Email Marketing Compliance Guide 2026: CAN-SPAM, GDPR, CCPA & More
Email marketing compliance is not optional. A single violation can cost tens of thousands of dollars, and repeated violations can destroy your sender reputation and get your account suspended.
This guide covers every major regulation affecting email marketing in 2026: CAN-SPAM (US), GDPR (EU/UK), CCPA/CPRA (California), HIPAA (healthcare), TCPA (SMS), and industry-specific rules.
Disclosure: This article is for informational purposes only and does not constitute legal advice. Consult with a qualified attorney for compliance guidance specific to your business.
CAN-SPAM Act Compliance (US)
The CAN-SPAM Act of 2003 sets the rules for commercial email in the United States. It applies to any email whose primary purpose is commercial (advertising or promoting a product or service).
7 CAN-SPAM Requirements
-
Do not use false or misleading header information
- "From" name must accurately identify the sender
- "From" email address must be valid and monitored
- Reply-to address must be valid for at least 30 days after sending
-
Use a clear and conspicuous subject line
- Subject line must accurately reflect the email content
- Do not use deceptive subject lines to trick opens
-
Identify the email as an advertisement
- If the email is an ad, you must disclose this clearly
- This can be in the header or body of the email
-
Include your physical postal address
- Valid physical postal address (street, PO box, or registered agent)
- Must be visible in every email (typically in the footer)
-
Provide a clear unsubscribe mechanism
- Must be clear and conspicuous
- Must be functional for at least 30 days after sending
- Can be a link or reply-to email
- Must be free (no fee, no requirement to log in)
-
Honor unsubscribe requests promptly
- Within 10 business days of receiving the request
- Do not require additional information beyond email address
- Do not sell or transfer the unsubscribed email address
-
Monitor what others do on your behalf
- You are responsible for emails sent by your contractors or affiliates
- Have written agreements with any third parties sending email on your behalf
CAN-SPAM Penalties
- Up to $51,744 per non-compliant email (updated 2024)
- FTC enforcement actions
- Potential criminal penalties for aggravated violations
GDPR Compliance (EU/UK)
The General Data Protection Regulation (GDPR) took effect in 2018 and applies to any organization that processes personal data of EU or UK residents — regardless of where the organization is based.
GDPR Requirements for Email Marketing
-
Lawful basis for processing
- Consent: Explicit, informed, and freely given. Must be opt-in (not opt-out).
- Legitimate interest: May apply for B2B marketing to existing customers, but requires a balancing test
-
Explicit consent requirements
- Pre-ticked checkboxes are not valid consent
- Consent must be specific to email marketing (not bundled with other terms)
- Must be as easy to withdraw consent as it was to give it
- Must maintain records of consent (when, how, what was promised)
-
Right to access and portability
- Subscribers can request a copy of their data
- Must be provided within 30 days
-
Right to be forgotten
- Subscribers can request deletion of all their data
- Must be completed within 30 days
-
Data breach notification
- Must notify authorities within 72 hours of a data breach
- Must notify affected individuals if the breach poses a high risk
GDPR Penalties
- Up to €20 million or 4% of global annual revenue, whichever is higher
- Lower tier: €10 million or 2% of global annual revenue
GDPR vs CAN-SPAM: Key Differences
| Aspect | CAN-SPAM (US) | GDPR (EU/UK) |
|---|---|---|
| Consent model | Opt-out (send until they unsubscribe) | Opt-in (consent before first email) |
| Physical address | Required | Not specifically required |
| Unsubscribe | Required, 10 business days | Required, immediate |
| Data portability | Not required | Required |
| Right to be forgotten | Not required | Required |
| Penalties | $51,744 per email | €20M or 4% of revenue |
CCPA/CPRA Compliance (California)
The California Consumer Privacy Act (CCPA), expanded by the California Privacy Rights Act (CPRA) in 2023, gives California residents rights over their personal data.
CCPA/CPRA Requirements
- Right to know: What personal data is collected and how it is used
- Right to delete: Request deletion of personal data
- Right to opt-out: Opt out of the sale or sharing of personal data
- Right to non-discrimination: Equal service regardless of privacy choices
- Privacy policy: Must include a clear privacy policy with required disclosures
CCPA Penalties
- Up to $7,500 per intentional violation
- $2,500 per unintentional violation
- Private right of action for data breaches
Does CCPA apply to you?
