Email marketing law doesn't stop at your own border. Depending on where you and your subscribers are located – and where messages are sent, accessed or processed – more than one country's rules may apply. Those rules keep changing, from Europe's GDPR (General Data Protection Regulation) to the UK's Data (Use and Access) Act 2025 and India's Digital Personal Data Protection Act.
The team at EmailOctopus have compiled this guide to make things easier. Our aim is to create a space where the email marketing community can keep each other up-to-date about regulations around the world, so it's easier for us all to be aware of new legislation, as and when it's implemented.
This guide is a community resource and is provided for general information only. It isn't legal advice, and EmailOctopus and its contributors accept no liability for decisions made based on it. Laws and penalty amounts change frequently, and information may be inaccurate or out of date – always consult a local lawyer before carrying out email marketing in any region.
For more detail about a country's legislation, click the country name.
| Country | Legislation | Content required | Opt-out required | Consent required | Penalties |
|---|---|---|---|---|---|
| Australia | Spam Act 2003 | Name, contact information | Yes | Express or limited inferred consent | Up to 3.64 million AUD per day |
| Belgium | Code of Economic Law (Book XII), GDPR | Clearly identifiable advertising and sender; electronic opt-out | Yes | Prior consent, with soft opt-in for existing customers and an exception for impersonal addresses of legal persons | Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation; separate domestic penalties may apply |
| Brazil | LGPD | No prescribed email fields; transparent sender identification and an opt-out are expected | Yes | Consent or documented legitimate interest (no statutory soft opt-in) | 2% of the revenue from Brazil, up to 50 million BRL per infraction |
| Canada | CASL | Name, mailing address, contact information | Yes | Express or limited implied consent, including qualifying existing relationships | Up to 10 million CAD per violation |
| China | Internet Email Services Measures, PIPL | Name, email address, "AD" in subject line | Yes | Prior express consent | Up to 30,000 CNY per violation; up to 50 million CNY or 5% of annual turnover under PIPL |
| Denmark | Danish Marketing Practices Act, GDPR | Recognisable marketing, clear sender identity and a valid opt-out address | Yes | Prior consent, with soft opt-in for existing customers | Tiered spam fines from 20,000 DKK; up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Finland | Act on Electronic Communications Services, GDPR | Recognisable marketing, clear sender identity and a valid opt-out address | Yes | Prior consent or customer soft opt-in for natural persons; legal persons may be emailed on an opt-out basis | Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Germany | Act Against Unfair Competition (UWG), GDPR, German Digital Services Act (DDG) | Name, mailing address, clear identification of the sender | Yes | Prior consent, with a narrow soft opt-in for existing customers | Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Hong Kong | The Unsolicited Electronic Messages Ordinance, PDPO | Name and functional contact details, clear identification of the sender | Yes | Implied consent (opt-out regime), but PDPO requires consent where personal data is used | Up to 1 million HKD and 5 years' imprisonment for address harvesting; unlimited fines and up to 10 years' imprisonment for fraud offences |
| Iceland | Electronic Communications Act, GDPR | Name, mailing address, clear identification of the sender | Yes | Prior consent, with soft opt-in for existing customers | Up to 4% of annual turnover for spam breaches; up to 2.4 billion ISK or 4% of turnover for data protection violations |
| India | DPDP Act 2023 (substantive obligations from May 2027) | None at present | Not until May 2027 | Not required at present; consent-based from May 2027 | None at present; up to 250 crore INR under the DPDP Act from May 2027 |
| Ireland | Irish Data Protection Act 2018, GDPR, ePrivacy Regulations | Clear identification of the sender, valid opt-out address | Yes | Explicit consent, with soft opt-in for existing customers (12-month limit) | Up to 20 million EUR or 4% of turnover (GDPR); up to 5,000 EUR per email (summary) or 250,000 EUR (indictment) under ePrivacy |
| Israel | Communications Law (Telecommunications and Broadcasting), Privacy Protection Law | Name, mailing address, contact information | Yes | Explicit written consent, with a narrow existing-customer exception | Fine of up to 226,000 ILS; administrative fines up to 5% of annual turnover under the Privacy Protection Law |
| Japan | ASCT, Anti-Spam Act | Sender identity and address; opt-out statement and email address or URL; enquiry contact details | Yes | Implied consent if you have a previous business relationship, otherwise explicit consent required | Up to 1 million JPY or 1 year of imprisonment for individuals; up to 30 million JPY for corporations |
| Singapore | PDPA, Spam Control Act 2007 | For unsolicited bulk email: accurate sender information, functional contact details and "<ADV>" in the subject line | Yes | PDPA consent generally required (business contact info excluded); Spam Control Act allows compliant unsolicited bulk email | 25 SGD per email, up to 1 million SGD; PDPA fines up to 10% of annual Singapore turnover or 1 million SGD – whichever is higher |
| South Africa | ECTA, CPA, POPIA | Name, email address | Yes | Prior consent, with soft opt-in for existing customers | Up to 10 million ZAR or 10 years' imprisonment under POPIA; CPA penalties up to the greater of 1 million ZAR or 10% of annual turnover |
| United Arab Emirates | PDPL, Modern Technology-Based Trade Law, TDRA telecoms rules | Sender identification and a free opt-out in practice | Yes | Opt-in in practice: consumers must be able to choose whether to receive marketing | Up to 10 million AED under the telecoms framework (directed at licensees); PDPL penalties pending |
| United Kingdom | UK GDPR, PECR, DPA 2018 (as amended by the Data (Use and Access) Act 2025) | Clear identification of the sender, valid contact address | Yes | Prior consent or a qualifying commercial or charitable-purposes soft opt-in | Up to 17.5 million GBP, or 4% annual global turnover – whichever is higher (now also the PECR maximum) |
| USA | CAN-SPAM | Name, mailing address, contact information | Yes | Prior consent is not required under CAN-SPAM | Up to 53,088 USD per violation |
Consent is permission given by an individual for an organisation to send marketing or process personal data where the applicable law requires it. Depending on the law, consent may be written, oral or electronic, but it generally must be freely given, specific, informed and indicated by an unambiguous affirmative action. Keep a record showing who consented, when, how and what they were told.
A typical example in email marketing is a website registration form with a clear, unticked checkbox allowing a person to agree to receive a newsletter.
- Soft opt-in: A narrow statutory exception to prior consent, not a form of explicit consent. A typical version applies when you obtained contact details directly during a sale, market only your own similar products or services, and offered a free, easy opt-out both when collecting the details and in every later message. Exact conditions and special variants differ by country.
- Single opt-in: A one-step opt-in, so only a registration form is filled out.
- Double opt-in: A multi-step opt-in, so the registration is confirmed via a link sent to the acquired email address.
Implied consent, also known as inferred consent, is derived from conduct, a qualifying relationship or another circumstance expressly recognised by the applicable law. A previous purchase or enquiry may be relevant, but it does not automatically authorise marketing: many soft opt-in rules also require an opt-out when the address is first collected and limit marketing to the sender's own similar products or services.
The exact boundaries for both types of consent are defined in the specific country laws.