LEGAL COMPLIANCE GUIDE

Email Marketing Compliance:
CAN-SPAM, GDPR, CCPA & Beyond

One non-compliant campaign can cost your business millions in fines and permanently damage sender reputation. Here is everything you need to know.

$2.5B+
GDPR Fines Issued Since 2018
$51K
Average CAN-SPAM Penalty Per Email
4
Major Laws Covered in This Guide
Alkan Balkayaby Alkan Balkaya · Last updated: 2026-04-27

Email Marketing Compliance: CAN-SPAM, GDPR, and CCPA Guide for 2026

Every email you send carries legal weight. Whether you are a solo founder sending a monthly newsletter or a marketing team managing millions of subscriber records, email marketing compliance is not optional. It is the foundation that determines whether your campaigns reach inboxes or trigger enforcement actions.

The regulatory landscape has only intensified since GDPR went into effect in 2018. The United States enforces CAN-SPAM at the federal level while California layers on CCPA and CPRA protections. Canada maintains its own rigorous framework through CASL. Violating any of these laws exposes your business to fines that can reach tens of millions of dollars, and the reputational damage often costs more than the penalties themselves.

This guide breaks down the four major email marketing laws, explains exactly what each requires, and gives you a practical checklist you can implement today. No legal jargon without explanation. No vague advice. Just the specific rules that keep your email program compliant and your sender reputation intact.

Key Takeaways

  • CAN-SPAM requires seven specific elements in every commercial email, including a physical address and a visible unsubscribe mechanism that must be honored within 10 business days.
  • GDPR demands explicit, freely given consent before sending marketing emails to EU residents, and subscribers have the right to request complete data erasure at any time.
  • CCPA/CPRA gives California consumers the right to know what personal data you collect, opt out of its sale or sharing, and request deletion with no retaliation from the business.
  • A single compliance checklist covering all four major laws (CAN-SPAM, GDPR, CCPA, CASL) protects your business globally and simplifies your email operations.

Why Email Marketing Compliance Matters in 2026

Compliance is not a checkbox exercise. It directly impacts deliverability, brand trust, and revenue. Internet service providers use engagement signals and complaint rates to decide whether your emails reach the inbox or the spam folder. A single spam complaint spike caused by non-compliant practices can tank your sender reputation for months.

The financial stakes are real. CAN-SPAM violations carry penalties of up to $51,744 per individual email. GDPR fines can reach 4% of annual global turnover or 20 million euros, whichever is greater. According to Statista’s tracking of GDPR enforcement actions, cumulative fines have surpassed 2.5 billion euros since the regulation took effect, with penalties accelerating year over year.

Beyond fines, non-compliance erodes subscriber trust. When recipients feel their data is mishandled or that they cannot easily unsubscribe, they mark your messages as spam. That feedback loop damages your domain reputation across every mailbox provider simultaneously.

Enforcement Reality Check
The FTC does not send warnings before CAN-SPAM enforcement. Your first indication of a violation is often a legal notice or a fine. GDPR supervisory authorities across the EU have increased cross-border investigations significantly since 2024, meaning a complaint filed in any EU member state can trigger action regardless of where your business is headquartered.

CAN-SPAM Act Requirements: The 7 Rules Every Sender Must Follow

The CAN-SPAM Act (Controlling the Assault of Non-Solicited Pornography and Marketing Act) has governed commercial email in the United States since 2003. Despite its age, it remains actively enforced. Here are the seven requirements that apply to every commercial message you send:

The 7 CAN-SPAM Requirements
1
No false or misleading header information. Your “From,” “To,” “Reply-To,” and routing information must accurately identify the person or business sending the message.
2
No deceptive subject lines. The subject line must accurately reflect the content of the email body.
3
Identify the message as an ad. If your email is an advertisement, you must disclose that fact clearly and conspicuously.
4
Include your physical postal address. Every commercial email must contain a valid physical address of the sender. A PO box or registered commercial mail receiving agency address qualifies.
5
Provide a clear opt-out mechanism. Every email must include a visible, easy-to-use method for recipients to unsubscribe from future messages.
6
Honor opt-out requests within 10 business days. Once a recipient unsubscribes, you cannot send them marketing emails. Most modern platforms process this instantly, but the legal maximum is 10 business days.
7
Monitor what others do on your behalf. If you hire a company to handle your email marketing, you are still legally responsible for compliance. Both the company whose product is promoted and the company that sends the message can be held liable.

A critical nuance: CAN-SPAM does not require prior consent to send commercial email. It operates on an opt-out model. You can email someone who has not explicitly opted in, as long as every message meets all seven requirements above. This is fundamentally different from GDPR and CASL, which require opt-in consent before the first email is sent.

Transactional emails (order confirmations, shipping notifications, account updates) are largely exempt from CAN-SPAM, but only if their primary purpose is transactional. If you add promotional content to a transactional email to the point where it becomes primarily commercial, all seven rules apply.

