How GDPR and CAN-SPAM compliance works
These are two different laws with opposite starting assumptions, which is why they are usually named together. The GDPR governs personal data in the European Union, with the United Kingdom keeping its own version of the same regime. It requires a lawful basis for holding and using someone’s details, and where that basis is consent, the consent has to be a specific, informed, freely given and active choice. A pre-ticked box is not consent, and withdrawing it must be as easy as giving it. Alongside it, the ePrivacy rules are what actually require permission before marketing email is sent.
CAN-SPAM is a United States federal law and works the other way round: commercial email may be sent without prior permission, but each message must carry accurate sender and header information, a subject line that is not misleading, a valid physical postal address, and a working way to opt out that is honoured promptly once used. Other markets sit somewhere between the two — Canada’s rules, for instance, are closer to the European approach.
Why GDPR and CAN-SPAM compliance matters
Which law applies is decided by where your recipients are, not by where you are sitting. A consultancy in Kathmandu with subscribers in London is inside the European regime for those contacts, and a Nepali business address does not change that. Most lists built over a few years contain people in several jurisdictions at once, which in practice means designing for the stricter rule and applying it to everybody.
Beyond the legal exposure, compliance and deliverability point in the same direction. A list of people who actively asked to hear from you complains less, bounces less and arrives more reliably than one assembled from whatever addresses were available.
Common mistakes with GDPR and CAN-SPAM compliance
The most common is bundling. One tick box that covers the terms of service, the account and marketing at the same time is not specific consent, because the person cannot agree to one part and decline another. Keep marketing permission separate and optional.
The second is having no record. If you cannot say when someone subscribed, from which form and what wording they agreed to, you have no answer when they or a regulator ask. The third group is procedural and easy to fix: an unsubscribe link that demands a login before it works, a footer with no real postal address or identifiable sender, and requests to be removed that sit unactioned while the next campaign goes out. Finally, buying a list and describing the interest in it as legitimate does not make it so.
How to act on it
Ask for marketing permission on its own, in plain words that say what you will send. Store the date, the source and the wording alongside the address, and use a confirmation step where the market or the list warrants it. Put your business name and a genuine postal address in every campaign footer, keep the unsubscribe link visible and working in a single step, and add every opt-out to a suppression list so no future import can undo it.
Then treat requests to see, correct or delete data as ordinary work with a named owner, not as an emergency. I am a marketer, not a lawyer: this page explains how the rules shape the way a list is built, and anything with real money or real risk attached deserves proper legal advice for the markets you actually mail.