CAN-SPAM, GDPR, & CASL
Stay compliant with key global email laws that protect user privacy and trust.
Three laws shape most marketing email: CAN-SPAM in the United States, GDPR in the European Union and CASL in Canada. This article explains, in plain words, what each one asks of you and how they differ. Following them also keeps people from reporting your email as spam, which protects your deliverability.
This is a plain-language overview, not legal advice. Laws change and details depend on your situation, so check with a lawyer before you rely on any of it.
Why the law affects deliverability
These laws protect people from unwanted, misleading or fraudulent email. They don’t decide inbox placement. Gmail and other providers do that. But the two are closely linked:
- Breaking the rules brings complaints. People who never agreed to your email, or can’t find the unsubscribe link, press “Report spam”. Few things hurt deliverability more.
- Your email service provider (ESP) enforces the law. An ESP is the company that sends email for you, such as Mailchimp or Postmark. Most ESPs make legal compliance a condition of your account and close accounts that break the rules.
- The rules match good practice. Clear consent, easy unsubscribe, honest content and a clear sender also keep your email in the inbox.
- The fines are large. CAN-SPAM fines are over $50,000 per email. GDPR fines can reach €20 million or 4% of worldwide yearly revenue, whichever is higher. CASL fines can reach $10 million CAD per violation.
Opt-out and opt-in
The biggest difference between the three laws is when you need permission.
- Opt-out (CAN-SPAM): you may send the first marketing email without asking. The person must be able to stop further email, and you must respect that.
- Opt-in (GDPR and CASL): you need the person’s permission (consent) before you send marketing email. With a few narrow exceptions, no permission means no email.
CAN-SPAM (United States)
CAN-SPAM became law in 2003. It is the main US law for commercial email, which is email whose main purpose is to sell or promote something. It covers email sent to or from the US, including email from one business to another.
What CAN-SPAM requires
- Honest header information. The From, To and Reply-To details and the sending route must show who really sent the message. A fake From name or address breaks the law.
- Honest subject lines. The subject must not mislead people about what’s inside. A subject that misrepresents the email is a violation.
- Say it’s an ad. Commercial email must make clear that it is an advertisement. The law doesn’t set a wording, but the notice must be easy to see.
- Include a postal address. Every commercial email needs a valid physical postal address. A street address, a PO box registered with the US Postal Service or a registered private mailbox all count.
- Give a clear way to opt out. Every commercial email must show an easy-to-find way to stop future email. People must not have to pay, give more than their email address and choices, or go through several steps. The opt-out must keep working for at least 30 days after you send.
- Honour opt-outs within 10 business days. After that, you can’t send them commercial email. You also can’t sell or pass their address to anyone else.
- Watch the companies you hire. If an agency sends email for you, you are both responsible. You can’t hand the legal duty to someone else.
What CAN-SPAM doesn’t require
- Permission before the first email. You may legally send to someone who never signed up.
- Double opt-in. Double opt-in means the person confirms their address by clicking a link in a first email. US law doesn’t require it, but it’s strongly recommended for deliverability.
- A set unsubscribe format. You choose how the opt-out works, as long as it meets the rules above.
Gmail and Yahoo set their own, stricter rules. If you send more than 5,000 messages a day to their users, they require a one-click unsubscribe, whatever the law says.
Transactional and commercial email
CAN-SPAM mainly covers commercial email. Transactional email is email a person needs because of something they did, such as an order confirmation, a shipping update or an account alert. It is mostly exempt. It still must not have false or misleading header information.
Mixed emails are tricky. An order confirmation with a big promotion may count as commercial if selling is its main purpose.
GDPR (European Union)
The General Data Protection Regulation (GDPR) has applied since May 2018. It is the EU’s main privacy law. It isn’t written only for email, but it affects email marketing because an email address is personal data (information that identifies a person).
Lawful basis
Under GDPR you need a lawful basis, meaning a reason the law accepts, to use someone’s personal data. For marketing email, two bases come up:
- Consent. The person clearly agreed to receive your marketing email. This is the most common and safest basis.
- Legitimate interest. The person would reasonably expect your email because of an existing relationship, such as a past purchase. It is narrower, and you should document why it applies.
The EU’s ePrivacy rules sit alongside GDPR and set the consent rule for marketing email. They allow a limited exception for existing customers, often called “soft opt-in”. In practice, plan on getting consent.
What valid consent looks like
GDPR consent must be:
- Freely given. Not tied to accepting your terms of service.
- Specific. For marketing email from you, not “partners” in general.
- Informed. The person knows what they’re agreeing to.
- Unambiguous. A clear action, like ticking an empty checkbox. A pre-ticked box doesn’t count.
