All guides
Email

Email Marketing Laws by Country: CAN-SPAM, GDPR, CASL & More

A plain-English guide to email marketing laws by country: CAN-SPAM, GDPR, PECR, CASL, Spam Act, POPIA, NDPA, DPDP and more, with consent rules and a checklist.

By Sahil Aggarwal, Founder, Growvia · September 26, 2026 · 16 min read

You built a good list. Customers in Texas, London, Toronto, Dubai and Lagos all asked to hear from you. Then a question lands in your head: which rules actually apply when you hit send? The honest answer is that it depends on where each reader is, not where you are.

That sounds scary, but it is manageable. Most email laws share the same core ideas: be honest about who you are, get permission when required, make leaving easy, and keep records.

This guide covers the US, UK, EU, Canada, Australia, UAE, Nigeria, Kenya, South Africa and India, plus a comparison table, consent wording, cold B2B email rules and a checklist. This is general information, not legal advice; check with a local lawyer for your situation.

Opt-in vs opt-out: the two models behind every law

Opt-out (permission assumed until refused)

Under an opt-out model, you may send commercial email without prior consent. The reader can then tell you to stop, and you must listen. The US is the best-known example.

Opt-in (permission first)

Under an opt-in model, you need consent before you send marketing. Consent usually has to be freely given, specific and recorded. The EU, UK (for individuals), Canada, Australia and South Africa all lean this way. Most also allow a narrow exception for existing customers, often called the soft opt-in or implied consent.

Why the difference matters

Each reader's own rule applies, so many small businesses just run opt-in for everyone. One standard is easier to manage than ten.

United States: CAN-SPAM and state laws

The US uses the CAN-SPAM Act. It applies to any commercial email, including B2B messages.

CAN-SPAM requirements

The FTC's CAN-SPAM compliance guide lists the main requirements:

  1. Don't use false or misleading header information, including From, To and Reply-To.
  2. Don't use deceptive subject lines.
  3. Identify the message as an ad, unless the reader has given affirmative consent.
  4. Include a valid physical postal address.
  5. Tell readers how to opt out, clearly and conspicuously.
  6. Honour opt-out requests within 10 business days.
  7. Keep the opt-out working for at least 30 days after you send.
  8. Monitor anyone who sends email on your behalf. You stay responsible.

You can't charge a fee to unsubscribe. You can't ask for more than an email address and opt-out preferences.

CAN-SPAM penalties

According to the FTC, each separate email that breaks the law can cost up to $53,088. That figure took effect in January 2025. The FTC later published a notice saying it would make no inflation adjustment in 2026 and would keep applying the 2025 levels.

Transactional messages

Receipts, shipping updates and account notices are mostly exempt, but their routing information must still be accurate.

State laws

CAN-SPAM overrides most state email laws, but not those aimed at falsity or deception. In 2025, Washington's Supreme Court read that state's email law as covering misleading subject lines. So never fake urgency, discounts or deadlines.

EU and UK: GDPR, ePrivacy and PECR

In the EU, two laws work together. The GDPR governs personal data in general. The ePrivacy Directive sets the specific rules for marketing email.

EU: consent for marketing email

For individuals, ePrivacy requires prior consent before you send marketing email. GDPR then sets the bar for that consent. It must be freely given, specific, informed and unambiguous. Pre-ticked boxes and silence don't count. You must also be able to prove when and how someone agreed.

EU: the soft opt-in

Article 13(2) of the ePrivacy Directive allows an exception for existing customers. You may email someone without fresh consent when all of these are true:

  • You got their email address in the context of a sale of a product or service.
  • You are marketing your own similar products or services.
  • You gave them a clear, free chance to refuse when you collected the address.
  • You give them that chance again in every message.

B2B email in the EU

This is where member states differ. Some, like Germany, expect consent even for many business emails. Others are more relaxed for corporate addresses. Whatever the local rule, GDPR still applies when the address names a person, such as anna.schmidt@company.de. You need a lawful basis, often legitimate interests, and you must honour objections.

EU: GDPR penalties

GDPR fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher.

UK: individuals vs corporate subscribers

In the UK, marketing email falls under PECR and the UK GDPR, enforced by the ICO. PECR treats addresses differently by owner. The ICO's B2B marketing guidance explains it well:

  • Individuals, sole traders and some partnerships need consent or the soft opt-in.
  • Corporate subscribers, such as limited companies and LLPs, can receive marketing without consent. You must identify yourself and offer an opt-out.

UK GDPR still applies to named business addresses. So keep a suppression list and honour every objection.

