EU Privacy Law EU, UK, US, Canada

Direct Marketing Compliance: Email, SMS, and Push Notification Rules by Jurisdiction

Opt-in and opt-out rules for email, SMS, and push marketing under the ePrivacy Directive, GDPR, UK PECR, CAN-SPAM, CASL, and TCPA, with the fines to know.

Regulation

ePrivacy Directive Article 13; GDPR Article 21; PECR; CAN-SPAM; CASL; TCPA

Max Penalty

Varies: GDPR-level fines in the EU; CASL up to CAD 10 million per violation

Enforcing Authority

National DPAs, UK ICO, US FTC/FCC, Canadian CRTC

Official Source

eur-lex.europa.eu

Executive Summary

  • The EU rule (ePrivacy Directive Article 13) is opt-in: electronic marketing to individuals requires prior consent, with a narrow soft opt-in exception for existing customers.
  • The US federal rule (CAN-SPAM) is opt-out for email, but TCPA makes unsolicited SMS and robocalls a class-action magnet with statutory damages of USD 500 to 1,500 per message.
  • Canada's CASL is the strictest in North America: opt-in with penalties up to CAD 10 million per violation.
  • Under GDPR Article 21(3), an objection to direct marketing is absolute; processing for marketing must stop, no balancing test.
  • The most common violation is mundane: continuing to email people who unsubscribed, or buying lists whose consent does not name you.

Direct marketing law answers one question per channel and country: opt-in or opt-out? Europe answers opt-in for electronic messages, the US answers opt-out for email but litigation-enforced opt-in for texts, and Canada answers opt-in with the harshest fine ceiling in North America. Multi-market campaigns therefore comply with the strictest rule touching each recipient, not with the sender’s home rules.

EU ruleePrivacy Directive Art. 13: opt-in, soft opt-in exception
US emailCAN-SPAM: opt-out regime
US SMSTCPA: express written consent, USD 500 to 1,500 per message
CanadaCASL: opt-in, up to CAD 10M per violation
Official textEUR-Lex CELEX 32002L0058

The EU regime

Article 13 of the ePrivacy Directive requires prior consent for marketing by email, SMS, and automated calls to individuals. The consent must meet GDPR quality standards: specific, informed, provable, and naming the actual sender. The soft opt-in is the one exception worth building on: existing customers may be emailed about similar products without fresh consent, if they could refuse at collection and every message carries an opt-out. GDPR adds Article 21(3): when someone objects to marketing, the right is absolute, and continuing afterward is one of Europe’s most commonly fined small violations.

Push notifications sit in the same frame: they are electronic messages to a device, and both the ePrivacy device rule and marketing rules can apply, so treat marketing pushes as consent-based.

The US regime

CAN-SPAM permits unsolicited commercial email but requires truthful headers, a physical postal address, a clear unsubscribe honored within 10 business days, and no further mail after opt-out. The FTC enforces it with civil penalties per email. Texts are different law entirely: TCPA’s private right of action and per-message statutory damages built an active class-action industry, so SMS programs need express written consent and disciplined records.

Canada

CASL requires express or narrowly defined implied consent before sending commercial electronic messages, with identification and unsubscribe requirements, and administrative penalties reaching CAD 10 million per violation for organizations. The CRTC has fined both companies and individual executives.

Making a program compliant

Keep provable consent per recipient per channel, honor every unsubscribe across all systems within the legal window, apply the strictest rule when audiences mix, and audit list sources: bought lists rarely carry consent that names you. Marketing pixels on your site feed these same lists, so verify what your pages collect with a free scan. Related reading: UK PECR compliance for the British rules, and GDPR consent management for consent quality.

Frequently Asked Questions

Do I need consent to send marketing emails in the EU?

Yes, prior opt-in consent under ePrivacy Article 13, unless the soft opt-in applies: you obtained the address from a sale or sale negotiation, you market only your own similar products, and every message offers a free, working opt-out.

What is the soft opt-in?

The existing-customer exception in Article 13(2): email marketing without fresh consent to people whose details you collected during a sale of similar products, provided they could refuse at collection and can opt out in every message. It does not cover bought lists or prospects.

Is B2B email marketing exempt in the EU?

It depends on the country. Some member states (and the UK under PECR) apply the opt-in rule only to individual subscribers, leaving corporate addresses under softer rules; others, like Germany, require consent for B2B too. Check each target market.

What are the US rules for marketing texts?

TCPA requires prior express written consent for marketing texts sent with autodialing technology, with statutory damages of USD 500 to 1,500 per message enforced through class actions. Email is governed separately by CAN-SPAM's opt-out regime.

Can I market to a purchased email list?

In the EU and Canada, almost never lawfully: valid consent must specifically cover you as sender, which rented and bought lists rarely establish. In the US, CAN-SPAM does not prohibit it, but deliverability, reputation, and state laws make it a poor idea.

Regulatory Crosswalk

GDPRUK PECRCAN-SPAMCASLTCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.