Definition
Email anti-spam laws regulate the sending of commercial electronic messages to protect consumers from unsolicited and deceptive email practices. The five major regulatory frameworks are CAN-SPAM (United States, 2003), CASL (Canada, 2014), GDPR (European Union and United Kingdom, 2018), the Australian Spam Act (2003), and POPIA (South Africa, 2020). Each law establishes requirements for consent, message identification, opt-out mechanisms, and enforcement penalties that email marketers must comply with when sending to recipients in those jurisdictions.
CAN-SPAM sets the least restrictive baseline, requiring truthful subject lines, accurate header information, a clear opt-out mechanism, and physical postal address disclosure. It operates on an opt-out model — commercial email is permitted unless the recipient explicitly unsubscribes. CASL is among the most restrictive, requiring express consent before sending commercial messages, strict record-keeping of consent, and a two-year consent validity period with renewal requirements. Penalties under CASL reach up to CAD 10 million per violation. GDPR imposes a similar opt-in model for direct marketing with the additional requirements of a lawful basis for processing personal data, data subject access rights, and the right to erasure.
The Australian Spam Act requires consent for commercial messages, mandates functional unsubscribe mechanisms processed within five working days, and prohibits sending to address-harvested lists. POPIA aligns closely with GDPR, requiring a lawful basis for processing, consent for direct marketing, and data subject rights including access, correction, and deletion. A comparative compliance checklist by jurisdiction helps multi-national email programmes ensure they meet the strictest applicable requirements rather than only their home-country law.
Best Practices
Apply the strictest jurisdiction's rules to your entire email programme if you send to recipients in multiple regions. Operating at the CASL or GDPR standard ensures compliance with nearly all other frameworks simultaneously.
Implement a consent management platform that records when, how, and what consent was given. Retain consent records for the duration of the subscription plus the applicable statute of limitations period.
Process all unsubscribe requests within 48 hours, well under the 10-day CAN-SPAM requirement and the 5-day Australian requirement. Faster processing reduces complaint risk and improves sender reputation.
Include a physical postal address in every commercial email as required by CAN-SPAM. For programmes sending primarily to EU/UK recipients, include a registered office address rather than a PO Box.
Review email compliance against each jurisdiction's requirements quarterly. Laws are updated with new interpretations and enforcement guidance. A quarterly review catches changes before they become compliance issues.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Click-Through Rate
Click-through rate (CTR) is the percentage of email recipients who clicked one or more links in your email campaign. It measures how compelling your content and call-to-action are.
Click-to-Convert Rate
Click-to-convert rate measures the percentage of email clicks that result in a desired conversion action such as a purchase, signup, or download. It shows how effective your post-click experience is at turning interest into results.
Frequently Asked Questions
Yes. GDPR applies to any organisation processing the personal data of EU residents, regardless of where the organisation is based. You must obtain valid consent, provide privacy information, and honour data subject rights for your EU subscribers.
Opt-out (CAN-SPAM) allows sending commercial email until the recipient unsubscribes. Opt-in (GDPR, CASL) requires active consent before sending any commercial messages. Opt-in frameworks require proof of consent, while opt-out frameworks require proof of unsubscribe processing.
CASL requires retaining proof of consent for three years after the consent is given or after the subscriber unsubscribes. GDPR has no fixed retention period but consent records should be kept as long as the data is processed. A retention period of three to six years is recommended for most programmes.
No. Purchased lists violate CASL, GDPR, the Australian Spam Act, and POPIA because the individuals have not given consent to receive messages from your organisation. Under CAN-SPAM, purchased lists are technically permitted but carry high reputation risk and should be avoided.
CAN-SPAM penalties reach £43,792 per violation. CASL penalties reach CAD 10 million per violation. GDPR fines reach the greater of £17.5 million or 4% of global annual revenue. Australian Spam Act penalties reach AUD 2.22 million per day. POPIA fines reach ZAR 10 million or imprisonment.