Direct marketing law answers one question per channel and country: opt-in or opt-out? Europe answers opt-in for electronic messages, the US answers opt-out for email but litigation-enforced opt-in for texts, and Canada answers opt-in with the harshest fine ceiling in North America. Multi-market campaigns therefore comply with the strictest rule touching each recipient, not with the sender’s home rules.
| EU rule | ePrivacy Directive Art. 13: opt-in, soft opt-in exception |
|---|---|
| US email | CAN-SPAM: opt-out regime |
| US SMS | TCPA: express written consent, USD 500 to 1,500 per message |
| Canada | CASL: opt-in, up to CAD 10M per violation |
| Official text | EUR-Lex CELEX 32002L0058 |
The EU regime
Article 13 of the ePrivacy Directive requires prior consent for marketing by email, SMS, and automated calls to individuals. The consent must meet GDPR quality standards: specific, informed, provable, and naming the actual sender. The soft opt-in is the one exception worth building on: existing customers may be emailed about similar products without fresh consent, if they could refuse at collection and every message carries an opt-out. GDPR adds Article 21(3): when someone objects to marketing, the right is absolute, and continuing afterward is one of Europe’s most commonly fined small violations.
Push notifications sit in the same frame: they are electronic messages to a device, and both the ePrivacy device rule and marketing rules can apply, so treat marketing pushes as consent-based.
The US regime
CAN-SPAM permits unsolicited commercial email but requires truthful headers, a physical postal address, a clear unsubscribe honored within 10 business days, and no further mail after opt-out. The FTC enforces it with civil penalties per email. Texts are different law entirely: TCPA’s private right of action and per-message statutory damages built an active class-action industry, so SMS programs need express written consent and disciplined records.
Canada
CASL requires express or narrowly defined implied consent before sending commercial electronic messages, with identification and unsubscribe requirements, and administrative penalties reaching CAD 10 million per violation for organizations. The CRTC has fined both companies and individual executives.
Making a program compliant
Keep provable consent per recipient per channel, honor every unsubscribe across all systems within the legal window, apply the strictest rule when audiences mix, and audit list sources: bought lists rarely carry consent that names you. Marketing pixels on your site feed these same lists, so verify what your pages collect with a free scan. Related reading: UK PECR compliance for the British rules, and GDPR consent management for consent quality.