GDPR, CAN-SPAM, and TCPA: What Marketers Actually Need to Know
A plain-language breakdown of GDPR, CAN-SPAM, and TCPA for marketers: what each law requires, where SMBs get exposed, and the minimum viable checklist to keep email and SMS campaigns compliant.
The FTC issued $35.4 million in civil penalties for CAN-SPAM violations in the last two years. GDPR fines in 2024 topped €750 million. TCPA judgments against marketers regularly hit six figures. You do not need to be a lawyer to stay compliant, but you do need to stop treating compliance as something the legal team handles.
This is a channel-by-channel breakdown of the three laws that matter most to email and SMS marketers.
CAN-SPAM is the email rulebook you cannot skip
CAN-SPAM does one thing: it sets the minimum bars for commercial email. If you send marketing emails in the US, to US recipients, CAN-SPAM applies. It is the law the FTC enforces the hardest, and the one most marketers ignore the longest.
Here is what CAN-SPAM requires:
Header and subject line. Your email headers—From, To, Reply-To—must be accurate. Your subject line cannot be deceptive. "Re: Your refund status" when it is not actually a reply is CAN-SPAM violation #1.
Physical address. You must include a legitimate postal address in every commercial email. A PO box works; a fake building does not. This is non-negotiable.
Opt-out handling. You must honor unsubscribe requests within 10 business days. If someone clicks unsubscribe on Monday, they should not get another email from you on Friday. Most ESPs handle this automatically, but only if you set it up correctly.
Identification. The email must clearly identify itself as an advertisement, or it must be a transactional message (order confirmation, shipping update, password reset). Marketing emails that masquerade as transactional emails violate CAN-SPAM.
The penalty for violations: up to $43,280 per message. One blast to 10,000 people that gets flagged incorrectly is a $432 million liability. Email compliance is simply not optional.
TCPA is where SMS campaigns get expensive
The Telephone Consumer Protection Act (TCPA) is older than email regulations and stricter about enforcement. It was written for telemarketing and applies to text messages with mechanical precision.
TCPA requires separate consent for SMS. Email permission does not carry over. If someone subscribed to your email list, you cannot text them without explicit prior written consent. That means a separate checkbox, a separate opt-in flow, or documented agreement.
Consent must be documented. Store the date, time, method, and channel the subscriber opted in through. If someone texts "STOP" to opt out, honor it instantly and log it. Many TCPA lawsuits hinge on poor record-keeping.
Class action risk is real. TCPA allows consumers to sue, and they often do—individually or in class action. Settlements are often six figures minimum. A single violated text to 100,000 people exposes you to theoretical damages in the hundreds of millions.
What to avoid: Do not scrape phone numbers from public sources. Do not buy texting lists. Do not use email consent to power SMS campaigns. Do not text people at 2 AM. The TCPA has a quiet hours rule (9 PM to 8 AM in the recipient's time zone).
GDPR makes proof of consent part of the job
GDPR applies to anyone marketing to residents of the EU or UK, regardless of where you live. It adds a compliance layer that US-only email laws do not touch: your burden is to prove you have lawful basis for processing personal data.
For email and SMS, lawful basis typically means explicit consent. You need to be able to prove the person agreed to receive communications from you. That means:
- Opt-in checkbox, not opt-out (pre-checked boxes do not count)
- Clear statement of purpose (not buried in a privacy policy)
- Timestamp and record of what they consented to
- Ability to revoke consent on demand
GDPR penalties scale with revenue and damage. The ceiling is €20 million or 4% of annual global revenue, whichever is higher. For a $25 million annual revenue business, that is a $1 million+ fine floor. Smaller violations can run €10 million or 2% of revenue.
Critically, GDPR applies per region. UK data subjects fall under UK GDPR (similar rules, separate enforcement). EU data subjects fall under EU GDPR. If you cannot prove consent for an EU subscriber, you cannot email them.
The minimum viable compliance checklist
Here is what an SMB needs to do this week:
- Capture consent at point of sign-up. Ask explicitly: "I want to receive marketing emails." Do not make it a buried default. Store the answer.
- Log the source and timestamp. Record when and how someone subscribed. Notion spreadsheet, database field, email service metadata—pick one. Stick with it.
- Keep email and SMS suppression lists separate. Your ESP should let you mark someone as unsubscribed from email but still SMS-eligible (or vice versa). If it does not, your workflow is broken.
- Audit templates before launch. Does your email include your business address and a working unsubscribe link? Is your SMS compliant with quiet hours? Run a pre-send checklist.
- Review third-party data sources before import. Did you buy a list? Did a customer provide phone numbers? Before importing, ask: Where did these come from? Do I have written permission?
- Keep documentation where you can find it. Screenshot consent flows, save opt-in timestamps, and store revocation logs. If an enforcement action lands, you will need evidence.
The mistakes that cause real damage
Buying or renting lists. Purchased contacts violate GDPR, TCPA, and CAN-SPAM all at once. Do not do this. Not even in a surge campaign.
Hiding unsubscribe links. Using tiny font, burying the link in footer text, or making it multi-click counts as obstruction. Your unsubscribe has to be obvious.
Reusing email consent for SMS. Mentioned above, but it bears repeating: one opt-in does not cover both channels.
Ignoring platform policy. Klaviyo, Mailchimp, HubSpot, and other ESPs have policies stricter than the law. Mailchimp bans purchased lists. Klaviyo flags unsubscribed or invalid addresses. Do not treat their rules as suggestions.
Treating regional differences as irrelevant. A UK subscriber gets UK GDPR rules. An EU subscriber gets EU GDPR rules. An Australian subscriber gets Australian Privacy Act rules. Compliance is not one-size-fits-all.
The bottom line
Compliance is not paperwork. It is campaign infrastructure. If you cannot prove permission, honor opt-outs within the required timeframe, and keep email and SMS rules separate, you are one send away from fines, lawsuits, or deliverability collapse.
Start with the checklist above. Run your current campaigns through it. Fix the gaps. The marketer who built compliance into their workflow from day one does not get surprised in year three.
Ready to audit your compliance setup? Start here: document your current sign-up flow, check your suppression list handling, and verify your ESP is set up to log consent. It takes an hour and it could save you six figures.
About the Author
Colin
Founder of Drip Drop.