CAN-SPAM, GDPR, CASL
What It Is
Email compliance law is the body of legislation that governs when, how, and to whom you can send commercial email. Three laws dominate global practice: the US CAN-SPAM Act (2003), Canada's Anti-Spam Legislation (CASL, in force since July 2014), and the EU General Data Protection Regulation (GDPR, enforceable from May 2018). Each operates on a different philosophical model, which is why understanding all three -- not just the one that covers your home country -- is essential for any marketer whose list crosses borders.
CAN-SPAM is an opt-out law: you can email anyone you like, but you must give recipients a clear, working mechanism to opt out and honor that request within ten business days. CASL and GDPR are opt-in laws: you need consent before you send. GDPR requires the stricter "express" consent -- a freely given, specific, informed, and unambiguous affirmative action. CASL also recognizes "implied" consent, which lasts two years from a purchase or business inquiry and six months from a job application. These distinctions matter because list-building tactics that are legal in the US may be illegal in Canada or Europe.
The penalties are not theoretical. As of January 17, 2025, the FTC set the CAN-SPAM per-email fine at $53,088 -- and both the sender and the advertised brand can face separate fines on the same campaign. GDPR fines can reach 20 million euros or 4% of global annual turnover, whichever is higher, and cumulative GDPR fines exceeded 5.88 billion euros across 2,245 enforcement actions by early 2025. CASL caps corporate penalties at CA$10 million per violation. A 2024 PerformLine audit of 5.7 million marketing assets found that 1 in 5 were flagged for potential compliance issues -- violations are widespread, not rare.
Real-World Example
In March 2024, the FTC announced a $2.95 million settlement against Verkada, a commercial security-camera company -- the largest CAN-SPAM penalty the FTC had ever imposed at that time. Verkada sent marketing emails to thousands of recipients without any functional unsubscribe mechanism. The case is notable because Verkada was not a fly-by-night spammer but a well-funded B2B tech company, signaling that the FTC has shifted toward higher-profile targets. On the GDPR side, LinkedIn Ireland was fined 310 million euros by Ireland's Data Protection Commission in October 2024 for using member data for behavioral advertising without a valid legal basis -- a reminder that "we have a business relationship" is not equivalent to "we have consent."
Why It Matters
- Your recipients' locations determine which law applies, not your company's location. A US company emailing a Canadian subscriber must follow CASL. Emailing an EU resident means GDPR applies. Many marketers incorrectly assume CAN-SPAM governs their entire operation.
- Per-message penalties compound fast. CAN-SPAM treats each non-compliant email as a separate violation. A campaign of 100,000 emails with a broken unsubscribe link is 100,000 potential violations at $53,088 each.
- Spam complaints destroy deliverability. 54% of email users will report a message as spam if they never gave permission to receive it; 49% will do so if the email lacks an unsubscribe option. High complaint rates wreck sender reputation across your entire domain.
- Inbox providers now enforce compliance independently. Google, Microsoft, and Yahoo require bulk senders (5,000 or more emails per day to their domains) to authenticate with SPF, DKIM, and DMARC, maintain spam complaint rates below 0.3%, and support one-click unsubscribe headers. Non-compliance means delivery blocking, not just legal risk.
- Eight new US state privacy laws took effect in 2025 -- Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, and Maryland -- each adding consent and retention requirements layered on top of CAN-SPAM.
How It Works
The three laws differ on four key dimensions: consent model, identification requirements, opt-out mechanics, and data retention.
CAN-SPAM -- the six requirements per email:
- The From name and address must accurately identify who is sending.
- Subject lines must not be misleading.
- Commercial messages must be clearly identified as advertisements (unless you have a pre-existing transactional relationship).
- A physical postal address -- office, P.O. box, or registered agent -- must appear in the body.
- A clear, functional opt-out mechanism must be present.
- Opt-out requests must be honored within 10 business days. You cannot charge a fee for opting out.
CASL -- consent before the first send:
- Document the form of consent and the date it was obtained.
- Express consent: use an unchecked checkbox. Pre-checked boxes are invalid under CASL.
- At the time of consent collection, identify your organization and describe what the subscriber is signing up for.
- Implied consent expires: two years from a purchase or inquiry, six months from a resume submission.
- Every message must clearly identify the sender and include a working unsubscribe mechanism honored within 10 days.
GDPR -- consent and data rights:
- Obtain express consent before sending. No soft opt-ins, no pre-ticked boxes, no consent bundled into Terms of Service.
- Record the consent artifact: who gave it, when, via which form, and the exact wording they saw. This is what regulators ask for.
- Every message must include your company identity and an easy route to withdraw consent.
- Honor data subject requests: access, erasure, and restriction must all be handled within 30 days.
- If you use a third-party email service provider, you need a Data Processing Agreement (DPA) with them.
Common Mistakes
Treating CAN-SPAM as global coverage. Many US-based marketers assume that following CAN-SPAM is sufficient for all their email sends. If even one subscriber is in Canada, CASL applies. If one is in the EU, GDPR applies. Running a single opt-out list globally exposes you to six- and seven-figure fines under GDPR and CASL. Segment your compliance posture by the location captured at signup -- not by where you are headquartered.
Relying on implied consent that has already expired. Under CASL, a purchase more than two years ago no longer gives you implied consent to email that contact. Most CRMs do not clean this automatically, so marketers unknowingly send to lapsed-consent subscribers for years. Automate an implied-consent expiry workflow: flag contacts at 18 months and run a re-permission campaign before the 24-month clock runs out. If they do not re-consent, suppress them.
Store consent metadata alongside every subscriber record at the moment of capture -- not just the email address. Log the consent type (express or implied), the source (which form or transaction), the timestamp, the IP address, and the exact consent language the subscriber saw. Under both GDPR and CASL, the burden of proof is on the marketer to demonstrate valid consent. Without that log, you have no defense when a regulator asks.
The One-Line Takeaway
Email compliance is not a one-time checkbox -- it is an ongoing operational discipline, and the cost of getting it wrong now routinely exceeds the cost of getting it right.







