Where your email list really is — seven privacy policies side by side

Ad contains ad links · · Prices checked 3 September 2026 · Next check 2 December 2026

The common assumption is that email tools are American and the list goes across the Atlantic. We read seven services’ own privacy policies on 3 September 2026, and five of seven store the list data in the EU.

When choosing an email tool, data location is either not considered at all or assumed settled in the wrong direction. The most common assumption is that the industry’s tools are American. We went through seven services’ own privacy policies on 3 September 2026 — not directories or other comparison sites’ tables — and the result is different: five of seven store the list data in the EU.

The short answer

In the EU: Brevo, GetResponse, Systeme.io, MailerLite and EmailOctopus. Outside the EU: Mailchimp and ActiveCampaign. Using either is lawful, but it requires a transfer basis and an entry in your own privacy policy.

Seven services side by side

First the same comparison table as on our other pages. The column Data in the EU is the most relevant for this page, and it comes straight from the same data as the prices — it is not written by hand on any page.

ToolFree plan500 contacts2,50010,000GDPR settingsData in the EUEnglish interface
Brevo Our pickSee prices300 emails/day€7€21€28YesYesYesTry
GetResponseSee pricesNo free plan (14-day trial)€16€27€69YesYesYesTry
Systeme.ioSee prices2,000 contacts, unlimited sending$17$17$47YesYesYesTry (ad)
MailerLiteSee prices250 subscribers, 2,500 emails/month€11€29€79YesYesYesTry
EmailOctopusSee prices2,500 subscribers, 10,000 emails/month (EmailOctopus branding in the emails)€9€16€36YesYesYesTry (ad)
MailchimpSee prices250 contacts, 500 emails/month (daily limit 250)€11.30€39.11€95.59YesNoYesTry
ActiveCampaignSee pricesNo free plan (14-day trial)€15€39€149YesPartlyYesTry

Prices exclude VAT, billed monthly unless stated otherwise.(ad) = ad link

  • The price is the monthly price of the cheapest paid plan at that list size. The Free plan column shows when you do not have to pay.
  • EmailOctopus and ActiveCampaign: the price list only shows the monthly price on annual billing. Monthly billing costs more.
  • GetResponse and ActiveCampaign: the smallest list sold is 1,000 contacts, so the 500-contact column shows that price.

What the policies say about the contracting party

The yes or no above does not tell the whole story. Below is who you contract with and where the data is according to the policy — the part a comparison table cannot condense.

ToolCompany and home countryWhat the policy says
BrevoFranceEU company, servers in the EU.
GetResponsePolandEU company, servers in the EU.
Systeme.ioITACWT Limited, IrelandData in AWS’s Irish data centre; according to the policy it is not transferred outside the EU.
MailerLiteMailerLite Limited, Ireland (EEA customers)The contracting party for EEA customers is an Irish company, data centre in the EU (ISO 27001). A separate US company for other customers.
EmailOctopusThree Hearts Digital Ltd, LondonCompany outside the EU, but the lists are in AWS’s Irish data centre inside the EEA.
MailchimpIntuit group, United StatesTransfer outside the EU; relies on the Data Privacy Framework and standard clauses.
ActiveCampaignUnited StatesIts own policy lists transfers to the United States, Australia, Ireland, Brazil and Costa Rica.

Read from the services’ own privacy policies on 3 September 2026: MailerLite, Systeme.io, EmailOctopus and ActiveCampaign. For Brevo (France), GetResponse (Poland) and Mailchimp (Intuit, United States) the information was read the same day from the services’ own policies. The check is repeated every 90 days.

The company’s home country is not the same thing as the data location

This is the most important row in the table and the one most comparisons skip. Two questions are different questions:

  • Who do you contract with? That decides which country’s company is the processor of the personal data and which country’s authorities it answers to.
  • Where are the servers? That decides whether the data physically moves outside the EU.

In our comparison these differ at two services. EmailOctopus is operated by London-based Three Hearts Digital Ltd, which since Brexit is a non-EU company — but the lists are in AWS’s Irish data centre inside the EEA. MailerLite has a dedicated Irish contracting party for EEA customers, MailerLite Limited, and a separate US company for other customers. So ask both questions, not just one.

What you have to record in your own policy

An email tool is a processor of personal data, and it is recorded in your own privacy policy. If the tool transfers data outside the EU, there is more to record — and the obligation comes straight from the regulation.

Article 13(1)(f) of the GDPR obliges you to tell the data subject three things: that you intend to transfer data to a third country, whether the Commission has adopted an adequacy decision for it, and, if the transfer rests on Article 46 safeguards, a reference to them and to where a copy is available. The original wording requires information on the transfer and “the existence or absence of an adequacy decision by the Commission”.

In practice this is a few lines. The difference between an EU provider and a non-EU one is therefore not that one is prohibited — it is that one requires an entry from you that has to be correct and up to date. The regulation’s general principle points the same way: under Article 44 any transfer to a third country “shall take place only if … the conditions laid down in this Chapter are complied with”, and the level of protection guaranteed by the regulation must not be undermined. Read 14 September 2026.

