Decay University · Part 4: Sending well: lists, content, practice
Lesson 31 of 64
Email marketing laws: CAN-SPAM, GDPR/PECR and CASL at working level
What CAN-SPAM, GDPR/PECR and CASL actually require, how one-click unsubscribe works, and what to verify before sending a single email for a client.
Last updated 19 July 2026
Three laws govern most of the world's marketing email, and they disagree on the basic question of whether you needed permission to send it. CAN-SPAM, the US law, says no, then regulates how you send. The EU and UK, through GDPR and the ePrivacy rules, say yes, with narrow exceptions. Canada's CASL says yes and makes you the one who has to prove it. The strategy that satisfies all of them at once is the one the last lesson already argued for on deliverability grounds: send only to people who asked, and most of the law takes care of itself.
One sentence before the tour, said plainly: this lesson is working knowledge for a sending practitioner, not legal advice. A real legal question about a real campaign belongs with a lawyer in the relevant jurisdiction.
CAN-SPAM is not an opt-in law
The most common belief about the US law is backwards. CAN-SPAM, in force since 2003, does not require permission before you send commercial email. It is an opt-out law: you may legally mail an American stranger, provided the message follows rules that are about honesty and exits rather than consent.
The FTC's compliance guide lists them. Header information must be truthful, meaning the From name and address identify who actually sent the mail. Subject lines must not deceive. The message must be identifiable as an advertisement (the law leaves room in how), and it must carry your valid physical postal address. There must be a clear way to opt out, the mechanism has to keep working for at least 30 days after the send, and an opt-out must be honored within 10 business days, with no fee and no login demanded first. Penalties are assessed per non-compliant email, not per campaign, which is what makes violations expensive at list scale.
Two details practitioners miss. Opted-out addresses can't be sold or handed onward. And responsibility is shared: both the company whose product the mail promotes and whoever actually pressed send can be liable. That second party can be you.
Permission first: GDPR and PECR
Cross the Atlantic and the model inverts. For marketing email to individuals in the EU and UK, the rule is prior consent. Two layers work together: the ePrivacy rules govern the act of sending electronic marketing (PECR is the UK's version; each EU country has its own), and GDPR defines what consent means and governs the personal data underneath.
The consent bar is specific, and most old lists fail it. Valid consent is a freely given, informed, unambiguous choice made by a clear affirmative action. A pre-ticked box doesn't qualify. Consent buried in terms and conditions doesn't qualify. "They downloaded our whitepaper" doesn't qualify, which is the same lead-versus-consent line the previous lesson drew. Consent must be as easy to withdraw as it was to give, and you keep records, because the operative question is never "do we have consent" but "can we show it".
There is one pressure valve, called the soft opt-in in the UK: if the address came from an actual sale, or negotiations toward one, you may market your own similar products to it, provided the person could refuse at collection and can refuse in every message since. The details differ across EU countries, particularly around business addresses, so "this varies by country" is the honest summary and the reason cross-border campaigns get legal review.
Jurisdiction follows the recipient, not you. A Texas company mailing subscribers in Berlin is inside this regime whether it has heard of it or not. GDPR's fine ceiling (up to 20 million euros or 4% of worldwide turnover, whichever is higher) was written for bigger sins than newsletters, but the consent standard applies at every size.
CASL, the strict one
Canada's law is the one practitioners underestimate. CASL requires consent, express or implied, before a commercial electronic message (its term covering marketing email and texts) is sent, and it flips the burden of proof: the sender must be able to show consent existed, not the recipient that it didn't.
Express consent is a clear affirmative request for your mail, and it does not expire until withdrawn. Implied consent is time-boxed: an existing business relationship, a purchase for instance, opens a two-year window, and the categories and clocks are specific enough that the CRTC's pages are worth reading before mailing Canadians at any scale. Every message must identify the sender and anyone on whose behalf it's sent, and carry an unsubscribe that keeps working for at least 60 days and is honored within 10 business days. Penalties run to one million dollars per violation for individuals and ten million for businesses, which is the number that makes "we'll risk it" a strange sentence to say out loud.
The superset strategy
Now notice what happens if you simply run consent-based sending everywhere: an affirmative opt-in with a record of when and where, honest identification, a working unsubscribe honored fast. You have met GDPR's consent standard, CASL's express-consent standard, and nearly all of CAN-SPAM in one motion. What remains is mechanical: the postal address in the template, the identification lines, the unsubscribe plumbing below.
