MailCleanup

Email Compliance: CAN-SPAM, GDPR, CASL, CCPA, and What Each One Actually Costs You

Search “email compliance” and you land in one of two different conversations. Half the results are about encrypting internal messages and meeting SEC retention rules, a compliance officer’s problem. The other half cover consent, unsubscribe links, and whether you’re even allowed to email someone in the first place, a marketer’s problem. This guide is about the second one.

If you send marketing emails, a newsletter, product updates, or a straight promotional campaign, four laws decide what email compliance actually means for you. CAN-SPAM covers the US, GDPR covers the EU, CASL covers Canada, and CCPA/CPRA covers California. Each sets its own consent rules, its own penalties, and its own definition of who counts as your subscriber. None of them care about your encryption policy.

Here’s what most email marketing compliance guides don’t tell you: the fine is rarely the real cost. We verify email lists for a living, and the pattern is consistent. Lists built on weak or purchased consent don’t just carry legal risk, they carry measurably worse deliverability outcomes, long before a regulator gets involved. What email verification actually catches before that risk reaches your send is worth understanding on its own. We’ll show you exactly where the compliance connection shows up later in this guide.

TL;DR on Email Compliance

  • Email compliance for marketers means four specific laws, CAN-SPAM, GDPR, CASL, and CCPA/CPRA, not the archiving-and-retention meaning the same phrase carries in regulated industries.
  • CAN-SPAM runs on opt-out consent, with a $53,088 per-email maximum penalty. GDPR and CASL require opt-in before the first message instead, with fines running into the tens of millions for the most serious violations.
  • Which laws apply to your program depends on subscriber location and, for GDPR specifically, active targeting behavior, not just where the business is based. CCPA/CPRA adds a separate revenue and data-volume threshold on top.
  • In MailCleanup’s own verification data, 27.34% of addresses processed needed real scrutiny before sending. That’s the kind of risk weak-consent list-building is most likely to produce, independent of which specific law gets broken.
  • HIPAA, PCI DSS, and ADA each add requirements beyond the four core marketing laws, bounded but real obligations most compliance guides skip entirely.

What Is Email Compliance for Marketers?

Email compliance for marketers means following the specific laws that govern consent, sender identification, and how people leave your list. It has nothing to do with the archiving and data-retention meaning used in regulated industries like finance and healthcare.

For most senders, four laws set the actual rules, and they don’t all work the same way. These are the email compliance regulations that actually govern a marketing send, not the dozens of adjacent rules a lawyer might also mention:

  • CAN-SPAM (US): opt-out consent. You can email someone without asking first, as long as you honor their request to stop.
  • GDPR (EU): opt-in consent required before you send anything at all.
  • CASL (Canada): opt-in consent required too, with a narrower set of exceptions than GDPR allows.
  • CCPA/CPRA (California): not a consent law in the same sense. It’s a data-rights law that governs what subscribers can demand you disclose or delete, and it applies once your business crosses specific size thresholds.

The opt-in versus opt-out split isn’t a minor technicality. It changes what “compliant” actually requires before you send a single email. Under CAN-SPAM, you can build a list from a trade show badge scan, a purchased contact, or a bare signup form, then start emailing. No prior permission required. You’re compliant as long as every message carries a working unsubscribe link and honest sender information. Under GDPR and CASL, that same list is illegal to email from day one. Both laws require proof of affirmative action, someone actively ticking an unchecked box, before their first message goes out.

Neither law treats “affirmative action” as loosely as you might assume. A pre-checked box doesn’t count. The EU’s top court ruled on this directly in 2019, in the Planet49 case, and confirmed it again in 2020. A checkbox someone has to actively uncheck isn’t consent, because consent has to come from action, not inaction. Bundling it into your terms of service doesn’t work either. GDPR requires marketing consent to be requested separately from any other agreement, not folded into one checkbox covering several things at once.

