emailmarketing.net

APAC Email Marketing Laws — Japan, New Zealand, Singapore, South Korea

Per-country reference: Japan's opt-in Specified Electronic Mail Act and APPI, NZ's Unsolicited Electronic Messages Act (express/inferred/deemed consent), Singapore's Spam Control Act (<ADV>, 10-business-day unsubscribe) + PDPA, and Korea's Network Act Art. 50 opt-in with the (광고) label and night-time rule.

Referencecompliancesender

Four APAC jurisdictions in one reference. All four are effectively opt-in for email marketing (Singapore's Spam Control Act is opt-out per message, but the PDPA layers an opt-in consent requirement for using personal data in direct marketing). Summary table, then per-country detail.

Country Law Consent standard Label Unsubscribe deadline Max penalty (email) Regulator
Japan Act on Regulation of Transmission of Specified Electronic Mail (2002, opt-in since 2008) + APPI Opt-in; exceptions: own address given, business relationship, published business address "Specified electronic mail" labeling per MIC Order Immediately on opt-out (no further sends) ≤1 yr imprisonment or ¥1M (individual); ¥30M (corporation) MIC + Consumer Affairs Agency; PPC for APPI
New Zealand Unsolicited Electronic Messages Act 2007 Express, inferred, or deemed (conspicuous publication) 5 working days; facility functional ≥30 days NZ$200,000 (individual) / NZ$500,000 (organisation) Department of Internal Affairs (DIA)
Singapore Spam Control Act 2007 + PDPA 2012 SCA: opt-out per message (bulk senders); PDPA: express opt-in for direct marketing using personal data <ADV> in subject 10 business days; facility valid ≥30 days Civil: $25/message up to $1M aggregate; PDPC fines up to 10% of SG turnover under PDPA PDPC (and civil actions under SCA)
South Korea Network Act Art. 50 (+ PIPA) Express prior opt-in; exception: own transaction contacts, same goods, within decree-set period (6 months) "(광고)" (advertisement) at start Immediate prohibition after refusal; result notification required Admin fine ≤ ₩30M; ≤1 yr imprisonment or ₩10M fine for evasion tactics KCC / KISA (spam); PIPC (PIPA)

Japan — Act on Regulation of Transmission of Specified Electronic Mail

特定電子メール法 (Act No. 26 of 2002), the "Anti-Spam Law." Enacted 2002 as an opt-out labeling regime; amended 2005 (stronger penalties) and 2008 (Act No. 54): converted to opt-in and extended to foreign-originated spam.

Provenance: the official Japanese Law Translation portal hosts an English translation current only to the 2005 version (pre-opt-in, old article numbering) — it still shows the opt-out Art. 3 "labeling" scheme. Current-law statements below follow MIC's English "Overview of Japanese Anti-Spam Law" (published via Dekyo, the Anti-Spam Consultation Center). Use the JLT text only for definitions.

  • Scope: "specified electronic mail" = email sent as a means of advertisement for the sender's or another's sales activities, by a for-profit organisation or an individual engaged in business.
  • Opt-in (current Art. 3): ad-mail may not be sent without the recipient's prior consent, except to persons who: notified request/consent; provided their own email address to the sender (e.g., in writing/business card); have a business relationship with the advertiser; or (for business senders) published their address in connection with business. Senders must keep records of consent (Art. 3(2)) — violation of an administrative order about record-keeping is separately fined.
  • Prohibition after opt-out (current Art. 3(3)): once the recipient notifies refusal, further ad-mail is prohibited.
  • Labeling duty (current Art. 4): per MIC Order, the message must display the sender's name and address, the email address for opt-out notifications, and prescribed matters (the pre-2008 requirement to tag "未承諾広告※/unsolicited advertisement" was replaced by the opt-in scheme's disclosure requirements).
  • Falsified sender information prohibited (Art. 5) — a direct criminal offence; sending to fictitious (program-generated) addresses prohibited (Art. 6). ISPs may refuse service to such senders (Art. 11).
  • Enforcement chain: MIC and the Consumer Affairs Agency issue administrative orders (Art. 7); on-site inspection and report collection (Art. 28); ISP contractor-information inquiries (Art. 29); information sharing with foreign enforcement agencies (Art. 30). Recipients and ISPs report spam via the registered organisation (Dekyo's Anti-Spam Consultation Center).
  • Penalties: violating Art. 5 (false sender info) or an administrative order — imprisonment up to 1 year or fine up to ¥1,000,000; the employing corporation is fined up to ¥30,000,000 (Arts. 34–35).
  • A parallel opt-in regime for e-commerce advertising email exists in the Specified Commercial Transactions Act (METI) — advertisers face both.

