CAN-SPAM, GDPR, & CASL
Why Legal Compliance Matters for Deliverability
Email compliance laws exist to protect recipients from unwanted, deceptive, or fraudulent email. While these laws don’t directly control inbox placement (mailbox providers make their own filtering decisions), compliance intersects with deliverability in critical ways:
- Non-compliant sending practices generate complaints. Sending without consent, hiding unsubscribe links, or misrepresenting content triggers spam reports — the most damaging signal for deliverability.
- ESPs enforce compliance. Most email service providers require senders to comply with applicable laws as a condition of service. Violations can result in account termination.
- Compliance best practices align with deliverability best practices. Clear consent, easy unsubscribe, honest content, and proper sender identification are both legally required and operationally beneficial.
- Financial penalties are significant. CAN-SPAM fines can reach $51,744 per email. GDPR fines can reach 4% of global revenue or €20 million. CASL fines can reach $10 million CAD per violation.
CAN-SPAM Act (United States)
Overview
The Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM), enacted in 2003, is the primary US federal law governing commercial email. It applies to any commercial email sent to or from a US address.
Key distinction: CAN-SPAM uses an opt-out model. It does not require prior consent to send commercial email. Instead, it requires that recipients can opt out, and that senders honor opt-out requests.
Requirements
1. No false or misleading header information The From, To, Reply-To, and routing information must accurately identify the person or business that initiated the message. You cannot use a deceptive From name or address.
2. No deceptive subject lines The subject line must not mislead the recipient about the content of the message. Clickbait subjects that misrepresent the email body are a violation.
3. Identify the message as an advertisement Commercial messages must include a clear indication that the message is an advertisement or solicitation. There is flexibility in how this is disclosed (no specific format is mandated), but it must be conspicuous.
4. Include your physical postal address Every commercial email must include a valid physical postal address. This can be a street address, a PO box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency.
5. Provide a clear opt-out mechanism Every commercial email must include a clear, conspicuous way to opt out of future messages. The opt-out mechanism must:
- Be easy to find and understand
- Not require the recipient to pay, provide information beyond the email address, or take multiple steps
- Be functional for at least 30 days after the message is sent
6. Honor opt-out requests within 10 business days Once a recipient opts out, you must stop sending commercial email to that address within 10 business days. You cannot sell or transfer the address to another entity for continued mailing.
7. Monitor third-party compliance If you hire another company to handle your email marketing, both parties are responsible for compliance. You cannot outsource legal responsibility.
What CAN-SPAM Does NOT Require
- Prior consent: You can legally send the first email without opt-in under CAN-SPAM
- Double opt-in: Not required by US law (but strongly recommended for deliverability)
- Specific unsubscribe format: The law allows flexibility in implementation
Transactional vs. Commercial
CAN-SPAM primarily applies to commercial messages — messages whose primary purpose is promoting a product, service, or business. Transactional messages (order confirmations, shipping updates, account alerts) are largely exempt from CAN-SPAM requirements (though they still cannot contain false or misleading headers).
The distinction matters because hybrid messages (commercial content within a transactional email) may be classified as commercial if the commercial purpose is the primary one.
GDPR (European Union)
Overview
The General Data Protection Regulation (GDPR), effective since May 2018, is the EU’s comprehensive data protection law. It does not specifically target email, but it fundamentally affects email marketing because email addresses are personal data.
Key distinction: GDPR uses a consent-first model. Processing personal data (including sending marketing email) requires a legal basis, and for marketing email, that basis is almost always explicit consent.
Key Principles Affecting Email
1. Lawful basis for processing To send marketing email to EU residents, you need a lawful basis. The two most common are:
- Consent: The individual has given specific, informed, unambiguous consent to receive marketing email. This is the most common and safest basis.
- Legitimate interest: You believe the individual would reasonably expect the communication based on an existing relationship. This is more restrictive and requires a documented assessment.
2. Consent requirements GDPR consent must be:
- Freely given: Not bundled with other terms or conditions
- Specific: Consent to receive email marketing from this specific entity
- Informed: The individual knows what they’re consenting to
- Unambiguous: A clear affirmative action (opt-in checkbox, not a pre-checked box)
- Documented: You must be able to prove when and how consent was given
- Revocable: The individual can withdraw consent at any time, as easily as they gave it
3. Right to erasure (Right to be forgotten) Individuals can request deletion of all their personal data, including their email address. You must comply within 30 days and remove them from all systems, including suppression lists (which creates a compliance conflict with CAN-SPAM’s requirement to maintain suppression lists).
4. Data portability Individuals have the right to receive their data in a machine-readable format and transfer it to another controller.
5. Data protection by design Systems handling email addresses must be designed with privacy in mind — encryption, access controls, minimal data collection, and retention limits.
