If you send marketing emails to contacts in the UK, two pieces of law apply directly to how you collect addresses, what consent you need, and how easy it must be to opt out: UK GDPR and PECR. If any of your list is US-based, CAN-SPAM adds a second layer of rules on top. None of this needs to be complicated once you understand what each actually requires.
For UK businesses, PECR (the Privacy and Electronic Communications Regulations) governs how you're allowed to send electronic marketing, while UK GDPR governs how you handle the personal data — like email addresses — behind it. In practice, they work together: PECR sets the consent bar for sending, and UK GDPR sets the standard for how that consent and data are managed.
For most B2C marketing email, you need clear, specific, opt-in consent before you send — a pre-ticked box or consent bundled into unrelated terms doesn't count. There's a narrower exception, often called the 'soft opt-in', that lets you email an existing customer about similar products or services they've bought from you before, provided you gave them a clear chance to opt out at the time and in every message since.
What valid consent looks like
Every marketing email needs a clear, working way to opt out, and that request needs to be honoured promptly — leaving someone on a list after they've unsubscribed is one of the most common compliance complaints. The unsubscribe link should be visible, not buried in tiny grey text at the very bottom, and it should take one click to work, not a login and a support ticket.
You need to be able to show, for any contact, when and how they consented to receive marketing — not just that they're on a list today. That means storing the signup source, timestamp and the exact wording they agreed to, alongside every unsubscribe event with its own timestamp.
Havari handles the record-keeping automatically
Every opt-in and opt-out in Havari is timestamped and tied to its source automatically, so if a contact's consent is ever questioned, the history is already there rather than something you have to reconstruct from spreadsheets.
If any part of your list is based in the US, CAN-SPAM applies on top of UK GDPR and PECR for those contacts. It works differently from the UK approach — rather than requiring opt-in consent upfront, it's an opt-out model, but it comes with its own strict rules about honesty and access.
CAN-SPAM's core requirements
Higher bar wins
If your list includes both UK and US contacts, the practical approach is to meet the stricter UK GDPR and PECR opt-in standard for everyone, then layer CAN-SPAM's specific disclosure requirements — like the postal address — on top for US recipients. It's simpler than running two different consent processes.
A simple compliance checklist to run through
Audit your signup forms
Confirm every form uses a genuinely unticked opt-in box with clear wording, not a pre-ticked or bundled consent.
Check your unsubscribe flow
Click it yourself — it should take one step and remove the contact immediately, not route through a login.
Verify your record-keeping
Make sure you can pull up the consent timestamp and source for any individual contact on request.
Separate marketing from transactional
Confirm marketing opt-outs never silence order confirmations or account emails.
Review US-facing sends
Add a physical postal address and confirm subject lines aren't misleading for any campaign reaching US contacts.
Do I need separate consent for email, SMS and WhatsApp?
Generally yes — consent should be channel-specific rather than one blanket tick box, since PECR treats different electronic communication channels distinctly. Havari tracks consent per channel so a contact can be opted into email but not SMS, or vice versa.
Is the soft opt-in the same as implied consent for any past customer?
No — it only applies to existing customers being marketed similar products or services to what they previously bought, and only if they were given a clear opt-out chance at the time of purchase and in every subsequent email.
Does CAN-SPAM require opt-in consent like UK GDPR?
No — CAN-SPAM is fundamentally an opt-out regime, focused on honesty, disclosure and an easy way to unsubscribe, rather than requiring consent before the first send.
None of this needs a legal team to get right day-to-day — it needs a signup process that asks properly, an unsubscribe link that works instantly, and a system that keeps the record for you. Get those three things right and most compliance risk disappears.