The acronyms sound intimidating, but the laws that govern marketing email come down to a short list of common sense rules. Get permission, say who you are, give people an easy way out, and do not lie. This guide explains what GDPR, CAN-SPAM, and CASL actually require, where each one applies, and the practical steps that keep your email program on the right side of all three.
One note up front: this is general guidance to help you understand the landscape, not legal advice. The penalties for getting this wrong can be steep, and your exact obligations depend on your business, your audience, and where everyone is located. When real money or real risk is on the line, talk to a qualified lawyer.
The Three Laws You Hear About Most
There are dozens of privacy and anti-spam laws around the world, but three come up again and again because they cover huge markets. They differ most on one question: do you need permission before you email someone, or only after?
- GDPR is the European Union's General Data Protection Regulation. It governs the personal data of people in the EU and the European Economic Area, and it leans heavily toward consent.
- CAN-SPAM is the United States law for commercial email. It is the most permissive of the three. You can email someone without prior consent, but you must let them stop hearing from you.
- CASL is Canada's Anti-Spam Legislation. It is the strictest. In most cases you need express consent before you send anything commercial.
Your audience, not your office address, decides which laws apply. If you are a US company emailing someone in Germany, GDPR is in play. If you email someone in Canada, CASL is in play. Most email programs that reach across borders should simply aim to satisfy the strictest standard for everyone.
GDPR: Permission and Control
GDPR is about personal data in general, and email is one slice of it. An email address tied to a person is personal data, so collecting and using it brings GDPR into the picture.
The core ideas that matter for email:
- Lawful basis. You need a legitimate reason to process someone's data. For marketing email, that reason is usually consent, and GDPR sets a high bar for what counts.
- Consent must be freely given, specific, and unambiguous. No pre-checked boxes. No burying the agreement inside a wall of terms. The person has to take a clear, affirmative action.
- The right to withdraw. Unsubscribing must be as easy as subscribing was. People can also ask what data you hold and request that you delete it.
- Records. You should be able to show when and how someone opted in.
In practice, this is why so many signup forms now use a plain, unchecked box that says something like "Yes, send me the newsletter." That single design choice does a lot of the GDPR work for you.
CAN-SPAM: Opt-Out, Not Opt-In
CAN-SPAM surprises people because it does not require permission before you send. It assumes commercial email is allowed and focuses on stopping abuse. That does not make it toothless. Each separate violation can carry a significant penalty.
The rules are concrete and easy to follow:
- Do not use deceptive headers or subject lines. The "from," "to," and routing information must be accurate, and the subject must reflect what is inside.
- Identify the message as an ad if it is one, though this can be done clearly in the body rather than as a giant label.
- Include a valid physical postal address. A real street address, a registered post office box, or a private mailbox registered with a commercial mail agency all qualify.
- Offer a clear way to opt out, and honor it within ten business days. You cannot charge a fee, make people log in, or require anything beyond sending a reply or visiting a single page.
CAN-SPAM also makes you responsible even if you hire someone else to send on your behalf. You cannot outsource the liability.
CASL: Express Consent First
CASL flips the US approach. In most situations you need consent before you send a commercial electronic message to someone in Canada, and that consent comes in two flavors.
- Express consent is an explicit yes: someone checks a box or fills out a form agreeing to receive your email. It does not expire on its own.
- Implied consent covers narrower situations, such as an existing business relationship or a recent purchase, and it expires after a set period (commonly two years for a purchase).
CASL also requires that every message identify you clearly and include a working unsubscribe mechanism that you act on quickly. Because the consent rules are strict and the penalties are large, the safest habit for any list that might include Canadians is to collect express consent for everyone.
The Rules All Three Share
Step back and the overlap is obvious. Across GDPR, CAN-SPAM, and CASL, the same handful of practices keep you compliant almost everywhere.
- Get permission you can prove. Even where the law allows opt-out, permission-based lists perform better and protect you. Our guide on how to build an email list walks through doing this without ever buying contacts.
- Tell people who you are. Your real name or company name belongs in every message, along with a postal address. A clear signature reinforces this, and you can create a free email signature that names you and your business in a couple of minutes.
- Be honest in the subject line and headers. No fake "Re:" tricks, no misleading sender names. This also keeps you out of spam folders, which our piece on how to avoid spam filters covers in depth.
- Make unsubscribing trivial and fast. One click, no login, no questions. Then stop sending promptly.
- Keep your data clean and secure. Remove people who leave, and do not hold data you do not need.
If you build these into your process once, you rarely have to think about which law applies to which subscriber.
A Practical Compliance Checklist
Run through this before you send your next campaign. None of it requires a lawyer to implement, though a lawyer should review your overall approach.
- Did every person on this list opt in through a clear, affirmative action, and can I show when?
- Is my "from" name a real, recognizable identity?
- Does the subject line honestly describe the contents?
- Is there a valid physical mailing address in the footer?
- Is there a visible, one-step unsubscribe link?
- Will an unsubscribe be processed within a day or two, not weeks?
- Have I removed everyone who opted out or bounced since last time?
- If I collect data, do I explain why and store only what I use?
A short legal note in your footer can also help here. Our guide to writing an effective email disclaimer explains what is worth including and what is just noise.
A Compliant Footer in Practice
Here is what the compliant elements look like at the bottom of a real marketing email. Notice it is short, honest, and gives the reader an easy exit.
Subject: Your March guide to spring planting is here
Hi Jordan,
Thanks for being part of the Greenfield Garden community. This month we cover soil prep, frost dates, and three vegetables worth starting indoors now.
You're receiving this because you signed up at greenfieldgarden.example when you downloaded our planting calendar.
Greenfield Garden Co., 482 Cedar Lane, Suite 5, Portland, OR 97204
Don't want these emails? Unsubscribe in one click and we'll stop right away.
Warmly, The Greenfield Garden Team
Every required piece is there: who you are, why they got it, a postal address, and a frictionless way to leave.
Frequently Asked Questions
Do these laws apply to one-to-one emails I send by hand?
Mostly no, but the line matters. A genuine personal email to a single person, like a sales note to a prospect or a reply to a customer, is generally treated differently from a bulk commercial campaign. That said, CAN-SPAM can still apply to commercial messages even when sent individually, and a string of unwanted "personal" pitches can cross into spam territory. The safest approach is to treat any commercial message to someone who did not ask to hear from you with care, and always honor a request to stop.
What counts as a valid physical address?
Under CAN-SPAM, a current street address works, as does a post office box you have registered with the postal service, or a private mailbox registered with a commercial mail receiving agency. The point is that mail could actually reach you there. A fake address, or no address at all, is a clear violation. If you run a home business and do not want to publish your home address, a registered PO box solves the problem cleanly.
Does GDPR apply to me if my business is not in Europe?
It can. GDPR follows the data subject, not your location. If you knowingly collect and email people in the EU or EEA, you fall under GDPR regardless of where your company sits. For most small businesses, the simplest response is to apply consent-based practices to everyone rather than trying to sort subscribers by geography. That also tends to satisfy CASL and exceeds CAN-SPAM at the same time.
Keeping It Simple
You do not need a law degree to run a compliant email program. Get permission you can prove, identify yourself, include a real address, tell the truth in your subject lines, and make leaving easy and fast. Do those things for everyone, regardless of where they live, and you will satisfy the spirit of GDPR, CAN-SPAM, and CASL together. When the stakes get real, bring in a lawyer to check the specifics, but the day-to-day habits are well within your reach.