Definition
Spam compliance refers to adherence to laws and regulations governing commercial email, primarily CAN-SPAM (US), CASL (Canada), and GDPR/ePrivacy (EU/UK). Compliance requirements cover consent, sender identification, subject line accuracy, physical address disclosure, unsubscribe processing, and data protection.
Non-compliance can result in substantial penalties — up to $43,792 per violation under CAN-SPAM and up to 4% of global turnover under GDPR.
Key Requirements by Regulation
| Requirement | CAN-SPAM (US) | CASL (Canada) | GDPR/ePrivacy (EU) |
|---|---|---|---|
| Consent type | Opt-out | Opt-in (implied expires 2 years) | Opt-in (explicit for marketing) |
| Sender identification | Required | Required | Required |
| Physical address | Required | Required | Required |
| Subject line accuracy | Required | Required | Required |
| Unsubscribe mechanism | Required within 10 days | Required within 10 business days | Required immediately |
| Consent records | Not required | Required | Required |
| Data protection | Not specified | Not specified | Comprehensive requirements |
Core Compliance Elements
- Consent: Obtain proper permission before sending commercial email
- Identification: Clearly identify yourself as the sender
- Subject lines: Do not use deceptive subject lines
- Physical address: Include a valid physical postal address
- Unsubscribe: Provide a clear, working unsubscribe mechanism
- Processing: Honour unsubscribe requests promptly
- Records: Maintain records of consent and unsubscribe requests
Best Practices
- Use confirmed opt-in (double opt-in) for the strongest consent record
- Include a physical address in every email footer
- Make unsubscribe a single-click process with no login required
- Process unsubscribes immediately rather than within legal timeframes
- Maintain clear records of when, where, and how consent was obtained
- Regularly audit your email programme for compliance gaps
- Stay informed about regulatory changes in jurisdictions where your subscribers live
Related Glossary Terms
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Right to Data Portability (GDPR)
The right to data portability allows individuals to obtain and reuse their personal data across different services, including exporting subscriber data from email marketing platforms.
Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, required under GDPR for email service providers.
Data Subject Access Request (DSAR)
A Data Subject Access Request (DSAR) is a GDPR right allowing individuals to request access to their personal data held by an organisation, including email marketing data.
Double Opt-In
Double opt-in (also called confirmed opt-in) is an email signup process that requires a new subscriber to confirm their email address by clicking a verification link in a confirmation email before they are added to your mailing list.
Email Accessibility Guidelines
Email accessibility guidelines ensure emails are usable by people with disabilities, following WCAG standards for screen readers, colour contrast, keyboard navigation, and readable content.
Frequently Asked Questions
Failing to have proper consent records is the most common compliance gap. Many marketers cannot demonstrate when, where, and how a subscriber consented. Without documented consent, any complaint or audit creates regulatory risk.
Yes. CAN-SPAM applies to all commercial email regardless of audience. CASL has specific provisions for business-to-business email. GDPR applies to personal data of individuals, including business email addresses that identify an individual. B2B email is not exempt from spam regulations.
Retain consent records for the duration of the subscriber relationship plus a reasonable period after they unsubscribe or are suppressed. Most experts recommend 3-6 years after the end of the relationship. Check specific requirements in your jurisdiction as some regulations have defined retention periods.