LegalOSS82.1ktracked
Legal Research & Search · Case Law & Legal Data · Compliance & Privacy

email-marketing-regulations

threeheartsdigital/email-marketing-regulations

Global email marketing legislation

Email marketing regulations around the world (2026)

Email marketing law doesn't stop at your own border. Depending on where you and your subscribers are located – and where messages are sent, accessed or processed – more than one country's rules may apply. Those rules keep changing, from Europe's GDPR (General Data Protection Regulation) to the UK's Data (Use and Access) Act 2025 and India's Digital Personal Data Protection Act.

The team at EmailOctopus have compiled this guide to make things easier. Our aim is to create a space where the email marketing community can keep each other up-to-date about regulations around the world, so it's easier for us all to be aware of new legislation, as and when it's implemented.

This guide is a community resource and is provided for general information only. It isn't legal advice, and EmailOctopus and its contributors accept no liability for decisions made based on it. Laws and penalty amounts change frequently, and information may be inaccurate or out of date – always consult a local lawyer before carrying out email marketing in any region.

At a glance

For more detail about a country's legislation, click the country name.

Country Legislation Content required Opt-out required Consent required Penalties
Australia Spam Act 2003 Name, contact information Yes Express or limited inferred consent Up to 3.64 million AUD per day
Belgium Code of Economic Law (Book XII), GDPR Clearly identifiable advertising and sender; electronic opt-out Yes Prior consent, with soft opt-in for existing customers and an exception for impersonal addresses of legal persons Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation; separate domestic penalties may apply
Brazil LGPD No prescribed email fields; transparent sender identification and an opt-out are expected Yes Consent or documented legitimate interest (no statutory soft opt-in) 2% of the revenue from Brazil, up to 50 million BRL per infraction
Canada CASL Name, mailing address, contact information Yes Express or limited implied consent, including qualifying existing relationships Up to 10 million CAD per violation
China Internet Email Services Measures, PIPL Name, email address, "AD" in subject line Yes Prior express consent Up to 30,000 CNY per violation; up to 50 million CNY or 5% of annual turnover under PIPL
Denmark Danish Marketing Practices Act, GDPR Recognisable marketing, clear sender identity and a valid opt-out address Yes Prior consent, with soft opt-in for existing customers Tiered spam fines from 20,000 DKK; up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation
Finland Act on Electronic Communications Services, GDPR Recognisable marketing, clear sender identity and a valid opt-out address Yes Prior consent or customer soft opt-in for natural persons; legal persons may be emailed on an opt-out basis Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation
Germany Act Against Unfair Competition (UWG), GDPR, German Digital Services Act (DDG) Name, mailing address, clear identification of the sender Yes Prior consent, with a narrow soft opt-in for existing customers Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation
Hong Kong The Unsolicited Electronic Messages Ordinance, PDPO Name and functional contact details, clear identification of the sender Yes Implied consent (opt-out regime), but PDPO requires consent where personal data is used Up to 1 million HKD and 5 years' imprisonment for address harvesting; unlimited fines and up to 10 years' imprisonment for fraud offences
Iceland Electronic Communications Act, GDPR Name, mailing address, clear identification of the sender Yes Prior consent, with soft opt-in for existing customers Up to 4% of annual turnover for spam breaches; up to 2.4 billion ISK or 4% of turnover for data protection violations
India DPDP Act 2023 (substantive obligations from May 2027) None at present Not until May 2027 Not required at present; consent-based from May 2027 None at present; up to 250 crore INR under the DPDP Act from May 2027
Ireland Irish Data Protection Act 2018, GDPR, ePrivacy Regulations Clear identification of the sender, valid opt-out address Yes Explicit consent, with soft opt-in for existing customers (12-month limit) Up to 20 million EUR or 4% of turnover (GDPR); up to 5,000 EUR per email (summary) or 250,000 EUR (indictment) under ePrivacy
Israel Communications Law (Telecommunications and Broadcasting), Privacy Protection Law Name, mailing address, contact information Yes Explicit written consent, with a narrow existing-customer exception Fine of up to 226,000 ILS; administrative fines up to 5% of annual turnover under the Privacy Protection Law
Japan ASCT, Anti-Spam Act Sender identity and address; opt-out statement and email address or URL; enquiry contact details Yes Implied consent if you have a previous business relationship, otherwise explicit consent required Up to 1 million JPY or 1 year of imprisonment for individuals; up to 30 million JPY for corporations
Singapore PDPA, Spam Control Act 2007 For unsolicited bulk email: accurate sender information, functional contact details and "<ADV>" in the subject line Yes PDPA consent generally required (business contact info excluded); Spam Control Act allows compliant unsolicited bulk email 25 SGD per email, up to 1 million SGD; PDPA fines up to 10% of annual Singapore turnover or 1 million SGD – whichever is higher
South Africa ECTA, CPA, POPIA Name, email address Yes Prior consent, with soft opt-in for existing customers Up to 10 million ZAR or 10 years' imprisonment under POPIA; CPA penalties up to the greater of 1 million ZAR or 10% of annual turnover
United Arab Emirates PDPL, Modern Technology-Based Trade Law, TDRA telecoms rules Sender identification and a free opt-out in practice Yes Opt-in in practice: consumers must be able to choose whether to receive marketing Up to 10 million AED under the telecoms framework (directed at licensees); PDPL penalties pending
United Kingdom UK GDPR, PECR, DPA 2018 (as amended by the Data (Use and Access) Act 2025) Clear identification of the sender, valid contact address Yes Prior consent or a qualifying commercial or charitable-purposes soft opt-in Up to 17.5 million GBP, or 4% annual global turnover – whichever is higher (now also the PECR maximum)
USA CAN-SPAM Name, mailing address, contact information Yes Prior consent is not required under CAN-SPAM Up to 53,088 USD per violation

Explicit vs implied consent and other key terms

Express or explicit consent

Consent is permission given by an individual for an organisation to send marketing or process personal data where the applicable law requires it. Depending on the law, consent may be written, oral or electronic, but it generally must be freely given, specific, informed and indicated by an unambiguous affirmative action. Keep a record showing who consented, when, how and what they were told.

A typical example in email marketing is a website registration form with a clear, unticked checkbox allowing a person to agree to receive a newsletter.

  • Soft opt-in: A narrow statutory exception to prior consent, not a form of explicit consent. A typical version applies when you obtained contact details directly during a sale, market only your own similar products or services, and offered a free, easy opt-out both when collecting the details and in every later message. Exact conditions and special variants differ by country.
  • Single opt-in: A one-step opt-in, so only a registration form is filled out.
  • Double opt-in: A multi-step opt-in, so the registration is confirmed via a link sent to the acquired email address.

Implied consent

Implied consent, also known as inferred consent, is derived from conduct, a qualifying relationship or another circumstance expressly recognised by the applicable law. A previous purchase or enquiry may be relevant, but it does not automatically authorise marketing: many soft opt-in rules also require an opt-out when the address is first collected and limit marketing to the sender's own similar products or services.

The exact boundaries for both types of consent are defined in the specific country laws.