Email marketing laws: a plain-English compliance guide

Email marketing is regulated, and the rules differ by where your recipients live, not where your company is based. This is a practical overview of the three laws that cover most senders. It is general information, not legal advice, so check with a lawyer for your situation.

Resources

The three laws you are most likely to face

CAN-SPAM (United States). Permission is not required to send, but every message must avoid false headers and subject lines, identify itself as an ad where relevant, include a valid physical postal address, and offer a working unsubscribe honored within 10 business days.

GDPR (European Union and EEA). The strictest of the three. You generally need clear, freely given, opt-in consent before emailing, and you must be able to prove when and how you got it. Pre-checked boxes and bundled consent do not count, and withdrawing consent must be as easy as giving it.

CASL (Canada). Also consent-based, with narrow exceptions for existing business relationships. It requires clear sender identification and a working unsubscribe, and its penalties are among the highest in the world.

What almost every law requires

  • Permission you can prove. Use opt-in and keep a record of the source and timestamp. Double opt-in makes that record stronger.

  • Honest headers and subjects. The from name, reply-to, and subject line must reflect what the email actually is.

  • A real identity. Your legitimate business name and a physical mailing address.

  • An easy unsubscribe. One that works, on every message, honored promptly. One-click unsubscribe is now expected by Gmail and Yahoo for bulk senders.

  • Respect for opt-outs. Once someone unsubscribes, suppress them permanently rather than deleting and risking a re-add later.

A short compliance checklist

  1. Collect consent through opt-in and log where each contact came from.

  2. Keep your physical address and sender identity current in your templates.

  3. Put a working unsubscribe in every send, and support one-click unsubscribe.

  4. Honor unsubscribes through a permanent suppression list, not a manual delete.

  5. Offer a preference center so people can choose less mail instead of leaving entirely.

  6. Give EU and Canadian contacts a way to access or remove their data on request.

In Loops, several of these are built in: double opt-in, one-click and standard unsubscribe, an automatic suppression list, and a branded preference center, so compliant defaults are the path of least resistance.

Frequently asked questions

Do I need consent to send marketing email?

Is one-click unsubscribe required?

Does CAN-SPAM apply if my company is outside the US?

What is the safest way to stay compliant across regions?