Skip to content
Websites & online business

The rules for marketing email, and why they change at the border

Almost every guide to email marketing describes one regime and implies it is the rule everywhere. It is not. The United States lets you email someone who never asked, provided the message is honest and carries a working unsubscribe. The UK and EU do not. Canada goes further still and puts the burden of proving consent on the sender. This is what each one requires, and where a compliant US list becomes a liability the moment it crosses a border.

8 min readPublished How we write these

The short version

  • CAN-SPAM has no consent requirement. You may email someone who never asked, provided the header and subject line are accurate, the message is identified as an ad, carries a valid postal address and a working opt-out.
  • The UK and EU work the other way: no marketing email to an individual without specific consent, save for a narrow soft opt-in covering your own past customers and similar products.
  • Canada's CASL requires express or implied consent before sending, and the sender carries the burden of proving it. Maximum penalties are CAD $1 million for an individual and CAD $10 million for an organisation.
  • A receipt with a promotion at the top of it is a marketing email. The FTC decides category by primary purpose, and content order is part of the test.

The question people ask is "what do I have to put in the footer". The question that decides whether the campaign is lawful is earlier than that: was this person allowed to be on the list at all. The answer depends on where they are, and the three main regimes disagree at the root.

Three regimes, and only one lets you email a stranger

US (CAN-SPAM)UK / EU (PECR, ePrivacy)Canada (CASL)
Consent needed to send?NoYes, unless soft opt-in appliesYes — express or implied
B2B treated differently?No — the law covers itCorporate bodies yes; sole traders noNo — covers business addresses
Who proves consent?Not applicableThe senderThe sender
Unsubscribe deadline10 business daysWithout undue delay10 business days
The second row is the one that surprises UK senders: emailing a limited company is generally permitted, emailing a sole trader is not.

CAN-SPAM is a content and conduct statute, not a permission statute. It makes no exception for business-to-business email, and it applies to a single message, not just to bulk sends. What it does not do is ask whether the recipient wanted to hear from you.

A receipt with an offer in it is a marketing email

Transactional and relationship messages sit outside most of CAN-SPAM — they must not have misleading routing information, but need no ad label, no postal address and no unsubscribe. The categories are narrow: completing or confirming a transaction the recipient agreed to, warranty and safety information, a change in the terms or in the recipient's standing in an ongoing relationship, account balance information, employment and benefits information, and delivery of goods or services already bought.

Where it goes wrong is mixed content, and the test turns on order. The FTC's own worked examples make this concrete: an order confirmation with a one-line "visit our website for our new range" at the bottom is still transactional; the same email with the promotion at the top and the shipping confirmation at the bottom is a commercial message subject to every requirement in the Act.

Where a message lands, and what it then owes

Would a reasonable reader of the subject line and the opening think this is an ad?

No — and the transactional content leads

Transactional or relationship. Truthful headers only. No ad label, address or unsubscribe required — but include one anyway if you are unsure.

Yes — or the promotion sits at the top

Commercial. Every CAN-SPAM requirement applies to the whole message, and under PECR and CASL it needs a lawful basis to have been sent at all.

Being a customer does not make a message transactional. The FTC warns specifically against assuming that anything sent to subscribers or members falls in the exempt category.

What every commercial message must contain

The CAN-SPAM content requirements, in full

  • Accurate "From", "To", "Reply-To" and routing information, identifying who initiated the message.
  • A subject line that reflects what is actually in the message.
  • A clear and conspicuous disclosure that the message is an advertisement.
  • A valid physical postal address — a street address, a registered PO box, or a registered private mailbox.
  • A clear explanation of how to opt out, working through a reply or a single web page.
  • An opt-out mechanism that keeps working for at least 30 days after the send.
  • Opt-outs honoured within 10 business days, with no fee, no extra personal information and no additional steps.

Two of these carry more weight than their length suggests. The address cannot be a virtual office you have not registered. And you cannot contract out of any of it: the FTC is explicit that both the company whose product is promoted and the company that sent the message can be held responsible, so an agency doing this badly is your problem as well as theirs. Each separate email in violation is subject to penalties of up to $53,088 on the figure the FTC currently publishes.

Privacy policy template

Full text, free. Marketing consent has to be described somewhere people can read it — what you collect at signup, what you will send, and how to withdraw. This is where that lives.

Open

The soft opt-in is narrower than almost everyone treats it

Regulation 22 of PECR prohibits marketing email to an individual without specific consent. The exception, universally called the soft opt-in, applies only where all of the following hold: the person bought or negotiated to buy from you, the goods or services you are now marketing are similar, you gave them a simple way to opt out when you first collected their details, and you give them one in every message since.

Why "they are a customer" is not the whole answer

Was an opt-out offered at collection?

Did they buy, or negotiate to buy?

No

Yes

No

No lawful basis

A stranger with no opt-out offered. This is what a bought list looks like from the regulator's side.

Soft opt-in fails

Your customer, but the chance to refuse was never given. The exception is unavailable and consent was never obtained.

Yes

Consent needed

You asked properly, but they never bought. Nothing to rely on except the consent itself — so make it a real tick.

Soft opt-in available

Only for similar products, only from you, and only while every message still carries the opt-out.

The bottom-left cell is the one that generates ICO complaints: a genuine customer, a genuinely similar product, and no opt-out ever offered at the point of collection.

