainly. Three situations where it decides:
- You answer customers’ data protection questions. A business customer’s procurement questionnaire asks for processors and transfers. Data stored in the EU is a one-line answer; non-EU data requires a transfer basis and its documentation.
- You process sensitive data or public sector data. Then your own organisation or your customer has usually set the policy in advance.
- You want to keep the documentation short. In a one-person business this is the weightiest reason: every entry you do not have to make is an entry you do not have to keep up to date.
If none of these applies to you, data location is one criterion among others — and not a reason to pay for a pricier tool. The whole field compared: best email marketing software.
What this page does not tell you
Three limits, so the reader knows what has been measured here and what has not.
- We have not audited anyone. Everything above was read from the services’ own privacy policies. A policy is the company’s own statement, not third-party verification.
- We do not cover sub-processors. Every service has its own processors, and their chain may reach elsewhere than the main data location. The services’ policies list them, and if your requirement is strict, the chain has to be gone through.
- We do not give legal advice. We say what the sources say and where to find them. Applying them to your own situation is your job or your lawyer’s.
The method in full and what we do not assess: how we compare. Consent, demonstrating it and the processing agreement: email marketing and GDPR.