Email Marketing

GDPR and CAN-SPAM Compliance

Also called Email compliance, email marketing law

The rules governing consent, sender identity and opt-out when you send marketing email into different countries.

Quick facts: GDPR and CAN-SPAM Compliance

Category
Email Marketing
Also called
Email compliance, email marketing law
Level
Intermediate
Affects
Consent collection, list building, email footers, unsubscribe handling
Where to see it
Your signup forms and consent records, your email platform's compliance settings and suppression list
In this article4
  1. How GDPR and CAN-SPAM compliance works
  2. Why GDPR and CAN-SPAM compliance matters
  3. Common mistakes with GDPR and CAN-SPAM compliance
  4. How to act on it

How GDPR and CAN-SPAM compliance works

These are two different laws with opposite starting assumptions, which is why they are usually named together. The GDPR governs personal data in the European Union, with the United Kingdom keeping its own version of the same regime. It requires a lawful basis for holding and using someone’s details, and where that basis is consent, the consent has to be a specific, informed, freely given and active choice. A pre-ticked box is not consent, and withdrawing it must be as easy as giving it. Alongside it, the ePrivacy rules are what actually require permission before marketing email is sent.

CAN-SPAM is a United States federal law and works the other way round: commercial email may be sent without prior permission, but each message must carry accurate sender and header information, a subject line that is not misleading, a valid physical postal address, and a working way to opt out that is honoured promptly once used. Other markets sit somewhere between the two — Canada’s rules, for instance, are closer to the European approach.

Why GDPR and CAN-SPAM compliance matters

Which law applies is decided by where your recipients are, not by where you are sitting. A consultancy in Kathmandu with subscribers in London is inside the European regime for those contacts, and a Nepali business address does not change that. Most lists built over a few years contain people in several jurisdictions at once, which in practice means designing for the stricter rule and applying it to everybody.

Beyond the legal exposure, compliance and deliverability point in the same direction. A list of people who actively asked to hear from you complains less, bounces less and arrives more reliably than one assembled from whatever addresses were available.

Common mistakes with GDPR and CAN-SPAM compliance

The most common is bundling. One tick box that covers the terms of service, the account and marketing at the same time is not specific consent, because the person cannot agree to one part and decline another. Keep marketing permission separate and optional.

The second is having no record. If you cannot say when someone subscribed, from which form and what wording they agreed to, you have no answer when they or a regulator ask. The third group is procedural and easy to fix: an unsubscribe link that demands a login before it works, a footer with no real postal address or identifiable sender, and requests to be removed that sit unactioned while the next campaign goes out. Finally, buying a list and describing the interest in it as legitimate does not make it so.

How to act on it

Ask for marketing permission on its own, in plain words that say what you will send. Store the date, the source and the wording alongside the address, and use a confirmation step where the market or the list warrants it. Put your business name and a genuine postal address in every campaign footer, keep the unsubscribe link visible and working in a single step, and add every opt-out to a suppression list so no future import can undo it.

Then treat requests to see, correct or delete data as ordinary work with a named owner, not as an emergency. I am a marketer, not a lawyer: this page explains how the rules shape the way a list is built, and anything with real money or real risk attached deserves proper legal advice for the markets you actually mail.

Do and do not

Do

  • Ask for marketing consent separately from terms and accounts
  • Record the date, source and wording of each consent
  • Show a real postal address and sender name in every campaign

Do not

  • Use pre-ticked boxes or bundled consent
  • Make unsubscribing require a login or a reply
  • Buy a list and call the interest legitimate

Questions people ask about this

Does GDPR apply to a business based in Nepal?

It can. The regime follows the people whose data you hold, not your office address, so it applies to the personal details of subscribers and customers located in the European Union or the United Kingdom. If your list includes contacts there, the safest approach is to build consent and record-keeping to that standard and apply it to everyone.

Can I email people who gave me a business card?

Handing over a card shows willingness to be contacted about the conversation you had, not permission for an ongoing marketing list. Follow up personally if that is what was discussed, and invite the person to subscribe rather than adding them silently. Rules differ by market and by whether the contact is a business or an individual, so take advice for yours.

What has to appear in the footer of a marketing email?

Identify who is sending, in a way the reader recognises, and include a valid physical postal address for the business. Provide a clear unsubscribe that works without a login and is actioned promptly. Do not disguise the sender in the From line or use a subject that misrepresents what the message contains.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.