There’s one genuine exception worth knowing, because it catches most senders off guard: the soft opt-in. Collect an email address during a sale, give a clear chance to decline marketing, and get no objection, and you’re in soft opt-in territory. You can email them about similar products without a separate opt-in step. All of that has to hold at once: the sale, the chance to decline, and every message staying limited to similar products. Miss one condition and you’re back to needing explicit consent before you send anything.

Which Email Compliance Regulations Actually Apply to You?

Which laws actually govern your email compliance depends on two things: where your subscribers live, and where your business operates. Not just one or the other, and the one that matters most surprises most senders.

Decision Diagram Showing Which Of Four Email Compliance Laws, GDPR, CASL, CCPA or CPRA, And CAN-SPAM, Applies Based On Subscriber Location And Business Size
  • Your subscribers include EU residents → GDPR applies, regardless of where your business is based.
  • Your subscribers include Canadian residents → CASL applies, regardless of where your business is based.
  • Your subscribers include California residents, and your business meets CCPA’s size thresholds → CCPA/CPRA applies.
  • You send commercial email from the US, to anyone, anywhere → CAN-SPAM applies to that message.
  • More than one of these is true at once → the strictest standard governs your process, even for messages a looser law would otherwise allow.

GDPR’s reach specifically trips up US-based senders who assume no EU office means they’re outside its scope. That’s not how Article 3 works. GDPR applies once you’re actively targeting EU customers, not just whenever one happens to sign up. Regulators look for real signals of intent. Pricing listed in euros, an EU-language signup form, shipping to EU addresses, or a country-code domain like .de or .fr all count.

A US company picking up an EU subscriber through organic search, with no EU pricing, language, or shipping, has a weaker GDPR case. One running EU-targeted ad campaigns has a much stronger one. Neither is a guarantee either way, but targeting behavior is what regulators actually evaluate, not a subscriber’s location by itself.

CCPA/CPRA’s threshold gets cited as “$25 million” more often than not, and that figure is stale. It adjusts for inflation, and for the 2026 compliance year it’s $26,625,000 in annual gross revenue, counted globally, not just California sales. You’re also covered if you buy, sell, or share the personal information of 100,000 or more California consumers or households a year. The same is true if 50% or more of your annual revenue comes from selling or sharing personal data, regardless of total revenue. A business well under the revenue threshold can still be in scope through the data-volume test alone.

Most of the confusion we see starts with assuming location alone decides this. Getting this right matters more as your email marketing compliance program expands into new regions, not less. It’s your subscriber’s location, and in GDPR’s case, your actual targeting behavior, not your office address, that determines what applies.

CAN-SPAM Email Compliance: The Seven Core Requirements

CAN-SPAM is the US federal law governing commercial email, enforced by the FTC, and it’s the baseline every US sender’s email compliance starts from. It doesn’t require consent before you send, the opt-out model covered earlier, but it does require every commercial message to clear seven specific requirements. Miss any one and the message is a violation, regardless of intent.

  1. Accurate header information. Your “From,” “To,” and routing information must honestly identify who sent the message, including the domain name and email address. SPF, DKIM, and DMARC are the technical mechanisms that let a receiving server verify that identification is genuine, not spoofed.
  2. Non-deceptive subject lines. The subject line can’t misrepresent what’s actually inside the email.
  3. Clear identification as an advertisement, where the message’s primary purpose is commercial.
  4. A valid physical postal address. A street address, PO box, or registered commercial mail receiving agency all satisfy this, but your message needs one.
  5. A visible, working opt-out mechanism in every message.
  6. Honoring opt-out requests within 10 business days, with no fee, no login requirement, and no information demanded beyond an email address.
  7. Monitoring what others do on your behalf. You’re liable for a violation even if an agency or affiliate sends the message under your name.

None of this requires bad intent. A missing address or a broken unsubscribe link triggers a violation on its own. Enforcement comes from the FTC, state attorneys general, and internet service providers, not individual recipients suing directly. There’s no private right of action for most people CAN-SPAM protects. Outsourcing your sending doesn’t transfer the liability either. If you hire an agency or an affiliate to send on your behalf, you’re still on the hook. What goes out under your name is your liability.

