Skip to content
Academy

GDPR and CAN-SPAM for Email Marketers

Understand the two laws that govern most email marketing on earth, what they require, and how to stay compliant without killing your campaigns.

ADVANCED·9 MIN READ·EMAIL & LIFECYCLE·UPDATED JUN 2026
Share:

GDPR and CAN-SPAM for Email Marketers

If you send commercial email, two laws almost certainly apply to you. CAN-SPAM (United States, 2003) and GDPR (European Union, 2018) set the global floor for email marketing.

Break them and you can face fines that run into millions of dollars per campaign. Follow them and you build the kind of trust that actually improves your open rates.

Quick Summary

  • CAN-SPAM is an opt-out law: you can email first, but you must let people leave easily.
  • GDPR is an opt-in law: you must get clear permission before sending a single marketing email to an EU resident.
  • The CAN-SPAM fine is $53,088 per individual email as of January 2025 (not per campaign).
  • Cumulative GDPR fines crossed 6.11 billion euros by early 2026, covering 2,685 enforcement actions.
  • Where your subscriber lives, not where your company is registered, determines which law applies.

Why This Matters (With Real Numbers)

Email marketing delivers roughly $42 in return for every $1 spent. That ROI collapses instantly if your account gets suspended or you face a regulatory fine.

Here is what enforcement actually looks like:

  • Verkada, March 2024: The FTC fined this B2B security-camera company $2.95 million, the largest CAN-SPAM penalty on record at the time, for sending marketing emails with no working unsubscribe mechanism. Verkada was a well-funded startup, not a spammer. That is the point regulators were making.
  • LinkedIn, October 2024: Ireland's Data Protection Commission fined LinkedIn 310 million euros for using member data to serve behavioral advertising without a valid legal basis. The company had a "business relationship" with its users, but that is not the same as consent under GDPR.
  • Experian, 2024: The FTC extracted a $650,000 settlement from Experian for sending marketing messages to consumers who had opted out.
Note

As of January 17, 2025, the FTC adjusted the CAN-SPAM civil penalty ceiling to $53,088 per email. Both the company that sent the email and the brand being advertised can be fined separately on the same campaign. A single 50,000-person send with a broken unsubscribe link is theoretically 50,000 violations.


How CAN-SPAM Works

CAN-SPAM (Controlling the Assault of Non-Solicited Pornography And Marketing Act) sets rules for commercial email in the United States. It uses an opt-out model: you are allowed to send the first email without permission, but you must make it easy for people to stop receiving future messages.

Six things every commercial email must have under CAN-SPAM:

  1. Honest From name and address, The sender must accurately identify who is sending. No misleading display names.
  2. Non-deceptive subject line, The subject line must reflect what is actually in the email.
  3. Clear ad identification, If the email is commercial, it must be identifiable as an advertisement (unless there is a pre-existing transactional relationship).
  4. Physical postal address, Your company's street address, P.O. Box, or registered agent address must appear in the email body.
  5. Working unsubscribe link, A clear, functional mechanism to opt out of future emails must appear in every message.
  6. Timely opt-out processing, You must honor unsubscribe requests within 10 business days. You cannot charge a fee or require the user to do more than send a reply email or visit a single web page.
Common Mistake

CAN-SPAM has one trap that catches experienced marketers: the 10-business-day window is not a license to keep emailing after an opt-out arrives. Best practice is to suppress the contact within 24-72 hours. If your system sends a scheduled broadcast the next morning after someone unsubscribed at midnight, that is still a violation, even if it is inside the legal window.


How GDPR Works

GDPR (General Data Protection Regulation) governs how companies collect, store, and use personal data for anyone in the European Union or UK. For email marketing, the critical rule is simple: you need explicit consent before you send anything.

"Consent" under GDPR is not a checkbox at the bottom of a checkout form. It must be:

  • Freely given: Not bundled into your Terms of Service or required to access a product.
  • Specific: The subscriber must understand what they are consenting to. "Marketing updates from Acme Ltd" is specific. "We may contact you" is not.
  • Informed: The subscriber must know who is sending and roughly what they will receive.
  • Unambiguous: No pre-ticked boxes. No silence counted as agreement. The person must take a positive action.

