The agreement prohibits Members from importing or uploading Social Security numbers, passwords, security credentials, or other sensitive personal information regulated by applicable law into any Mailchimp account, audience, email, or server.
This analysis describes what Mailchimp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a data hygiene obligation for all Members using list import or audience upload features, requiring that sensitive personal data categories be excluded from any data transferred to Mailchimp's infrastructure.
Interpretive note: The phrase 'sensitive personal information regulated by applicable law' is not exhaustively defined and its scope varies by jurisdiction, creating interpretive variability for Members operating across multiple legal regimes.
Under this clause, Members are prohibited from incorporating Social Security numbers, passwords, security credentials, or regulated sensitive personal information into Mailchimp accounts or uploads. The agreement does not specify a defined enforcement mechanism for violations of this specific prohibition beyond the general suspension and termination authority.
Cross-platform context
See how other platforms handle Prohibition on Uploading Sensitive Personal Information and similar clauses.
Compare across platforms →"Import or incorporate any of the following information into any account, audience, emails, or otherwise upload to our servers: Social Security numbers, passwords, security credentials, or sensitive personal information regulated by applicable law.Excerpt from Mailchimp's Acceptable Use Policy
(1) REGULATORY LANDSCAPE: This provision engages GDPR, CCPA, and U.S.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision creates a data hygiene obligation for all Members using list import or audience upload features, requiring that sensitive personal data categories be excluded from any data transferred to Mailchimp's infrastructure.
Under this clause, Members are prohibited from incorporating Social Security numbers, passwords, security credentials, or regulated sensitive personal information into Mailchimp accounts or uploads. The agreement does not specify a defined enforcement mechanism for violations of this specific prohibition beyond the general suspension and termination authority.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mailchimp.