The penalty itself is steeper than most guides report, and more precisely dated too. The FTC’s civil penalty maximum sits at $53,088 per individual violating email, not per campaign. That figure has been current since a January 2025 inflation adjustment. The 2026 update that would normally follow was suspended by the Office of Management and Budget, so $53,088 remains operative through this year. A lot of compliance content still quotes the older $51,744 figure from 2024.

That per-email structure is what makes the exposure real: a single campaign to 10,000 addresses carries 10,000 individual violations if it’s non-compliant, not one. The FTC’s largest CAN-SPAM settlement to date, $2.95 million against Verkada Inc. in August 2024, shows regulators do pursue this at scale. Actual settlements typically land well below the theoretical maximum, though.

One clarification that trips up B2B senders specifically: CAN-SPAM doesn’t exempt business email. A note to your own past client about a new product line is covered exactly the same as a cold consumer blast. The opt-out model does mean B2B cold outreach to a work address is legal without prior consent, friendlier ground than GDPR or CASL allow. None of that changes just because CAN-SPAM email compliance feels like a domestic, low-stakes law compared to GDPR. Every other requirement still applies in full: the address, the opt-out link, the honest headers.

Getting Email GDPR Compliance Right: Consent, Rights, and Penalties

GDPR gives you six lawful bases for processing personal data in general, and email compliance under it rests mainly on two of them. Getting email GDPR compliance right starts with knowing which of those two actually applies to your situation. For actual marketing emails, only consent, covered earlier, and legitimate interest are realistically in play. The other four, contractual necessity, legal obligation, vital interests, and public task, essentially never apply to a newsletter signup.

Legitimate interest lets you process data without asking permission first, if you can document a genuine three-part case. That means a real purpose, actual necessity, and a balancing test showing the person’s privacy rights don’t outweigh your interest. Direct marketing to existing customers is explicitly named as a valid legitimate interest under GDPR’s own Recital 47. In practice, though, the ePrivacy Directive layers its own opt-in requirement on top of GDPR for electronic marketing specifically. That’s why the soft opt-in exception, not a bare legitimate-interest argument, is what actually lets most senders email existing customers without fresh consent. Relying on legitimate interest instead means documenting that three-part test yourself, not just asserting it.

GDPR also hands your subscribers eight specific rights, and you need a working process for each one, not just a policy that mentions them:

  1. Access to a copy of the data you hold on them.
  2. Rectification of inaccurate data.
  3. Erasure, the “right to be forgotten.”
  4. Restriction of processing.
  5. Data portability, a copy in a usable format.
  6. Objection to processing, including opting out of your marketing specifically.
  7. Rights related to automated decision-making, including profiling.
  8. Withdrawal of consent at any time, as easily as it was given.

Every request gets a response within one month. Miss that window and it’s a violation independent of whatever the original request concerned.

There’s a practical checkpoint most email marketers skip. Your email service provider is processing personal data on your behalf, which makes it a processor under GDPR. That relationship needs a Data Processing Agreement in writing. Working through a real GDPR email compliance checklist before you launch in a new region catches most of this in advance. Before you sign with an ESP or a list-verification tool, confirm one exists. It’s a standard document at this point, and any vendor that can’t produce one is a real flag, not a technicality to skip past.

Two things sit outside a marketer’s direct control but are still worth knowing exist:

  • A Data Protection Officer becomes mandatory for public authorities, and for organizations whose core business involves large-scale systematic monitoring or large-scale sensitive-data processing.
  • A data breach has to be reported to the relevant supervisory authority within 72 hours of your organization becoming aware of it.

Neither is usually the marketing team’s job to execute. But an email list is exactly the kind of thing that gets breached, so knowing the clock exists is worth more than not knowing.

