APAC Email Marketing Laws — Japan, New Zealand, Singapore, South Korea
Per-country reference: Japan's opt-in Specified Electronic Mail Act and APPI, NZ's Unsolicited Electronic Messages Act (express/inferred/deemed consent), Singapore's Spam Control Act (<ADV>, 10-business-day unsubscribe) + PDPA, and Korea's Network Act Art. 50 opt-in with the (광고) label and night-time rule.
Reference13 min read
Who it is for Compliance teams, Senders
Applies to senders on any platform
ContentsOn this page — 5 sections
If you send marketing email to recipients in Japan, New Zealand, Singapore or South Korea, plan on needing their consent. All four countries are effectively opt-in for email marketing. Singapore's Spam Control Act works by opt-out for each message, but its Personal Data Protection Act (PDPA) adds a requirement for opt-in consent to use personal data for direct marketing. A summary table comes first, followed by the details for each country.
| Country | Law | Consent standard | Label | Unsubscribe deadline | Maximum penalty (email) | Regulator |
|---|---|---|---|---|---|---|
| Japan | Act on Regulation of Transmission of Specified Electronic Mail (2002, opt-in since 2008) and the Act on the Protection of Personal Information (APPI) | Opt-in. Exceptions: the recipient gave their own address, a business relationship exists, or the business address was published | Labeling of "specified electronic mail" as set by the order of the Ministry of Internal Affairs and Communications (MIC) | Immediately on opt-out (no further sends) | ≤1 yr in prison or ¥1M (individual); ¥30M (corporation) | MIC and the Consumer Affairs Agency; the Personal Information Protection Commission (PPC) for the APPI |
| New Zealand | Unsolicited Electronic Messages Act 2007 | Express, inferred, or deemed (conspicuous publication) | None | 5 working days; the facility must work for ≥30 days | NZ$200,000 (individual) / NZ$500,000 (organisation) | Department of Internal Affairs (DIA) |
| Singapore | Spam Control Act 2007 and PDPA 2012 | Spam Control Act (SCA): opt-out for each message (bulk senders). PDPA: express opt-in for direct marketing that uses personal data | <ADV> in the subject |
10 business days; the facility must be valid for ≥30 days | Civil: $25 per message, up to $1M in total. Fines from the Personal Data Protection Commission (PDPC) of up to 10% of turnover in Singapore under the PDPA | PDPC (and civil actions under the SCA) |
| South Korea | Network Act Art. 50 (and the Personal Information Protection Act (PIPA)) | Express prior opt-in. Exception: contacts from the sender's own transactions, for the same goods, within a period set by decree (6 months) | "(광고)" ("advertisement") at the start | Sending must stop immediately after a refusal; the result must be notified | Administrative fine ≤ ₩30M; ≤1 yr in prison or a fine of ₩10M for evasion tactics | Korea Communications Commission (KCC) and Korea Internet & Security Agency (KISA) for spam; the Personal Information Protection Commission (PIPC) for PIPA |
Japan: Act on Regulation of Transmission of Specified Electronic Mail
特定電子メール法 (Act No. 26 of 2002) is known as the "Anti-Spam Law." It was enacted in 2002 as an opt-out regime based on labeling. It was amended in 2005 (stronger penalties) and in 2008 (Act No. 54), when it became opt-in and was extended to spam sent from outside Japan.
Sources: the official Japanese Law Translation (JLT) portal has an English translation that is current only to the 2005 version, before opt-in, with the old numbering of articles. It still shows the opt-out "labeling" scheme of Art. 3. The statements below about the current law follow MIC's English "Overview of Japanese Anti-Spam Law", published through Dekyo, the Anti-Spam Consultation Center. Use the JLT text only for definitions.
- Scope. "Specified electronic mail" means email sent as a means of advertisement for the sales activities of the sender or of another party, by a for-profit organisation or by an individual engaged in business.
- Opt-in (current Art. 3). Advertising mail may not be sent without the recipient's prior consent. The exceptions are people who gave notice of a request or consent; who gave their own email address to the sender (for example, in writing or on a business card); who have a business relationship with the advertiser; or, for business senders, who published their address in connection with their business. Senders must keep records of consent (Art. 3(2)). Breaking an administrative order about record-keeping carries its own fine.
