Compliance & Laws

Email compliance: the rules that decide what you may send

Two separate systems govern a commercial send, and they answer to different people. Statute law says whether the message may be sent at all and what it must contain. Mailbox provider policy decides whether it reaches an inbox. A campaign can satisfy one and fail the other, which is why compliance work that stops at the legal checklist still ends up in the spam folder. This category covers both, one document per law and one page per national authority that enforces it.

Consent and opt-outRegulators by countryProvider requirements

The rule that applies is the recipient’s

Jurisdiction follows the person in the To field, not the company in the From field. A list that spans several countries is governed by all of them at once, so the working assumption for a mixed list is the strictest rule in the set rather than the one where the business is registered.

The two models differ at the start of the relationship. CAN-SPAM in the United States permits the first message and regulates the exit: a working opt-out, honored within 10 business days, functional for at least 30 days after the send, plus a valid postal address in every message. GDPR in the European Union regulates the entrance: a lawful basis has to exist before the first send, and withdrawal has to be as easy as the original consent. CASL and the Australian Spam Act follow the consent model with their own definitions of what counts as implied.

What every send has to carry

A basis for sending

Where consent is required, it has to be recorded: what was agreed, when, and through which form. An unprovable opt-in is treated as no opt-in.

Double opt-in and what it proves

A way out

Free, in one step, with no login and no data beyond the address. The deadline to honor it differs by country; the obligation does not.

Unsubscribe law, country by country

An identity

A truthful From line, a subject that matches the content, and a physical postal address. Most of this lands in the footer.

What belongs in an email footer

The regulators

GDPR is one text enforced by many authorities, and they do not read it identically. Guidance on consent wording, cookie walls and retention differs enough that the supervisory authority for your main market is worth reading directly. This category holds a page for each: CNIL in France, the ICO in the United Kingdom, the BfDI in Germany, the Garante in Italy, the AEPD in Spain and the DSB in Austria.

Outside Europe the same pattern repeats under different names: the ANPD in Brazil, the PPC in Japan and the PDPC in Singapore each publish their own guidance for marketing mail, and each is the body that would open a file on a complaint from a recipient in that country.

The layer the law does not cover

Mailbox providers set requirements of their own, and they enforce them faster than any regulator: not with a fine but with the spam folder. Authenticated mail, a one-click unsubscribe header on bulk sends and a complaint rate under the published threshold are conditions of delivery, not of legality. The current set is documented in the guide to bulk sender rules at Gmail, Yahoo and Microsoft.

Implementation is where the two layers meet. The visible opt-out and the header that satisfies the provider are set in the same place, platform by platform, in the unsubscribe guides, and the records that prove who sent the message are covered in the authentication guides.