- Recorded. You can prove when and how they agreed.
- Easy to withdraw. Leaving must be as easy as joining.
People’s rights
- Right to erasure (the “right to be forgotten”). A person can ask you to delete their personal data, including their email address. You must respond within one month. Many senders still keep a minimal entry on a suppression list (a list of addresses you must never email) so the person isn’t emailed again. Check how your regulator treats this.
- Right of access. A person can ask for a copy of the data you hold about them. This is called a data subject access request (DSAR).
- Data portability. A person can ask for their data in a machine-readable format, such as a CSV file, to move it elsewhere.
- Privacy by design. Build your systems to protect data from the start: collect only what you need, limit who can see it, and delete it when you no longer need it.
GDPR in practice
- Use double opt-in. It is the clearest proof of consent.
- Be ready for requests. Have a way to find and export all data linked to an email address.
- Handle erasure with care. Remove the person from every marketing list. Keep only what you need to never email them again.
Who GDPR applies to
GDPR applies to:
- Organisations based in the EU, wherever they process the data
- Organisations outside the EU that offer goods or services to people in the EU
- Organisations outside the EU that monitor the behaviour of people in the EU
If you have subscribers in the EU, GDPR probably applies to you.
CASL (Canada)
Canada’s Anti-Spam Legislation (CASL) has applied since 2014. It is one of the strictest email laws in the world. CASL calls marketing email a “commercial electronic message” (CEM), and you need consent before you send one.
Express and implied consent
Express consent means the person clearly agreed to get your messages. When you ask, you must:
- Ask them to take a clear action, such as ticking a box
- Say who is asking for consent
- Say what messages you’ll send
- Say they can withdraw consent at any time
Express consent doesn’t expire, but the person can withdraw it.
Implied consent applies only in limited cases:
- An existing business relationship. The person bought from you or had a contract with you in the last two years, or made an inquiry in the last six months.
- An existing non-business relationship. The person donated, volunteered or was a member in the last two years. This mainly applies to charities, political groups and clubs.
- A published address. The person published their address without saying “no unsolicited email”, and your message relates to their job or role. This exception is narrow.
Implied consent runs out when those time limits pass, so ask for express consent before then.
What every CASL message must include
- Your name, or the name of the business you’re sending for
- A mailing address, plus a phone number, email address or web address
- An unsubscribe link that is easy to use and free
The contact details and the unsubscribe link must keep working for at least 60 days after you send. You must act on an unsubscribe within 10 business days.
Records and penalties
If someone challenges you, you must prove you had consent, so keep records of when and how you got it.
CASL fines can reach $10 million CAD per violation for a business and $1 million CAD for an individual. The law also includes a right for people to sue senders directly, but the government suspended that part in 2017 and it has never come into force.
The three laws side by side
| Requirement | CAN-SPAM (US) | GDPR (EU) | CASL (Canada) |
|---|---|---|---|
| Consent before sending | No (opt-out) | Yes | Yes (express or implied) |
| Double opt-in | Not required | Not required, strongly recommended | Not required, recommended |
| Unsubscribe in every message | Yes | Yes | Yes |
| Time to act on an opt-out | 10 business days | Without undue delay | 10 business days |
| Postal address in the email | Yes | No, but you must say who you are | Yes |
| Proof of consent | Not required | Yes | Yes |
| Consent expires | Not applicable | No, but can be withdrawn | Implied: yes. Express: no |
| Maximum fine | Over $50,000 per email | €20M or 4% of revenue | $10M CAD per violation |
| Who it covers | Email sent to or from the US | People in the EU | Email sent to Canada |
Other countries
Other countries have their own rules. A few you may meet:
- United Kingdom. The UK GDPR and the Privacy and Electronic Communications Regulations (PECR). In practice they work much like the EU rules.
- Australia. The Spam Act 2003 requires consent, clear sender identification and a working unsubscribe.
- Brazil. The LGPD, Brazil’s data protection law since 2020, follows many GDPR principles.
- India. The Digital Personal Data Protection (DPDP) Act generally requires consent to process personal data, including for marketing.
Checklist
These steps meet the strictest of the rules above:
- Use double opt-in for new subscribers.
- Record proof of consent: the time, the form, its wording and the IP address.
- Put a one-click unsubscribe in every marketing email.
- Act on unsubscribes within 24 hours, faster than any law requires.
- Show who you are and include your postal address.
- Use honest subject lines and a real From name.
- Ask for marketing consent separately from other agreements.
- Have a process for data requests before you get one.
- Make sure agencies that send for you follow the rules too.
- Review your setup once a year, because laws change.
The law is the minimum. The habits that satisfy it also keep your email in the inbox.