Compliance
- APAC Email Marketing Laws — Japan, New Zealand, Singapore, South Korea
Per-country reference: Japan's opt-in Specified Electronic Mail Act and APPI, NZ's Unsolicited Electronic Messages Act (express/inferred/deemed consent), Singapore's Spam Control Act (<ADV>, 10-business-day unsubscribe) + PDPA, and Korea's Network Act Art. 50 opt-in with the (광고) label and night-time rule.
- Australia — Spam Act 2003 and ACMA Enforcement
Australia's opt-in regime: express/inferred consent, sender ID and unsubscribe rules (5 business days, 30 days, no login), ACMA penalties incl. Commonwealth Bank's record AU$3.55M, plus OAIC APP 7 and tracking-pixel guidance.
- Brazil — LGPD for Email Marketing
LGPD legal bases for email marketing (consent vs. legitimate interest per the ANPD guide), controller/operator roles as they hit ESPs, international transfer state (Resolução 19/2024, EU adequacy), children's-data position, and sanctions up to R$50M.
- CAN-SPAM Act (United States)
FTC compliance requirements for commercial email in the US: the seven core rules, the commercial vs. transactional distinction, sender liability, and penalties.
- CAN-SPAM Rulemaking (16 CFR Part 316)
The FTC's regulatory detail behind CAN-SPAM: the codified definitions of sender, primary purpose, and valid physical postal address; the multi-sender designation test; forward-to-a-friend liability; the 10-business-day opt-out; and aggravated violations.
- CASL — Canada's Anti-Spam Legislation
CRTC rules for commercial electronic messages sent to Canada: express vs. implied consent (with time limits), CEM identification and unsubscribe requirements, exemptions, and penalties up to $10M.
- Consent Guidance Updates: Recent Regulator Positions to Track
A running digest of recent consent guidance and enforcement the KB should track — NZ DIA spam case studies (real outcomes), ACMA's 2024 statement on what 'consent' now requires in Australia, and CNIL's rules for sharing B2C data with marketing partners — each with the operational lesson.
- Consent Record-Keeping and the Burden of Proof
What to capture and retain to prove consent to a regulator or blocklist: the ICO's obtain/record/manage data points, the emerging record structure standards (Kantara Consent Receipt → ISO/IEC 29184 → ISO/IEC TS 27560 → W3C DPV), and an ESP-implementable consent-record schema with retention and evidence-production guidance.
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail
Digest of CRTC CASL enforcement — penalties, undertakings, the section 9 intermediary-liability bulletin, compliance-program guidance, and program statistics — plus the CAN-SPAM statute itself (15 U.S.C. 7704 prohibitions, aggravated violations incl. harvesting, and 7705 promoted-business liability), each with the lesson for an ESP.
- ESP as GDPR Processor — Roles, DPA Requirements, Transfers
The ESP's own GDPR obligations: controller/processor roles per EDPB 07/2020, the Article 28 DPA clauses an ESP must offer, sub-processor rules, international transfers (SCCs 2021/914, EU-US DPF 2023/1795), and data-subject-request handling as a processor.
- EU ePrivacy Directive + GDPR — Email Marketing
The EU opt-in rule for email marketing: ePrivacy Art. 13 and its soft opt-in, the GDPR consent standard per EDPB 05/2020, lawful basis (consent vs. legitimate interests), tracking pixels under Art. 5(3) per EDPB 2/2023, and the member-state divergence table.
- France — CNIL Email Prospecting Rules and the Tracking-Pixel Recommendation
CNIL's rules for commercial email (B2C opt-in, existing-customer exception, B2B professional-relevance test) and the 2026 recommendation requiring consent for most email tracking pixels — including the deliverability-measurement exemption every ESP needs to know.
- GDPR and ESP Suppression Lists
The erasure-vs-suppression tension — M3AAWG's Dec 2024 support document on when suppressing an address keeps an ESP a Data Processor and when it makes the ESP a Data Controller, with the 13 suppression events analyzed.
- Germany — UWG §7 Email Marketing
Germany's unfair-competition route to email consent: UWG §7(2) no. 2 express prior consent for B2C and B2B, the §7(3) exception's four cumulative conditions, the double-opt-in case law, and enforcement by competitors via cease-and-desist.
- Minors and Email Marketing — COPPA, the UK Children's Code, and GDPR Article 8
When collecting a child's email address triggers US COPPA (under-13 rule, verifiable parental consent, the FTC six-step plan), the UK Age Appropriate Design Code's 15 standards, GDPR Article 8 age thresholds, and what all of this means for ESP signup forms and age gates.
- Netherlands (ACM) and the B2B Email Question Across Jurisdictions
Dutch spam rules under Telecommunicatiewet Art. 11.7 (ACM), the ICO's B2B marketing guidance, and a cross-jurisdiction answer to 'can I email business addresses without consent?' for UK, France, Germany, and the Netherlands.
- Right to Object and Right to Erasure in Marketing Operations
How GDPR/UK GDPR objection, opt-out, consent withdrawal, and erasure requests interact with marketing lists and suppression — ICO operational guidance plus enforcement patterns from the EDPB one-stop-shop case digest (551 Art. 17 and 80 Art. 21 decisions).
- UK PECR — Electronic Mail Marketing
ICO guidance on direct marketing by electronic mail under PECR and UK GDPR: consent standard, the two soft opt-ins, individual vs. corporate subscribers, bought-in lists, and refer-a-friend.