Two regimes, two different questions. What CAN-SPAM requires at send time, what GDPR requires before it, and the consent record that survives a complaint.
The two regimes governing most commercial email ask fundamentally different questions. CAN-SPAM asks what a message must contain and how quickly you must honour an opt-out, and it assumes you may send until somebody tells you to stop. GDPR and the ePrivacy rules alongside it ask whether you had a lawful basis before the first message went out, and treat sending without one as the violation regardless of how well the message is labelled. A sender fully compliant with one can be squarely in breach of the other, which is why "we have an unsubscribe link" answers only half the question.
What CAN-SPAM actually requires
The United States rule is a labelling and exit regime rather than a consent regime. Header information and subject lines must not be deceptive, commercial messages must be identifiable as advertising where that applies, a valid physical postal address must appear, and an opt-out mechanism must remain functional for at least thirty days after sending and be honoured within ten business days. Prior permission is not required, which is the source of most confusion when American practice is exported to European lists. Note that liability attaches to the advertiser as well as to the party pressing send, so outsourcing the send does not outsource the exposure.
What GDPR and ePrivacy require before that
The European framework inverts the order of operations. Under ePrivacy rules as implemented by each member state, unsolicited commercial email to individuals generally requires prior consent, with a narrow soft opt-in covering existing customers offered similar products. GDPR then governs the quality of that consent: freely given, specific, informed, unambiguous, and evidenced by a clear affirmative act. Pre-ticked boxes and consent bundled into terms acceptance do not qualify. The burden of proof sits with you, and that single sentence converts an abstract legal standard into a concrete schema requirement, because a claim you cannot evidence is indistinguishable from no claim at all.
The consent record that survives a complaint
- Timestamp of the opt-in, stored in UTC
- Source identified specifically: the exact form, landing page, or import batch, not "website"
- The wording shown at the moment of consent, versioned so you can reproduce what that person saw
- IP address or equivalent evidence of the affirmative act
- Confirmation event for double opt-in flows, stored separately from the initial request
- Scope: which purposes and which message types the person agreed to receive
- Full history of later preference and withdrawal events, retained after withdrawal as proof
Where the two regimes converge
For all their differences, both push toward the same operational shape, and the bulk sender requirements Gmail and Yahoo have announced for next year push harder in the same direction. Opt-out must be easy, immediate, and free of authentication walls. Identity must be honest, with a From address naming the actual sender. Records must exist and must be retrievable. A programme built to the stricter standard satisfies the looser one in every market it operates in, and the cost of that decision is a smaller list, which is a cost worth paying because the addresses it excludes are the ones that generate complaints.
“Build to the stricter regime. The addresses it excludes are the ones that were going to complain.”
The failure mode worth guarding against is a compliance posture that lives in a policy document and nowhere in the sending stack. Consent evidence that cannot be produced within a working day is not evidence, an opt-out honoured in the marketing platform but not in the transactional one is not honoured, and a list acquired before your current process existed is not grandfathered by the passage of time. Audit the acquisition paths you actually operate, then decide deliberately what to do about the segments that predate them.
Frequently Asked Questions
Does a purchased or rented list ever comply?
Is double opt-in legally required?
Do B2B addresses fall outside GDPR?
How fast must an unsubscribe take effect?
Key Takeaways
- CAN-SPAM regulates the message and the exit; GDPR and ePrivacy regulate whether you could send at all
- European consent must be freely given, specific, informed, and unambiguous, and you carry the burden of proving it
- Consent evidence is a schema requirement: timestamp, source, wording shown, mechanism, and full change history
- Both regimes and the incoming provider requirements converge on honest identity, easy exit, and retained records
- Build to the stricter standard once rather than maintaining two sending policies
Related articles

Half-Year Review: Email in the AI Inbox Era
Six months that rearranged the reading layer: Gemini in Gmail, Microsoft rejecting outright, DMARC finally a standard. What the first half of 2026 means for senders.

Deliverability Postmortems: Learning From Incidents
The incident is over, placement recovered, and the pressure to move on is enormous. The blameless postmortem practice that converts each incident into prevention.

Writing for AI Readers: Structure When Gemini Summarizes You
Five months of AI Overviews data shows opens up and clicks down: recipients read summaries. How to structure email so the model's version still does your job.