APPI touchpoints for marketers

The Act on the Protection of Personal Information (APPI), enforced by the PPC (Personal Information Protection Commission), governs the address data itself. PPC publishes English translations (the consolidated PDF fetched here is the June-2020 amended text; a version consolidated to 1 Apr 2023 with renumbered articles is on the PPC legal page — only the Japanese text has legal effect). Marketing-relevant duties: specify and publish the purpose of use and stay within it; third-party provision of personal data requires prior consent or use of the notified opt-out mechanism (filed with the PPC; opt-out provision cannot be used for sensitive data) — this is what constrains list selling/sharing; keep provision records; obtain consent for transfers to third parties outside Japan (with information about the destination country) unless the country is whitelisted (EU/UK adequacy is mutual); cease use on request where handling is unlawful. The 2020 amendment (effective Apr 2022) raised corporate fines to up to ¥100M for certain violations (e.g., ignoring PPC orders, unlawful database provision).


New Zealand — Unsolicited Electronic Messages Act 2007

Administered and enforced by the Department of Internal Affairs (DIA) Electronic Messaging Compliance Unit. Covers commercial electronic messages — email, SMS/TXT, fax, instant messages, image messages — with a New Zealand link (sent to, from, or within NZ; not limited to .nz addresses). Pop-ups and voice calls excluded. The regime deliberately mirrors Australia's (Spam Act); DIA presents it as three steps:

  1. Consent
    • Express — a direct indication (form, checkbox, verbal). Keep records; the sender must prove consent.
    • Inferred — from conduct and an ongoing business relationship with a reasonable expectation of messages. DIA calls its application "limited": a single purchase does not create ongoing inferred consent; a business card supports only messages relevant to the relationship in which it was exchanged; a tertiary institution messaging enrolled students about campus services qualifies.
    • Deemed (conspicuous publication) — an address conspicuously published in a business or official capacity (website, brochure, directory) counts as consent unless accompanied by a no-unsolicited-messages statement, and only for messages relevant to the person's business, role, functions or duties.
  2. Identify — clearly identify the business that authorised the message and how to contact it; contact details must remain accurate for 30 days after sending.
  3. Unsubscribe — every message needs a functioning unsubscribe facility that is clear and conspicuous, free, uses the same medium as the message (an SMS campaign must accept reply-STOP; email-only unsubscribe for SMS breaches the Act), remains functional ≥ 30 days, and is honoured within 5 working days (clock starts the day after the request).

Also prohibited: address-harvesting software and harvested-address lists used to send unsolicited commercial messages.

Penalties: DIA escalates from formal warnings and civil infringement notices to court proceedings; failure to comply risks fines up to NZ$500,000 for organisations (DIA states the $500K figure; the Act, s 45, sets NZ$200,000 for individuals). Recipients forward spam complaints to DIA (7726 for TXT).


Singapore — Spam Control Act 2007 + PDPA

Two layers: the Spam Control Act 2007 (SCA) regulates the sending of unsolicited commercial electronic messages in bulk (email and mobile messages, including to instant-messaging accounts, with a Singapore link), and the Personal Data Protection Act 2012 (PDPA) regulates the use of the address — and the PDPC requires opt-in consent for direct marketing.

