February 9, 20268 min read

What Are the Email Consent Requirements?

Email consent requirements depend on where your recipients are located. GDPR (EU) requires explicit opt-in before marketing. CAN-SPAM (US) allows sending without prior consent but requires unsubscribe. CASL (Canada) requires express or implied consent. When in doubt, explicit opt-in is always legally safe and produces better engagement.

Consent Requirements by Region

United States (CAN-SPAM)

CAN-SPAM is the least restrictive major regulation. However, mailbox providers still filter unwanted email aggressively.

European Union (GDPR + ePrivacy)

Canada (CASL)

United Kingdom (UK GDPR + PECR)

Global Best Practice

If you email internationally, applying the strictest standard (GDPR-style explicit opt-in) globally ensures compliance everywhere and produces higher-quality lists.

Types of Consent

Explicit Consent (Opt-In)

Strongest form, required by GDPR:

Implied Consent

Allowed in some jurisdictions (Canada, partial UK):

Double Opt-In (Confirmed Opt-In)

Gold standard but not legally required:

Valid Consent Elements

For consent to be valid (especially under GDPR):

Invalid Consent Practices

Documenting Consent

Maintain records proving consent:

Consent for Different Email Types

Marketing Email

Requires explicit consent under GDPR, opt-out option under CAN-SPAM.

Transactional Email

Does not require separate marketing consent if directly related to a transaction the person initiated.

Service Announcements

Account-related, security, and service updates generally do not require marketing consent if necessary for the service relationship.

Frequently Asked Questions

Does consent expire?
Under GDPR, consent does not automatically expire but should be refreshed periodically. Under CASL, implied consent expires after 2 years. Express consent does not expire but can be withdrawn.
Can I email business contacts without consent?
Depends on jurisdiction. B2B email has some allowances in certain regions, but GDPR applies to all personal data including business email addresses of individuals.
What if someone gave consent years ago?
If properly documented and still valid under applicable law, old consent can remain valid. However, if the person has not engaged in years, re-confirming consent is good practice.
Is double opt-in legally required?
No law specifically requires double opt-in. However, it provides the strongest consent documentation and cleanest lists. It is best practice even if not mandatory.

Build Compliant Email Programs

SortedIQ helps senders implement proper consent practices for global audiences.

Talk to Our Team