- Prohibition after opt-out (current Art. 3(3)). Once the recipient gives notice of refusal, no further advertising mail may be sent.
- Labeling duty (current Art. 4). As set by MIC order, the message must show the sender's name and address, the email address for opt-out notices, and other prescribed information. Before 2008, messages had to be tagged "未承諾広告※" ("unsolicited advertisement"); the opt-in scheme replaced that with these disclosure requirements.
- False sender information is prohibited (Art. 5), and this is a direct criminal offence. Sending to fictitious addresses generated by a program is also prohibited (Art. 6). ISPs may refuse service to such senders (Art. 11).
- How enforcement works. MIC and the Consumer Affairs Agency issue administrative orders (Art. 7), and can carry out on-site inspections and collect reports (Art. 28), ask ISPs for information about their contractors (Art. 29), and share information with enforcement agencies abroad (Art. 30). Recipients and ISPs report spam through the registered organisation (Dekyo's Anti-Spam Consultation Center).
- Penalties. Breaking Art. 5 (false sender information) or an administrative order is punished by up to 1 year in prison or a fine of up to ¥1,000,000. The employing corporation can be fined up to ¥30,000,000 (Arts. 34–35).
- A separate opt-in regime for e-commerce advertising email exists in the Specified Commercial Transactions Act, overseen by the Ministry of Economy, Trade and Industry (METI). Advertisers must comply with both.
APPI touchpoints for marketers
The Act on the Protection of Personal Information (APPI), enforced by the PPC (Personal Information Protection Commission), governs the address data itself. The PPC publishes English translations. The consolidated PDF used here is the text as amended in June-2020, and a version consolidated to 1 Apr 2023, with renumbered articles, is on the PPC legal page. Only the Japanese text has legal effect.
The duties that matter for marketing:
- Specify and publish the purpose of use, and stay within it.
- Providing personal data to a third party requires prior consent, or the notified opt-out mechanism, which is filed with the PPC and cannot be used for sensitive data. This is what restricts selling and sharing lists.
- Keep records of what data was provided.
- Obtain consent for transfers to third parties outside Japan, with information about the destination country, unless the country is on the approved list (the EU and the UK have mutual adequacy decisions with Japan).
- Stop using the data on request where it is being handled unlawfully.
The 2020 amendment (in force from Apr 2022) raised corporate fines to up to ¥100M for certain violations, such as ignoring PPC orders or providing a database unlawfully.
New Zealand: Unsolicited Electronic Messages Act 2007
The Electronic Messaging Compliance Unit of the Department of Internal Affairs (DIA) administers and enforces the Act. It covers commercial electronic messages (email, SMS or TXT, fax, instant messages, image messages) with a New Zealand link: messages sent to, from or within New Zealand, not only to .nz addresses. Pop-ups and voice calls are excluded. The regime deliberately mirrors Australia's (Spam Act), and DIA presents it as three steps:
- Consent
- Express: a direct indication, such as a form, a checkbox or a spoken agreement. Keep records, because the sender must prove consent.
- Inferred: from conduct and an ongoing business relationship, where the recipient can reasonably expect messages. DIA describes its use as "limited". A single purchase does not create ongoing inferred consent. A business card supports only messages relevant to the relationship in which it was exchanged. A tertiary institution messaging its enrolled students about campus services qualifies.
- Deemed (conspicuous publication): an address conspicuously published in a business or official capacity (on a website, in a brochure or in a directory) counts as consent, unless it is published with a statement that unsolicited messages are not wanted. It covers only messages relevant to the person's business, role, functions or duties.
- Identify: clearly identify the business that authorised the message and how to contact it. The contact details must stay accurate for 30 days after sending.
- Unsubscribe: every message needs a working unsubscribe facility that is clear and conspicuous, free, and uses the same medium as the message. An SMS campaign must accept a reply of STOP, and offering an email-only unsubscribe for SMS breaches the Act. The facility must keep working for ≥ 30 days, and requests must be honoured within 5 working days, counted from the day after the request.
Address-harvesting software, and lists of harvested addresses used to send unsolicited commercial messages, are also prohibited.
Penalties. DIA escalates from formal warnings and civil infringement notices to court proceedings. Failure to comply risks fines of up to NZ$500,000 for organisations. DIA states the $500K figure; the Act, in s 45, sets NZ$200,000 for individuals. Recipients forward spam complaints to DIA (to 7726 for TXT messages).