Provenance: SCA text via Wikisource's transcription and Wayback captures of Singapore Statutes Online (sso.agc.gov.sg lazy-loads content and blocks fetchers); PDPC Advisory Guidelines on Key Concepts PDF (Revised 29 Apr 2026) retrieved via Wayback from the assigned pdpc.gov.sg URL.

Spam Control Act mechanics

  • "Sending in bulk" (s 6): more than 100 messages with same/similar subject-matter in 24 hours, 1,000 in 30 days, or 10,000 in 1 year.
  • Dictionary attacks and address-harvesting software (s 9): messages may not be sent to addresses generated or obtained by either — regardless of consent or content.
  • Second Schedule requirements for unsolicited commercial messages sent in bulk (s 11):
    • Unsubscribe facility: an email address (and, for mobile messages, a number capable of receiving texts), valid and capable of receiving requests for at least 30 days after sending, at no more than usual cost; after an unsubscribe request, no further messages once 10 business days expire.
    • Labeling: <ADV> marking so the message is clearly identified as an advertisement (per the Act/regulations, in the subject line or, if none, prominently in the message).
    • Accurate header and sender information: no false/misleading subject line or header; an accurate, functional email address or telephone number for the sender.
  • Enforcement is civil, not regulatory: any person suffering loss may sue (ss 13–14); statutory damages up to $25 per message, capped at $1 million in aggregate unless actual loss exceeds that. Aiding/abetting is actionable (s 12). First Schedule excludes, e.g., government/emergency messages in the public interest.

PDPA layer (PDPC Advisory Guidelines on Key Concepts)

  • Business contact information is excluded from the Data Protection Provisions (name, title, business phone/address/email not provided solely for personal purposes) — B2B prospecting to corporate addresses does not require PDPA consent (the SCA still applies to bulk sends).
  • Direct marketing needs express opt-in consent: the Personal Data Protection Regulations 2021 provide that deemed consent by notification does not apply to sending direct marketing messages (¶12.27), and the PDPC "does not consider the opt-out method (e.g., a pre-checked box) appropriate" for marketing consent (¶12.28).
  • Deemed consent by conduct covers only purposes objectively obvious from the transaction (booking a taxi ≠ consent to market a limousine service).
  • Third-party lists: an organisation buying data must exercise due diligence that the seller validly obtained consent for disclosure (contractual undertakings, written confirmation, or copies of consent evidence, ¶¶12.33–12.34).
  • Withdrawal of consent (s 16 PDPA): must be allowed and facilitated; a withdrawal notice effective within 10 business days is the PDPC's rule-of-thumb for "reasonable notice" (¶12.41); on withdrawal the organisation must make its data intermediaries and agents cease processing too (¶12.52). A generic "unsubscribe" click is read as withdrawing the channel it was sent on only (¶¶12.47–12.48).
  • ESPs are "data intermediaries": processing on behalf of and for the purposes of another organisation under a written contract subjects the intermediary only to the Protection, Retention Limitation, and (notify-your-customer) Data Breach Notification obligations — but the customer-organisation remains fully liable as if it processed the data itself (s 4(3), ¶¶6.15–6.27), and overseas processing triggers the customer's Transfer Limitation Obligation.
  • Related: Singapore's Do Not Call Registry covers telephone numbers (voice/SMS/fax), not email.

South Korea — Network Act Article 50 (+ PIPA)

The Act on Promotion of Information and Communications Network Utilization and Information Protection ("Network Act") Art. 50 governs "transmission of advertising information for profit" by any electronic transmission medium; the Personal Information Protection Act (PIPA) (PIPC) governs the underlying data. Spam enforcement sits with the Korea Communications Commission (KCC), operationally supported by KISA's Illegal Spam Response Center.

