If your list crosses borders, so do your obligations. Email marketing laws by country differ in their details — some ask for permission before the first message, others let you mail until someone opts out — but they rhyme far more than they clash. Once you strip away the acronyms, nearly every major regime is built on the same few ideas: get permission in some form, say who you are, make leaving easy, and stop when asked. This guide is the high-level map of that landscape — a tour of the big regimes and the practical throughline that runs through all of them.
Why the same four ideas keep coming back#
Read the statutes side by side and a pattern appears. The differences are real and worth understanding, but they are variations on a small set of themes rather than five unrelated rulebooks. Almost everywhere, a compliant marketing message does four things.
First, it rests on some form of permission. What counts as permission is the biggest point of variation — full prior opt-in in some places, a narrower existing-relationship allowance in others, a right to opt out in the most permissive. Second, it identifies the sender honestly: accurate header information, a real name, and often a physical postal address. Third, it offers a clear, working way to unsubscribe — and, just as importantly, it honours those requests. Fourth, running underneath all of it, is the expectation that you only mail people you actually have a basis to mail, which is really a list-hygiene discipline dressed up in legal language.
Email marketing laws by country at a glance#
The table below sketches the consent model and the core requirement for the regimes that cover the largest share of Western inboxes. It is a starting map, not the territory — each of these laws carries definitions, exceptions, and edge cases the summary cannot hold, which is exactly why the detail articles and your own counsel matter.
| Region | Main law | Consent model | Core requirement |
|---|---|---|---|
| United States | CAN-SPAM Act | Opt-out | Truthful headers, a physical address, and honour opt-outs promptly |
| Canada | CASL | Opt-in (express or implied) | Consent, sender identification, working unsubscribe |
| EU & UK | GDPR + ePrivacy / PECR | Consent, with a limited soft opt-in | Valid lawful basis, easy withdrawal, clear identification |
| Australia | Spam Act 2003 | Consent (express or inferred) | Consent, accurate sender details, functional unsubscribe |
| Many other countries | Their own national laws | Varies (often opt-in) | Usually some mix of the four ideas above |
United States: CAN-SPAM and the opt-out model#
The US CAN-SPAM Act is the most permissive of the major regimes on the consent question: it does not generally require prior permission to send a commercial email. Instead it sets rules for how you send. Header and routing information must be accurate, subject lines must not deceive, messages must be identifiable as advertising where relevant, and every commercial email must include a valid physical postal address.
The part that trips senders up is the exit. CAN-SPAM requires a clear opt-out mechanism and requires you to honour opt-out requests — the well-established window is within 10 business days — after which you must not keep mailing that person. You are also responsible for messages sent on your behalf, so you cannot outsource your way out of the rules. Enforcement can carry substantial per-email civil penalties, which is a strong practical reason to treat the opt-out plumbing as seriously as the send itself. The dedicated CAN-SPAM compliance guide walks through each requirement in turn.
Canada: CASL and consent up front#
Canada's Anti-Spam Legislation, universally shortened to CASL, sits at the other end of the spectrum and is often described as one of the strictest email regimes in the world. Its default is consent: in most cases you need permission before you send a commercial electronic message. That consent can be express — someone actively agreeing — or implied, which covers situations such as an existing business relationship and generally comes with time limits.
On top of consent, CASL asks for two familiar things: clear identification of who is sending (and how to reach them) and a working unsubscribe mechanism that you action promptly. Because implied consent expires and express consent has to be documented, CASL rewards senders who keep clean records of who agreed to what and when. The CASL compliance guide covers express versus implied consent and the identification rules in more depth.
EU and UK: GDPR, ePrivacy, and the soft opt-in#
In the EU and the UK, two layers of law meet. The GDPR governs personal data generally and requires a lawful basis for processing the addresses on your list, while the ePrivacy rules — the ePrivacy Directive across the EU and the Privacy and Electronic Communications Regulations (PECR) in the UK — govern electronic marketing specifically. Together they make consent the usual route for marketing email to individuals: freely given, specific, informed, and unambiguous, with the right to withdraw it at any time.
