Email marketing laws: a plain-English compliance guide
Email marketing is regulated, and the rules differ by where your recipients live, not where your company is based. This is a practical overview of the three laws that cover most senders. It is general information, not legal advice, so check with a lawyer for your situation.
Resources
The three laws you are most likely to face
CAN-SPAM (United States). Permission is not required to send, but every message must avoid false headers and subject lines, identify itself as an ad where relevant, include a valid physical postal address, and offer a working unsubscribe honored within 10 business days.
GDPR (European Union and EEA). The strictest of the three. You generally need clear, freely given, opt-in consent before emailing, and you must be able to prove when and how you got it. Pre-checked boxes and bundled consent do not count, and withdrawing consent must be as easy as giving it.
CASL (Canada). Also consent-based, with narrow exceptions for existing business relationships. It requires clear sender identification and a working unsubscribe, and its penalties are among the highest in the world.
What almost every law requires
Permission you can prove. Use opt-in and keep a record of the source and timestamp. Double opt-in makes that record stronger.
Honest headers and subjects. The from name, reply-to, and subject line must reflect what the email actually is.
A real identity. Your legitimate business name and a physical mailing address.
An easy unsubscribe. One that works, on every message, honored promptly. One-click unsubscribe is now expected by Gmail and Yahoo for bulk senders.
Respect for opt-outs. Once someone unsubscribes, suppress them permanently rather than deleting and risking a re-add later.
A short compliance checklist
Collect consent through opt-in and log where each contact came from.
Keep your physical address and sender identity current in your templates.
Put a working unsubscribe in every send, and support one-click unsubscribe.
Honor unsubscribes through a permanent suppression list, not a manual delete.
Offer a preference center so people can choose less mail instead of leaving entirely.
Give EU and Canadian contacts a way to access or remove their data on request.
In Loops, several of these are built in: double opt-in, one-click and standard unsubscribe, an automatic suppression list, and a branded preference center, so compliant defaults are the path of least resistance.
Frequently asked questions
Do I need consent to send marketing email?
Is one-click unsubscribe required?
Does CAN-SPAM apply if my company is outside the US?
What is the safest way to stay compliant across regions?