Provenance: Article text from the Korea Legislation Research Institute's official English translation of the Network Act (consolidated through the 23 Jan 2024 amendments). The assigned law.go.kr page (2026 partial amendment, lsiSeq=282481) is JS-only and could not be read directly; the KLRI translation was used instead.

  • Opt-in (Art. 50(1)): express prior consent of the addressee is required. Exception 1: a sender who directly collected the contact details in a transaction may advertise the same kind of goods/services it handles to that customer within a period set by Presidential Decree (the Enforcement Decree sets 6 months from the end of the transaction — decree figure; the Act text delegates it). Exception 2 covers telemarketers under the Door-to-Door Sales Act (voice calls).
  • Refusal/withdrawal (Art. 50(2)): once the addressee refuses or revokes, transmission is prohibited — even where the transaction exception applied.
  • Night-time rule (Art. 50(3)): transmissions between 21:00 and 08:00 the following day require separate express consent, except for media prescribed by Presidential Decree — the Decree exempts electronic mail (the rule bites SMS/push, not email; decree detail).
  • Mandatory disclosures (Art. 50(4)): the ad must specify the sender's name and contact details and the measures and methods by which the addressee can easily refuse or revoke consent. The Enforcement Decree prescribes the "(광고)" ("advertisement") marking at the beginning of the subject line for email (decree detail).
  • Prohibited evasion tactics (Art. 50(5), amended Jan 2024): blocking/evading opt-out; auto-generating addresses by combining characters (dictionary attacks); auto-registering phone numbers/emails for sending; concealing sender identity or transmission source; deceptive tricks to induce responses.
  • Free opt-out (Art. 50(6)): the addressee must not bear any cost (e.g., call charges) to refuse or revoke.
  • Result notification (Art. 50(7)): the sender must inform the addressee of the outcome of processing their consent, refusal, or revocation (per Decree: within 14 days, as commonly implemented; decree detail).
  • Periodic reconfirmation (Art. 50(8)): senders must regularly verify the addressee still consents — the Enforcement Decree sets a 2-year cycle (decree figure).
  • Outsourced sending (Art. 50-3): a business entrusting ad transmission to a third party must control and oversee it; for damage-liability purposes the commissioned sender is deemed an employee of the principal — the Korean analogue of "you cannot outsource your risk," directly relevant to ESPs.
  • ISPs may refuse service used for violating transmissions (Art. 50-4); ad-displaying/data-collecting programs need user consent (Art. 50-5); posting ads on websites needs the operator's consent (Art. 50-7).
  • Penalties: violations of Art. 50(1)–(3) (sending without consent / after refusal / at night), (4) (missing or false disclosures), (6) (cost-shifting), (8) (no reconfirmation) — administrative fine up to ₩30,000,000 (Art. 76(1)7–9-2). Art. 50(5) evasion tactics — criminal: imprisonment up to 1 year or fine up to ₩10,000,000 (Art. 74(1)4), with corporate joint liability (Art. 75). PIPA adds separate (heavier) sanctions for unlawful collection/use of the personal data itself.

ESP triage view

  • All four jurisdictions punish unsubscribe failure independently of consent — the same one-click, free, no-login flow built for Australia/CASL satisfies NZ (5 working days), SG (10 business days), JP (stop on refusal), KR (immediate + result notice).
  • Labels are the APAC-specific trap: <ADV> (Singapore, bulk unsolicited) and (광고) (Korea) belong in the subject line; Korea additionally restricts non-email channels at night.
  • Korea and Japan both criminalise sender falsification and auto-generated address lists — refuse such lists at onboarding (see Spam Traps and Consent Methods).
  • Japan (APPI), Singapore (PDPA), Korea (PIPA) each add a data-protection layer with its own consent/transfer rules on the address data — for the ESP-as-processor angle, the PDPA "data intermediary" model is the clearest statement of the split.

Not legal advice — see compliance/README.md.

#compliance#legal#apac#japan#new-zealand#singapore#south-korea#consent#opt-in#unsubscribe