Email compliance isn't optional. In 2026, regulations like GDPR and CAN-SPAM carry fines of up to 4% of global annual revenue or €20 million — whichever is higher. And beyond the financial risk, non-compliance destroys the trust you've built with your subscribers.
Whether you're running a newsletter, a cold outreach campaign, or transactional emails, this guide covers everything you need to know about email compliance across major jurisdictions — and how to stay on the right side of the law without making your email program impossible to run.
The Three Pillars of Email Compliance
Every major email regulation — GDPR, CAN-SPAM, CASL, and others — boils down to three principles:
| Pillar | What It Means |
|---|---|
| Consent | The recipient must have agreed to receive your emails (actively or through legitimate interest) |
| Transparency | You must clearly identify who you are, why you're emailing, and how to opt out |
| Control | Recipients must be able to easily unsubscribe, and you must honor their request promptly |
The specifics differ by jurisdiction, but if you build your email program around these three pillars, you're 90% of the way to compliance everywhere.
GDPR: General Data Protection Regulation (EU/EEA + UK)
Applies to: Any organization that processes personal data of individuals in the EU, EEA, or UK — regardless of where your company is based.
Consent Under GDPR
GDPR requires one of six lawful bases for processing personal data. For email marketing, the two most relevant are:
| Lawful Basis | When It Applies | Example |
|---|---|---|
| Consent | The subscriber explicitly agreed to receive emails | "Tick this box to receive our newsletter" (unchecked by default) |
| Legitimate interest | You have a valid reason, and it doesn't override the individual's rights | Sending a follow-up to someone who downloaded your whitepaper |
Consent Requirements
- Affirmative action: Pre-checked boxes are not valid consent. The subscriber must take a deliberate action.
- Granular: Consent for marketing must be separate from consent for terms of service
- Informed: Explain exactly what they're signing up for (type, frequency, channel)
- Withdrawable: Unsubscribing must be as easy as subscribing
- Documented: Keep records of when, how, and what consent was given
Right to Access and Erasure
Under GDPR, subscribers can:
- Request all data you hold about them (Data Subject Access Request — DSAR)
- Request deletion of their data (Right to Erasure / "Right to be Forgotten")
You must respond within 30 days. Having a clean, searchable database makes this much easier — if you can't find a subscriber's data, you can't comply.
GDPR Fines
- Lower tier: Up to €10 million or 2% of global annual revenue
- Upper tier: Up to €20 million or 4% of global annual revenue
Real examples: Meta was fined €1.2 billion in 2023 for GDPR violations related to data transfers.
CAN-SPAM: Controlling the Assault of Non-Solicited Pornography and Marketing Act (United States)
Applies to: All commercial emails sent to or from the United States.
CAN-SPAM is less strict than GDPR — it operates on an opt-out model rather than opt-in. But it still carries significant requirements:
CAN-SPAM Requirements
| Requirement | What You Must Do |
|---|---|
| No false headers | "From," "To," and routing information must be accurate and identify the sender |
| No deceptive subjects | Subject line must reflect the actual content of the email |
| Identify as advertisement | Disclose that the message is an advertisement (implied if it's clearly promotional) |
| Physical address | Include a valid physical postal address in every email |
| Opt-out mechanism | Clear unsubscribe link that works for at least 30 days after sending |
| Honor opt-outs promptly | Process unsubscribe requests within 10 business days |
| Monitor third parties | You're responsible for compliance even if a third party sends on your behalf |
CAN-SPAM Fines
- Up to $51,744 per violation (each email that violates the law counts as a separate violation)
- Aggravated damages for knowingly violating the law
CASL: Canada's Anti-Spam Legislation
Applies to: Commercial electronic messages sent from or accessed in Canada.