UK: what the Data (Use and Access) Act 2025 changed

The Data (Use and Access) Act 2025 received Royal Assent in June 2025. Two changes matter most for email marketers, and both took effect on 5 February 2026:

  • Higher PECR fines. The old cap of £500,000 is gone. PECR fines now match UK GDPR levels: up to £17.5 million or 4% of global annual turnover, whichever is higher.
  • A charity soft opt-in. Charities can now email supporters about their charitable purposes without consent, if they meet conditions set out in the ICO's charitable purpose soft opt-in guidance.

For most businesses, the daily rules are the same. Mistakes just cost far more now.

Canada and Australia: CASL and the Spam Act

Canada's Anti-Spam Legislation (CASL) is among the strictest email laws anywhere. It covers B2B too.

Canada: express vs implied consent

The CRTC's CASL FAQ sets out two types of consent.

Express consent is a clear "yes", given in writing or orally. It has no expiry date, but people can withdraw it at any time. Pre-checked boxes are not allowed.

Implied consent applies only in set situations. The main ones are:

  • An existing business relationship from a purchase, valid for two years.
  • An inquiry or application, valid for six months.
  • A conspicuously published business address, with no statement refusing messages, where your message relates to the person's role.

Once an implied window closes, you need express consent to continue.

Canada: identification and unsubscribe

Every message must identify the sender and include contact details. It also needs an unsubscribe mechanism. You must process requests without delay, and no later than 10 business days. The mechanism must keep working for at least 60 days after you send.

Canada: CASL penalties

The CRTC can impose penalties of up to $1 million per violation for individuals and up to $10 million for businesses. Directors and officers can be personally liable if they directed or authorised a breach.

Australia: Spam Act 2003

Australia's Spam Act 2003 is enforced by the ACMA. It applies to commercial email, SMS and instant messages with an Australian link.

The ACMA's guidance on avoiding spam boils the law down to three rules:

  1. Consent. Express consent is best, such as ticking a box or signing up. Inferred consent may apply where there is an existing relationship and the message relates to it.
  2. Identify. Accurately name your business and include contact details that stay valid for 30 days after sending.
  3. Unsubscribe. Include a working unsubscribe in every message. Honour requests within 5 working days. Keep it working for 30 days. Don't charge a fee or ask for extra details.

The Act also bans address-harvesting software and lists built with it.

UAE, Nigeria and Kenya: data protection laws that cover marketing

These countries have no dedicated anti-spam act. Their data protection laws cover marketing email instead.

UAE

The main law is Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law (PDPL). The official UAE government portal notes that it generally prohibits processing personal data without consent. It also notes that the Consumer Protection Law restricts suppliers from using consumer data for marketing. The PDPL gives people a right to object to direct marketing.

Two points need care. The PDPL's executive regulations had not been fully issued at last check, so details may still change. And free zones such as DIFC and ADGM have their own separate data protection laws. The TDRA, the telecoms regulator, oversees spam rules for messages on UAE networks. For UAE audiences, opt-in consent plus an easy unsubscribe is the safe default.

Nigeria

Nigeria's Data Protection Act 2023 (NDPA) is enforced by the Nigeria Data Protection Commission (NDPC). It requires a lawful basis for processing, with consent the usual basis for marketing. People have the right to object to processing for direct marketing. The NDPC's General Application and Implementation Directive (GAID) took effect on 19 September 2025 and adds detail on how to comply.

Penalties for data controllers of major importance can reach the higher of ₦10 million or 2% of annual gross revenue. Lower caps apply to smaller controllers.

Kenya

Kenya's Data Protection Act 2019 is enforced by the Office of the Data Protection Commissioner (ODPC). Section 37 limits commercial use of personal data unless you have consent or legal authority. The Data Protection (General) Regulations 2021 add specific rules. You may market to someone when you collected their data yourself, told them it would be used for marketing, got consent, and gave them a free, simple opt-out they haven't used.

The ODPC has fined firms for unsolicited marketing without consent or an opt-out. Treat Kenya as opt-in.

South Africa and India

South Africa: POPIA section 69

Section 69 of South Africa's POPIA bans electronic direct marketing unless the person has consented or is an existing customer. The Information Regulator enforces it and published a guidance note on direct marketing in 2024.

Key rules under section 69:

  • One chance to ask. You may approach someone once to request consent, and only if they haven't already refused.
  • Customer exception. You may email existing customers about your own similar products or services. You must have collected their details during a sale and offered a free opt-out at that time.
  • Every message must identify you and include a way to opt out.