Filters and regulators, for once, want the same thing.
One-click, mechanically
The bulk sender rules lesson covered the requirement: Gmail and Yahoo demand one-click unsubscribe from bulk senders, honored within two days. Here is what the machinery does. Two headers ride on the message. List-Unsubscribe carries an unsubscribe address, an https URL or a mailto or both. List-Unsubscribe-Post: List-Unsubscribe=One-Click is the promise defined in RFC 8058 that makes it one-click: the mail client may fire a single automated request at that URL and the recipient is out. No page, no login, no "tell us why". The unsubscribe button Gmail shows at the top of a message is these headers at work; the footer link is the separate, human-facing exit the statutes care about.
The timing ladder is worth having straight. Statute gives you 10 business days (CAN-SPAM and CASL both). The mailbox providers give bulk senders two. Build every system to the two-day bar and every legal clock is satisfied with room to spare.
Mainstream ESPs usually set the headers for you. Where they go missing is home-built sending: an app firing campaigns through a raw email API, no headers, no suppression list, and nobody noticed because nothing errors. The free health check reads the headers off a real message you send it, which settles the "are we actually doing this" question in about a minute.
Before you take the money
When you send on a client's behalf, these laws reach you as well as them, so the checks below decide whether you're about to share liability with a stranger. Four questions, before the first send, answers in writing.
Where did every segment of the list come from? Not "is the list okay" but the provenance of each import: this form, that integration, a CSV from the old agency, a partner "share". A client who can't answer can't prove consent, which under CASL is itself the failure, and which the filters will punish in any jurisdiction.
Does unsubscribe actually work, end to end? Subscribe yourself, unsubscribe, confirm the mail stops. Then open the raw message and look for the two headers. A surprising number of unsubscribe links resolve to a page saying "you have been unsubscribed" above a database that never heard about it.
Who is actually on the list, and where? Jurisdiction follows recipients, and an American client's "mostly US" list usually has European and Canadian addresses in it. "We didn't know" carries no legal weight anywhere.
Does the template identify the client, carry a real postal address, and make the exit visible? Minutes to check, and it is the mechanical half of every regime above.
I'll add the admission that belongs here: no scanner can audit consent. Our checks can prove your unsubscribe headers exist; nothing outside your client's records can prove their list was asked for. Provenance is interview work, which is why it is the practitioner's job and not a tool's.
A client who bristles at these questions is telling you something. The engagement you decline on provenance grounds costs less than the one you spend delisting a domain for.
The rules move
This lesson decays too. Laws get amended, regulators revise guidance, and the provider rules that operationalize all this ratcheted hard in 2024 and haven't stopped. Check the primary sources (the FTC guide, the ICO, the CRTC) before repeating a rule to a client, including the ones you just read.
A list built lawfully starts dying anyway, one job change and abandoned mailbox at a time; the list hygiene lesson covered that decay and its sunset repair. Next: the message itself, and what filters actually weigh in it.
Terms from this lesson
- opt-out model - CAN-SPAM's premise: unsolicited commercial email is lawful if it is honest, identified, and carries a working opt-out that gets honored.
- opt-in model - the GDPR/PECR and CASL premise: consent comes before the first marketing message, with narrow exceptions.
- PECR - the UK's electronic-marketing rules (from the EU ePrivacy family); the law that governs the act of sending marketing email to UK recipients.
- soft opt-in - the UK exception: addresses from a real sale may receive marketing for similar products, with a refusal option at collection and in every message.
- CASL - Canada's anti-spam law: consent required, sender bears the burden of proving it, unsubscribe honored within 10 business days.
- express consent - under CASL, a clear affirmative request for your mail; it lasts until withdrawn.
- implied consent - under CASL, consent arising from a relationship such as a purchase; time-limited, typically a two-year window.
List-Unsubscribe-Post- the RFC 8058 header authorizing a mail client to unsubscribe a reader with one automated request, no page or login involved.
Check yourself
1. A US client tells you 'we can't email anyone who hasn't opted in, CAN-SPAM forbids it.' What's the accurate correction?
2. Which signup produces valid consent for marketing email under the GDPR standard?
3. Under CASL, which statement is right?
Scenario
A new client, a US software company, hands you a CSV: 6,400 addresses exported from their badge-scanner app across two years of trade shows. 'These are warm leads, they visited our booth. Send the launch announcement this week.'
What do you do first?