Deliverability
Email Marketing Compliance: CAN-SPAM, GDPR, and CASL Made Simple

Three regimes govern most of the marketing email a small business sends, and they disagree with each other in a specific way: the United States lets you email people who never asked, Canada and the EU do not. Because you cannot reliably tell where a subscriber is when they hit submit, the practical answer is to build for the strictest of the three. The penalties, which are usually quoted vaguely, are worth quoting exactly.
CAN-SPAM: no consent required, and the penalties are per message
CAN-SPAM does not require opt-in. It requires honesty and an exit. Headers and subject lines must not be deceptive, commercial messages must be identifiable as advertisements, you must include a valid physical postal address, and you must provide an opt-out mechanism that works for at least 30 days after sending and which you honour within 10 business days.
What makes it serious is the unit of violation. Each individual non-compliant message is a separate violation. The maximum civil penalty is inflation-adjusted annually under the Federal Civil Penalties Inflation Adjustment Act and stood at $53,088 per message following the adjustment effective 17 January 2025. A single careless send to a modest list is arithmetically a company-ending number, which is why the FTC’s actual enforcement targets deception rather than paperwork slips. Do not test the theory.
The classification rule at 16 CFR 316.3 also matters here. A message mixing commercial and transactional content is deemed commercial if the subject line would lead a reasonable recipient to expect an advertisement, or if the transactional content does not appear in whole or substantial part at the beginning of the body. That is how a receipt becomes a marketing email that needed an unsubscribe link it did not have.
GDPR and ePrivacy: two instruments, not one
People say "GDPR" when they mean two separate laws. GDPR Article 6 requires a lawful basis for processing personal data, of which consent is one of six. Article 7 sets the conditions for that consent: the controller must be able to demonstrate that the person consented, the request must be clearly distinguishable from other matters and in plain language, withdrawal must be as easy as giving it, and the person must be told about the right to withdraw before consenting.
The actual permission-to-send rule for marketing email, however, comes from Article 13 of the ePrivacy Directive (2002/58/EC), which requires prior consent for unsolicited commercial email. Article 13(2) contains the soft opt-in: if you obtained the address in the context of a sale of a product or service, you may market your own similar products or services to that person, provided they were given an easy, free opportunity to object both at the point of collection and in every subsequent message. The Court of Justice has confirmed that where the soft opt-in conditions are met, a separate GDPR consent is not additionally required, but the exception is read strictly.
The exposure is under Article 83(5), the higher of the two GDPR fining tiers, which covers infringements of the basic principles for processing including the conditions for consent in Articles 5, 6, and 7. That tier runs to €20 million or 4% of worldwide annual turnover, whichever is higher.
CASL: the strictest of the three
Canada’s Anti-Spam Legislation requires express or clearly defined implied consent before sending a commercial electronic message, full identification of the sender, and a working unsubscribe mechanism. Implied consent is time-limited: an existing business relationship such as a purchase generally supports implied consent for a bounded period, after which you need express consent or you stop. The burden of proving consent is on the sender, which in practice means keeping the timestamp, source, and wording of every opt-in.
Administrative monetary penalties under CASL reach CAD $1 million per violation for an individual and CAD $10 million per violation for a business. Section 20 of the Act sets out what the CRTC weighs in setting an amount, including the nature and scope of the violation, prior history, financial benefit obtained, ability to pay, and cooperation with the investigation.
| CAN-SPAM (US) | GDPR + ePrivacy (EU) | CASL (Canada) | |
|---|---|---|---|
| Consent before sending | Not required | Required, unless the Article 13(2) soft opt-in applies | Required, express or clearly defined implied |
| Proof of consent | Not applicable | Required. Article 7(1) puts the burden on the controller | Required. Burden on the sender |
| Postal address in the message | Required | Not specified, but identification is required | Required |
| Unsubscribe | Mechanism valid 30 days, honoured within 10 business days | Withdrawal must be as easy as consent, and offered in every message | Working mechanism required in every message |
| Maximum penalty | $53,088 per message, adjusted annually | €20m or 4% of global turnover, Article 83(5) | CAD $1m per violation (individual), $10m (business) |
Sources: FTC CAN-SPAM compliance guidance and 16 CFR 316.3; GDPR Articles 6, 7 and 83; ePrivacy Directive 2002/58/EC Article 13; CRTC guidance on CASL.
Compliance and deliverability are the same discipline
Every requirement above reduces the probability that a recipient hits "report spam," which is the metric mailbox providers actually filter on. Google and Yahoo’s 2024 bulk sender rules converge on the same behaviours from a different direction: prove who you are, make leaving trivial, and keep complaints under 0.3%. Building for the strictest regime is not a legal cost centre, it is the configuration that also keeps you in the inbox.