GDPR’s penalty structure runs two tiers, not one flat number:

TierCoversMaximum
LowerRecord-keeping failures, processor agreement violations, missed breach notifications€10 million or 2% of global annual turnover, whichever is higher
UpperCore violations: unlawful processing, ignored data subject rights, invalid consent€20 million or 4% of global annual turnover, whichever is higher

Most compliance content quotes only the €20 million or 4% figure, as if it’s the only number email compliance regulations set. A processor agreement you never signed, or a breach notification you filed late, falls under the lower tier. That’s still real money, before you’ve touched a single core violation.

CASL Email Compliance: Consent, Requirements, and Penalties

CASL, Canada’s Anti-Spam Legislation, is the third piece of email marketing compliance most senders need to track. It applies to any commercial electronic message sent from Canada or received there. Location doesn’t shield you either way. A US company emailing Canadian subscribers is in scope, and so is a Canadian company emailing abroad.

Consent under CASL comes in two forms, and they don’t work the same way. Real CASL email compliance starts with knowing which consent type, express or implied, actually covers a given contact. Express consent means someone actively opted in, and it never expires, though they can withdraw it anytime. Implied consent is temporary and only holds under specific relationships:

  • An existing business relationship, from your own purchase, lease, or contract within the last two years, or an inquiry within the last six months.
  • An existing non-business relationship, membership, volunteering, or similar ties.
  • A referral from someone with an existing relationship to both you and the recipient.
  • Conspicuously published contact information, if the message relates to the recipient’s role or business.

One detail most guides skip: an email asking someone for consent is itself a commercial electronic message under CASL. You can’t use an unsolicited email to go get the permission you need to send it.

Every compliant message needs three things: clear identification of who’s sending it, a working unsubscribe mechanism, and valid consent behind it. The unsubscribe link specifically has to keep working for 60 days after the message, not just at the moment you send.

CASL’s penalties run steep: up to $10 million CAD per violation for a business, enforced by the CRTC. This isn’t a law you can afford to guess at. A real case resulted in a $1.1 million penalty for sending without proper consent. One structural detail worth knowing: CASL’s private right of action would have let individuals sue directly. It was suspended indefinitely in 2017 and still hasn’t come into force. Enforcement runs through the CRTC alone, the same shape as CAN-SPAM’s FTC-only enforcement, not through private lawsuits. That’s one more place where email compliance risk sits with regulators, not competitors or customers directly.

CCPA Email Compliance: What California’s Privacy Law Actually Requires

CCPA/CPRA doesn’t ask permission before your first send the way GDPR and CASL do, which makes its email compliance angle genuinely different. Real CCPA email compliance starts with knowing whether your business even meets the size thresholds in the first place. It hands subscribers rights over data you’ve already collected. For email specifically, the right that matters most is opting out of having that data sold or shared.

“Shared” is broader than it sounds. The CPRA amendments defined it to cover cross-context behavioral advertising, not just a direct sale for cash. Regulators have confirmed that any exchange of data for value counts, monetary or not. If your email platform passes subscriber data to an ad network for targeting, that can qualify even if no money changes hands.

Two specific mechanics apply directly to email programs:

  • A “Do Not Sell or Share My Personal Information” link, clear and conspicuous, wherever you disclose that you sell or share data.
  • Global Privacy Control signal recognition. When a subscriber’s browser sends this signal, you have to treat it as a valid opt-out automatically, no separate action required from them.

Two enforcement actions show what actually gets punished, and neither should feel abstract if you’re running email campaigns at any real scale. Sephora paid $1.2 million in 2022 for not disclosing a data sale and ignoring Global Privacy Control signals. It was the first CCPA settlement not tied to a breach. Disney’s $2.75 million settlement, the largest to date, centered on opt-out failures specifically. That’s exactly the kind of request your own unsubscribe or preference flow has to honor. Neither involved a hack or a leak. Both were process failures, the kind your own team controls directly.

