EU-Hosted, GDPR-First Newsletter Plugins for European Businesses

WordPress newsletter plugins compared on subscriber data residency, processors and consent records

For a European business, the newsletter question is not which plugin has the best composer. It is where the subscriber list physically sits, which companies touch it on the way to an inbox, and whether you can answer both questions in a procurement document without hedging.

Self-hosting changes the answer fundamentally. A plugin storing subscribers in your own database on an EU server, sending through an EU relay, involves two parties you have chosen. A hosted platform involves that platform, its infrastructure provider and whoever it subcontracts to. This article follows the data hop by hop and compares the plugins on residency rather than on features.

Verified August 2026. This is general information about software, not legal advice. Your data protection obligations depend on your circumstances and your own advisers.


Where the list actually lives

There are two architectures, and they produce very different answers to the same question.

Self-hosted. Subscribers live in your WordPress database, on your server, in whatever country you chose when you picked a host. The plugin vendor never sees the list. Your processor list for the newsletter is short: your host, and whichever service transmits the email.

Platform-hosted. Subscribers live with the provider. That provider has its own infrastructure suppliers, its own subprocessors and its own data locations, which may or may not be where its marketing pages imply. It also means your list is a copy on somebody else’s system, which is exactly the thing an erasure request has to reach.

Self-hosting does not make anything automatically compliant. It reduces the number of parties involved and moves control to you, which makes the obligations easier to satisfy and easier to document. It also means the responsibility for security, backups and retention is yours rather than somebody else’s, and a subscriber table sitting on a poorly secured server is not a better outcome than a well-run platform.

The second hop is the one people forget. Even with a self-hosted list, the emails themselves must travel through something. A sending relay sees every recipient address and every message, which makes it a processor, and its location matters as much as your database’s.


The 6 options compared

1. FluentCRM

The strongest self-hosted option for an organisation that needs both records and control. $103, $199 and $399 a year, per site, unlimited contacts.

Contacts, tags, activity histories and campaign records all sit in your own database, which means a subject access request is answerable from your own admin rather than by asking a vendor to export something. The per-contact activity history is genuinely useful here: it is also the record that proves when somebody subscribed and through which form, which is what a consent enquiry actually needs. Because pricing is per site rather than per contact, retaining detailed records does not cost you money, which removes a perverse incentive present in per-subscriber platforms. You still choose and document a sending relay, and that choice is where your data leaves the country if it leaves at all.

  • List location: Your database
  • Consent records: Strong, per contact
  • Best for: Organisations needing documented records
  • Watch out for: Sending relay is a separate decision

2. MailPoet

The convenient option, with a caveat that matters for this specific question. Free to 500 subscribers and 5,000 emails a month, Business plans from around $10 a month.

Subscribers are stored in your WordPress database, which is the answer you want. But the convenience of the product comes largely from its bundled sending service, and using that service means your recipient addresses pass through the vendor’s infrastructure rather than a relay you selected. That is not disqualifying; it is a processor you need to identify and document. The alternative is to configure your own sending credentials, which keeps the friendly interface while putting the transmission hop back under your control. For an EU business that route is usually the right one, and it is worth knowing that the option exists before you assume the product is unsuitable.

  • List location: Your database
  • Consent records: Yes, with double opt-in
  • Best for: Small sites configuring their own relay
  • Watch out for: Bundled sending adds a processor

3. The Newsletter Plugin

The minimal-dependency choice: free, no subscriber cap, and no vendor service involved at any point.

Because there is no bundled sending and no vendor account, the plugin is genuinely just software running on your server. Your processor list is your host and your relay, and nothing else. For an organisation that has to document every party touching personal data, that brevity is worth more than a nicer interface. Double opt-in and unsubscribe handling are present, and the subscriber record includes the timestamp and source you need for a consent enquiry. The costs are the familiar ones: a dated admin, limited automation, and more of the configuration burden landing on you. Choose it when minimising third parties is the actual requirement.

  • List location: Your database
  • Consent records: Yes, with timestamps
  • Best for: Minimising the number of processors
  • Watch out for: More configuration falls to you

4. Mailster

The self-hosted option for large lists, sold as a one-time licence, with the sending engineering to match.

An organisation with tens of thousands of subscribers has a technical problem alongside the compliance one, and this is the plugin that solves it: proper queueing, batching, retry logic and automatic bounce handling. That last item is quietly relevant here, because removing dead addresses promptly is both a deliverability practice and a data minimisation one. Storage is entirely in your database and there is no vendor service in the path. As with everything self-hosted, your relay choice determines whether transmission stays inside your preferred jurisdiction, and that decision deserves as much attention as the plugin choice itself.

  • List location: Your database
  • Consent records: Yes
  • Best for: Large self-hosted lists
  • Watch out for: Technical product; assumes competence

5. An EU-based sending relay

Not a newsletter plugin, and the component that decides the answer to the second half of the question.