Singapore: Spam Control Act 2007 and PDPA
There are two layers. The Spam Control Act (SCA) regulates the sending of unsolicited commercial electronic messages in bulk: email and mobile messages, including messages to instant-messaging accounts, with a Singapore link. The Personal Data Protection Act 2012 (PDPA) regulates the use of the address, and the PDPC requires opt-in consent for direct marketing.
Sources: the SCA text comes from Wikisource's transcription and from Wayback Machine captures of Singapore Statutes Online, because sso.agc.gov.sg loads its content late and blocks automated retrieval. The PDPC Advisory Guidelines on Key Concepts (PDF, revised 29 Apr 2026) were retrieved through the Wayback Machine from the pdpc.gov.sg URL listed in the sources.
Spam Control Act mechanics
- "Sending in bulk" (s 6) means more than 100 messages on the same or a similar subject in 24 hours, 1,000 in 30 days, or 10,000 in 1 year.
- Dictionary attacks and address-harvesting software (s 9). Messages may not be sent to addresses generated or obtained by either method, whatever the consent or the content.
- Requirements of the Second Schedule for unsolicited commercial messages sent in bulk (s 11):
- Unsubscribe facility: an email address (and, for mobile messages, a number that can receive text messages) that is valid and can receive requests for at least 30 days after sending, at no more than the usual cost. After an unsubscribe request, no further messages may be sent once 10 business days have passed.
- Labeling: an
<ADV>marking, so that the message is clearly identified as an advertisement. Under the Act and its regulations, it goes in the subject line or, if there is no subject line, prominently in the message. - Accurate header and sender information: no false or misleading subject line or header, and an accurate, working email address or telephone number for the sender.
- Enforcement is by civil action, not by a regulator. Anyone who suffers loss may sue (ss 13–14). Statutory damages are up to $25 per message, with a total cap of $1 million, unless the actual loss is greater. Aiding or abetting a breach can also be sued over (s 12). The First Schedule excludes some messages, such as government or emergency messages in the public interest.
PDPA layer (PDPC Advisory Guidelines on Key Concepts)
- Business contact information is excluded from the Data Protection Provisions: a name, title, business phone number, business address or business email address that was not provided only for personal purposes. Prospecting to corporate addresses in B2B does not need consent under the PDPA, although the SCA still applies to bulk sends.
- Direct marketing needs express opt-in consent. The Personal Data Protection Regulations 2021 state that deemed consent by notification does not apply to sending direct marketing messages (¶12.27), and the PDPC "does not consider the opt-out method (e.g., a pre-checked box) appropriate" for consent to marketing (¶12.28).
- Deemed consent by conduct covers only purposes that are objectively obvious from the transaction. Booking a taxi is not consent to be marketed a limousine service.
- Lists from third parties. An organisation that buys data must take care to confirm that the seller validly obtained consent to disclose it, through contractual undertakings, written confirmation, or copies of the evidence of consent (¶¶12.33–12.34).
- Withdrawal of consent (s 16 PDPA) must be allowed and made easy. The PDPC's rule of thumb for "reasonable notice" is that a withdrawal takes effect within 10 business days (¶12.41). When consent is withdrawn, the organisation must also make its data intermediaries and agents stop processing the data (¶12.52). A general "unsubscribe" click is read as withdrawing consent only for the channel the message was sent through (¶¶12.47–12.48).
- ESPs are "data intermediaries". An intermediary that processes data on behalf of another organisation, for that organisation's purposes and under a written contract, is subject only to the Protection, Retention Limitation and Data Breach Notification obligations (for the last one, it must notify its customer). The customer organisation remains fully liable, as if it had processed the data itself (s 4(3), ¶¶6.15–6.27). Processing overseas triggers the customer's Transfer Limitation Obligation.
- Singapore's Do Not Call Registry covers telephone numbers (voice, SMS and fax), not email.
South Korea: Network Act Article 50 (and PIPA)
Article 50 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Network Act") governs the "transmission of advertising information for profit" through any electronic medium. The Personal Information Protection Act (PIPA), overseen by the PIPC, governs the underlying data. The Korea Communications Commission (KCC) enforces the spam rules, with operational support from the Illegal Spam Response Center of KISA.