POPIA also protects "juristic persons", meaning companies. So B2B email is not a loophole in South Africa. Administrative fines can reach R10 million.

India: DPDP Act 2023 and DPDP Rules 2025

The government notified the DPDP Rules on 14 November 2025, according to the Press Information Bureau. Compliance is phased over 18 months. The Data Protection Board provisions started straight away. Consent manager rules follow at 12 months. The core duties, including notice and consent, apply after 18 months, around May 2027.

Consent under the DPDP Act must be free, specific, informed and unambiguous, with a clear affirmative action. People can withdraw it as easily as they gave it. Maximum penalties run up to ₹250 crore for security failures, and up to ₹50 crore for other breaches.

India has no specific anti-spam law for email. TRAI rules cover calls and SMS. Use the time left to move Indian contacts onto recorded opt-in.

Comparison table: email marketing laws by country

A simplified summary. "B2B cold email" means a first email to a business contact without prior consent.

CountryMain lawConsent modelB2B cold email allowed?Unsubscribe ruleRegulator
United StatesCAN-SPAM ActOpt-outYes, with CAN-SPAM rulesHonour within 10 business daysFTC
European UnionGDPR + ePrivacyOpt-in, soft opt-in for customersVaries by member stateEasy, free, every messageNational DPAs
United KingdomPECR + UK GDPROpt-in for individualsYes to corporate subscribersOpt-out in every messageICO
CanadaCASLOpt-in (express or implied)Only with implied consent, e.g. published addressWithin 10 business days, works 60 daysCRTC
AustraliaSpam Act 2003Opt-in (express or inferred)Only with inferred consentWithin 5 working days, works 30 daysACMA
UAEPDPL + Consumer Protection LawConsent-basedRisky, get consentRight to objectUAE Data Office, TDRA
NigeriaNDPA 2023Lawful basis, usually consentRisky, needs lawful basisRight to objectNDPC
KenyaDPA 2019 + 2021 RegulationsOpt-inRisky, needs consentFree, simple opt-outODPC
South AfricaPOPIA s69Opt-in, one consent requestOne request onlyOpt-out in every messageInformation Regulator
IndiaDPDP Act 2023 + Rules 2025Opt-in (phasing in)Risky once rules applyWithdraw as easily as givenData Protection Board

Cold B2B email: how to do it legally by region

Cold email is legal in some places and risky in others.

Where it is broadly allowed

  • United States. Allowed if you follow CAN-SPAM: honest headers and subject, postal address, working opt-out.
  • UK, to corporate subscribers. Allowed to limited companies and LLPs. Not to sole traders or most partnerships without consent.

Where it needs a specific basis

  • Canada. Only with implied consent, such as a conspicuously published work address with no "no spam" notice, and a message relevant to the person's job.
  • Australia. Similar inferred consent rules apply to published work addresses.
  • EU. Depends on the member state. Check local rules before emailing a country for the first time.

Where to avoid it

In South Africa, you get one request for consent and that's it. In Kenya, UAE and Nigeria, consent is the safest basis. Once India's DPDP duties apply, treat it the same.

A safer cold email routine

  1. Email one relevant person, about their actual role.
  2. Say who you are and how you found their address.
  3. Keep it short and offer a one-line way to say no.
  4. Add anyone who declines to your suppression list at once.
  5. Stop follow-ups the moment they reply.

Consent wording examples

For a newsletter form:

"Yes, send me the monthly newsletter with tips and offers from [Business]. I can unsubscribe at any time."

For a quote or contact form, with an unticked box:

"Also email me occasional offers and updates. You can unsubscribe in one click."

For the soft opt-in at checkout:

"We'll email you about similar products. Untick this box if you'd rather not hear from us."

Avoid vague phrases like "marketing purposes". Say what people will get and how often.

Double opt-in

Double opt-in sends a confirmation email after signup, and the person clicks to confirm. No law above strictly requires it. But it proves the address is real and the owner agreed, and it keeps typos and fake signups out.

What to record for every contact

Most laws put the burden of proof on you. Keep these details for each contact:

  • The date and time they gave consent.
  • The source, such as a form name, page URL or event.
  • The exact wording they agreed to.
  • The IP address or other proof, where available.
  • Any later changes, including unsubscribes.

Handling unsubscribes

The safest standard is the fastest one. Gmail and Yahoo now expect unsubscribes processed within two days. That beats every legal deadline above. Keep unsubscribed addresses on a suppression list forever, so they never get re-imported by mistake.