Several established European providers offer transactional and bulk sending with EU data centres and processing terms written for European customers. Pairing any self-hosted plugin above with one of these produces the architecture most EU businesses actually want: list in your own database in the EU, transmission through an EU processor, no third jurisdiction involved. The large cloud sending services also offer European regions, and using one is a legitimate choice provided you select the region deliberately and document the arrangement rather than accepting a default. Whichever you pick, confirm where the service stores logs and bounce data, because those contain recipient addresses too and are frequently overlooked.

  • List location: Not applicable; transmits only
  • Consent records: Not applicable
  • Best for: Keeping the sending hop inside the EU
  • Watch out for: Log and bounce data locations

6. An EU-hosted email platform

The comparison point, and a perfectly reasonable answer for organisations without technical staff.

Established European email platforms hold your list on EU infrastructure, provide processing agreements written for European customers, and take responsibility for security, deliverability and availability. For an organisation with no developer, handing those obligations to a specialist is frequently the more defensible choice, not the weaker one: a well-run platform is safer than a subscriber table on a neglected server. What you accept is that your list is a copy on somebody else’s system, that pricing scales with its size, and that erasure requests have to reach them as well as you. Judge this against your own capacity rather than against an abstract preference for self-hosting.

  • List location: Provider infrastructure, EU regions
  • Consent records: Yes, maintained by them
  • Best for: Organisations without technical staff
  • Watch out for: Cost scales with list size

Comparison table

OptionCostList storageVendor sees listProcessors involved
FluentCRM$103/yrYour databaseNoHost plus relay
MailPoetFrom $10/moYour databaseIf bundled sending usedHost, relay, maybe vendor
The Newsletter PluginFreeYour databaseNoHost plus relay
MailsterOne-timeYour databaseNoHost plus relay
EU sending relayPer emailTransmits onlySees recipientsOne
EU email platformPer subscriberTheir infrastructureYesPlatform plus theirs

Consent, retention and erasure in practice

Architecture is half the job. These are the operational parts, and they are where audits actually find problems.

  • Use double opt-in and keep the record. The confirmation click, with a timestamp, is the strongest evidence that somebody asked to hear from you. Store when they subscribed, from which form, and when they confirmed.
  • Never pre-tick the box. Consent has to be an affirmative action, and a pre-selected checkbox is not one. This is among the most common findings in enforcement decisions and the easiest to avoid.
  • Separate newsletter consent from everything else. Somebody buying a product or booking an appointment has not agreed to marketing. Ask separately, and record the answer separately.
  • Make unsubscribing one click and honour it immediately. Keep a record of the unsubscribe too, because proving you stopped is as important as proving you were allowed to start.
  • Set a retention rule and enforce it. Subscriber tables grow forever by default. Decide how long an inactive subscriber is kept, then actually delete them. This improves deliverability as well.
  • Be able to export and erase one person. A subject access request means producing everything you hold about somebody, and an erasure request means removing it from your database, your backups policy and your relay logs. Work out how before you receive one.

The self-hosted architecture makes the last point noticeably easier, because everything is in one database you control. It also makes it entirely your responsibility, with nobody to ask. That trade is the real substance of this decision.


Frequently asked questions

Does self-hosting make me compliant?

No. It reduces the number of parties involved and gives you control, which makes obligations easier to meet and document. Consent, retention and erasure are still your work.

Does my sending service see subscriber data?

Yes, every recipient address and message passes through it, which makes it a processor. Choose its region deliberately and check where it stores logs and bounce data.

Is double opt-in legally required?

Requirements vary by country, but it produces the clearest evidence of consent and is standard practice across the EU. The confirmation timestamp is what you would rely on.

How long can I keep an inactive subscriber?

Keeping data no longer than necessary is the principle; the number is yours to justify. Set a rule, enforce it, and note that pruning improves deliverability too.

Can I use a large cloud sending service?

Yes, selecting a European region deliberately and documenting the arrangement. The point is choosing and recording it rather than accepting whatever default appears.

Which plugin makes erasure requests easiest?

Any self-hosted one, because everything is in a database you control. FluentCRM is strongest for producing a full record of what you hold about one person.


The verdict

The architecture most EU businesses want is a self-hosted list plus an EU sending relay. Two processors, both chosen by you, both documentable in a sentence.

For organisations needing records: FluentCRM at $103 a year, whose per-contact activity history answers a consent enquiry from your own admin, priced per site so keeping records costs nothing extra.

To minimise third parties entirely: The Newsletter Plugin, free and uncapped, with no vendor service anywhere in the path.

And if you have no technical staff, an EU-hosted platform is the more defensible choice. A well-run platform beats a subscriber table on a neglected server, and choosing honestly between the two is worth more than a preference for self-hosting on principle.