📧 Email

Email Marketing Compliance: UK GDPR, PECR and CAN-SPAM Explained

Havari Team·10 March 2026·10 min read

If you send marketing emails to contacts in the UK, two pieces of law apply directly to how you collect addresses, what consent you need, and how easy it must be to opt out: UK GDPR and PECR. If any of your list is US-based, CAN-SPAM adds a second layer of rules on top. None of this needs to be complicated once you understand what each actually requires.

UK GDPR and PECR — the rules that matter first

For UK businesses, PECR (the Privacy and Electronic Communications Regulations) governs how you're allowed to send electronic marketing, while UK GDPR governs how you handle the personal data — like email addresses — behind it. In practice, they work together: PECR sets the consent bar for sending, and UK GDPR sets the standard for how that consent and data are managed.

Consent under PECR

For most B2C marketing email, you need clear, specific, opt-in consent before you send — a pre-ticked box or consent bundled into unrelated terms doesn't count. There's a narrower exception, often called the 'soft opt-in', that lets you email an existing customer about similar products or services they've bought from you before, provided you gave them a clear chance to opt out at the time and in every message since.

What valid consent looks like

An unticked checkbox the person actively ticks themselves
Clear wording about what they're signing up for — no vague 'updates from us and our partners'
A record of when and how consent was given
No consent bundled silently into signing up for something else, like a purchase

Unsubscribe requirements

Every marketing email needs a clear, working way to opt out, and that request needs to be honoured promptly — leaving someone on a list after they've unsubscribed is one of the most common compliance complaints. The unsubscribe link should be visible, not buried in tiny grey text at the very bottom, and it should take one click to work, not a login and a support ticket.

Record-keeping

You need to be able to show, for any contact, when and how they consented to receive marketing — not just that they're on a list today. That means storing the signup source, timestamp and the exact wording they agreed to, alongside every unsubscribe event with its own timestamp.

💡

Havari handles the record-keeping automatically

Every opt-in and opt-out in Havari is timestamped and tied to its source automatically, so if a contact's consent is ever questioned, the history is already there rather than something you have to reconstruct from spreadsheets.

CAN-SPAM — the secondary layer for US contacts

If any part of your list is based in the US, CAN-SPAM applies on top of UK GDPR and PECR for those contacts. It works differently from the UK approach — rather than requiring opt-in consent upfront, it's an opt-out model, but it comes with its own strict rules about honesty and access.

CAN-SPAM's core requirements

No misleading subject lines or falsified sender information
Clear identification that the message is an advertisement, where relevant
A valid physical postal address included in the email
A working, one-click unsubscribe method
Unsubscribe requests processed within 10 business days
⚠️

Higher bar wins

If your list includes both UK and US contacts, the practical approach is to meet the stricter UK GDPR and PECR opt-in standard for everyone, then layer CAN-SPAM's specific disclosure requirements — like the postal address — on top for US recipients. It's simpler than running two different consent processes.

A simple compliance checklist to run through

1

Audit your signup forms

Confirm every form uses a genuinely unticked opt-in box with clear wording, not a pre-ticked or bundled consent.

2

Check your unsubscribe flow

Click it yourself — it should take one step and remove the contact immediately, not route through a login.

3

Verify your record-keeping

Make sure you can pull up the consent timestamp and source for any individual contact on request.

4

Separate marketing from transactional

Confirm marketing opt-outs never silence order confirmations or account emails.

5

Review US-facing sends

Add a physical postal address and confirm subject lines aren't misleading for any campaign reaching US contacts.

10
Business days CAN-SPAM allows to honour an unsubscribe
1-click
The standard every unsubscribe link should meet

Do I need separate consent for email, SMS and WhatsApp?

Generally yes — consent should be channel-specific rather than one blanket tick box, since PECR treats different electronic communication channels distinctly. Havari tracks consent per channel so a contact can be opted into email but not SMS, or vice versa.

Is the soft opt-in the same as implied consent for any past customer?

No — it only applies to existing customers being marketed similar products or services to what they previously bought, and only if they were given a clear opt-out chance at the time of purchase and in every subsequent email.

Does CAN-SPAM require opt-in consent like UK GDPR?

No — CAN-SPAM is fundamentally an opt-out regime, focused on honesty, disclosure and an easy way to unsubscribe, rather than requiring consent before the first send.

None of this needs a legal team to get right day-to-day — it needs a signup process that asks properly, an unsubscribe link that works instantly, and a system that keeps the record for you. Get those three things right and most compliance risk disappears.

Ready to see it in action?

Join UK businesses using Havari to reach customers across SMS, WhatsApp, Email, Instagram and Messenger — all from one shared inbox.

Get 25 Free Messages

25 free messages · No credit card required · Cancel anytime