Those transferring to the United States: what the adequacy decision covers

At two of the tools we compare the data goes to the United States. For them the decisive question is whether the Commission’s adequacy decision covers that specific company — and the answer is not “yes, because the United States”.

Commission Implementing Decision (EU) 2023/1795 was adopted on 10 July 2023, and its Article 1 limits adequacy precisely: the level of protection is adequate for transfers “to organisations in the United States that are included in the ‘Data Privacy Framework List’, maintained and made publicly available by the U.S. Department of Commerce”. Adequacy therefore does not apply to the United States as a country but to the individual organisations that have joined the list.

The list is public at dataprivacyframework.gov. We do not publish individual services’ list status on this page, and the reason is methodological: the status can change in a day, and our 90-day cycle does not guarantee it is current. Check it yourself and use the company’s official name — the service may be listed under its parent company, in which case a search by product name finds nothing. If the company is not on the list, the transfer needs an Article 46 safeguard under the GDPR — in practice the Commission’s standard clauses and the assessment made to support them. Why that is so and what the standard clauses require: Schrems II and moving an email list.

When this matters in practice

Data location is not equally important to everyone, and that is worth saying plainly. Three situations where it decides:

  1. You answer customers’ data protection questions. A business customer’s procurement questionnaire asks for processors and transfers. Data stored in the EU is a one-line answer; non-EU data requires a transfer basis and its documentation.
  2. You process sensitive data or public sector data. Then your own organisation or your customer has usually set the policy in advance.
  3. You want to keep the documentation short. In a one-person business this is the weightiest reason: every entry you do not have to make is an entry you do not have to keep up to date.

If none of these applies to you, data location is one criterion among others — and not a reason to pay for a pricier tool. The whole field compared: best email marketing software.

What this page does not tell you

Three limits, so the reader knows what has been measured here and what has not.

  • We have not audited anyone. Everything above was read from the services’ own privacy policies. A policy is the company’s own statement, not third-party verification.
  • We do not cover sub-processors. Every service has its own processors, and their chain may reach elsewhere than the main data location. The services’ policies list them, and if your requirement is strict, the chain has to be gone through.
  • We do not give legal advice. We say what the sources say and where to find them. Applying them to your own situation is your job or your lawyer’s.

The method in full and what we do not assess: how we compare. Consent, demonstrating it and the processing agreement: email marketing and GDPR.

Frequently asked questions

Which email tools store data in the EU?
Five of the seven we compare. Brevo is a French company and GetResponse a Polish one. Systeme.io is operated by Irish ITACWT Limited and according to its privacy policy the data is not transferred outside the EU. MailerLite’s contracting party for EEA customers is Irish MailerLite Limited and the data centre is in the EU. EmailOctopus is a British company, but the lists are stored in AWS’s Irish data centre inside the EEA. The exceptions are Mailchimp and ActiveCampaign. Read from the services’ own privacy policies on 3 September 2026.
Is a non-EU tool prohibited?
No. A transfer outside the EU is allowed when it has a transfer basis under Chapter V of the GDPR. Article 44 sets the general principle: a transfer to a third country may take place only if the conditions of that chapter are met, and a Commission adequacy decision is the first of those bases. The difference from an EU provider is therefore in the amount of work and documentation, not in lawfulness.
What do I have to record in my own privacy policy?
If you transfer personal data outside the EU, Article 13(1)(f) of the GDPR obliges you to tell the data subject about the transfer, whether the Commission has adopted an adequacy decision, and, if the transfer rests on Article 46 safeguards, to refer to them and to where a copy is available. In practice this is a few lines in the policy — but they have to be written, and written correctly.
Is the company’s home country the same thing as the data location?
No, and this is the most important detail in the comparison. EmailOctopus is operated by London-based Three Hearts Digital Ltd, but the lists are in AWS’s Irish data centre inside the EEA: the company is outside the EU, the data is not. At MailerLite the setup is the other way round: the contracting party for EEA customers is Irish MailerLite Limited, and other customers have a separate US company. So ask both: who you contract with and where the servers are.
How often do you check the information?
On the same 90-day cycle as the prices. Data location does not change as often as price, but it changes without notice: the data centre moves, the company structure is reorganised or the policy is rewritten. That is why every fact has a reading date next to it, and if the date is old, the fact is old.
How do I know whether a US service is covered by the adequacy decision?
Commission Implementing Decision (EU) 2023/1795 limits adequacy to the organisations on the Data Privacy Framework List maintained by the US Department of Commerce. Article 1 of the decision says it directly: an adequate level of protection applies to transfers “to organisations in the United States that are included in the ‘Data Privacy Framework List’”. The list is public at dataprivacyframework.gov, and it is worth checking yourself under the company’s official name — we do not publish individual services’ status, because it can change in a day.
Does choosing an EU provider make me GDPR-compliant?
No, it only removes one entry. Consent still has to be demonstrable, a processing agreement has to be in place, the unsubscribe link has to be in every message and the right to erasure has to work. Data location is one line on the checklist, not the whole list.

Ad link

More information