emailmarketing.net

Learn / Compliance · 18 articles

Compliance

If you only read one

CAN-SPAM Act (United States)

FTC compliance requirements for commercial email in the US: the seven core rules, the commercial vs. transactional distinction, sender liability, and penalties. 7 min

  1. CAN-SPAM Act (United States)

    FTC compliance requirements for commercial email in the US: the seven core rules, the commercial vs. transactional distinction, sender liability, and penalties.

    Reference

    7 min

  2. CAN-SPAM Rulemaking (16 CFR Part 316)

    The FTC's regulatory detail behind CAN-SPAM: the codified definitions of sender, primary purpose, and valid physical postal address; the multi-sender designation test; forward-to-a-friend liability; the 10-business-day opt-out; and aggravated violations.

    Reference

    11 min

  3. CASL — Canada's Anti-Spam Legislation

    CRTC rules for commercial electronic messages sent to Canada: express vs. implied consent (with time limits), CEM identification and unsubscribe requirements, exemptions, and penalties up to $10M.

    Reference

    5 min

  4. Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail

    Digest of CRTC CASL enforcement — penalties, undertakings, the section 9 intermediary-liability bulletin, compliance-program guidance, and program statistics — plus the CAN-SPAM statute itself (15 U.S.C. 7704 prohibitions, aggravated violations incl. harvesting, and 7705 promoted-business liability), each with the lesson for an ESP.

    Reference

    13 min

  5. EU ePrivacy Directive + GDPR — Email Marketing

    The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.

    Reference

    12 min

  6. ESP as GDPR Processor — Roles, DPA Requirements, Transfers

    The ESP's own GDPR obligations: controller/processor roles per EDPB 07/2020, the Article 28 DPA clauses an ESP must offer, sub-processor rules, international transfers (SCCs 2021/914, EU-US DPF 2023/1795), and data-subject-request handling as a processor.

    Reference

    12 min

  7. UK PECR — Electronic Mail Marketing

    ICO guidance on direct marketing by electronic mail under PECR and UK GDPR: consent standard, the two soft opt-ins, individual vs. corporate subscribers, bought-in lists, and refer-a-friend.

    Reference

    9 min

  8. Germany — UWG §7 Email Marketing

    Germany's unfair-competition route to email consent: UWG §7(2) no. 2 express prior consent for B2C and B2B, the §7(3) exception's four cumulative conditions, the double-opt-in case law, and enforcement by competitors via cease-and-desist.

    Reference

    7 min

  9. France — CNIL Email Prospecting Rules and the Tracking-Pixel Recommendation

    CNIL's rules for commercial email (B2C opt-in, existing-customer exception, B2B professional-relevance test) and the 2026 recommendation requiring consent for most email tracking pixels — including the deliverability-measurement exemption every ESP needs to know.

    Reference

    13 min

  10. Netherlands (ACM) and the B2B Email Question Across Jurisdictions

    Dutch spam rules under Telecommunicatiewet Art. 11.7 (ACM), the ICO's B2B marketing guidance, and a cross-jurisdiction answer to 'can I email business addresses without consent?' for UK, France, Germany, and the Netherlands.

    Reference

    9 min

  11. Australia — Spam Act 2003 and ACMA Enforcement

    Australia's opt-in regime: express/inferred consent, sender ID and unsubscribe rules (5 business days, 30 days, no login), ACMA penalties incl. Commonwealth Bank's record AU$3.55M, plus OAIC APP 7 and tracking-pixel guidance.

    Reference

    10 min

  12. Brazil — LGPD for Email Marketing

    LGPD legal bases for email marketing (consent vs. legitimate interest per the ANPD guide), controller/operator roles as they hit ESPs, international transfer state (Resolução 19/2024, EU adequacy), children's-data position, and sanctions up to R$50M.

    Reference

    10 min

  13. APAC Email Marketing Laws — Japan, New Zealand, Singapore, South Korea

    Per-country reference: Japan's opt-in Specified Electronic Mail Act and APPI, NZ's Unsolicited Electronic Messages Act (express/inferred/deemed consent), Singapore's Spam Control Act (<ADV>, 10-business-day unsubscribe) + PDPA, and Korea's Network Act Art. 50 opt-in with the (광고) label and night-time rule.

    Reference

    13 min

  14. Right to Object and Right to Erasure in Marketing Operations

    How GDPR/UK GDPR objection, opt-out, consent withdrawal, and erasure requests interact with marketing lists and suppression — ICO operational guidance plus enforcement patterns from the EDPB one-stop-shop case digest (551 Art. 17 and 80 Art. 21 decisions).

    Operational

    11 min

  15. GDPR and ESP Suppression Lists

    The erasure-vs-suppression tension — M3AAWG's Dec 2024 support document on when suppressing an address keeps an ESP a Data Processor and when it makes the ESP a Data Controller, with the 13 suppression events analyzed.

    Operational

    7 min

  16. Consent Record-Keeping and the Burden of Proof

    What to capture and retain to prove consent to a regulator or blocklist: the ICO's obtain/record/manage data points, the emerging record structure standards (Kantara Consent Receipt → ISO/IEC 29184 → ISO/IEC TS 27560 → W3C DPV), and an ESP-implementable consent-record schema with retention and evidence-production guidance.

    Operational

    14 min

  17. Minors and Email Marketing — COPPA, the UK Children's Code, and GDPR Article 8

    When collecting a child's email address triggers US COPPA (under-13 rule, verifiable parental consent, the FTC six-step plan), the UK Age Appropriate Design Code's 15 standards, GDPR Article 8 age thresholds, and what all of this means for ESP signup forms and age gates.

    Reference

    14 min

  18. Consent Guidance Updates: Recent Regulator Positions to Track

    A running digest of recent consent guidance and enforcement the KB should track — NZ DIA spam case studies (real outcomes), ACMA's 2024 statement on what 'consent' now requires in Australia, and CNIL's rules for sharing B2C data with marketing partners — each with the operational lesson.

    Reference

    7 min