GitHub - threeheartsdigital/email-marketing-regulations: A repository of email marketing legislation around the world, compiled by EmailOctopus.

GitHub

5 min read Original article ↗
Australia Spam Act 2003 Name, contact information Yes Express or limited inferred consent Up to 3.64 million AUD per day Belgium Code of Economic Law (Book XII), GDPR Clearly identifiable advertising and sender; electronic opt-out Yes Prior consent, with soft opt-in for existing customers and an exception for impersonal addresses of legal persons Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation; separate domestic penalties may apply Brazil LGPD No prescribed email fields; transparent sender identification and an opt-out are expected Yes Consent or documented legitimate interest (no statutory soft opt-in) 2% of the revenue from Brazil, up to 50 million BRL per infraction Canada CASL Name, mailing address, contact information Yes Express or limited implied consent, including qualifying existing relationships Up to 10 million CAD per violation China Internet Email Services Measures, PIPL Name, email address, "AD" in subject line Yes Prior express consent Up to 30,000 CNY per violation; up to 50 million CNY or 5% of annual turnover under PIPL Denmark Danish Marketing Practices Act, GDPR Recognisable marketing, clear sender identity and a valid opt-out address Yes Prior consent, with soft opt-in for existing customers Tiered spam fines from 20,000 DKK; up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation Finland Act on Electronic Communications Services, GDPR Recognisable marketing, clear sender identity and a valid opt-out address Yes Prior consent or customer soft opt-in for natural persons; legal persons may be emailed on an opt-out basis Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation Germany Act Against Unfair Competition (UWG), GDPR, German Digital Services Act (DDG) Name, mailing address, clear identification of the sender Yes Prior consent, with a narrow soft opt-in for existing customers Up to 20 million EUR, or 4% annual global turnover – whichever is higher for a serious GDPR violation Hong Kong The Unsolicited Electronic Messages Ordinance, PDPO Name and functional contact details, clear identification of the sender Yes Implied consent (opt-out regime), but PDPO requires consent where personal data is used Up to 1 million HKD and 5 years' imprisonment for address harvesting; unlimited fines and up to 10 years' imprisonment for fraud offences Iceland Electronic Communications Act, GDPR Name, mailing address, clear identification of the sender Yes Prior consent, with soft opt-in for existing customers Up to 4% of annual turnover for spam breaches; up to 2.4 billion ISK or 4% of turnover for data protection violations India DPDP Act 2023 (substantive obligations from May 2027) None at present Not until May 2027 Not required at present; consent-based from May 2027 None at present; up to 250 crore INR under the DPDP Act from May 2027 Ireland Irish Data Protection Act 2018, GDPR, ePrivacy Regulations Clear identification of the sender, valid opt-out address Yes Explicit consent, with soft opt-in for existing customers (12-month limit) Up to 20 million EUR or 4% of turnover (GDPR); up to 5,000 EUR per email (summary) or 250,000 EUR (indictment) under ePrivacy Israel Communications Law (Telecommunications and Broadcasting), Privacy Protection Law Name, mailing address, contact information Yes Explicit written consent, with a narrow existing-customer exception Fine of up to 226,000 ILS; administrative fines up to 5% of annual turnover under the Privacy Protection Law Japan ASCT, Anti-Spam Act Sender identity and address; opt-out statement and email address or URL; enquiry contact details Yes Implied consent if you have a previous business relationship, otherwise explicit consent required Up to 1 million JPY or 1 year of imprisonment for individuals; up to 30 million JPY for corporations Singapore PDPA, Spam Control Act 2007 For unsolicited bulk email: accurate sender information, functional contact details and "<ADV>" in the subject line Yes PDPA consent generally required (business contact info excluded); Spam Control Act allows compliant unsolicited bulk email 25 SGD per email, up to 1 million SGD; PDPA fines up to 10% of annual Singapore turnover or 1 million SGD – whichever is higher South Africa ECTA, CPA, POPIA Name, email address Yes Prior consent, with soft opt-in for existing customers Up to 10 million ZAR or 10 years' imprisonment under POPIA; CPA penalties up to the greater of 1 million ZAR or 10% of annual turnover United Arab Emirates PDPL, Modern Technology-Based Trade Law, TDRA telecoms rules Sender identification and a free opt-out in practice Yes Opt-in in practice: consumers must be able to choose whether to receive marketing Up to 10 million AED under the telecoms framework (directed at licensees); PDPL penalties pending United Kingdom UK GDPR, PECR, DPA 2018 (as amended by the Data (Use and Access) Act 2025) Clear identification of the sender, valid contact address Yes Prior consent or a qualifying commercial or charitable-purposes soft opt-in Up to 17.5 million GBP, or 4% annual global turnover – whichever is higher (now also the PECR maximum) USA CAN-SPAM Name, mailing address, contact information Yes Prior consent is not required under CAN-SPAM Up to 53,088 USD per violation