GDPR-compliant mail infrastructure: what actually matters
EU servers alone are not enough. What a truly GDPR-compliant email infrastructure requires, and why most SaaS senders have gaps.
Since GDPR, email marketing has been a balancing act. Many providers advertise "EU servers". That's a start, but far from enough. What a truly clean infrastructure needs goes much further.
Beyond "EU servers"
GDPR distinguishes between data processing and data storage. Even if your data sits in the EU, a third country transfer is still on the table when the provider has a US parent company or uses subprocessors outside the EU. Schrems II made this very clear.
Concrete points we enforce technically at JD Mail:
- Bare metal servers in an Austrian data center (no cloud hyperscaler, no US transfer)
- No subprocessors outside the EU, including for CDN, monitoring or logs
- Full at rest encryption (LUKS) and in transit (TLS 1.3)
- Data processing agreement with every customer, without SCC workarounds
Bounce and click tracking: an often overlooked point
Tracking pixels and click redirects are technically IP logging. In many DPAs this is not cleanly documented. We only log what is genuinely needed for newsletter delivery:
- Bounces: yes, anonymized after 24 hours
- Opens: yes, with IP hash instead of clear IP
- Clicks: yes, no cross site profiling
Result
Instead of a "GDPR checkbox" we have an architecture where we can sleep soundly with every legal challenge. That's the real promise.