CASL is the strictest of the three major regulations:
| Requirement | Details |
|---|---|
| Express consent | Required for most commercial emails (implied consent expires after 2 years) |
| Identification | Full sender name, mailing address, and contact info (phone, email, or web) |
| Unsubscribe mechanism | Must be free, functional for 60 days, and processed within 10 business days |
| Burden of proof | You must prove you have consent — the recipient doesn't have to prove they didn't consent |
CASL Fines
- Up to CAD $10 million per violation for corporations
- Directors and officers can be held personally liable
Other Jurisdictions to Know
| Regulation | Region | Key Difference |
|---|---|---|
| LGPD | Brazil | Modeled after GDPR — opt-in consent, data access/deletion rights |
| PDPA | Singapore | Consent-based, requires "reasonable purpose" notification |
| POPIA | South Africa | Opt-in for direct marketing, strict cross-border data transfer rules |
| CCPA/CPRA | California, US | Right to know, delete, and opt-out of data sale — applies to email addresses |
| PIPEDA | Canada (general) | Overlaps with CASL, adds data accuracy and safeguarding requirements |
Practical approach: If you comply with GDPR and CAN-SPAM, you're compliant with or very close to compliance with most other regulations. GDPR is the highest bar.
Compliance in Practice: What to Implement
1. Consent Collection
Signup forms must:
- Have an unchecked checkbox for marketing consent (GDPR)
- List what subscribers will receive and how often
- Link to your privacy policy
- Use double opt-in (confirmed opt-in) — not legally required everywhere, but strongly recommended
2. Unsubscribe Mechanism
Every marketing email must include:
- A one-click unsubscribe link (visible, not hidden in tiny text)
- A List-Unsubscribe header (RFC 8058) for one-click unsubscribe in Gmail/Yahoo UI
- Processing within 10 business days (CAN-SPAM), ideally immediately
Google and Yahoo now require one-click unsubscribe for bulk senders (5,000+ emails/day).
3. Data Handling
- Store email addresses and consent records securely
- Keep consent logs (timestamp, IP, form URL, what was consented to)
- Allow subscribers to view and download their data (GDPR)
- Allow subscribers to request deletion (GDPR)
- Don't transfer data to third parties without explicit consent
4. Privacy Policy
Your privacy policy must explain:
- What data you collect (email, name, IP, behavior)
- Why you collect it (marketing, analytics, personalization)
- How long you keep it
- Who has access (employees, third-party tools)
- How subscribers can access, correct, or delete their data
5. Data Retention Policy
Define and document how long you keep subscriber data:
| Data Type | Recommended Retention |
|---|---|
| Active subscribers | Indefinitely (while they remain opted in) |
| Unsubscribed emails | 3 years (for suppression list — to avoid accidentally re-adding) |
| Bounced/invalid emails | 6 months (for deliverability analysis, then purge) |
| Consent records | 3–7 years (for legal defense) |
| DSAR responses | 3 years (proof of compliance) |
6. Email List Verification and Compliance
Verifying your email list supports compliance in several ways:
- Reduces the risk of sending to recycled spam traps: A spam trap hit can trigger regulatory scrutiny if it suggests you're not maintaining your list
- Protects data accuracy: GDPR Article 5(1)(d) requires personal data to be "accurate and, where necessary, kept up to date"
- Minimizes data: GDPR's data minimization principle means you shouldn't store invalid addresses — verify and remove them
- Supports DSAR responses: A clean database makes it easier to find and respond to access/deletion requests within the 30-day deadline
Compliance Checklist
Use this checklist before every campaign:
□ CAN-SPAM: Physical mailing address included in footer?
□ CAN-SPAM/CASL/GDPR: Working unsubscribe link present?
□ Gmail/Yahoo: List-Unsubscribe header configured?
□ GDPR: Consent documented for all recipients?
□ GDPR: Privacy policy linked and up to date?
□ All: Sender name and email address clearly visible?
□ All: Subject line accurate (no misleading claims)?
□ All: List verified and cleaned before sending?
Key Takeaways
- GDPR requires opt-in consent and applies to any EU/EEA/UK resident data — fines up to 4% of global revenue
- CAN-SPAM is opt-out based but requires physical address, accurate headers, and working unsubscribe
- CASL is the strictest — express consent required, burden of proof on the sender
- Double opt-in and email verification are your best defenses against accidental non-compliance
- Document everything: consent, unsubscribes, DSAR responses, data retention policies
- If you comply with GDPR, you're covered for almost every other jurisdiction