New: The free 7-Day Email Profit BootcampStart free →
Skip to content
Guide · 5 min

Email Compliance in Plain English: CAN-SPAM, GDPR & CASL

What the three email laws most marketers encounter actually require, side by side, plus a practical compliance checklist. Not legal advice.

Not legal advice: This guide is general educational information, not legal advice. Laws change and details depend on your situation. For specific questions, consult a qualified lawyer in the relevant jurisdiction.

Email laws have a reputation for being scary and confusing. They don’t have to be. At their core, the major anti-spam and privacy laws ask for the same few things: be honest, get permission where required, make it easy to leave, and protect people’s data. This guide breaks down the three laws most email marketers run into: CAN-SPAM (United States), GDPR (European Union and, in a similar UK version, the United Kingdom) and CASL (Canada).

Which law applies to you?

A key idea: these laws generally follow the recipient, not just where your business is based. If you’re a U.S. business emailing people in the EU, GDPR can apply. If you email people in Canada, CASL can apply. Since most lists include people from multiple countries, many senders simply adopt the strictest common-sense practices across the board.

CAN-SPAM (United States)

CAN-SPAM covers commercial email. Notably, it’s an opt-out law: it doesn’t require prior consent to send commercial email, but it sets clear rules for how you send it.

The main requirements

  • No false or misleading header information. Your “From,” “To,” “Reply-To” and routing info must be accurate.
  • No deceptive subject lines. The subject must reflect the content.
  • Identify the message as an ad where it’s commercial (this can be done in various clear ways).
  • Include your valid physical postal address. A street address, a registered P.O. box or a private mailbox registered with a commercial mail receiving agency.
  • Tell recipients how to opt out with a clear, working mechanism.
  • Honor opt-outs promptly, within 10 business days. You can’t charge a fee, require extra info beyond an email address and opt-out preferences, or make them do more than send a reply or visit one page.
  • Monitor what others do on your behalf. You can be responsible even if you hire someone else to send.

The opt-out mechanism must work for at least 30 days after you send, and you can’t sell or transfer the addresses of people who opted out.

Pro tip: CAN-SPAM’s 10 business days is the legal outer limit. Mailbox provider rules for bulk senders (like Gmail and Yahoo) expect one-click unsubscribe requests to be honored much faster, within two days. Build to the stricter standard.

GDPR (European Union) and UK GDPR

The General Data Protection Regulation is a broad privacy law covering how you collect and use personal data, including email addresses. For email marketing, it works alongside the ePrivacy rules (in the UK, PECR), which specifically govern electronic marketing messages.

Under GDPR you need a lawful basis to process personal data. For marketing emails to individuals, that’s typically consent. Valid consent must be:

  • Freely given: a genuine choice.
  • Specific: for a clear purpose, like “weekly newsletter and offers.”
  • Informed: people know who you are and what they’re signing up for.
  • Unambiguous: a clear affirmative action. No pre-ticked boxes.

There is a limited exception in the ePrivacy/PECR rules, often called the “soft opt-in,” that can allow marketing to existing customers about your own similar products, provided they were given a chance to opt out when their details were collected and in every message. Its exact scope varies by country, so check carefully before relying on it.

Other key GDPR principles for email

  • Keep records of consent: when, where and how someone signed up.
  • Make withdrawing consent as easy as giving it.
  • Be transparent in a privacy notice about what you collect, why, how long you keep it and who you share it with.
  • Respect data subject rights, such as access, correction and deletion requests.
  • Data minimization: collect only what you need.
  • Use processors appropriately: your email platform processes data for you, so have an appropriate data processing agreement in place.

Watch out: Bundling consent is risky. For example, requiring newsletter signup to download a freebie may conflict with the “freely given” requirement in some interpretations. A common safer approach is to be crystal clear that the freebie comes with the newsletter, or offer a separate opt-in checkbox.

CASL (Canada)

Canada’s Anti-Spam Legislation is widely considered one of the stricter email laws. It’s an opt-in law: you generally need consent before sending a commercial electronic message.

  • Express consent is a clear yes, such as someone actively checking an unticked box or signing up for your newsletter. It doesn’t expire unless withdrawn.
  • Implied consent can arise from certain relationships, such as an existing business relationship (for example, a purchase) or an inquiry. It is time-limited, generally two years after a purchase or contract and six months after an inquiry.

What every message needs

  • Identify the sender (and anyone on whose behalf it’s sent)
  • Contact information, including a mailing address and a phone number, email or web address
  • An unsubscribe mechanism that is easy to use
  • Process unsubscribes within 10 business days

Under CASL, the burden of proving consent falls on the sender. Keep good records.

Quick comparison

CAN-SPAM (US) GDPR + ePrivacy (EU/UK) CASL (Canada)
Model Opt-out Opt-in (consent) for most marketing Opt-in
Consent before sending? Not generally required Generally yes Yes (express or implied)
Physical address Required Identity/contact details expected Required
Unsubscribe Required; honor within 10 business days Withdrawal must be easy Required; honor within 10 business days
Consent records Not specifically required Strongly expected Burden of proof on sender

The “sleep well at night” compliance checklist

If you follow these practices, you’ll be in a strong position under all three laws and with mailbox providers too:

  • Only email people who clearly opted in; use unticked checkboxes where needed
  • Say exactly what people are signing up for, and how often you’ll email
  • Store consent records: date, time, source form and IP where available
  • Use accurate from names, reply-to addresses and honest subject lines
  • Include your physical mailing address in every marketing email
  • Include a clear unsubscribe link and support one-click unsubscribe
  • Process unsubscribes immediately (your platform can do this automatically)
  • Publish a plain-language privacy policy and link it near your forms
  • Never buy, rent or scrape email lists
  • Disclose affiliate links and sponsored content

Profit move: Compliance and profitability point the same way. Lists built on clear consent tend to have better engagement, fewer complaints and stronger deliverability, which means more of your emails get seen and more of them earn.

Key takeaways

  • Laws generally follow the recipient’s location, so most lists touch several laws.
  • CAN-SPAM is opt-out but requires honesty, a physical address and a working unsubscribe.
  • GDPR and CASL generally require consent before marketing, and records of it.
  • Following the strictest common practices everywhere is the simplest way to stay safe. This is not legal advice.

Join the Profit Inbox Insiders

Weekly email marketing plays, free tools and templates. Plus the free 7-Day Email Profit Bootcamp.

Free every week

One email a week. More money from every email you send.

Join the Profit Inbox Insiders and get the free Starter Kit: 50 subject line formulas, a deliverability checklist and 30 email secrets.