GDPR Email Audit: Complete Checklist 2026 | InfoSwitch

Back to blog Compliance

GDPR Email Audit: Complete Checklist 2026

The InfoSwitch Team 27 juillet 2026 11 min read

Your email system is one of the most exposed services for GDPR compliance — yet it's often the most neglected during audits. Here is a complete checklist to ensure your professional email setup is fully compliant in 2026.

Part 1: Hosting and Data Location

  • Identify your email provider and its nationality
  • Verify server location: are they in Europe/Switzerland?
  • Is your provider subject to the CLOUD Act? (Any US company → yes)
  • Is there a signed DPA (Data Processing Agreement) with your provider?
  • Is the provider ISO 27001 certified?
Provider Data location CLOUD Act DPA GDPR score
Infomaniak Switzerland No Yes 5/5
OVH France/EU No Yes 4/5
Google Gmail USA Yes Partial 2/5
Microsoft Exchange EU option Yes Partial 2.5/5

Part 2: Encryption and Security

  • TLS enabled in transit: are all your emails encrypted in transit?
  • SPF records configured on your domain
  • DKIM records configured on your domain
  • DMARC policy defined (at minimum p=quarantine)
  • S/MIME or PGP for highly sensitive communications

Part 3: Access and Authentication

  • 2FA (two-factor authentication) enabled on all mailboxes
  • Strong password policy (12+ characters, complexity)
  • Immediate access revocation when employees leave
  • Regular access audits: who has access to which mailboxes?
  • No generic access (contact@, info@ — know who can read these)

Part 4: Retention and Archiving

  • Defined retention policy: how long do you keep emails?
  • Legal duration respected: commercial emails must be kept 5+ years in most EU countries
  • Automatic deletion after the retention period
  • Encrypted backup of email archives

Part 5: Email Marketing and Newsletters

  • Explicit opt-in for all subscribers (no pre-ticked boxes)
  • Proof of consent stored (date, source, wording)
  • Working unsubscribe link in every email
  • Unsubscribes processed within 48 hours
  • GDPR-compliant newsletter provider (Infomaniak Newsletter, Brevo)

Priority Actions Based on Your Score

If you use Gmail or Outlook/Exchange

Priority action: evaluate a migration to Infomaniak. It's the only action that definitively removes your CLOUD Act exposure.

If you already use a European host

Focus on: 2FA, DMARC (p=reject), retention policy, and newsletter consent.

Migrate to GDPR-Compliant Email

Ready to migrate to Infomaniak?

Contact us for a free 15-minute audit. We will analyze your situation and provide you with a personalized quote.

Request a free audit
Share this article:

Also read