Skip to main content
Campaign Monitor logo

Campaign Monitor

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026

D-
AITS IA

AI Trust Summary

AI Training
Not disclosed in documentation
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
D-
BasePrivacy
C+
  • In AI: it does not document explanations for automated decisions, which can generate uncertainties for contractors.
  • In Basic Privacy: it clearly identifies sub-processors, increasing transparency in privacy practices.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • Campaign Monitor
  • does not provide explanations for automated decisions that impact users, which can generate uncertainties.
  • omits information about data retention of AI interactions, compromising privacy.
  • it is necessary to demand contractual clauses that address these aspects.

Automated AI decisions have no explanation available

The policy mentions the need for transparency, but does not provide explanations for automated decisions that impact users.

AI data retention (prompts and responses) is not disclosed

The policy does not mention how data from AI interactions is retained, which may impact user privacy.

Use of data for AI training is not disclosed

The policy does not clarify whether email campaign data is used to train AI models, which can generate uncertainties for clients.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Campaign Monitor
  • clearly defines its roles as data controller and processor, ensuring compliance with GDPR.
  • lists sub-processors involved in detail, increasing transparency.
  • these practices facilitate due diligence and client trust.

Use of artificial intelligence clearly disclosed in policies

The policy explicitly states the use of AI in functionalities, increasing transparency about how email campaign data is processed.

AI features clearly identified with their purposes

The policy mentions functionalities that use AI, helping clients understand how these tools can benefit their email campaigns.

AI training opt-out control available

The policy mentions the ability to withdraw consent for data processing, although it does not specify opt-out for AI training.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data retention period not stated in the policy

The policy does not specify retention periods for email campaign data, which can generate uncertainties for clients.

Data controller and processor roles clearly defined

The policy clearly defines Campaign Monitor as the data controller and processor for email campaign data, ensuring compliance with GDPR.

Personal data recipients clearly identified in the policy

The policy lists in detail the sub-processors involved in sending email campaigns, increasing transparency for clients.

Source: vendor public documents

Critical Alerts

  • Retenção de prompts e respostas de IA sem prazo definido: Importante para a conformidade com as expectativas de retenção de dados de campanhas de email..
  • Uso de dados para treinamento de IA não é declarado: Crucial para a transparência e confiança no uso de dados de campanhas de email.

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Clearly defined data controller and processor roles

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 14
Compliant

Recipients of personal data clearly identified in the policy

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Enhancing Your Email Marketing with Campaign Monitor: Privacy Insights

Clear Roles in Data Management

Campaign Monitor excels in defining its roles as both a data controller and a data processor. This clarity is crucial for users who want to understand how their data is being handled. With a privacy score of 58%, the platform ensures that users are informed about who is responsible for their personal data. This transparency helps in building trust, as users can easily identify who to contact regarding their data rights. Additionally, the clear identification of data recipients in the privacy policy further enhances user confidence, ensuring that they know exactly who has access to their information.

Transparency in Sub-Processors

Another strength of Campaign Monitor is its clear identification of sub-processors involved in data handling. This aspect is vital for users, especially in light of regulations like the GDPR and LGPD, which emphasize the importance of knowing where and how personal data is processed. By providing detailed information about sub-processors, Campaign Monitor allows users to make informed decisions about their data privacy, ensuring compliance with international standards such as ISO 27701. This level of transparency is a significant advantage for businesses looking to maintain robust privacy practices.

Lack of Explanation for Automated Decisions

Despite its strengths, Campaign Monitor has notable weaknesses, particularly concerning automated decision-making. The platform does not document explanations for automated decisions made by its AI systems. This lack of transparency can lead to uncertainties for users, especially those concerned about how their data might be used in automated processes. With an IA score of just 25%, this is a significant area of concern. Users should be aware that without clear explanations, they may not fully understand how their data is influencing automated outcomes.

Undefined Data Retention Policies

Another critical weakness is the undefined retention period for prompts and responses generated by AI. This ambiguity raises questions about how long user data is stored and used, which can conflict with GDPR and LGPD requirements for data minimization and purpose limitation. Users should take proactive measures by regularly reviewing their data usage settings within Campaign Monitor and considering limiting the use of AI features that may retain data longer than necessary.

Mitigating Risks with Practical Settings

To mitigate the risks associated with the weaknesses mentioned, users should take practical steps. First, review the settings related to data retention and AI usage within the platform. If possible, disable features that retain data indefinitely or that do not provide clear explanations for automated decisions. Additionally, consider reaching out to Campaign Monitor’s support team for clarification on their data handling practices, particularly regarding AI training data. This proactive approach can help users safeguard their privacy while using the platform.

Exploring Alternatives for Enhanced Privacy

For users who find the weaknesses in Campaign Monitor concerning, it may be worth exploring alternative email marketing platforms that offer stronger privacy protections. Look for platforms that provide clear documentation on automated decision-making processes and have well-defined data retention policies. Additionally, consider platforms that prioritize user consent and transparency, ensuring compliance with privacy regulations like GDPR and LGPD. By carefully evaluating your options, you can choose a solution that aligns better with your privacy expectations while still meeting your email marketing needs.

Other Email Marketing software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents