Warning
This post is intended to illustrate the complexity of laws are around sending commercial email messages. It is not intended to be used as a check-box for campaign compliance. I do not practice law so please do not take anything in this post as legal advice.
Bulk email falls into one of two categories: commercial and non-commercial. Non-commercial messages are often referred to a transactional or service messages because they relate directly to a service that the sender is providing. Examples of transactional messages include invoices and password-reset notifications. Commercial messages are everything else including special offers, promotional content, and lead/demand generation activities.
Many countries have laws related to the sending of commercial email. This post will focus on four significant markets: the United States, Canada, Europe, and the United Kingdom.
The table below compares the core requirements for sending commercial email in these markets.
| United States | Canada | Europe | United Kingdom | |
|---|---|---|---|---|
| Legislation | CAN-SPAM1 | CASL2 | GDPR3, EU ePrivacy Directive4 | PECR5, UK GDPR6, Data Protection Act 20187 |
| Jurisdiction | United States | Canada | Only European Union (EU) and European Economic Area (EEA) countries | United Kingdom |
| Fine | USD $53,088 per message | CAD $10M | 2-4% of global turnover or EUR €10-20M | 2-4% of global turnover or GBP £8.7-17.5M |
| Prior Consent | Not required | Required (unless prior commercial relationship) | Varies across EU member states | Not required (with exceptions) |
| Unsubscribe | Required and must be honored within 10 business days | Required and must be honored within 10 business days | Required and must be honored without undue delay (outer limit of within 1 month) | Required and must be honored without undue delay (outer limit of within 1 month) |
| Unsubscribe Link Validity | 30 days post-send | 60 days post-send | Forever | Forever |
| Sender Identification | Required | Required | Required | Required |
| Postal address | Required | Required | Required | Required |
| Valid From/Reply-To Address | Required | Required | Required | Required |
| Scope | US-based recipients and US-based senders regardless of recipient location | CA-based recipients and CA-based senders regardless of recipient location (with some exceptions) | EU/EEA-based recipients and EU/EEA-based senders regardless of recipient location | UK-based recipients and UK-based senders regardless of recipient location |
| Governing Body | Federal Trade Commission (FTC) | Canadian Radio-television and Telecommunications Commission (CRTC), The Competition Bureau, and the Privacy Commissioner. | European Data Protection Board (EDPB) plus member state (national) Data Protection Authorities (DPAs) | Information Commissioner’s Office (ICO) |
There can be significant complexity around complying with sending commercial email regulations. For example:
- You may be required to comply with legislation from two jurisdictions depending on where you and the recipient are located.
- Unsubscribe links in the EU/EEA and UK technically need to remain active indefinitely since they are indirectly covered by rights around objecting to data processing which never expire. In reality there are work-arounds.
- While unsolicited or opt-out commercial messages are permitted in some jurisdictions, not all mailbox providers permit them - see the bulk sender guidelines post for more information.
The governing bodies (linked to in the table) are best place to start for more information on a particular piece of legislation. I have also included some additional resources below. I would strongly suggest you seek legal counsel before sending bulk commercial messages and especially if you intend to send unsolicited ones as that’s normally where the tears start and fines begin.
External Resources
- Association of National Advertisers (US)
- Certified Senders Alliance (CSA)
- Data and Marketing Association (UK)
- DLA Piper Global Data Protection Laws of the World
- Federation of European Data and Marketing (Europe)
- International Comparative Legal Guides (ICLG)
Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003, 15 U.S.C. §§ 7701–7713 (2003). Available at: https://www.govinfo.gov/content/pkg/COMPS-932/uslm/COMPS-932.xml ↩︎
An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities… (CASL), S.C. 2010, c. 23. Available at: https://laws-lois.justice.gc.ca/eng/acts/e-1.6/ ↩︎
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), [2016] OJ L 119/1. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩︎
Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), [2002] OJ L 201/37. Available at: http://data.europa.eu/eli/dir/2002/58/2009-12-19 ↩︎
Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426. Available at: https://www.legislation.gov.uk/uksi/2003/2426 ↩︎
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation). Available at: https://www.legislation.gov.uk/eur/2016/679 ↩︎
Data Protection Act 2018, c. 12, available at Legislation.gov.uk. ↩︎