Penalties run $2,500 per unintentional violation and $7,500 per intentional one, both adjusted for inflation the same way the revenue threshold is. One structural difference from the other three laws: CCPA carries a limited private right of action. It only covers data breaches caused by inadequate security, not a missed opt-out or an absent disclosure link. You still answer to the California Privacy Protection Agency and the Attorney General alone for those.

The Email Compliance Risk Grid

Four laws, four different mechanisms, and if you’ve read email compliance content before, most of it compares them two at a time. CAN-SPAM against GDPR, or GDPR against CCPA, never all four side by side against the same categories. Here’s what actually differs once they’re lined up:

Comparison Grid Of CAN-SPAM, GDPR, CASL, And CCPA or CPRA Across Who Each Law Applies To
LawApplies ToConsent ModelCore RequirementVerified PenaltyDeliverability Risk If Ignored
CAN-SPAMCommercial email from the US, to any recipientOpt-outHonest headers, working unsubscribe, physical address$53,088 per email (FTC, current since Jan. 2025)No consent requirement removes the natural check a list would otherwise get before its first send.
GDPRAny business actively targeting EU subscribersOpt-inDocumented lawful basis, honored data subject rights€20M or 4% of global turnover, whichever is higherForced opt-in tends to filter out the weakest addresses before they ever reach a list.
CASLCommercial email sent from or received in CanadaOpt-in, express or time-limited impliedIdentification, 60-day working unsubscribe, valid consent$10M CAD (CRTC; no active private right of action)Same opt-in-quality effect as GDPR, filtering happens at signup, not after.
CCPA/CPRABusinesses meeting California’s size or data-volume thresholdsNot consent-based; opt-out of sale or sharingDo-Not-Sell/Share link, GPC signal honored, timely request response$7,500 per intentional violation; limited private right of action for breaches onlyNot directly tied to list quality. A violation here is a disclosure or process failure, not a sign of a dirty list.

The asymmetry in that last column is real, not smoothed over for a tidier row. Three of these four laws gate whether you can send in the first place. That gate happens to correlate with list quality as a side effect. CCPA doesn’t gate sending at all. It governs what you disclose and honor after someone’s already on your list. That’s exactly why a business can be fully CCPA-compliant while still mailing a list full of invalid and disposable addresses.

Real CASL email compliance and CCPA email compliance both still matter even where GDPR doesn’t reach. Compliance with one doesn’t substitute for the others, whatever stage your email marketing compliance program is at. This table is the fastest way to see why.

Industry-Specific Email Compliance Rules Most Guides Skip

Everything covered so far applies regardless of industry. Three more rules apply only if your business touches specific kinds of data, and most email compliance guides never mention any of them.

Comparison Of HIPAA, PCI, And ADA Email Compliance Obligations

Email HIPAA Compliance

HIPAA doesn’t cover every email a healthcare business sends, which is where its email compliance rules differ most from the other four. It covers email that uses or discloses Protected Health Information, PHI, and the bar for what counts is lower than most marketers expect. “Reminder: your follow-up is scheduled for 3pm” references PHI. A general newsletter about seasonal flu prevention, sent to a mailing list with no connection to anyone’s specific care, generally doesn’t.

Once PHI is genuinely involved, two things become mandatory. First, prior written authorization from the patient before you use their PHI for marketing, a materially higher bar than an ordinary opt-in checkbox. Second, a signed Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on your behalf, your ESP included. A vendor that won’t sign a BAA isn’t a compliant option, no matter how good the platform otherwise is.

PCI Email Compliance

PCI DSS isn’t a law, though it still shapes your email compliance obligations if you handle payment data. It’s a private security standard set by the payment card industry and enforced through your merchant agreement, not a government regulator. That distinction changes what non-compliance actually costs: higher processing fees or a revoked ability to accept cards, not a fine from an agency.