The exception does not stretch to prospects, to bought-in lists, or to a different product line you would like to cross-sell. It also does not cover non-commercial promotion — but that changed in one direction on 5 February 2026, when the Data (Use and Access) Act 2025 inserted a charitable purposes soft opt-in into PECR, letting charities email people who have expressed an interest in or offered to support their cause. The ICO published final guidance on it on 28 April 2026. It is a real widening, and it is charity-specific: it does nothing for commercial senders.

CASL is the strict one, and the burden of proof is yours

Canada requires consent before a commercial electronic message is sent, and splits it in two. Express consent is an affirmative act — a ticked box, a signed form, an oral agreement you have recorded — and lasts until the person withdraws it. Implied consent is time-limited: an existing business relationship arising from a purchase or contract runs for two years from the transaction, and an enquiry runs for six months.

Every message must identify the sender, give a mailing address and contact route that stays valid for at least 60 days after sending, and carry an unsubscribe mechanism that is given effect without delay and in any event within 10 business days. Maximum administrative monetary penalties are CAD $1 million for an individual and CAD $10 million for anyone else. Unlike CAN-SPAM, the sender must be able to show the consent existed — which is a record-keeping obligation dressed as a consent rule.

The clocks that start when you press send

Four deadlines running from one send

  1. Send

    Every clock starts

    Nothing about the send date resets a consent you already had, and nothing extends one that had lapsed.

  2. 10 business days

    Opt-outs honoured

    The US and Canadian deadline. In the UK and EU the standard is without undue delay, which in practice is faster.

  3. 30 days

    Opt-out link still working

    CAN-SPAM requires the mechanism to process requests for at least 30 days after the message went out.

  4. 60 days

    Contact details still valid

    CASL requires the mailing address and contact route in the message to remain live for at least 60 days.

Suppressing an address on the platform is not the same as honouring the opt-out: the address has to be blocked everywhere it lives, including in any list you have shared with a partner.

Why a purchased list fails in every regime at once

A bought list is not a consent problem in the United States, where no consent is needed — it is a deliverability and reputation problem, and a fraud problem if the seller misrepresented how the addresses were collected. In the UK, EU and Canada it is a straightforward breach: consent has to be given to you, not to whoever compiled the list, and the "consent" a data broker sells is almost never specific enough to name you.

The practical test is the one the ICO and CRTC both apply. Can you produce, for this address, the wording the person was shown, the box they ticked, the date, and the source? If not, you do not have consent — you have a spreadsheet. Keeping that record per subscriber is the single highest-value thing an email programme does, and it costs nothing at signup and a great deal to reconstruct afterwards.

Building for the strictest market you sell into

There is no version of this where you segment your way out cheaply. Location data at signup is unreliable, people move, and a single message to the wrong address is a violation in its own right. The workable answer is to collect consent to the Canadian standard everywhere, record it, and let the US and UK positions fall out of it — the cost is a slightly smaller list, and the benefit is a list you can defend.

What you promise at signup then has to match what your published pages say. The consent wording sits alongside the privacy policy and, where you are sending on behalf of sellers on a platform, the marketplace terms that decide whose list it is in the first place. The same discipline governs tracking pixels in the message itself — an open-tracking pixel is device access, and it is subject to cookie consent rules like any other tracker. Which of these pages you are obliged to publish at all is covered in which legal pages your website needs.

The uncomfortable conclusion for most senders is that the list is smaller than the CRM says. Addresses acquired without a recorded opt-in, addresses inherited in an acquisition, addresses that came from an event badge scan three years ago: none of them survive the test in the UK, EU or Canada. Deleting them is cheaper than defending them, and the deliverability improves.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Do I need permission before sending a marketing email?

It depends entirely on where the recipient is. Under US law you do not: CAN-SPAM regulates the content and the opt-out, not the permission. Under UK and EU rules you do, unless the narrow soft opt-in for your own past customers applies. Under Canada's CASL you need express or implied consent and must be able to prove it. If you sell internationally, collect consent as though the strictest rule applies.

Is it legal to buy an email list?

Buying the list is not itself unlawful, but using it usually is outside the United States. Consent under PECR and CASL must have been given to you, identified by name, for the kind of message you are sending. A broker cannot transfer that. In the US the list can be mailed lawfully if your message meets every CAN-SPAM requirement, though the deliverability damage is usually worse than the legal risk.

How quickly do I have to action an unsubscribe?

CAN-SPAM gives you 10 business days, and the opt-out mechanism must keep working for at least 30 days after the message was sent. CASL also allows 10 business days but requires the unsubscribe to be given effect without delay. UK and EU rules set no fixed number and expect it to happen without undue delay. Most platforms suppress immediately, which is the right default everywhere.

Does an order confirmation need an unsubscribe link?

A genuine transactional message does not — it needs only truthful routing information. But the category is narrow and decided by primary purpose. If the promotional content leads the message, or the subject line reads like an advertisement, it is a commercial message and every requirement applies. If a receipt carries anything more than an incidental promotion, treat it as marketing.

What records of consent should I keep?

For each address: the exact wording shown, what was ticked or clicked, the date and time, the source page or form, and the IP or account identifier where you have it. Under CASL and PECR the sender carries the burden of proof, so a record that cannot be produced is the same as no consent. Keep it for as long as you rely on the consent, plus a limitation period.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week