Why you shouldn't buy email lists

Bought lists fail almost every consent test, because nobody on them agreed to hear from you. In Australia, lists built with harvesting software are banned outright. Bought lists also carry old, dead and trap addresses, which damage your sender reputation. If you inherit a list, clean it and re-confirm consent before you send. Our email deliverability guide to SPF, DKIM and DMARC explains why reputation is so hard to rebuild.

Sending from one country to another: which law applies?

The short answer: the recipient's location usually decides. A business in India emailing someone in Canada must follow CASL.

GDPR applies to businesses outside the EU when they offer goods or services to people in the EU. CASL applies when a message is accessed from a computer in Canada. Your own country's law may apply too.

For a mixed list, you have two practical options:

  1. Segment by country and apply each rule to each segment.
  2. Use one global standard based on the strictest rules: opt-in consent, clear identity, and a fast, easy unsubscribe.

Most small businesses choose the second, because it is simpler. Our WhatsApp Business API guide covers opt-in for chat.

Gmail and Yahoo bulk sender rules: the de facto global law

Even where the law is relaxed, the inbox providers are not. Since 2024, Gmail and Yahoo have enforced firm bulk sender rules, wherever you send from.

Google's sender guidelines FAQ defines a bulk sender as anyone sending close to 5,000 or more messages to personal Gmail accounts in 24 hours. Key rules include:

  • Authenticate your domain with SPF, DKIM and DMARC.
  • One-click unsubscribe in marketing messages, using the List-Unsubscribe header (RFC 8058).
  • Process unsubscribes within 48 hours.
  • Keep spam rates low. Google says to stay below 0.1% and never reach 0.3% or higher.

Yahoo's sender best practices match closely: spam rate below 0.3%, one-click unsubscribe, and unsubscribes honoured within two days. Google said it was ramping up enforcement from November 2025, including temporary and permanent rejections.

Smaller senders should follow them too. They protect you as you grow.

Compliance checklist

Use this before every campaign. If you're planning a full month of marketing, add it to your 30-day marketing plan.

CheckWhy it mattersWhere it's required
Consent recorded with date, source and wordingProves you had permissionEU, UK, Canada, Australia, South Africa, Kenya, India
Accurate From name and honest subject lineAvoids deception claimsEverywhere, especially US
Business name and contact details in footerIdentifies the senderUS, Canada, Australia, South Africa, Kenya
Physical postal addressLegal requirementUnited States
Visible unsubscribe link in every emailLets people leave easilyEverywhere
One-click unsubscribe headerInbox provider requirementGmail and Yahoo bulk senders
Unsubscribes processed within 2 daysBeats every legal deadlineGmail, Yahoo, and all laws
Suppression list kept permanentlyStops re-mailing people who leftEverywhere
Implied consent windows trackedConsent expiresCanada (2 years, 6 months)
No bought or harvested listsFails consent and hurts reputationEverywhere
Spam rate under 0.3%Keeps you out of spam foldersGmail and Yahoo

Tools can take some of this load. In Growvia, every campaign includes a one-click unsubscribe, and bounced or unsubscribed contacts are skipped automatically. Website forms built in Growvia also record consent with the source and time, so your records stay in one place.

Frequently asked questions

Is cold email legal?

It depends on where the recipient is. In the US, cold email is legal if you follow CAN-SPAM. In the UK, you can email corporate subscribers without consent. In Canada, Australia and South Africa, you need a specific basis such as implied consent, or you can make only one consent request.

Which law applies if I'm in India and email customers in the US?

Mainly the law where the recipient is, so CAN-SPAM applies to your US readers. India's DPDP Act may also apply to how you handle that data. If your list mixes countries, follow the strictest rule across all of them.

Do I need double opt-in to comply with GDPR?

No. GDPR does not require double opt-in. It requires consent you can prove. Double opt-in is a strong way to prove it, which is why many EU senders use it.

How long does implied consent last under CASL?

Implied consent from a purchase lasts two years. Implied consent from an inquiry or application lasts six months. After that, you need express consent to keep sending marketing.

Can I email people whose addresses I found on their website?

In the US, yes, if you follow CAN-SPAM. In Canada and Australia, a published work address can give implied or inferred consent if your message relates to their role and they haven't said "no spam". Elsewhere, especially South Africa and the EU, it is much riskier.

What is the CAN-SPAM fine per email?

The FTC says each email that breaks CAN-SPAM can cost up to $53,088. That is the 2025 inflation-adjusted figure, which the FTC kept for 2026.

Put this into practice with Growvia

Audit your website, track Google rankings and AI mentions, send follow-ups and manage every lead and message in one place. Free forever plan, 14-day Pro trial, no card.

Start growing free

More guides