

Campaign Monitor
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document explanations for automated decisions, which can generate uncertainties for contractors.
- •In Basic Privacy: it clearly identifies sub-processors, increasing transparency in privacy practices.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Campaign Monitor
- •does not provide explanations for automated decisions that impact users, which can generate uncertainties.
- •omits information about data retention of AI interactions, compromising privacy.
- •it is necessary to demand contractual clauses that address these aspects.
Automated AI decisions have no explanation available
The policy mentions the need for transparency, but does not provide explanations for automated decisions that impact users.
AI data retention (prompts and responses) is not disclosed
The policy does not mention how data from AI interactions is retained, which may impact user privacy.
Use of data for AI training is not disclosed
The policy does not clarify whether email campaign data is used to train AI models, which can generate uncertainties for clients.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Campaign Monitor
- •clearly defines its roles as data controller and processor, ensuring compliance with GDPR.
- •lists sub-processors involved in detail, increasing transparency.
- •these practices facilitate due diligence and client trust.
Use of artificial intelligence clearly disclosed in policies
The policy explicitly states the use of AI in functionalities, increasing transparency about how email campaign data is processed.
AI features clearly identified with their purposes
The policy mentions functionalities that use AI, helping clients understand how these tools can benefit their email campaigns.
AI training opt-out control available
The policy mentions the ability to withdraw consent for data processing, although it does not specify opt-out for AI training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data retention period not stated in the policy
The policy does not specify retention periods for email campaign data, which can generate uncertainties for clients.
Data controller and processor roles clearly defined
The policy clearly defines Campaign Monitor as the data controller and processor for email campaign data, ensuring compliance with GDPR.
Personal data recipients clearly identified in the policy
The policy lists in detail the sub-processors involved in sending email campaigns, increasing transparency for clients.
Source: vendor public documents
Critical Alerts
- •Retenção de prompts e respostas de IA sem prazo definido: Importante para a conformidade com as expectativas de retenção de dados de campanhas de email..
- •Uso de dados para treinamento de IA não é declarado: Crucial para a transparência e confiança no uso de dados de campanhas de email.
Conformance analysis (20)
Clearly defined data controller and processor roles
Reference: ISO/IEC 27701 (7.3)
Recipients of personal data clearly identified in the policy
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Enhancing Your Email Marketing with Campaign Monitor: Privacy Insights
Clear Roles in Data Management
Campaign Monitor excels in defining its roles as both a data controller and a data processor. This clarity is crucial for users who want to understand how their data is being handled. With a privacy score of 58%, the platform ensures that users are informed about who is responsible for their personal data. This transparency helps in building trust, as users can easily identify who to contact regarding their data rights. Additionally, the clear identification of data recipients in the privacy policy further enhances user confidence, ensuring that they know exactly who has access to their information.
Transparency in Sub-Processors
Another strength of Campaign Monitor is its clear identification of sub-processors involved in data handling. This aspect is vital for users, especially in light of regulations like the GDPR and LGPD, which emphasize the importance of knowing where and how personal data is processed. By providing detailed information about sub-processors, Campaign Monitor allows users to make informed decisions about their data privacy, ensuring compliance with international standards such as ISO 27701. This level of transparency is a significant advantage for businesses looking to maintain robust privacy practices.
Lack of Explanation for Automated Decisions
Despite its strengths, Campaign Monitor has notable weaknesses, particularly concerning automated decision-making. The platform does not document explanations for automated decisions made by its AI systems. This lack of transparency can lead to uncertainties for users, especially those concerned about how their data might be used in automated processes. With an IA score of just 25%, this is a significant area of concern. Users should be aware that without clear explanations, they may not fully understand how their data is influencing automated outcomes.
Undefined Data Retention Policies
Another critical weakness is the undefined retention period for prompts and responses generated by AI. This ambiguity raises questions about how long user data is stored and used, which can conflict with GDPR and LGPD requirements for data minimization and purpose limitation. Users should take proactive measures by regularly reviewing their data usage settings within Campaign Monitor and considering limiting the use of AI features that may retain data longer than necessary.
Mitigating Risks with Practical Settings
To mitigate the risks associated with the weaknesses mentioned, users should take practical steps. First, review the settings related to data retention and AI usage within the platform. If possible, disable features that retain data indefinitely or that do not provide clear explanations for automated decisions. Additionally, consider reaching out to Campaign Monitor’s support team for clarification on their data handling practices, particularly regarding AI training data. This proactive approach can help users safeguard their privacy while using the platform.
Exploring Alternatives for Enhanced Privacy
For users who find the weaknesses in Campaign Monitor concerning, it may be worth exploring alternative email marketing platforms that offer stronger privacy protections. Look for platforms that provide clear documentation on automated decision-making processes and have well-defined data retention policies. Additionally, consider platforms that prioritize user consent and transparency, ensuring compliance with privacy regulations like GDPR and LGPD. By carefully evaluating your options, you can choose a solution that aligns better with your privacy expectations while still meeting your email marketing needs.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Campaign Monitor:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents