Email marketing laws: a plain-English compliance guide
Email marketing is regulated, and which laws apply depends on where your recipients are, where you send from, and how you handle personal data, not only where your company is based. This is a practical overview of CAN-SPAM, GDPR, and CASL, plus the EU ePrivacy rules on email-marketing consent. It is general information, not legal advice, so check with a lawyer for your situation.
CAN-SPAM, GDPR, and CASL
CAN-SPAM (United States). Permission is not required to send, but every commercial message must avoid false headers and subject lines, identify itself as an ad where relevant, include a valid physical postal address, and offer a working unsubscribe honored within 10 business days.
GDPR and ePrivacy rules (European Union and EEA). GDPR governs personal-data processing. National ePrivacy laws set email-marketing consent rules, including conditions for marketing similar products to existing customers. When you rely on consent, it must be freely given, specific, informed, and provable. Pre-checked boxes do not count, and withdrawing consent must be as easy as giving it.
CASL (Canada). Also consent-based. CASL permits express consent and defined forms of implied consent, including certain existing business relationships. The sender must be able to prove the consent relied on. Commercial electronic messages generally need sender identification and an unsubscribe mechanism, with requests honored within 10 business days.
Sending practices to adopt
Permission you can prove. Use opt-in and keep a record of the source and timestamp. Double opt-in makes that record stronger.
Honest headers and subjects. The from name, reply-to, and subject line must reflect what the email actually is.
A real identity. Your legitimate business name and a physical mailing address.
An easy unsubscribe. One that works, on every marketing message, honored promptly. Gmail and Yahoo require one-click unsubscribe for bulk marketing and subscribed messages under their 2024 sender requirements.
Respect for opt-outs. Once someone unsubscribes, suppress them permanently rather than deleting and risking a re-add later.
A short compliance checklist
Collect consent through opt-in and log where each contact came from.
Keep your physical address and sender identity current in your templates.
Put a working unsubscribe in every marketing send, and support one-click unsubscribe. Keep required transactional messages separate.
Honor unsubscribes through a permanent suppression list, not a manual delete.
Offer a preference center so people can choose less mail instead of leaving entirely.
Give EU and Canadian contacts a way to access or remove their data on request.
In Loops, marketing email respects subscription preferences while required transactional email can still send. Hard bounces and spam complaints suppress both. Keep promotional content out of transactional sends.
Frequently asked questions
Do I need consent to send marketing email?
Is one-click unsubscribe required?
Does CAN-SPAM apply if my company is outside the US?
What is the safest way to stay compliant across regions?
Should a marketing unsubscribe stop transactional email?