The rule that matters for email: full card numbers never go out over email, encrypted or not, under Requirement 4.2. This mostly isn’t a marketing-email problem. It shows up in transactional flows, receipts, order confirmations, failed-payment notices, where a full card number can end up embedded by accident. Masking to the last four digits and linking to a secure page for anything more keeps your receipts out of PCI’s reach entirely.

ADA Email Compliance

ADA email compliance is the least legally settled of the three rules here. The ADA doesn’t name email anywhere in its own text. No government body has issued a formal technical standard, so you’re working from case law and guidance rather than a fixed checklist. Courts have treated the ADA as covering digital communications since 2017, though. When accessibility cases do reach email, they point to the Web Content Accessibility Guidelines as the working standard. That means alt text, real color contrast, and content a screen reader can actually parse. Template by template, that’s [its own full breakdown, in a dedicated email accessibility guide].

How Consent Fits Into Email Compliance From the Start

Consent doesn’t exist in isolation from the rest of your email compliance program. It’s one piece of the broader email marketing practice, and getting it right early avoids rebuilding your list later.

CAN-SPAM’s opt-out model means you can start sending before consent exists. GDPR and CASL don’t, and this is where the actual mechanism matters, not just the legal requirement. Single opt-in adds an address to your list the moment someone submits a signup form, no further verification involved. Double opt-in adds one more step. Your system fires a confirmation email immediately after signup. Only a click on the link inside that email moves the address onto your active list.

That single extra click does two things at once. It proves the person who entered the address can actually access that inbox, catching typos and addresses entered by someone other than their owner. And it creates a timestamped, documented record that consent was real and freely given. That’s exactly what GDPR and CASL both require you to be able to show, not just claim.

The tradeoff is real, not hypothetical. Confirmed subscribers from your double opt-in flow tend to open and click at meaningfully higher rates than a single opt-in list of comparable size. Everyone on it chose to be there twice. The cost is volume: a real share of people who fill out the form never click the confirmation. They’re gone before they ever became a subscriber. [Double opt-in against single opt-in, including where each one genuinely wins, gets a full comparison of its own in a dedicated post].

Unsubscribe Requirements Every Email Compliance Program Needs

Every law covered so far requires some working form of opt-out in your own program, but the baseline has moved past a footer link. The actual mechanism behind that shift is worth understanding, not just the deadline. Google and Yahoo’s bulk sender rules require one-click unsubscribe, not just any working link, for senders pushing 5,000 or more daily messages, since 2024. Microsoft added the same requirement in 2025.

The mechanism runs through two headers on your own emails, not visible page design: List-Unsubscribe and List-Unsubscribe-Post. Together they tell Gmail, Yahoo, and Outlook to render their own native “Unsubscribe” button right next to the sender’s name. This happens before the recipient even opens the message. A click sends a simple request straight to your server: no landing page, no login, no second confirmation. You have 48 hours to actually process it.

Those headers also need to sit inside a valid DKIM signature, or mailbox providers will ignore them even if everything else is configured correctly. The entire point is friction removal. Someone who can leave your list in one click has far less reason to hit Report Spam instead. That’s exactly the behavior every complaint-rate threshold in this guide is measuring. [Implementing one-click unsubscribe correctly is a header-level detail worth its own separate walkthrough].

A single unsubscribe link removes someone entirely, the only option it gives. A preference center adds a middle option: let someone cut frequency or drop one specific topic without leaving the list altogether. For a compliance program specifically, that middle option matters. Several of the rights covered earlier, GDPR’s restriction right and CCPA’s sale opt-out, are satisfied by scaling back what you send, not full removal. It also keeps more of your list genuinely engaged instead of gone for good. [Building a preference center that actually works gets the same treatment in its own dedicated post].

What Email Compliance Failures Actually Cost You Beyond the Fine

Compliance and list quality aren’t the same test, but they’re not unrelated either. A list built on real, verified opt-in is, by definition, addresses a real person actively confirmed wanting your mail. A list built by skirting consent, purchased addresses, scraped ones, or CAN-SPAM’s opt-out loophole pushed to its limit, is a different kind of list. Old, abandoned, mistyped, or outright fake, nobody actually vetted any of it.

