Email Marketing & Automation · Testing, metrics, reporting and compliance · lesson 14 of 16 · 16 min
Email compliance: CAN-SPAM, GDPR, PECR and beyond
Why compliance protects your business
Email laws exist to protect people from unwanted and deceptive messages. Following them protects your deliverability, reputation and finances. This lesson summarises key principles; it is not legal advice. Laws differ by country and change, so check official guidance or a qualified adviser for your situation.
United States: CAN-SPAM
The CAN-SPAM Act applies to commercial email. Key requirements:
- No false or misleading header information (From, To, Reply-To, routing).
- No deceptive subject lines.
- Identify the message as an advertisement where applicable (clearly and conspicuously).
- Include a valid physical postal address (a street address, a registered PO box or a private mailbox meeting postal regulations).
- Provide a clear opt-out mechanism that works for at least 30 days after sending, and honour opt-outs within 10 business days. You cannot charge a fee or require more than an email address and a simple action to opt out.
- Monitor what others do on your behalf: you remain responsible even if an agency sends the email.
CAN-SPAM is an opt-out law (it does not require prior consent for most commercial email), but mailbox provider rules and best practice strongly favour consent. Text messages fall under separate rules such as the TCPA, which generally require prior express consent for marketing texts.
UK and EU: GDPR/UK GDPR plus PECR/ePrivacy
- Consent for marketing emails to individuals: under the UK's PECR and similar EU rules, you generally need consent to send marketing emails to individuals. Consent must be freely given, specific, informed and unambiguous – a positive action such as ticking an unticked box.
- The soft opt-in (UK): you may email existing customers (or people who were in negotiations for a sale) about your own similar products or services without explicit consent, provided you gave them a simple chance to opt out when you collected their details and in every message. In the UK, the Data (Use and Access) Act 2025 extended a version of the soft opt-in to charities (for supporters who expressed interest in or support for their charitable purposes, with an opt-out offered). EU countries apply similar concepts with local variations.
- Business contacts: in the UK, PECR's consent rule for emails applies to individual subscribers (including sole traders and some partnerships), while emails to corporate subscribers are treated differently – but GDPR still applies to personal data such as named work emails, and you must always identify yourself and offer an opt-out.
- Transparency: privacy notices must explain how you use data.
- Records: keep evidence of consent.
- Rights: honour access, correction, deletion and objection requests. An objection to direct marketing is absolute – stop.
- Enforcement: the same 2025 UK Act raised maximum fines for PECR breaches (including unlawful marketing emails and texts) to up to £17.5 million or 4% of global turnover for conduct from February 2026.
Gulf and Pakistan
- UAE: the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) sets rules on consent and processing, and the Telecommunications and Digital Government Regulatory Authority (TDRA) has rules on unsolicited electronic communications. Financial free zones (DIFC, ADGM) have their own data protection laws.
- Saudi Arabia: the Personal Data Protection Law (PDPL), fully enforceable since September 2024, and its implementing regulations include rules on direct marketing, requiring consent and an opt-out mechanism; the Communications, Space and Technology Commission regulates unsolicited messages.
- Pakistan: the Prevention of Electronic Crimes Act 2016 addresses spamming and unsolicited messages, and data protection legislation has been under development. Check the current position.
Practical compliance checklist
- Documented, consent-based sign-up (or valid soft opt-in) for every subscriber.
- Clear sender identity and honest subject lines.
- Business name and postal address in every marketing email.
- Working one-click unsubscribe, processed promptly (Gmail and Yahoo require within two days for bulk senders; CAN-SPAM allows up to 10 business days – use the shortest applicable).
- Suppression list maintained and applied across all tools (email platform, CRM, WhatsApp).
- Privacy notice explaining email use and tracking.
- Agreements with processors (your email platform) as required by GDPR-type laws.
- Separate consent for different channels (email, SMS, WhatsApp) where required.
- Staff and agencies trained; no sending from personal tools that bypass suppression lists.
Transactional vs marketing emails
Transactional emails (order confirmations, password resets, receipts) generally have different rules because the recipient needs them. Keep them primarily transactional. Adding significant promotional content can turn them into marketing messages subject to marketing rules.
Worked example
A UK and UAE e-commerce brand audit finds: a pre-ticked marketing box at checkout, unsubscribes processed manually once a month and a separate SMS tool that does not use the suppression list. Fixes: unticked checkbox with clear wording, automatic one-click unsubscribe synced across the email platform and SMS tool, a soft opt-in notice for UK customers with an opt-out at checkout, and an updated privacy notice covering UAE PDPL requirements.
Common mistakes
- Assuming "they gave us their email for delivery" means consent for marketing (outside a valid soft opt-in).
- Deceptive subject lines or From names.
- Unsubscribes not synced across tools.
