Basely

Email marketing and privacy law: the required minimum

R
Rafaell Sousa

updated Oct 5, 2026 · 5 min

The short answer

In the US, CAN-SPAM lets you email people without prior consent, but every message must be honest about who sent it, have a truthful subject line, include a valid postal address and offer an unsubscribe that you honor promptly. If you email people in the EU or the UK, GDPR and the local email rules usually require prior consent and proof of it. The safe minimum for a small business: build the list from opt-in forms, keep a record of each signup, and make leaving the list one click.

Email marketing law depends on where your recipients live. For a US small business, two rulebooks matter most:

  • CAN-SPAM (US federal law, enforced by the FTC) is an opt-out law. You can send commercial email without prior permission, but each message has to meet a set of honesty and unsubscribe rules.
  • GDPR (EU, with a close UK version) plus the email marketing rules in each country usually require prior consent before you send marketing to individuals, and you must be able to prove it.

The practical minimum for most small businesses is the same in both worlds: build your list from people who asked to hear from you, keep a record of when and where they signed up, say clearly who you are, and let them leave in one click.

Quick note: this is a practical guide, not legal advice. For your specific situation, talk to a lawyer.

What CAN-SPAM actually requires

The FTC summarizes CAN-SPAM in a handful of rules. In plain terms, every commercial email you send must:

  1. Use honest header information. The From name, reply-to address and sending domain must identify you, not hide who sent it.
  2. Have a subject line that matches the content. A subject promising a refund that leads to a sales pitch is exactly what the law targets.
  3. Identify the message as an ad when it is one, in a clear way.
  4. Include a valid physical postal address for your business. A street address, a registered PO box or a private mailbox registered under postal rules all work.
  5. Tell people how to opt out and make it easy, such as a visible unsubscribe link.
  6. Honor opt-outs promptly. The FTC sets a deadline in business days, and you cannot charge a fee, ask for extra personal data or make people visit several pages to unsubscribe.
  7. Watch what others do for you. If you hire an agency to send your campaigns, you are still responsible for compliance.

Penalties are assessed per violating email, so a single bad campaign to a large list adds up fast. The FTC publishes the current amount.

When GDPR enters the picture

GDPR applies when you process personal data of people in the EU, for example if you actively sell online to European customers or market to tourists who booked with you. The UK has its own version with similar rules.

Under GDPR you need a lawful basis to use someone's email. For marketing to individuals, the email rules in most European countries add a stricter layer: prior consent is the norm, with a narrow exception in some countries for existing customers who bought something similar and were given a chance to opt out.

Consent under GDPR has to be:

  • Freely given: not forced as a condition for something unrelated.
  • Specific and informed: the person knows they are signing up for marketing from you.
  • Unambiguous: a clear action, like ticking an unchecked box. Pre-ticked boxes do not count.
  • Provable: you keep a record of it.
  • Easy to withdraw: as easy as it was to give.

People also have rights over their data: to see what you hold, correct it and ask you to delete it in many cases.

Bought, scraped or borrowed lists

Buying a "targeted" list or scraping emails from websites is the shortcut that causes the most trouble. Under GDPR there is no consent to prove. Under CAN-SPAM, harvesting addresses from websites is specifically called out as an aggravating factor.

There is a technical cost too. Gmail, Outlook and Yahoo track how many recipients mark your mail as spam and require bulk senders to authenticate their domain and offer easy unsubscribes. A few campaigns to people who never asked for them can push your future mail, sometimes even your normal business email, into spam folders.

The same applies to a list you got from a partner, a former business or a trade show organizer. Those people agreed to hear from someone else, not from you.

What every campaign should include

ItemWhy it matters
A sender name people recognizeFewer spam complaints, clear accountability
Sending from your own domainProves the mail is yours and helps delivery
A visible one-click unsubscribeRequired by law and by the big inbox providers
Your business postal addressRequired by CAN-SPAM
A subject that matches the emailDeceptive subjects are a direct violation

Sending promotions from a personal Gmail with everyone in CC breaks most of these at once, and exposes every address to every recipient.

Keep the paper trail

Whatever law applies, the strongest position is a record for each contact:

  1. Date and time of signup.
  2. Which form and which page.
  3. The exact consent text they saw.
  4. When they confirmed, if you use double opt-in.
  5. When they unsubscribed, if they did.

A spreadsheet with no dates and no source proves nothing. The list should grow from your forms, not from copy and paste.

How to do it on Basely

Basely's email marketing was built so the minimum happens without relying on memory:

  • The list comes from your site's forms, with the consent recorded alongside each contact. People who did not tick the box do not become active subscribers.
  • Campaigns go out from the client's own domain, never from a sender shared with other businesses.
  • The unsubscribe link and postal address are added automatically to every campaign, and an unsubscribe takes effect right away.
  • AI writes the campaign in the brand's template, but it starts as a draft. A person clicks Send.

Plans start at $2.49/month. The platform does not decide what you send or to whom, but it handles the parts that usually get forgotten: recording, identifying and letting people leave.

A checklist to start today

  1. Review your signup form: unchecked box, clear text, separate from the quote request.
  2. Set aside any contacts with no known source.
  3. Test that unsubscribe works in one click.
  4. Send from your domain, with a recognizable name and your postal address.
  5. Keep the record of every signup.

Start with the list you have the right to use, even if it is small, and let your forms grow it.

Try it on Basely

The first AI site is free with a confirmed email.

See how it works

Questions

Does CAN-SPAM apply to emails I send to existing customers?
CAN-SPAM covers commercial messages, meaning email whose main purpose is to promote a product or service, no matter who receives it. Purely transactional messages, such as a receipt or a shipping update, are treated differently, but a promotion sent to a past customer is still commercial.
I am a US business. Do I need to care about GDPR?
If you deliberately market to people in the EU or UK, such as tourists who booked with you or online buyers overseas, GDPR can apply to that data. If your list is purely local, it matters less, but following consent-based practices keeps you covered either way.
Is double opt-in legally required?
Neither CAN-SPAM nor GDPR names double opt-in as a requirement. It is a good way to prove the address belongs to the person who signed up and to keep typos and fake signups off your list, which also protects your deliverability.
Can I keep the email of someone who unsubscribed?
Keeping the address on a suppression list, marked as unsubscribed, is the usual way to make sure they never get another campaign by mistake. Deleting it entirely can let it slip back in on your next import.