Email Marketing · Security & Compliance

Email Marketing Security & Compliance Guide

Your email tool holds your most valuable and most regulated asset: your subscribers' personal data. This is the plain-English guide to keeping it safe and legal — what the badges actually mean, what to verify before you sign, the consent rules that catch senders out, and which of the email platforms we rank document each protection. The one column most buyers skip — HIPAA — is the one we lead with.

Reviewed by · Updated June 2026· How we vet

The criterion buyers skip — until a regulator asks

Email tools get chosen on templates, automation and price. Security and compliance feels pre-solved — every vendor's homepage says "GDPR-ready" — so people move on. That is the mistake. An ESP holds your entire list, and the cost of a mishandled consent record, an unhonoured deletion request, or a healthcare brand sending patient data through a tool that never signed a BAA dwarfs years of subscription savings. Security and compliance is one of the five weighted criteria in our methodology; this guide is where we make it visible for email.

Hold one idea above all: compliance is shared. The vendor gives you a certified platform, EU hosting and a DPA; you own lawful consent, prompt unsubscribes and your authentication records. So the job is two parts — verify what the vendor genuinely provides, then configure your side. We take each in turn, defining every term, and we put the HIPAA question first because it is the one that quietly turns a routine campaign into a federal violation.

The badges, in plain English

What to verify before you buy

SOC 2
An outside audit of their security controls

SOC 2 is a US audit report in which an independent firm checks that the security practices a vendor claims are real and working. Ask for the Type II report — it covers a span of months, not one inspection day, so it is far harder to stage. For a tool that holds your entire subscriber list, the inability to produce one under NDA is a warning.

ISO 27001
An international security-management certificate

ISO 27001 shows the vendor runs a formal, audited system for managing information security — policies, risk reviews, staff training. Where SOC 2 is the American reference point, ISO 27001 is the international one. Most of the email platforms we rank now hold it; its absence on a tool storing personal data is a genuine concern.

GDPR & the DPA
The contract for handling subscriber data

GDPR applies the moment you email anyone in the EU or UK — and most US senders do without thinking about it. The practical artefact to obtain is a DPA, the Data Processing Agreement where the vendor commits to process subscriber data lawfully, host it in the right region and help with access and deletion requests. Confirm EU-region hosting if your list is European; Brevo and MailerLite host in the EU by default.

HIPAA & the BAA
The line most ESPs will not cross

HIPAA is the US healthcare law covering PHI — data that identifies a patient and relates to their health. To send it, you need the vendor to sign a BAA, a Business Associate Agreement sharing legal responsibility. This is the sharpest divide in email compliance: nearly every mainstream ESP refuses. Only ActiveCampaign (Enterprise) and Constant Contact (its own BAA, with limits) offer one among the tools we rank. Never assume — confirm in writing for your exact plan.

SPF / DKIM / DMARC
Authentication that is now mandatory

These three DNS records prove your email genuinely comes from your domain and tell inboxes how to treat forgeries. Since Gmail and Yahoo tightened bulk-sender rules in 2024, authenticated sending is required, not optional — it is simultaneously a security control against brand spoofing and a deliverability gate. Every platform here supports it; getting the records right is your side of the job.

How our ranked platforms document it

The compliance matrix

Here is where each of the eight platforms in our email marketing ranking stands on the four contracts and certificates that matter, verified as of June 2026. Read the HIPAA column first: a tick means a BAA is available, a tilde means only on a specific edition or with stated limits, and a dash means no BAA — so it cannot lawfully hold patient health data. The story it tells is stark: only two of eight will touch PHI at all. Editions and policies change; always confirm the current position in writing for your exact plan.

Email platform SOC 2 ISO 27001 GDPR / DPA HIPAA BAA
ActiveCampaign
Klaviyo
Mailchimp
Brevo
GetResponse
Constant Contact
MailerLite
Kit (ConvertKit)

✓ available  ·  ∼ edition-specific, limited, or not publicly documented  ·  — not offered. Verified June 2026 from vendor documentation; confirm the current position for your exact plan before relying on it.

Your side of the line

The four configuration jobs the vendor cannot do for you

Capture and prove consent. GDPR needs a freely given, specific opt-in you can evidence — timestamp, source, and what the person agreed to. Use confirmed opt-in where you can and never import a purchased or scraped list; that is the most common way a compliant ESP becomes a non-compliant programme.

Honour unsubscribes and deletion fast. Every ranked tool automates unsubscribe suppression; your duty is not to undo it — no re-importing cleaned contacts — and to action data-subject deletion requests promptly. A re-mailed unsubscribe is both a CAN-SPAM and a trust failure.

Set up authentication. Add SPF, DKIM and DMARC for your sending domain. The ESP supports it; the DNS records are yours to configure, and since 2024 bulk senders without them land in spam or get rejected outright.

Keep PHI out unless you hold a BAA. If you are in healthcare and your platform is not ActiveCampaign Enterprise or Constant Contact under its BAA, then names tied to a condition, appointment reminders, or even a segment called "diabetes patients" do not belong in it. When in doubt, see our medical-practice ranking for the narrower field that will sign.

Common questions
Which email marketing platforms are HIPAA compliant?

Very few — and this is the single most important thing to verify. Of the eight email tools we rank, only ActiveCampaign will sign a Business Associate Agreement (BAA), and only on its Enterprise plan; Constant Contact will sign its own BAA but bars highly sensitive PHI such as mental-health, substance-abuse or HIV information. Mailchimp, Klaviyo, Brevo, GetResponse, MailerLite and Kit (ConvertKit) do not offer a BAA, which means it is a federal violation to send patient-identifiable data through them — no matter how the patient opted in. If you are a healthcare brand, the BAA is the first question, not the last.

What is the difference between SOC 2, ISO 27001 and GDPR?

They answer different questions. SOC 2 is a US audit report where an outside firm verifies the security controls a vendor claims are actually working — ask for the Type II version, which covers months, not a single day. ISO 27001 is an international certificate that the vendor runs a formal information-security management system. GDPR is the EU/UK data-protection law; the thing to obtain is a DPA, the Data Processing Agreement in which the vendor commits to handle your subscribers' data lawfully. The strongest ESPs hold SOC 2 and ISO 27001 and offer a DPA. Missing all three is a red flag for a tool holding your entire list.

Does using a GDPR-compliant email tool make me GDPR compliant?

No, and this is the costly misunderstanding. Compliance is shared. The vendor provides the certified platform, EU-region hosting and a DPA; you are responsible for lawful consent — how you collect opt-ins, prove them, honour unsubscribes promptly, and delete data on request. A perfectly GDPR-ready ESP loaded with a purchased list you have no consent for is still a GDPR breach. The platform is necessary, not sufficient.

What email authentication do I need — SPF, DKIM, DMARC?

All three, and they are now effectively mandatory. SPF and DKIM prove your messages genuinely come from your domain; DMARC tells inboxes what to do with fakes and gives you reporting. Since 2024, Gmail and Yahoo require authenticated mail from bulk senders, so this is both a security control against spoofing of your brand and a deliverability requirement. Every ESP we rank supports authenticated sending domains — the work is setting the DNS records correctly on your side.

Get the email marketing shortlist

One email when the rankings move. The shortlist, the tradeoffs, the compliance changes. No filler.