Email marketing laws: GDPR, CAN-SPAM and consent

TL;DR, the essentials
- There is no single global rulebook. The law that applies depends on where your recipients are, not where you are. The three big frameworks are the EU/UK GDPR, the US CAN-SPAM Act, and Canada’s CASL.
- The EU and UK run on an opt-in model: you generally need prior consent before emailing an individual. The US runs on an opt-out model: you may email until the person unsubscribes.
- Whatever the framework, every marketing email must identify the sender, offer a clear way to unsubscribe, and honour that request quickly.
- Fines are real: up to €20 million or 4% of global annual turnover under the GDPR, and up to $53,088 per email under CAN-SPAM (2025 adjustment).
Sending a newsletter or a promotional campaign is not just a matter of picking the right tool. It is a legal question first. A person’s email address is personal data, and the moment you collect and use one to communicate, several bodies of law can apply at once. This guide explains, in plain English, what the main email marketing laws require in 2026, how the EU, UK and US approaches differ, and how to stay on the right side of all of them. One caveat throughout: rules, thresholds and figures vary by country, so treat this as a map, not legal advice.
Which email marketing laws actually apply to you?
The single most misunderstood point is jurisdiction. These laws follow the recipient, not the company. If you are based in one country but email people in the EU, the GDPR applies to those contacts. Email someone in the United States and CAN-SPAM applies. A single campaign to an international list can therefore be governed by several frameworks simultaneously.
EU & UK: the GDPR (plus PECR/ePrivacy)
An opt-in regime. You generally need prior consent to email an individual, with narrow exceptions for existing customers.
United States: the CAN-SPAM Act
An opt-out regime. You may send commercial email without prior consent, but you must let people unsubscribe and stop when they do.
Canada: CASL, and others
Canada’s CASL is one of the strictest laws worldwide (express or implied consent). Many other countries have their own rules on top.
In one sentence
Your obligations depend on where your recipients live, so a list that mixes EU and US contacts must satisfy the strictest applicable rule for each contact.

What does the GDPR require for email marketing?
The General Data Protection Regulation does not mention “email marketing” by name. It governs any processing of personal data, and an email address is personal data. Once you collect, store or use addresses to communicate, you become a data controller. That means you must have a valid legal basis, inform people about what you do with their data, keep it secure, and respect their rights (access, rectification, erasure, objection).
For marketing to individuals, two legal bases matter: consent (the default for consumers) and legitimate interest (available in narrow professional contexts). The UK follows the same logic through the UK GDPR and the PECR (Privacy and Electronic Communications Regulations), which turn these principles into concrete email rules. The entire compliance question turns on picking the right basis and being able to prove it.
Do you need consent (opt-in) to send a marketing email?
Under the GDPR, to email individuals the answer is usually yes. Consent must be freely given, specific, informed and unambiguous, and must result from a clear affirmative action. In practice that means a dedicated, unchecked tick box on your sign-up form, kept separate from your terms and conditions. Pre-ticked boxes do not count as valid consent. And because the burden of proof is on you, you must be able to show when, how and where each person consented.
A solid consent record is built in three moves:
A dedicated, empty box
On the sign-up form, a separate tick box, never pre-checked, explains clearly what the person is agreeing to.
A confirmation (double opt-in)
A confirmation email verifies the address and time-stamps the consent. It is the strongest evidence if a regulator ever asks.
A stored trail
You archive the source, date and form used to collect consent, because you carry the burden of proof.
A pre-ticked box, consent buried in the terms, or a mailing list you forced on someone at checkout do not amount to valid consent under the GDPR.
A tool that handles compliance for you
Double opt-in, automatic unsubscribe handling, EU or region-specific hosting: our comparison ranks the platforms that do this best.
How is the US CAN-SPAM Act different?
The United States takes the opposite starting point. The CAN-SPAM Act does not require prior consent: you may send commercial email to someone who never asked for it, provided you follow the rules. It is an opt-out regime built around honesty and an easy exit. Under CAN-SPAM you must:
- use accurate header information (the “from”, “to” and routing details must identify who sent the message);
- avoid deceptive subject lines that misrepresent the content;
- identify the message as an advertisement where relevant;
- include a valid physical postal address for your business;
- offer a clear opt-out mechanism and honour requests within 10 business days;
- monitor what others do on your behalf: you stay responsible even if a vendor sends for you.
Watch out
CAN-SPAM sets a floor, not a ceiling. Individual US states can add stricter rules, and platforms like Gmail and Yahoo enforce their own bulk-sender requirements (authentication, one-click unsubscribe) on top of the law.
What about B2B and existing customers?
Even under the GDPR, two situations soften the strict opt-in rule. Both are narrow, and the exact conditions vary by country, so check your local regulator.
- B2B and legitimate interest: when emailing a named professional at a work address related to their role, you may sometimes rely on legitimate interest, provided the message concerns their job, they were informed, and they can object easily. Generic addresses like info@ or contact@ are treated differently because they are not tied to a named individual.
- The soft opt-in (existing customers): in the UK and much of the EU, you can email an existing customer about similar products or services without fresh consent, if you offered a simple opt-out both when you collected their details and in every message since. It does not apply to prospects or bought-in lists.
