Email Marketing Strategy

Email Marketing Compliance: GDPR, CAN-SPAM, and CCPA Explained

What each law actually requires of a sender, where they contradict each other, and the defaults that satisfy all three.

4 min read 9 of 10 in this topic Updated August 2026

On this page

The short version

  • The three regimes differ most on one question: whether you need permission before sending, or only a way out afterwards.
  • Where they conflict, the strictest requirement is the safe default, and adopting it costs less than maintaining separate practices per jurisdiction.
  • Records are the part that gets skipped. Being compliant and being able to demonstrate compliance are different things.

This is a plain-language summary of what these laws ask of a sender, not legal advice — the details vary by circumstance and the penalties are real enough to be worth a lawyer's time if you are unsure. What follows is the shape of the obligations and where they disagree.

The single most useful thing to understand is that GDPR is a consent regime, CAN-SPAM is an opt-out regime, and CCPA is primarily a data rights regime that touches email indirectly. They are answering different questions, which is why complying with one tells you very little about the others.

What each regime actually requires

The obligations differ in kind, not only in strictness
RequirementGDPR (EU/UK)CAN-SPAM (US)CCPA/CPRA (California)
Permission before sendingYes, freely given and specificNoNot directly
Proof of permissionYes, must be demonstrableNot requiredNot directly
Working unsubscribeYesYesNot directly
Unsubscribe honoured withinWithout undue delay10 business daysPer deletion rules
Physical postal addressNot specifiedYes, requiredNot specified
Honest headers and subjectYesYesYes
Right to see stored dataYesNoYes
Right to deletionYesNoYes
Applies based onWhere the person isWhere the message goesBusiness size and revenue

The last row is the one people get wrong. GDPR follows the individual, so an EU resident on a US company's list is still covered.

The defaults that satisfy all three

Rather than branching your practice by jurisdiction — which requires knowing where every subscriber is, reliably, forever — most senders adopt the strictest requirement across the board. It is simpler and it is defensible everywhere.

That means: explicit opt-in with an unticked box, a record of when and how consent was given, unsubscribe honoured immediately rather than within ten days, a postal address in every commercial send, and honest from-lines and subjects. None of these harm performance. Several improve it, because a list built on explicit consent engages better than one built on pre-ticked boxes.

The strict-default configuration

  • Opt-in is an affirmative action, never pre-ticked or bundled with terms acceptance
  • Consent record stores source, timestamp, IP and the exact wording shown
  • Unsubscribe is one click, works without login, and takes effect immediately
  • A valid postal address appears in every commercial message
  • From name, from address and subject line describe the message honestly
  • A documented process exists for access and deletion requests
  • Retention period for inactive subscribers is written down and applied

Soft opt-in and where it applies

Some jurisdictions allow contacting existing customers about similar products without fresh consent, provided the address was collected during a sale, an opt-out was offered at that point, and every message since has carried one. This is a genuine and useful exception.

It is also narrower than people assume. It covers similar products, not your whole catalogue, and it applies to customers rather than to anyone who once filled in a form. Treating it as a general permission to mail anyone who ever transacted is the most common way senders end up outside it.

Retention

Almost nobody has a stated retention period for email subscribers, and most regimes expect one. The question is simple: how long do you keep an address belonging to someone who has never engaged?

Answering it has a convenient side effect. The retention period you would defend to a regulator is usually close to the sunset threshold you should be applying for deliverability reasons anyway, so the compliance answer and the performance answer point the same direction.

Frequently asked questions

Does GDPR apply to a US business with no EU presence?

It can, because the regulation follows the individual rather than the sender. If you knowingly market to people in the EU or UK, it is in scope. This is why the strict-default approach is usually simpler than trying to segment by geography.

Is double opt-in legally required?

No regime named here requires it. It is a strong way to evidence consent and it improves list quality, but single opt-in with a proper record satisfies the requirement in most cases.

Can we email people who gave us a business card?

It depends on the jurisdiction and on what was said at the time. Handing over a card at an event is not, on its own, consent to a marketing list under a consent regime — record what was offered and agreed if you intend to rely on it.