Practical Email Marketing Under GDPR
- Use double opt-in. It’s the clearest evidence of consent.
- Record consent evidence. Store when, where, and how each subscriber consented.
- Separate consent requests. Don’t bundle marketing consent with terms of service.
- Make unsubscribe as easy as subscribe. One-click opt-out is best practice.
- Process DSARs (Data Subject Access Requests) promptly. Have a system to find and export all data associated with an email address.
- Handle erasure requests carefully. You need a process that removes the email from all marketing lists while documenting that the person existed (for compliance records) without retaining their personal data.
Territorial Scope
GDPR applies to:
- Organizations established in the EU, regardless of where data is processed
- Organizations outside the EU that offer goods or services to EU residents
- Organizations outside the EU that monitor the behavior of EU residents
If you have any EU subscribers, GDPR likely applies to you.
CASL (Canada)
Overview
Canada’s Anti-Spam Legislation (CASL), effective since 2014, is one of the strictest email marketing laws in the world. It uses an opt-in model with explicit consent requirements.
Key Requirements
1. Express consent or implied consent
Express consent: The recipient explicitly agreed to receive commercial electronic messages (CEMs) from you. This requires:
- A clear opt-in action
- Identification of who is seeking consent
- Description of what messages will be sent
- Statement that consent can be withdrawn
Implied consent: Exists in limited circumstances:
- Existing business relationship (purchase, contract, inquiry within the last 2 years)
- Existing non-business relationship (membership, donation within the last 2 years)
- Published email address without “no unsolicited email” notice (very narrow exception)
Implied consent expires after 2 years. Express consent does not expire (but must be revocable).
2. Identification requirements Every CEM must include:
- The sender’s name (or the person on whose behalf the message is sent)
- Mailing address and at least one of: phone number, email address, or web address
- Contact information must be valid for at least 60 days after the message is sent
3. Unsubscribe mechanism Every CEM must include a functional unsubscribe mechanism that:
- Is easy to use
- Doesn’t require the recipient to provide information beyond identification
- Must be processed within 10 business days
4. Record-keeping Senders must maintain records of consent, including when and how it was obtained.
CASL Penalties
CASL penalties are among the highest in the world:
- Up to $10 million CAD per violation for businesses
- Up to $1 million CAD per violation for individuals
- Private right of action allowing individuals to sue for up to $200 per message ($1 million per day)
Comparison Matrix
| Requirement | CAN-SPAM (US) | GDPR (EU) | CASL (Canada) |
|---|---|---|---|
| Prior consent required | No (opt-out model) | Yes (consent required) | Yes (express or implied) |
| Double opt-in required | No | Not technically, but strongly recommended | No, but recommended |
| Unsubscribe required | Yes | Yes | Yes |
| Unsubscribe processing time | 10 business days | Without undue delay | 10 business days |
| Physical address required | Yes | Yes (data controller ID) | Yes |
| Sender identification | Yes | Yes | Yes |
| Record of consent required | Not explicitly | Yes | Yes |
| Consent expiration | N/A | No (but must be revocable) | Implied: 2 years; Express: no |
| Maximum penalty (per violation) | $51,744 | 4% of global revenue or €20M | $10M CAD |
| Applies to non-residents | If sent to/from US | If targeting EU residents | If sent to Canadian addresses |
Other Jurisdictions
Several other jurisdictions have email marketing laws worth noting:
- UK (PECR + UK GDPR): Post-Brexit, the UK has its own GDPR equivalent plus the Privacy and Electronic Communications Regulations. Very similar to EU GDPR in practice.
- Australia (Spam Act 2003): Requires consent, identification, and unsubscribe mechanism. Fines up to $2.1M AUD per day.
- Brazil (LGPD): Brazil’s data protection law (effective 2020) mirrors many GDPR principles, including consent requirements for marketing email.
- India (DPDP Act): India’s Digital Personal Data Protection Act requires consent for processing personal data, including for marketing communications.
Compliance Best Practices Across All Jurisdictions
Regardless of which laws apply to your sending, these practices satisfy the strictest requirements:
- Use double opt-in for all new subscribers
- Record consent evidence — timestamp, source, IP address, and form content
- Include a one-click unsubscribe in every commercial message
- Process opt-outs within 24 hours (faster than any law requires)
- Include clear sender identification and physical address
- Don’t use deceptive subjects or misleading From names
- Separate marketing consent from other agreements
- Have a data subject request process ready before you need it
- Review third-party compliance — you’re responsible for vendors acting on your behalf
- Audit compliance annually as laws evolve and new jurisdictions add requirements
Legal compliance is the floor, not the ceiling. The practices that satisfy the strictest laws also happen to be the practices that produce the best deliverability outcomes. Following them protects your reputation, your inbox placement, and your business.