Sources: the text of the provisions comes from the official English translation of the Network Act by the Korea Legislation Research Institute (KLRI), consolidated up to the amendments of 23 Jan 2024. The law.go.kr page listed in the sources (a partial amendment in 2026, lsiSeq=282481) works only with JavaScript and could not be read directly, so the KLRI translation was used instead.
- Opt-in (Art. 50(1)). The addressee's express prior consent is required. Exception 1: a sender that collected the contact details directly in a transaction may advertise the same kind of goods or services it deals in to that customer within a period set by Presidential Decree. The Enforcement Decree sets 6 months from the end of the transaction (a figure from the decree; the Act delegates it). Exception 2 covers telemarketers under the Door-to-Door Sales Act (voice calls).
- Refusal or withdrawal (Art. 50(2)). Once the addressee refuses or withdraws consent, sending is prohibited, even where the transaction exception applied.
- Night-time rule (Art. 50(3)). Sending between 21:00 and 08:00 the next day requires separate express consent, except for media set by Presidential Decree. The Decree exempts electronic mail, so the rule applies to SMS and push notifications, not to email (a detail from the decree).
- Mandatory disclosures (Art. 50(4)). The advertisement must state the sender's name and contact details and the means by which the addressee can easily refuse or withdraw consent. For email, the Enforcement Decree requires the "(광고)" ("advertisement") marking at the start of the subject line (a detail from the decree).
- Prohibited evasion tactics (Art. 50(5), amended Jan 2024). Blocking or evading opt-out; generating addresses automatically by combining characters (dictionary attacks); registering phone numbers or email addresses automatically for sending; hiding the sender's identity or the source of the transmission; and using deceptive tricks to get responses.
- Free opt-out (Art. 50(6)). The addressee must not pay any cost (for example, call charges) to refuse or withdraw consent.
- Notice of the result (Art. 50(7)). The sender must tell the addressee the outcome of processing their consent, refusal or withdrawal. Under the Decree this is done within 14 days, as commonly implemented (a detail from the decree).
- Regular reconfirmation (Art. 50(8)). Senders must regularly check that the addressee still consents. The Enforcement Decree sets a 2-year cycle (a figure from the decree).
- Outsourced sending (Art. 50-3). A business that has a third party send its advertisements must control and supervise that party. For liability for damages, the contracted sender is treated as an employee of the business. This is the Korean equivalent of "you cannot outsource your risk", and it applies directly to ESPs.
- ISPs may refuse service used for sending in breach of the rules (Art. 50-4). Programs that display advertisements or collect data need the user's consent (Art. 50-5). Posting advertisements on websites needs the operator's consent (Art. 50-7).
- Penalties.
- Breaches of Art. 50(1)–(3) (sending without consent, after a refusal, or at night), (4) (missing or false disclosures), (6) (passing costs to the addressee) and (8) (no reconfirmation) carry an administrative fine of up to ₩30,000,000 (Art. 76(1)7–9-2).
- The evasion tactics in Art. 50(5) are criminal, punished by up to 1 year in prison or a fine of up to ₩10,000,000 (Art. 74(1)4), and the corporation is jointly liable (Art. 75).
- PIPA adds separate, heavier sanctions for collecting or using the personal data itself unlawfully.
ESP triage view
- All four countries punish unsubscribe failures separately from consent. The same one-click, free, no-login flow built for Australia and CASL satisfies New Zealand (5 working days), Singapore (10 business days), Japan (stop on refusal) and Korea (stop immediately and send a notice of the result).
- Labels are the trap specific to these countries.
<ADV>(Singapore, for unsolicited bulk mail) and (광고) (Korea) go in the subject line. Korea also restricts channels other than email at night. - Korea and Japan both make falsifying the sender and lists of automatically generated addresses criminal offences. Refuse such lists at onboarding (see Spam Traps and Consent Methods).
- Japan (APPI), Singapore (PDPA) and Korea (PIPA) each add a data protection layer with its own rules on consent and transfers for the address data. For an ESP acting as a processor, Singapore's PDPA model of the "data intermediary" states the split of responsibilities most clearly.
This is not legal advice. See the compliance notice.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- CAN-SPAM Act (United States)
- CAN-SPAM Rulemaking (16 CFR Part 316)
- CASL — Canada's Anti-Spam Legislation
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail