How-To

Is Hotjar, Mailchimp, or HubSpot GDPR Compliant? What You Must Configure

·10 min read

Quick answer: Most popular SaaS tools — Hotjar, Mailchimp, HubSpot, Intercom, Zendesk — process personal data and require GDPR compliance measures. Whether they're "GDPR compliant" depends on how you configure them, not just whether the vendor claims compliance. Here's what you need to check for each tool.

Why "GDPR Compliant" Doesn't Mean What You Think

When a SaaS vendor says they're "GDPR compliant," they mean their platform supports GDPR compliance — not that using their tool automatically makes you compliant. Under GDPR,you are the data controller. The vendor is your data processor. You're responsible for:

  • Having a valid Data Processing Agreement (DPA) with every vendor
  • Getting user consent before the tool loads (if it sets cookies or tracks behavior)
  • Disclosing the tool in your privacy policy
  • Ensuring cross-border data transfers have adequate safeguards
  • Responding to data subject requests (access, deletion) across all vendors

Tool-by-Tool GDPR Compliance Guide

Hotjar — Session Recording & Heatmaps

AspectStatusAction Required
DPA available?YesSign it in Settings > Account > DPA
Data locationEU (AWS Ireland) by defaultVerify in account settings
Cookie consent needed?Yes — sets tracking cookiesLoad Hotjar only AFTER consent
Records personal data?Yes — IP, session recordings, form inputsEnable IP anonymization, suppress sensitive fields
Consent Mode support?Yes (v2 compatible)Configure via Consent Mode V2

Key risk: Hotjar session recordings can capture personal data typed into forms(names, emails, passwords). You MUST enable the "Suppress all text" option or manually tag sensitive elements with data-hj-suppress.

Mailchimp — Email Marketing

AspectStatusAction Required
DPA available?Yes (Standard Contractual Clauses included)Accepted automatically in ToS since 2021
Data locationUS (Intuit servers)SCCs cover EU→US transfers under new DPF
Cookie consent needed?Yes — embedded forms set cookiesUse custom forms or load after consent
Double opt-in?Supported but not defaultEnable double opt-in for EU lists
Data deletion?Supports GDPR delete requestsProcess via Mailchimp API or manually

Key risk: Mailchimp transfers data to the US. While now covered by the EU-US Data Privacy Framework, some DPAs still scrutinize US transfers. Always have SCCs in place as a fallback. See our cross-border transfers guide.

HubSpot — CRM & Marketing Automation

AspectStatusAction Required
DPA available?YesSign in Settings > Account Defaults > Security
Data locationUS, EU (Germany), or Australia — you chooseSelect EU datacenter for EU customers
Cookie consent needed?Yes — HubSpot tracking code sets cookiesUse HubSpot's cookie banner or your CMP
Consent tracking?Built-in consent managementEnable GDPR features in Settings > Privacy
Data portability?Full export availableAvailable via Settings > Import/Export

Key risk: HubSpot's tracking code loads before consent by default. You must configure it to respect your consent banner — either through HubSpot's built-in cookie policy tool or by conditionally loading the script via yourCMP.

Intercom — Live Chat & Support

AspectStatusAction Required
DPA available?YesRequest via Intercom support or legal portal
Data locationUS and EU (you can request EU hosting)Request EU-only hosting for EU users
Cookie consent needed?Yes — sets session and identity cookiesLoad Intercom widget only after consent
AI features?Fin AI agent processes conversation dataDisclose AI use in privacy policy per EU AI Act
Data deletion?Supported via API and dashboardAutomate with DSAR workflow

Key risk: Intercom's AI features (Fin) process user conversations, which may trigger EU AI Act transparency obligations. You must disclose AI-powered support in your privacy policy and provide a way for users to reach a human agent.

Zendesk — Customer Support

AspectStatusAction Required
DPA available?Yes (comprehensive)Included in Enterprise agreement; request for other tiers
Data locationUS, EU, Australia, JapanEnable EU data locality for EU customers
Cookie consent needed?Yes — widget sets cookiesLoad Web Widget conditionally
Sub-processors?Published list at zendesk.com/trustReview and monitor for changes
EncryptionIn-transit and at-restEnable Advanced Encryption for sensitive data

Complete GDPR Compliance Checklist for SaaS Tools

  1. Sign a DPA with every vendor that processes personal data
  2. Don't load tracking scripts before consent — use your CMP to conditionally load them
  3. List every tool in your privacy policy with purpose, data processed, and legal basis
  4. Choose EU data centers when available (HubSpot, Zendesk, Intercom all offer this)
  5. Enable data anonymization features (IP anonymization in Hotjar, GA4)
  6. Map your data flows — know exactly where each vendor sends your users' data
  7. Test with PrivacyChecker — scan your site to detect which third-party scripts load, when they set cookies, and whether they fire before consent
  8. Audit regularly — vendors change sub-processors and data practices. Set quarterly reviews

Frequently Asked Questions

Do I need consent to use Hotjar?

Yes. Hotjar sets tracking cookies and records user behavior, which constitutes personal data processing under GDPR. You must obtain consent before loading the Hotjar script.

Is Mailchimp legal to use in Europe?

Yes, provided you have SCCs or rely on the EU-US Data Privacy Framework for transfers. Enable double opt-in for EU subscribers, and always use Mailchimp's GDPR-compliant signup forms.

How do I check which SaaS tools my website loads?

Use PrivacyChecker to scan your website. It detects all third-party scripts, cookies, and trackers — including tools you may have forgotten about. You might be surprised by how many services load on your pages.

Check your website now — free

Run a complete privacy audit in under 60 seconds. Get your score, find issues, and learn how to fix them.

Start Free Audit