GDPR Email Marketing Requirements: Consent, Rights, and Data Processing

The General Data Protection Regulation applies to any business that sends marketing emails to residents of the European Union or European Economic Area, regardless of where that business is located. If you have even one EU subscriber, GDPR applies to how you collect, store, and process their data.

Consent Under GDPR

GDPR consent must be freely given, specific, informed, and unambiguous. In practice, this means:

Double opt-in (where a subscriber confirms their email address via a confirmation link) is not technically required by GDPR, but it is strongly recommended because it provides clear evidence of consent that holds up during audits.

Subscriber Rights Under GDPR

GDPR Subscriber Rights You Must Honor
Right to Access
Subscribers can request a copy of all personal data you hold about them. You must respond within 30 days.
Right to Erasure
Also called the “right to be forgotten.” Subscribers can request complete deletion of their data from your systems.
Right to Rectification
Subscribers can demand correction of inaccurate personal data. This includes updating email addresses or names.
Right to Portability
Subscribers can request their data in a structured, machine-readable format to transfer to another service.

Data processing agreements (DPAs) are mandatory under GDPR whenever you share subscriber data with third-party processors. This includes your email marketing platform, analytics tools, and any integration that touches personal data. If your email platform stores subscriber data on servers outside the EU, adequate data transfer mechanisms (such as Standard Contractual Clauses) must be in place.

CCPA and CPRA Compliance for Email Marketers

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), protects California residents and applies to any for-profit business that meets at least one of these thresholds: annual gross revenue exceeding $25 million, processing personal information of 100,000 or more California consumers, or deriving 50% or more of revenue from selling or sharing consumer data.

For email marketers, CCPA/CPRA differs from GDPR in several important ways. According to HubSpot’s marketing research, over 70% of marketers now collect data from California residents, making CCPA/CPRA compliance functionally mandatory for most businesses with a US audience.

RequirementGDPRCCPA/CPRA
Consent ModelOpt-in requiredOpt-out (right to say no)
ScopeEU/EEA residentsCalifornia residents
Right to DeleteYes (right to erasure)Yes (with exceptions)
Data PortabilityYesYes
Max Penalty4% global turnover / 20M EUR$7,500 per intentional violation

The key CCPA/CPRA obligations for email marketers include providing a clear “Do Not Sell or Share My Personal Information” link, responding to consumer data requests within 45 days, maintaining a privacy policy that discloses all categories of personal information collected, and never retaliating against consumers who exercise their rights (for example, by charging them higher prices or providing degraded service).

CPRA also introduced the concept of “sensitive personal information,” which includes precise geolocation, race, religion, and health data. If your email segmentation uses any of these categories, consumers have the right to limit how that data is used.

CASL: Canada’s Anti-Spam Legislation

Canada’s Anti-Spam Legislation is widely considered the most stringent email marketing law in North America. Unlike CAN-SPAM, CASL requires express consent before you send the first commercial electronic message (CEM) to a Canadian recipient.

CASL recognizes two types of consent:

Every commercial electronic message under CASL must include the sender’s name and contact information (mailing address plus phone number, email, or web address), a clear statement of purpose, and a functioning unsubscribe mechanism. Unsubscribe requests must be processed within 10 business days. Penalties for CASL violations reach up to $10 million CAD per violation for businesses and $1 million CAD for individuals.

Email Marketing Compliance Checklist

Use this checklist to audit your email marketing program against all four major regulations. If you can check every box, your program meets the highest global standard.

Complete Compliance Checklist
Every signup form uses explicit opt-in (no pre-checked boxes)
Double opt-in is enabled for all new subscribers
Consent records (timestamp, source, IP) are stored for every subscriber
Every email includes a visible, one-click unsubscribe link
Unsubscribe requests are processed instantly (or within 10 days maximum)
Physical mailing address appears in every commercial email
From name and email address accurately identify your business
Subject lines truthfully reflect email content
Privacy policy is published, current, and linked from signup forms
Data processing agreements are signed with all third-party tools
Process exists to handle data access, deletion, and portability requests
Purchased or rented email lists are never used
Suppression lists are maintained and checked before every send
List-Unsubscribe header is included in email headers (RFC 8058)
Send Compliant Emails with Mailsoftly →

Common Violations and Penalties

Understanding what other companies have gotten wrong helps you avoid repeating their mistakes. Here are the most common violations that trigger enforcement actions:

Sending without valid consent (GDPR/CASL). This is the most frequent violation in GDPR enforcement. Companies that inherited email lists from acquisitions, scraped addresses from websites, or assumed consent from a business card exchange have all faced penalties. The burden of proof lies with the sender: if you cannot produce evidence of consent for a specific subscriber, you are in violation.

Missing or broken unsubscribe mechanisms. Under all four laws, the unsubscribe process must work reliably. Links that lead to error pages, require a login to complete, or redirect subscribers through multiple steps have all triggered enforcement. Google and Yahoo’s 2024 sender requirements now mandate one-click List-Unsubscribe support, adding a technical requirement on top of the legal one.