- Ignoring regional rules because the business is based elsewhere.
Hands-on: what a consent record should hold
Whatever tool you use, make sure you can answer "when, where, how and to what did this person agree?" for every subscriber:
subscriber_id 8f3c... (internal ID)
email sana@example.com
channel email (separate records for sms / whatsapp)
status subscribed | unsubscribed | suppressed
basis consent | soft_opt_in (UK) | legitimate_interest (B2B, where lawful)
source popup_summer_guide / checkout_optin / event_qr_riyadh
wording_version consent_v3_2026-05 ("Yes, email me the guide and news...")
timestamp_utc 2026-09-14T10:22:31Z
ip_address (as captured, if your policy allows)
double_opt_in confirmed_at 2026-09-14T10:24:02Z
unsubscribed_at null
unsubscribe_method null | one_click | link | reply | complaint
Hands-on: a quarterly compliance audit
[ ] Every sign-up form: unticked box, clear wording, privacy link, source captured
[ ] Double opt-in or equivalent proof of consent stored
[ ] Soft opt-in used only for own similar products, with opt-out at collection (UK)
[ ] One-click unsubscribe works; processed within 48 hours in EVERY tool
[ ] Suppression list synced: ESP, CRM, SMS, WhatsApp provider, ad custom audiences
[ ] Footer: business name, postal address, reason for receiving, privacy link
[ ] Transactional emails kept primarily transactional
[ ] Processor agreements (DPAs) in place with email, SMS and WhatsApp providers
[ ] Regional checks: UAE PDPL notice; KSA PDPL marketing consent; PK position reviewed
[ ] AI tools: no personal data in unapproved tools; AI replies disclosed where required
Worked example 2: a Pakistani brand selling to the UK and Gulf
A Lahore modest-fashion brand ships to the UK, UAE and Saudi Arabia. Its audit finds one global list with no country field and consent wording that only covers "order updates". Fixes: a new consent line at checkout ("Email me new collections and offers – unsubscribe anytime"), country captured from the shipping address, UK customers offered the soft opt-in with a clear opt-out box, a re-permission email to existing subscribers whose consent evidence was missing, and suppression synced between the email platform and WhatsApp provider. The list shrinks by a quarter but complaint rates fall and revenue per recipient rises.
How to measure success
- 100% of subscribers have a consent record with source, wording version and timestamp (or a documented soft opt-in basis).
- Unsubscribes processed within 48 hours across all tools – tested monthly with a seed address.
- Zero regulator complaints; quarterly audit completed and actions closed.
Video lecture: Email compliance: the rules that protect your list and your business
Lecture coming soon · 11 chapters · about 8 minutes. Read the full transcript below.
- Email compliance
- US: CAN-SPAM
- UK and EU
- More UK/EU points
- Gulf and Pakistan
- Consent record
- Transactional + Example 1
- Example 2: Lahore brand, 3 markets (illustrative)
- Quarterly audit
- Mistakes and measures
- Recap and try this now
Lecture transcript
Email compliance
Email laws can feel like a maze of acronyms: CAN-SPAM, GDPR, PECR, PDPL. But underneath, they all protect people from the same things: messages they didn't agree to, senders who hide who they are, and unsubscribe links that don't work. Follow the principles, and you'll comply almost everywhere, and your deliverability will thank you too. In this lecture you'll learn the key rules in the US, UK and EU, the Gulf and Pakistan, what a consent record should contain, and a quarterly audit checklist. This is general guidance, not legal advice, so check official sources or an adviser for your situation.
US: CAN-SPAM
Let's start with the United States and the CAN-SPAM Act, which covers commercial email. No false or misleading header information: from, to, reply-to and routing. No deceptive subject lines. Identify the message as an advertisement where applicable. Include a valid physical postal address. Provide a clear opt-out that works for at least thirty days after sending, and honour opt-outs within ten business days, without charging a fee or asking for more than an email address and a simple action. And you remain responsible even if an agency sends on your behalf. CAN-SPAM is an opt-out law, but mailbox providers and best practice strongly favour consent.
UK and EU
Now the UK and EU. Under the UK's PECR and similar EU rules, you generally need consent to send marketing emails to individuals. Consent must be freely given, specific, informed and unambiguous, a positive action like ticking an unticked box. There's a narrow exception in the UK called the soft opt-in. You may email existing customers, or people who were in negotiations for a sale, about your own similar products or services, as long as you gave them a simple chance to opt out when you collected their details and in every message. The Data Use and Access Act twenty twenty-five extended a version of it to charities.
