Skip to content
Academy
Marketing Academy · Field Work●Email & Lifecycle
MiniTeardown· 25 minutes

Teardown: Spot the Violations in This Email Footer

Adyen

Objective: Given a synthetic but realistic commercial email footer and opt-in flow, identify every CAN-SPAM and GDPR compliance defect using the lesson's checklists.

You're reviewing a draft promotional email for Adyen's merchant newsletter before it goes to a list that includes both US and EU subscribers.

Find every compliance defect in the supplied footer and sign-up flow, and rank them by legal severity.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeLog each defect, its severity, and its lesson reference in a shared tracker

Free, easy to hand off to legal or dev for prioritization

The process

Specimens to review

List every defect in this footer against the CAN-SPAM and GDPR requirements from the lesson, then rank by severity.

Sample output
EMAIL FOOTER (as sent):

Adyen Merchant Updates

You're receiving this because you're an Adyen customer.

[Unsubscribe] (link goes to a 'confirm your email' page requiring login)

--
Adyen B.V.

Specimen: synthetic, realistic

This checkout form is the only place EU merchants provide their email. List the GDPR consent defects.

Sample output
SIGN-UP FORM (as built):

[Checkout page]
Email: ____________
[X] By completing checkout, you agree to our Terms of Service and to receive marketing emails.
(checkbox is pre-ticked, bundled into the required Terms of Service agreement)

Specimen: synthetic, realistic

Final deliverable

A severity-ranked list of every compliance defect found in the footer and sign-up flow, with a fix owner assigned to each.

See a reference example
Sample output
Nubank, Compliance Teardown Log (excerpt)

CRITICAL: Pre-ticked marketing checkbox bundled with ToS -> owner: developer -> fix: separate unticked checkbox with specific wording
CRITICAL: No physical address in footer -> owner: either -> fix: add registered agent address
MODERATE: No consent log -> owner: developer -> fix: capture timestamp + IP on submit

Success criteria

You're done when you can:

  • Identifies all 3 critical defects in the footer and all 3 in the sign-up flow
  • Correctly rejects both distractors as non-violations
  • Assigns a plausible fix owner (you/developer/either) to each real defect