Failing to honor opt-out requests promptly. Continuing to send emails after a subscriber unsubscribes is a violation under every major regulation. Even a single email sent after an unsubscribe request constitutes a violation. Research from Litmus’s State of Email report shows that delayed unsubscribe processing is one of the top drivers of spam complaints, which compounds the legal risk with deliverability damage.

Ignoring data subject access requests. Under GDPR and CCPA, failing to respond to a consumer’s request for their data within the mandated timeframe (30 days for GDPR, 45 days for CCPA) is itself a violation, separate from any underlying data handling issues.

Using deceptive sender information or subject lines. CAN-SPAM explicitly prohibits misleading headers and subject lines. Using a personal name as the sender when the email is from a company, or subject lines that imply urgency that does not exist, both fall under this category.

Penalty Ranges by Regulation
CAN-SPAM
$51,744
per email violation
GDPR
4%
of global annual turnover
CCPA/CPRA
$7,500
per intentional violation
CASL
$10M CAD
per violation (business)

How Mailsoftly Helps You Stay Compliant

Email marketing compliance should not require a legal team for every campaign. Mailsoftly builds compliance directly into the platform so that the default behavior is the compliant behavior.

Built-in double opt-in. Every new subscriber goes through a confirmation step that creates an auditable consent record. The timestamp, source form, and IP address are logged automatically, giving you the evidence GDPR requires without any manual tracking.

One-click unsubscribe with List-Unsubscribe header. Every email sent through Mailsoftly includes both a visible unsubscribe link in the footer and the List-Unsubscribe header that Gmail, Yahoo, and Apple Mail use to surface their native unsubscribe buttons. Opt-out requests are processed instantly and synced across all lists.

Automatic suppression management. When a subscriber unsubscribes, bounces, or files a complaint, they are added to a global suppression list that prevents any future sends. This applies across all campaigns and automations, eliminating the risk of accidentally emailing someone who has opted out.

Physical address injection. Your business address is configured once in account settings and automatically inserted into every email footer. No risk of forgetting to include it in a rushed campaign.

Data export and deletion tools. When a subscriber exercises their right to access or erasure, Mailsoftly provides one-click data export and permanent deletion directly from the contact record. This keeps your response time well within the 30-day GDPR and 45-day CCPA windows.

Mailsoftly’s free plan includes all compliance features at no cost: 500 contacts and 2,000 emails per month with full access to double opt-in, suppression management, and data handling tools. There is no compliance paywall.

Email Marketing Compliance: CAN-SPAM, GDPR, and CCPA Guide — visual 1
Email Marketing Compliance: CAN-SPAM, GDPR, and CCPA Guide — visual 2

Frequently Asked Questions

Does CAN-SPAM apply if my business is outside the United States?

Yes. CAN-SPAM applies to any commercial email that is sent to a recipient in the United States, regardless of where the sender is located. If you have US subscribers on your list, you must comply with all seven CAN-SPAM requirements. The FTC has jurisdiction over messages received in the US, not messages sent from the US.

Do I need separate consent for email marketing under GDPR if someone is already a customer?

GDPR allows a “soft opt-in” exception for existing customers under the legitimate interest legal basis, but only for marketing related to products or services they have already purchased. You must still provide an easy opt-out in every email, and you must have offered the option to object at the point of data collection. For marketing unrelated to their purchase, separate explicit consent is required.

What is the difference between CAN-SPAM and CASL for email consent?

CAN-SPAM uses an opt-out model: you can send commercial email to anyone as long as you include an unsubscribe mechanism and honor opt-out requests. CASL uses an opt-in model: you need express or implied consent before sending the first message. CASL is significantly more restrictive and carries higher penalties per violation.

Can I use purchased email lists if I include an unsubscribe link?

Under CAN-SPAM alone, technically yes, because the law does not require prior consent. However, this violates GDPR, CASL, and most email service providers’ terms of service. Purchased lists also contain spam traps and invalid addresses that destroy your sender reputation. No legitimate email marketing strategy relies on purchased lists, and every compliance framework beyond CAN-SPAM explicitly prohibits them.

How long do I need to keep consent records under GDPR?

GDPR does not specify a retention period for consent records, but the regulation requires you to be able to demonstrate valid consent for as long as you are processing that individual’s data. In practice, you should retain consent records for the entire duration of the subscriber relationship and for a reasonable period after (most legal advisors recommend at least three years post-unsubscribe to cover the statute of limitations for regulatory actions).

Stay Compliant Without the Complexity
Mailsoftly handles double opt-in, suppression lists, unsubscribe headers, and data deletion out of the box. Start for free with 500 contacts.
Try Mailsoftly Free →
Alkan Balkaya
Alkan Balkaya
Founder & CEO at Mailsoftly
Alkan is the founder and CEO of Mailsoftly, building email marketing tools for businesses of all sizes. He writes about email marketing strategy, deliverability, and the future of marketing automation.