| Australia |
Spam Act 2003 |
Name, contact information |
Yes |
Express or limited inferred consent |
Up to 3.64 million AUD per day |
| Belgium |
Code of Economic Law (Book XII), GDPR |
Clearly identifiable advertising and sender; electronic opt-out |
Yes |
Prior consent, with soft opt-in for existing customers and an exception for impersonal addresses of legal persons |
Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation; separate domestic penalties may apply |
| Brazil |
LGPD |
No prescribed email fields; transparent sender identification and an opt-out are expected |
Yes |
Consent or documented legitimate interest (no statutory soft opt-in) |
2% of the revenue from Brazil, up to 50 million BRL per infraction |
| Canada |
CASL |
Name, mailing address, contact information |
Yes |
Express or limited implied consent, including qualifying existing relationships |
Up to 10 million CAD per violation |
| China |
Internet Email Services Measures, PIPL |
Name, email address, "AD" in subject line |
Yes |
Prior express consent |
Up to 30,000 CNY per violation; up to 50 million CNY or 5% of annual turnover under PIPL |
| Denmark |
Danish Marketing Practices Act, GDPR |
Recognisable marketing, clear sender identity and a valid opt-out address |
Yes |
Prior consent, with soft opt-in for existing customers |
Tiered spam fines from 20,000 DKK; up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Finland |
Act on Electronic Communications Services, GDPR |
Recognisable marketing, clear sender identity and a valid opt-out address |
Yes |
Prior consent or customer soft opt-in for natural persons; legal persons may be emailed on an opt-out basis |
Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Germany |
Act Against Unfair Competition (UWG), GDPR, German Digital Services Act (DDG) |
Name, mailing address, clear identification of the sender |
Yes |
Prior consent, with a narrow soft opt-in for existing customers |
Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation |
| Hong Kong |
The Unsolicited Electronic Messages Ordinance, PDPO |
Name and functional contact details, clear identification of the sender |
Yes |
Implied consent (opt-out regime), but PDPO requires consent where personal data is used |
Up to 1 million HKD and 5 years' imprisonment for address harvesting; unlimited fines and up to 10 years' imprisonment for fraud offences |
| Iceland |
Electronic Communications Act, GDPR |
Name, mailing address, clear identification of the sender |
Yes |
Prior consent, with soft opt-in for existing customers |
Up to 4% of annual turnover for spam breaches; up to 2.4 billion ISK or 4% of turnover for data protection violations |
| India |
DPDP Act 2023 (substantive obligations from May 2027) |
None at present |
Not until May 2027 |
Not required at present; consent-based from May 2027 |
None at present; up to 250 crore INR under the DPDP Act from May 2027 |
| Ireland |
Irish Data Protection Act 2018, GDPR, ePrivacy Regulations |
Clear identification of the sender, valid opt-out address |
Yes |
Explicit consent, with soft opt-in for existing customers (12-month limit) |
Up to 20 million EUR or 4% of turnover (GDPR); up to 5,000 EUR per email (summary) or 250,000 EUR (indictment) under ePrivacy |
| Israel |
Communications Law (Telecommunications and Broadcasting), Privacy Protection Law |
Name, mailing address, contact information |
Yes |
Explicit written consent, with a narrow existing-customer exception |
Fine of up to 226,000 ILS; administrative fines up to 5% of annual turnover under the Privacy Protection Law |
| Japan |
ASCT, Anti-Spam Act |
Sender identity and address; opt-out statement and email address or URL; enquiry contact details |
Yes |
Implied consent if you have a previous business relationship, otherwise explicit consent required |
Up to 1 million JPY or 1 year of imprisonment for individuals; up to 30 million JPY for corporations |
| Singapore |
PDPA, Spam Control Act 2007 |
For unsolicited bulk email: accurate sender information, functional contact details and "<ADV>" in the subject line |
Yes |
PDPA consent generally required (business contact info excluded); Spam Control Act allows compliant unsolicited bulk email |
25 SGD per email, up to 1 million SGD; PDPA fines up to 10% of annual Singapore turnover or 1 million SGD – whichever is higher |
| South Africa |
ECTA, CPA, POPIA |
Name, email address |
Yes |
Prior consent, with soft opt-in for existing customers |
Up to 10 million ZAR or 10 years' imprisonment under POPIA; CPA penalties up to the greater of 1 million ZAR or 10% of annual turnover |
| United Arab Emirates |
PDPL, Modern Technology-Based Trade Law, TDRA telecoms rules |
Sender identification and a free opt-out in practice |
Yes |
Opt-in in practice: consumers must be able to choose whether to receive marketing |
Up to 10 million AED under the telecoms framework (directed at licensees); PDPL penalties pending |
| United Kingdom |
UK GDPR, PECR, DPA 2018 (as amended by the Data (Use and Access) Act 2025) |
Clear identification of the sender, valid contact address |
Yes |
Prior consent or a qualifying commercial or charitable-purposes soft opt-in |
Up to 17.5 million GBP, or 4% annual global turnover – whichever is higher (now also the PECR maximum) |
| USA |
CAN-SPAM |
Name, mailing address, contact information |
Yes |
Prior consent is not required under CAN-SPAM |
Up to 53,088 USD per violation |