Outside these cases, fall back to explicit consent. When in doubt, opt-in is always the safe default.
What must every marketing email include?
Across all the major frameworks, the common denominator is that recipients must know who is writing and be able to stop future messages easily. A compliant email typically contains:
- the sender’s identity, clearly visible (your business name);
- a working unsubscribe link, free and simple, in every message (many mailbox providers now expect one-click unsubscribe);
- a valid physical postal address (mandatory under CAN-SPAM, good practice elsewhere);
- a link to your privacy policy explaining data rights and how to contact you;
- prompt handling of opt-outs: an objection must be acted on without unreasonable delay.
Watch out
Continuing to email someone after they unsubscribe, or hiding the opt-out link, is a directly punishable breach under both the GDPR and CAN-SPAM.
How long can you keep contact data?
The GDPR requires storage limitation: you do not keep data “just in case”. You should retain contact data only for as long as it serves the purpose you collected it for, then delete or anonymise it. Regulators in several countries use a rule of thumb of around two to three years from the last meaningful contact from a prospect (a click, a request for information), but the exact period is not fixed and differs by jurisdiction. Simply opening an email is generally not treated as a contact.
Once the period lapses, you delete or archive the record, or re-engage the person to ask whether they want to stay on the list. No positive reply means they come off it. Regularly cleaning your lists is therefore not just good for deliverability, it is a legal expectation. The US CAN-SPAM Act, by contrast, sets no retention limit, but the opt-out and honesty rules still apply.
What are the penalties for getting it wrong?
The stakes are not theoretical. Under the GDPR, the most serious breaches can trigger an administrative fine of up to €20 million or 4% of annual global turnover, whichever is higher. Lesser breaches are capped at €10 million or 2%. Data protection authorities have fined multiple companies over marketing practices in recent years, often publicly, adding reputational damage to the financial risk.
In the United States, CAN-SPAM violations are assessed per email. The maximum civil penalty rose to $53,088 per non-compliant email after the FTC’s inflation adjustment effective January 2025. Because it applies to each individual message, a single bad campaign can generate enormous theoretical exposure, which gives regulators strong leverage in any settlement.
Figures to date
These amounts are indicative for 2026: the GDPR caps are fixed in the regulation, while the CAN-SPAM figure is adjusted for inflation each year. Always check the current amount with the relevant regulator.
How do you stay compliant in practice?
The good news: a serious email platform automates most of these obligations (double opt-in, unsubscribe handling, consent history, sender authentication). A handful of habits cover the bulk of the risk:
- Use a clear sign-up form with a dedicated, unchecked box, and turn on double opt-in to time-stamp and prove consent.
- Put a working unsubscribe link and, for US recipients, a physical postal address in every campaign, and process opt-outs automatically.
- Clean your lists: purge contacts who have been inactive beyond your retention window.
- Keep a record of processing and publish an accessible privacy policy.
- Prefer a provider that lets you host data in the recipient’s region (EU hosting for EU contacts) to limit cross-border transfers.
- Segment by geography so each contact receives a campaign that meets their country’s rules.
Smart move
Decide your legal basis first (opt-in for EU consumers, opt-out for the US, legitimate interest for narrow B2B), then configure your tool to match. A clean form plus double opt-in covers most of the legal risk.
Move to a compliant, region-hosted tool
Our 2026 selection compares the best email marketing software on compliance, price and deliverability.
Your next step
Looking for a compliant platform hosted in your region? Read our best email marketing software 2026 comparison, or browse the email marketing hub for guides and reviews.
Frequently asked questions
Do I need consent to send a marketing newsletter?
It depends on where your recipient lives. In the EU and UK, the GDPR generally requires prior opt-in consent through a dedicated, unchecked box, with limited exceptions for existing customers (the soft opt-in) and some B2B contacts. In the United States, the CAN-SPAM Act does not require consent, but you must offer a working unsubscribe option and stop when the person opts out.
What is the difference between GDPR and CAN-SPAM?
The GDPR (EU and UK) is an opt-in law: you generally need prior consent before emailing an individual, and you must be able to prove it. CAN-SPAM (US) is an opt-out law: you can email without prior consent as long as your headers are accurate, the message is honestly identified, you include a physical postal address, and you honour unsubscribe requests within 10 business days.
What are the penalties for breaking email marketing laws?
Under the GDPR, the most serious breaches can lead to fines of up to €20 million or 4% of global annual turnover, whichever is higher. Under the US CAN-SPAM Act, penalties are assessed per email, up to $53,088 per non-compliant message following the 2025 inflation adjustment. Exact figures vary and are updated over time, so check the current amount with the relevant regulator.
Does B2B email escape these laws?
No. A named work email address is still personal data under the GDPR. In some cases you can rely on legitimate interest to email a professional about their role, with prior information and an easy way to object. Generic mailboxes like contact@ are treated differently. US rules and other countries have their own B2B provisions, so confirm the local position for each market you email.
Which law applies if my list is international?
The applicable law follows the recipient, not your company. A single campaign to an international list can be governed by several frameworks at once. The safest approach is to segment your list by country and apply the strictest rule relevant to each contact, for example opt-in and EU hosting for EU recipients, and an unsubscribe link plus postal address for US recipients.