GDPR also gives subscribers rights you must support:

RightWhat it means in practice
AccessSubscriber can request all data you hold on them
ErasureSubscriber can ask to be deleted within 30 days
RestrictionSubscriber can ask you to stop processing data
PortabilitySubscriber can request their data in a machine-readable format
Withdraw consentSubscriber can pull consent at any time, easily
Real Example

Here is the difference between a compliant and non-compliant sign-up form.

Non-compliant (pre-ticked, bundled): A checkout form with a pre-ticked box that says "By purchasing, you agree to our Terms of Service and consent to receive marketing emails."

Compliant (specific, unticked, separate): A dedicated, empty checkbox below the purchase form that says: "Yes, I want to receive weekly marketing tips from Acme Ltd. I can unsubscribe at any time." The consent is separate from the purchase, unticked by default, and describes exactly what the user is signing up for.

When a regulator asks you to prove consent, you will need to show: the email address, the timestamp, the IP address, the form version, and the exact wording the subscriber saw. Log all of it.


The Key Difference: Opt-Out vs. Opt-In

This single distinction changes everything about how you build and manage your list.

The practical implication: your list-building strategy must be different for different audiences. A lead magnet that collects emails without a clear opt-in is legal in the US but illegal for EU recipients.

Geographic segmentation at the point of signup, not just at the point of sending, is the only safe approach.


What Inbox Providers Add on Top

Since February 2024, Google, Yahoo, and Microsoft have enforced their own requirements for bulk senders (5,000 or more emails per day to their domains). These are not laws, they are technical gatekeeping rules.

Violate them and your email is blocked, not just reported.

Requirements include:

  • Email authentication: SPF, DKIM, and DMARC must all be configured.
  • Spam complaint rate: Must stay below 0.3%. Above 0.1% starts hurting deliverability.
  • One-click unsubscribe headers: Gmail and Yahoo require the List-Unsubscribe-Post header so users can opt out directly from the inbox UI.
Pro Tip

Spam complaint rates and legal unsubscribe compliance are related but not identical. A subscriber can tolerate your emails for months and never unsubscribe legally, but if they hit "Mark as spam" in Gmail, that counts against your sender reputation immediately. The only defense is to send emails subscribers actually want to receive, from a recognizable sender name, at a predictable frequency they signed up for.


GDPR vs. CAN-SPAM Side by Side


Common Mistakes That Get Marketers Fined

  1. Assuming CAN-SPAM covers everything. If even one subscriber on your list is in the EU, GDPR applies to that subscriber's data. Running a single opt-out list globally is the most common compliance mistake among US-based email marketers.

  2. Using pre-ticked checkboxes for consent. Pre-ticked boxes are explicitly invalid under GDPR. Regulators treat them as no consent at all, meaning every email you sent to that subscriber is potentially a violation.

  3. Not logging consent. Proving you had consent is the marketer's burden, not the regulator's. Without a timestamped consent record, you have no defense. Store the email address, the date, the form URL, the IP address, and the exact consent wording together.

  4. Forgetting the physical address. CAN-SPAM requires a physical mailing address in every commercial email. This is one of the most commonly skipped requirements, especially for small businesses and solopreneurs who use a home address and feel uncomfortable publishing it. A registered agent address or P.O. Box is acceptable.

  5. Soft opt-ins for GDPR audiences. "By signing up for our free guide, you agree to receive marketing emails" is not valid GDPR consent. Consent must be a separate, affirmative action, not a condition for accessing something.


A Simple Compliance Checklist

Before your next campaign send, run through this:

Every email (all jurisdictions):

  • From name accurately identifies the sender
  • Subject line is not misleading
  • Physical mailing address is in the footer
  • Working unsubscribe link is present
  • Unsubscribe requests are suppressed within 10 business days

For EU or UK subscribers (GDPR):

  • Consent was obtained before the subscriber was added
  • Consent record exists (timestamp, IP, form, wording)
  • Data Processing Agreement is signed with your email service provider
  • You can fulfill access and erasure requests within 30 days

For technical bulk senders (5,000+ emails/day):

  • SPF record is configured
  • DKIM is signing your email
  • DMARC policy is published
  • List-Unsubscribe-Post header is enabled in your ESP

The One-Line Takeaway

Compliance is not a legal department problem, it is a list quality problem, and fixing it improves your open rates at the same time as it keeps you out of court.

Test Your Knowledge
Loading questions…

You Might Also Like