DPIA Information

Version: June 2026

When you use MailBlue’s services, you are the controller and MailBlue is the processor. Pursuant to Article 35 of the GDPR, it may be necessary to carry out a Data Protection Impact Assessment (DPIA) before you commence the processing. This page provides the information you need in order to carry out a DPIA in respect of the use of MailBlue’s services.

Do you have any further questions? Please contact our Privacy Officer at avg@mailblue.nl.

Processor details

MailBlue B.V.
Akkerstraat 227
4811 JL Breda, the Netherlands
Chamber of Commerce (KvK) number: 68740077

Nature and purpose of the processing

MailBlue processes personal data exclusively on the instructions of the controller. The processing takes place for the purposes of the following services:

  • email marketing and newsletters;
  • marketing automations;
  • SMS marketing;
  • WhatsApp marketing (via the official WhatsApp Business API);
  • CRM and contact management;
  • site tracking and behavioural analysis;
  • forms and landing pages;
  • transactional emails.


The personal data is processed exclusively on the basis of the controller’s instructions and not for MailBlue’s own purposes.

Categories of personal data

The following categories of personal data may be processed, depending on the configuration of your account:
Category Explanation
Identification data Name, email address
Contact details Telephone number, address details
Behavioural data Open and click behaviour in emails (where tracking is enabled)
Technical data IP address (where open tracking or link tracking is enabled)
Other data All other fields created by the controller itself within the system

By default, MailBlue does not process special categories of personal data (such as health data, biometric data or criminal-offence data) unless the controller enters such data itself. In that case, the controller is itself responsible for the lawfulness of that processing.

Categories of data subjects

  • customers of the controller;
  • prospective customers (leads);
  • marketing contacts;
  • newsletter subscribers.

Retention periods

SituationRetention period
During an active subscriptionFor the duration of the agreement
After termination of the subscriptionThe account is archived; data is deleted no later than 12 months after the expiry date
Reactivation possibleWithin 6 months of the expiry date, for a minimum period of 1 month
Statutory retention obligationWhere applicable, only for the duration of that obligation

Retention periods

SituationRetention period
During an active subscriptionFor the duration of the agreement
After termination of the subscriptionThe account is archived; data is deleted no later than 12 months after the expiry date
Reactivation possibleWithin 6 months of the expiry date, for a minimum period of 1 month
Statutory retention obligationWhere applicable, only for the duration of that obligation

Technical and organisational security measures

MailBlue is certified in accordance with ISO 27001. The following measures apply:

Technical measures

  • encryption of personal data in transit (TLS) and at rest;
  • pseudonymisation where applicable;
  • access control based on the need-to-know principle;
  • multi-factor authentication for staff;
  • continuous monitoring of systems and networks;
  • automatic back-ups and recovery facilities.

Organisational measures

  • a duty of confidentiality for all staff;
  • privacy and security training for staff;
  • an established incident response process;
  • an established data breach procedure (notification to the controller within 72 hours);
  • a record of processing activities in accordance with Article 30(2) of the GDPR.

The current ISO 27001 certificate, where applicable, and the accompanying Statement of Applicability can be requested via avg@mailblue.nl.

Sub-processors and international transfers

MailBlue uses sub-processors in the performance of its services. A current and complete list of all sub-processors engaged, including their place of establishment and the nature of the processing, is available at mailblue.nl/legal/sub-verwerkers/.

Transfers outside the EEA – To the extent that personal data is transferred to parties outside the European Economic Area (EEA), this takes place exclusively on the basis of one of the following lawful transfer mechanisms:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission;
  • the EU-US Data Privacy Framework (DPF), to the extent that the receiving party is certified under it;
  • an adequacy decision of the European Commission in respect of the recipient’s country.


The primary sub-processor for email marketing is ActiveCampaign (established in the US, DPF-certified). Depending on the data centre location, personal data is stored in the US or within the EU.

Sub-processors and international transfers

Access to personal data is limited to:

  • MailBlue staff who require access for the performance of the services;
  • authorised staff of sub-processors, solely to the extent necessary;
  • MailBlue uses an ‘impersonate’ feature for technical support; this is limited to resolving the specific issue for which access has been requested.

Sub-processors and international transfers

MailBlue supports the controller in handling requests from data subjects under the GDPR (access, rectification, erasure, restriction, data portability). MailBlue provides the required information within 5 business days of receipt of a request.

Requests may be submitted via avg@mailblue.nl.

Risk assessment for use in your DPIA

The following elements are relevant to the risk assessment in your DPIA:

Risk factor

MailBlue’s assessment

Large-scale processing

Possible, depending on usage

Special categories of personal data

Not by default; depends on how the controller configures its account

Profiling or automated decision-making

Possible via lead scoring and automations; the controller is itself responsible

Transfers outside the EEA

Yes, see “Sub-processors and international transfers”; appropriate safeguards are in place

Access by third parties

Limited to sub-processors bound by contractual obligations

Data breach risk

Addressed by ISO 27001, the incident response process and the data breach procedure

Contact

For additional information for the purposes of your DPIA, such as technical documentation, the Statement of Applicability or specific questions about the processing, please contact:

Privacy Officer, MailBlue B.V.
avg@mailblue.nl