More UK/EU points
A few more UK and EU points. Emails to corporate subscribers are treated differently from individuals under PECR, but GDPR still applies to personal data like named work emails, and you must always identify yourself and offer an opt-out. Privacy notices must explain how you use data. Keep evidence of consent. Honour rights requests, and remember that an objection to direct marketing is absolute: you must stop. And enforcement has teeth. The UK's twenty twenty-five Act raised maximum fines for breaking the electronic marketing rules to seventeen and a half million pounds or four percent of global turnover, for conduct from February twenty twenty-six.
Gulf and Pakistan
Now the Gulf and Pakistan. The UAE's Personal Data Protection Law sets rules on consent and processing, the telecoms regulator, the TDRA, has rules on unsolicited electronic communications, and the DIFC and ADGM free zones have their own data protection laws. Saudi Arabia's Personal Data Protection Law, fully enforceable since September twenty twenty-four, requires consent and an opt-out for direct marketing, and the Communications, Space and Technology Commission regulates unsolicited messages. Pakistan's Prevention of Electronic Crimes Act addresses spamming, and a data protection law has been under development, so check the current position.
Consent record
Let's make consent concrete. For every subscriber, you should be able to answer: when, where, how and to what did this person agree? A good consent record holds an internal ID, the email, the channel, with separate records for SMS and WhatsApp, the status, the lawful basis, like consent or soft opt-in, the source, like the summer guide pop-up, the version of the consent wording they saw, a timestamp, double opt-in confirmation, and how and when they unsubscribed, if they did. The template is in the lesson text. If a regulator or a mailbox provider ever asks, this record is your proof.
Transactional + Example 1
Now a practical point about transactional emails, like order confirmations, password resets and receipts. They generally have different rules, because the recipient needs them. But keep them primarily transactional. Stuffing heavy promotional content into them can turn them into marketing messages, subject to marketing rules. Here's a simple worked example. A UK and UAE e-commerce brand audits its programme and finds a pre-ticked marketing box at checkout, unsubscribes processed manually once a month, and an SMS tool that ignores the email suppression list. The fixes: an unticked box with clear wording, automatic one-click unsubscribe synced across email and SMS, a soft opt-in notice for UK customers, and an updated privacy notice covering UAE requirements.
Example 2: Lahore brand, 3 markets (illustrative)
Now a realistic cross-border scenario. A Lahore modest-fashion brand ships to the UK, UAE and Saudi Arabia. Its audit finds one global list with no country field, and consent wording that only covers order updates. The fixes: a new consent line at checkout, email me new collections and offers, unsubscribe any time. Country captured from the shipping address. UK customers offered the soft opt-in with a clear opt-out box. A re-permission email to existing subscribers whose consent evidence was missing. And suppression synced between the email platform and the WhatsApp provider. The list shrinks by about a quarter, but complaints fall and revenue per recipient rises.
Quarterly audit
Put it all together in a quarterly audit, from the lesson text. Check every sign-up form for unticked boxes, clear wording, a privacy link and source capture. Check consent proof is stored. Check the soft opt-in is only used for your own similar products, with an opt-out. Test that one-click unsubscribe works and is processed within forty-eight hours in every tool, including SMS, WhatsApp and ad audiences. Check footers, transactional emails and processor agreements with your providers. Review regional rules. And check AI use: no personal data in unapproved tools, and AI replies disclosed where required.
Mistakes and measures
Common mistakes. Assuming they gave us their email for delivery means consent for marketing, outside a valid soft opt-in. Deceptive subject lines or from names. Unsubscribes not synced across tools, so someone who opted out by email still gets texts. And ignoring regional rules because the business is based somewhere else. How do you measure success? Every subscriber has a consent record with source, wording version and timestamp, or a documented soft opt-in basis. Unsubscribes are processed within forty-eight hours across all tools, tested monthly with a seed address. And the quarterly audit is completed, with actions closed.
Recap and try this now
Let's recap. CAN-SPAM requires honest headers and subject lines, ad identification, a postal address and opt-outs honoured within ten business days. UK and EU rules generally require consent for marketing to individuals, with a narrow UK soft opt-in, and UK fines are now much higher. The UAE, Saudi Arabia and Pakistan have their own rules, so check current guidance. Keep a consent record for everyone, sync suppression across every tool, keep transactional emails transactional, and audit quarterly. Here's your try this now. Run the audit checklist from the lesson text against your email programme, or a brand you subscribe to, and list three gaps with specific fixes.
Key takeaways
- CAN-SPAM requires honest headers and subject lines, ad identification, a postal address and opt-outs honoured within 10 business days.
- UK and EU rules generally require consent for marketing emails to individuals, with a limited soft opt-in for existing customers in the UK.
- UAE, KSA and Pakistan have their own data protection and anti-spam rules; check current guidance.
- Keep consent records, sync suppression lists across tools and keep transactional emails primarily transactional.
Try it
Run the compliance checklist against your email programme (or a brand you subscribe to) and list three gaps with specific fixes.