Key takeaways
- ✓CAN-SPAM requires no consent, but each non-compliant message is a separate violation carrying up to $53,088 under the January 2025 inflation adjustment.
- ✓Permission to send marketing email in the EU comes from ePrivacy Article 13, not GDPR. GDPR Articles 6 and 7 govern the consent’s validity and provability.
- ✓The Article 13(2) soft opt-in permits marketing similar products to existing customers, if they can object easily at collection and in every message.
- ✓Consent breaches sit in GDPR’s higher fining tier: €20 million or 4% of global turnover.
- ✓CASL puts the burden of proof on the sender, with penalties up to CAD $10 million per violation for a business.
Related reading
Sources
- 16 CFR 316.3, Primary purpose, eCFR, U.S. Federal Trade Commission
- CAN-SPAM Act: A Compliance Guide for Business, U.S. Federal Trade Commission
- Article 7 GDPR: Conditions for consent, GDPR text
- Article 83 GDPR: General conditions for imposing administrative fines, GDPR text
- Frequently Asked Questions about Canada’s Anti-Spam Legislation, CRTC

Valter Brandt
Chief Marketing Officer
Valter Brandt is the Chief Marketing Officer of ThisCom, working with clients across the United States and Europe. He has led marketing strategy through the major shifts in social advertising, mobile, content marketing, programmatic media, and marketing automation.
All articles by Valter Brandt →Frequently asked questions
Does CAN-SPAM require opt-in consent?+
No. CAN-SPAM permits sending commercial email to people who never asked, provided the headers and subject line are not deceptive, the message is identifiable as an advertisement, it carries a valid physical postal address, and it offers an opt-out that stays functional for at least 30 days and is honoured within 10 business days. Opt-in is still the right default, because complaint rates decide whether Gmail delivers you.
Do I have to follow GDPR if I’m not in the EU?+
Yes, when you are targeting people in the EU. The obligation follows the individual, not your incorporation. Note that the rule requiring permission to send marketing email comes from Article 13 of the ePrivacy Directive rather than GDPR itself, while GDPR Articles 6 and 7 govern whether your lawful basis is valid and whether you can prove the consent.
What must every marketing email include to be compliant?+
A truthful sender name and subject line, a working unsubscribe that is at least as easy to use as the signup was, and your physical postal address. Under GDPR and CASL you additionally need a retrievable record of when, how, and to what wording each recipient consented, because in both regimes the burden of proving consent falls on you.
How quickly must I honor an unsubscribe?+
CAN-SPAM allows 10 business days and requires the mechanism itself to keep working for at least 30 days after the message was sent. That is the legal floor, not the operating standard: Yahoo asks bulk senders to process unsubscribes within two days, and any competent platform removes the contact immediately. Treat immediate as the requirement.
Related articles
Email Marketing for Small Business: The Complete 2026 Guide
The famous $36-per-$1 return is a self-reported survey figure, not a promise. Here is how a small business actually builds an email program that reaches the inbox and drives revenue, from list to automation to metrics.
Read →Email MarketingHow to Build an Email List From Scratch (Without Buying One)
A permission-based email list is your most valuable marketing asset. Here are the lead magnets, opt-in forms, and tactics that grow it ethically and fast.
Read →Email AutomationWelcome Email Sequences That Convert New Subscribers
The welcome sequence is the highest-engagement email you will ever send. Here is a proven structure to turn new subscribers into customers automatically.
Read →Related reading
- Email Automation
Email Automation 101: Workflows Every Small Business Should Set Up
Automated email flows run 24/7 and drive a large share of email revenue. Here are the core workflows every small business should set up first.
- Email Automation
Abandoned Cart Emails: Recover Lost Revenue on Autopilot
Most online carts are abandoned before checkout. A well-built abandoned-cart flow recovers a meaningful share of that revenue automatically.
- Email Marketing
Email Segmentation: Send the Right Message to the Right People
Blasting the same email to everyone is the fastest way to train your list to ignore you. Segmentation lifts engagement and revenue dramatically.
- Email Marketing
Writing Email Subject Lines That Get Opened (With Examples)
The subject line decides whether your email is read or ignored. Here are the principles and proven formulas that lift open rates, plus what to avoid.
- Deliverability
Email Deliverability: How to Stay Out of the Spam Folder
The best email in the world is worthless in the spam folder. Deliverability is infrastructure, here is how small businesses earn and protect inbox placement.