CCPA applies to businesses that:
- Have annual revenue over $25 million, OR
- Buy, sell, or share personal information of 100,000+ consumers, OR
- Derive 50% or more of annual revenue from selling or sharing personal information
HIPAA Compliance (Healthcare)
If you are a healthcare provider, health plan, or business associate, HIPAA applies to email marketing that involves protected health information (PHI).
HIPAA Requirements
- Do not include PHI in marketing emails without explicit patient authorization
- Use encrypted email for any communication containing PHI
- Sign a Business Associate Agreement (BAA) with your email marketing platform
- Access controls: Ensure only authorized personnel can access patient email data
- Audit trails: Maintain logs of who accessed patient data and when
Email platforms that offer BAAs:
- Mailchimp (Enterprise plan)
- Constant Contact (does not offer BAA — not HIPAA-compliant)
- GetResponse (does not offer BAA — not HIPAA-compliant)
- HubSpot (Enterprise plan with BAA)
Important: Most email marketing platforms are NOT HIPAA-compliant. If you are a healthcare provider, verify that your platform offers a BAA before sending any patient-related emails.
TCPA Compliance (SMS Marketing)
If you send SMS marketing messages, the Telephone Consumer Protection Act (TCPA) applies.
TCPA Requirements
- Express written consent before sending any marketing SMS
- Clear disclosure that message frequency varies
- Opt-out mechanism: Reply STOP to unsubscribe
- No automated calls without prior express consent
- Time restrictions: No messages before 8am or after 9pm (recipient's local time)
TCPA Penalties
- $500 per violation (unintentional)
- $1,500 per violation (willful or knowing)
Industry-Specific Rules
Financial Services (FINRA, SEC)
- Must include risk disclosures
- Cannot make guarantees about investment returns
- Communications must be reviewed and approved by a principal
- Archival requirements: all communications must be retained for 3+ years
Insurance (State Regulations)
- Must comply with state insurance department advertising rules
- Include agent license number where required
- Cannot make misleading claims about policy terms or rates
Legal (ABA Model Rules)
- Must identify as attorney advertising where required
- Cannot make false or misleading claims about results
- State bar rules vary — check your jurisdiction
Real Estate (RESPA, Fair Housing)
- Cannot discriminate based on protected classes (Fair Housing Act)
- Must include equal housing opportunity logo where required
- RESPA prohibits kickbacks for referrals
Compliance Checklist
For every email you send:
- Clear and accurate "From" name and email address
- Subject line accurately reflects email content
- Physical postal address in the footer
- One-click unsubscribe link visible and functional
- Unsubscribe requests honored within 10 business days
- No deceptive headers or subject lines
- Email identified as advertisement where required
For GDPR compliance:
- Explicit opt-in consent obtained before first email
- Consent records maintained (when, how, what was promised)
- Privacy policy linked in every email
- Data portability process in place
- Right to be forgotten process in place
- No pre-ticked checkboxes on signup forms
For CCPA compliance:
- "Do Not Sell My Personal Information" link on website (if applicable)
- Privacy policy includes required CCPA disclosures
- Process for handling deletion requests
- Process for handling opt-out requests
For SMS marketing (TCPA):
- Express written consent obtained before first message
- Reply STOP opt-out mechanism included
- No messages outside 8am-9pm local time
- Message frequency disclosed
Compliance Tools & Platform Features
Most email marketing platforms include compliance features:
| Feature | What It Does | Available On |
|---|---|---|
| Double opt-in | Confirms subscriber's email and consent | All major platforms |
| Consent tracking | Records when and how consent was given | GetResponse, ActiveCampaign, Mailchimp |
| One-click unsubscribe | Required by Gmail/Yahoo for bulk senders | All major platforms |
| Preference center | Lets subscribers manage subscriptions | GetResponse, Mailchimp, ActiveCampaign |
| Suppression lists | Automatically removes unsubscribed emails | All major platforms |
| GDPR signup forms | Includes consent checkbox and privacy link | All major platforms |
| BAA (HIPAA) | Business Associate Agreement for healthcare | Mailchimp Enterprise, HubSpot Enterprise |
Recommendation: Choose a platform that includes double opt-in, consent tracking, and one-click unsubscribe. These features handle 90% of compliance requirements automatically.
Last updated: August 2026. This guide is for informational purposes only and does not constitute legal advice. Consult with a qualified attorney for compliance guidance specific to your business and jurisdiction.