Your email system is one of the most exposed services for GDPR compliance — yet it's often the most neglected during audits. Here is a complete checklist to ensure your professional email setup is fully compliant in 2026.
Part 1: Hosting and Data Location
- ☐ Identify your email provider and its nationality
- ☐ Verify server location: are they in Europe/Switzerland?
- ☐ Is your provider subject to the CLOUD Act? (Any US company → yes)
- ☐ Is there a signed DPA (Data Processing Agreement) with your provider?
- ☐ Is the provider ISO 27001 certified?
| Provider | Data location | CLOUD Act | DPA | GDPR score |
|---|---|---|---|---|
| Infomaniak | Switzerland | No | Yes | 5/5 |
| OVH | France/EU | No | Yes | 4/5 |
| Google Gmail | USA | Yes | Partial | 2/5 |
| Microsoft Exchange | EU option | Yes | Partial | 2.5/5 |
Part 2: Encryption and Security
- ☐ TLS enabled in transit: are all your emails encrypted in transit?
- ☐ SPF records configured on your domain
- ☐ DKIM records configured on your domain
- ☐ DMARC policy defined (at minimum p=quarantine)
- ☐ S/MIME or PGP for highly sensitive communications
Part 3: Access and Authentication
- ☐ 2FA (two-factor authentication) enabled on all mailboxes
- ☐ Strong password policy (12+ characters, complexity)
- ☐ Immediate access revocation when employees leave
- ☐ Regular access audits: who has access to which mailboxes?
- ☐ No generic access (contact@, info@ — know who can read these)
Part 4: Retention and Archiving
- ☐ Defined retention policy: how long do you keep emails?
- ☐ Legal duration respected: commercial emails must be kept 5+ years in most EU countries
- ☐ Automatic deletion after the retention period
- ☐ Encrypted backup of email archives
Part 5: Email Marketing and Newsletters
- ☐ Explicit opt-in for all subscribers (no pre-ticked boxes)
- ☐ Proof of consent stored (date, source, wording)
- ☐ Working unsubscribe link in every email
- ☐ Unsubscribes processed within 48 hours
- ☐ GDPR-compliant newsletter provider (Infomaniak Newsletter, Brevo)
Priority Actions Based on Your Score
If you use Gmail or Outlook/Exchange
Priority action: evaluate a migration to Infomaniak. It's the only action that definitively removes your CLOUD Act exposure.
If you already use a European host
Focus on: 2FA, DMARC (p=reject), retention policy, and newsletter consent.
Ready to migrate to Infomaniak?
Contact us for a free 15-minute audit. We will analyze your situation and provide you with a personalized quote.
Request a free audit