There is one important carve-out. A limited soft opt-in lets a business email existing customers about its own similar products or services, provided the person was given a clear chance to opt out when their details were collected and in every message since. It is narrower than it sounds and does not cover cold prospects or bought lists. Alongside consent sit the same basics — honest sender identification and an easy way out. For the marketing-specific angle see the GDPR email marketing guide, and for how these rules touch list cleaning and data residency, the GDPR and email verification guide goes deeper.
Australia: the Spam Act 2003#
Australia's Spam Act 2003 is consent-based and, like CASL, recognises both express consent and inferred consent from an existing relationship. It is often summarised as three obligations: send only with consent, identify the sender accurately, and include a functional unsubscribe facility that you act on promptly. The shape is by now familiar — the same permission, identification, and easy-exit trio that shows up everywhere, with Australia's own definitions layered on top.
Everywhere else: assume a law exists#
The four regimes above are not the whole world. A great many other countries — across Latin America, Asia, the Middle East, and Africa — have their own marketing or data-protection laws, and comprehensive privacy legislation has been spreading steadily. Some closely mirror the GDPR's consent-first approach; others borrow from the opt-out model; many blend the two. This article cannot be exhaustive, and no short overview should be treated as covering the specific countries you mail into.
The safe working posture is simple: if you send to a country, assume it has rules worth checking, and get local advice before you rely on a border being "quiet." The good news is that the four-idea throughline travels well. A programme built to get permission, identify itself, and honour unsubscribes cleanly tends to satisfy the spirit of most regimes, even before you tune it to the letter of any one.
What this means in practice#
You do not run five separate email programmes for five sets of laws. In practice you run one disciplined programme and let it clear the highest bar that applies to each recipient. That comes down to a handful of durable habits.
Collect permission deliberately and keep the evidence — the difference between single and double opt-in is partly a consent- quality question, and a confirmed opt-in gives you a cleaner record of who agreed. Identify yourself honestly in every message, physical address included where it is required. Make unsubscribing trivial and instant: a visible link, plus one-click unsubscribe support, with requests suppressed promptly and permanently. And keep the list itself clean — regular list cleaning removes dead and risky addresses, while email verification catches invalid mailboxes before you send to them, so you are only ever mailing addresses you actually have a basis to reach.
None of that is a compliance guarantee — the law is applied to your facts, not to a checklist. But these habits are the operational core that every regime above assumes, which is why they are worth building once and running everywhere. The email compliance checklist turns them into a concrete, repeatable routine.
Frequently asked questions#
Which email marketing law applies to me?#
Generally, the law of the place you send to matters, not just where your company is based — so if you email people in Canada, the EU, the UK, or Australia, those countries' rules can apply to those messages regardless of where you sit. Many senders reach recipients in several regimes at once, which is why building to the strictest bar that applies to each recipient is a common practical approach. A qualified lawyer can tell you which specific laws govern your programme.
Do I always need consent to send marketing email?#
It depends on the jurisdiction. Canada, Australia, and the EU and UK are built around consent (with limited exceptions such as an existing relationship or the EU/UK soft opt-in), while the US CAN-SPAM Act is opt-out and does not generally require prior permission to send a commercial email. Because a single campaign often reaches recipients under different regimes, many senders default to gathering permission everywhere and keeping records of it.
What is the difference between opt-in and opt-out laws?#
Opt-in regimes require some form of permission before you send, so the burden is on you to have and document consent. Opt-out regimes let you send until the recipient asks to stop, putting the emphasis on an easy, promptly honoured unsubscribe. Most of the world's stricter laws are opt-in; the notable opt-out example among major markets is the US CAN-SPAM Act. Both models still require honest sender identification and a working way to unsubscribe.
Does keeping my list clean help with compliance?#
It supports the operational habits these laws assume, though it is not a substitute for legal advice. Verifying addresses and regularly cleaning your list means you are mailing real, engaged recipients rather than dead or risky addresses, and suppressing unsubscribes and bounces promptly is exactly the kind of hygiene that honouring opt-out requests requires. It is one part of a compliant programme, alongside proper consent and identification.
Good list hygiene is the habit every one of these regimes quietly assumes: honouring unsubscribes, suppressing dead addresses, and mailing only people you actually have a basis to reach. Qualisend helps with that layer — try the free email checker on a sample, or start with 100 free credits to clean a real list before your next send.