We verify email addresses for a living, and here’s what that looks like at real scale. In MailCleanup’s most recent two-month verification window, through July 2026, 27.34% of the addresses we processed needed real scrutiny before anyone sent to them. That splits between outright undeliverable, accept-all, and genuinely unknown. Spam traps showed up at roughly 8 per million addresses verified.

That’s a small number until a single live trap hit starts dragging down sender reputation for an entire domain. None of this claims which specific list-building method produced which address; that data cut doesn’t exist in what we track. It’s a real, current picture of how much risk sits inside an average unverified list. Weak-consent list-building is exactly the practice most likely to hand you that risk without warning.

Email Compliance Cost - MailCleanup Verification Data Breakdown

That risk turns into an email compliance cost no law’s penalty schedule captures. Gmail and Yahoo require bulk senders to keep spam complaints under a specific threshold just to keep sending at all. A list full of addresses nobody actually opted into is a direct path to crossing it. Miss that threshold and the consequence isn’t a fine. It’s your email landing in spam for everyone, compliant recipients included.

Common Email Compliance Mistakes

The same handful of email compliance mistakes are ones you’ll see across lists and industries. Most trace back to a handful of email compliance regulations getting confused with each other, not real ignorance of any single one.

  • Assuming B2B email is exempt from CAN-SPAM. It isn’t. The opt-out model applies the same way to a past client of yours as to a cold consumer list.
  • Using a pre-checked consent box for EU or Canadian subscribers. GDPR and CASL both require an affirmative, unchecked action, and a pre-ticked box has failed a real CJEU ruling since 2019.
  • Treating a footer unsubscribe link as sufficient once you’re sending in bulk. Gmail, Yahoo, and now Microsoft require the header-level one-click mechanism, not just any working link.
  • Confusing CCPA’s opt-out with an unsubscribe request. Opting out of data sale or sharing and opting out of marketing email are two separate rights under two different mechanisms.
  • Assuming all healthcare business email you send needs HIPAA-level lockdown. Only messages that actually use or disclose PHI trigger it. A general newsletter with no patient-specific content usually doesn’t. Real email HIPAA compliance hinges on PHI, not industry alone.
  • Quoting penalty figures without checking the current number before you cite them. CAN-SPAM’s cap moved from $51,744 to $53,088 in January 2025. CCPA’s revenue threshold moved from $25 million to $26,625,000. Both still get cited at the old figure regularly.

Email Compliance Checklist

Everything above compresses into one email compliance checklist you can actually run. Not every item here applies to every email marketing compliance program, industry-specific rows included. Not every business touches every one of these email compliance regulations.

Email Compliance Checklist Organized Into Four Categories

Consent and data

  • Opt-in consent captured through an unchecked, affirmative action for any EU, Canadian, or otherwise opt-in-governed subscriber
  • Consent records kept and dated in your own systems, not just assumed to exist
  • Soft opt-in conditions documented if you’re relying on it for existing customers

Every message

  • Accurate sender information and a valid physical postal address
  • Subject lines that don’t misrepresent the content
  • A working, header-level one-click unsubscribe on any list of yours over 5,000 daily messages
  • Opt-out requests honored within CAN-SPAM’s 10-day window and CASL’s 60-day link requirement

Data rights

  • A Data Processing Agreement in place with your ESP and any list-verification vendor
  • A working process for access, deletion, and correction requests within the applicable window
  • A “Do Not Sell or Share My Personal Information” link if CCPA/CPRA applies to your business

Think of the GDPR-specific rows here as your own working GDPR email compliance checklist, not just a subset of a longer list.

Industry-specific

The rows below only apply if HIPAA, PCI, or ADA genuinely touch your program. Real PCI email compliance and ADA email compliance both only matter in specific, narrower cases than the four core laws covered earlier.

  • A Business Associate Agreement with any vendor touching PHI, if HIPAA applies to you
  • No full card numbers in any email, transactional flows included
  • Alt text, real contrast, and screen-reader-friendly structure on every template

Make This Checklist Part of Your Regular Email Compliance Routine

Four laws, three industry overlays, and a checklist won’t keep your email compliance accurate on their own. Every specific figure in this guide has moved at least once in the past two years. CAN-SPAM’s penalty ceiling rose in January 2025, and CCPA’s revenue threshold adjusted upward the same way. Microsoft joined Gmail and Yahoo’s one-click unsubscribe requirement in 2025 without much advance warning. None of those shifts made headlines outside compliance circles, so if you’re not checking for them, you won’t hear about them elsewhere either. A guide, or a checklist, written even a year ago is already carrying at least one stale number.

The realistic starting point isn’t rereading this whole guide from scratch every quarter. It’s the checklist above, run against whichever laws you identified as applicable using the framework earlier in this guide. Add a standing reminder to re-verify any specific figure before it goes into a contract, a policy, or your own documentation. Routine list verification belongs in that same habit. A compliant list that’s gone stale still creates the deliverability risk covered earlier, whether or not any law was actually broken.

FAQs on Email Compliance

Do small businesses have to follow email compliance laws?

Yes, most email compliance laws apply regardless of company size. CAN-SPAM, GDPR, and CASL don’t exempt small businesses. CCPA/CPRA is the one exception, applying only once your business crosses $26,625,000 in annual revenue or handles 100,000 California consumers’ data a year.

Can I email people I met at a trade show without asking first?

Generally yes, under CAN-SPAM’s opt-out model, as long as every message you send includes a working unsubscribe link and honest sender information. GDPR and CASL are stricter, requiring opt-in consent if those contacts are in the EU or Canada. CASL’s own implied-consent window only lasts 6 months from an inquiry, a real email compliance trap for anyone assuming a badge scan counts indefinitely.

Is it legal to buy an email list and send marketing to it?

Under CAN-SPAM, yes, as long as every message meets the law’s email compliance requirements: honest headers, a working unsubscribe link, and a physical address. For your EU or Canadian subscribers, GDPR or CASL says no. Both require affirmative opt-in consent before the first send, and a purchased list, by definition, never collected that consent directly.

What’s the difference between CAN-SPAM and GDPR?

CAN-SPAM runs on opt-out consent: you can email someone without asking first, as long as you honor their unsubscribe request. GDPR requires opt-in consent before you send anything at all. That single difference is the most common email compliance mistake senders make when expanding from the US into the EU.

Do I need double opt-in to be GDPR compliant?

Not strictly, but it’s the practical way most senders actually prove consent was real rather than just claimed. GDPR requires affirmative opt-in before you send. Double opt-in, a confirmation click before someone’s officially subscribed, is the clearest record that this email GDPR compliance requirement was actually met.

Can I email existing customers without getting new consent?

Often yes, through GDPR and CASL’s soft opt-in exception. Collect their address during an actual sale, give them a clear chance to decline marketing, and get no objection, and you’re covered. You can email them about similar products without a fresh opt-in step, a genuine email compliance shortcut most senders don’t know exists.

Do transactional emails have to follow the same rules as marketing emails?

No, and this distinction matters more than most senders realize when you’re deciding what needs consent. A password reset or order confirmation is transactional and generally exempt from opt-in consent requirements. That same email including a discount code or product recommendation crosses into marketing territory, where the full email compliance rulebook applies again.

How much can I be fined for a CAN-SPAM violation?

Up to $53,088 per individual email, not per campaign, current since a January 2025 FTC adjustment. A single non-compliant campaign of yours to 10,000 addresses carries 10,000 separate violations in theory. Real settlements typically land well below that maximum, but the per-email structure is exactly why CAN-SPAM email compliance can’t be treated casually.