CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Consent Verification Process

Is it illegal for a company to not let you unsubscribe?

Back to InsightsIs it illegal for a company to not let you unsubscribe?

Is it illegal for a company to not let you unsubscribe?

Key Facts

  • A broken unsubscribe link isn't a glitch — CAN-SPAM violations cost up to $53,088 per email, per the FTC's official compliance guide.
  • Companies must honor opt-out requests within 10 business days, and the unsubscribe mechanism must stay functional for at least 30 days according to CAN-SPAM rules.
  • Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — after its unsubscribe flow failed during a platform migration per enforcement records.
  • GDPR fines reach €20 million or 4% of global annual revenue, whichever is higher according to compliance analysis.
  • Canada's CASL carries penalties up to $10 million CAD per violation for organizations per industry research.
  • The law follows your recipient, not your office — a U.S. business emailing someone in Germany triggers GDPR per compliance experts.
  • Since February 2024, Gmail has permanently rejected bulk senders who skip one-click unsubscribe per published platform policy.

The Short Answer: Yes, It's Illegal — and the Fines Are Steep

If you have ever hit "unsubscribe" and kept getting emails anyway, you are not imagining things — and the company sending them is breaking the law. Failing to provide a working opt-out is not a gray area; it is a direct violation of consent law in the United States, Europe, Canada, and most major jurisdictions.

In the U.S., the FTC's official CAN-SPAM compliance guide is unambiguous: every commercial email must include a clear, functional opt-out mechanism, and senders must honor requests within 10 business days. The mechanism must stay live for at least 30 days after sending, and opt-out requests never expire — they must be honored in perpetuity unless the recipient opts back in, per the same legal framework. Violations carry penalties of up to $53,088 per individual email, a figure the FTC updated in January 2025, according to industry compliance analysis.

The penalties scale sharply outside the U.S. as well:

  • GDPR (EU): Up to €20 million or 4% of global annual revenue, whichever is higher.
  • CASL (Canada): Up to $10 million CAD per violation for organizations.
  • CCPA/CPRA (California): $2,663 per unintentional violation, $7,998 per intentional one, per consumer.

Enforcement is not theoretical. In 2024, security camera maker Verkada paid a $2.95 million settlement — the largest CAN-SPAM settlement in FTC history. A year earlier, Experian paid $650,000 because its unsubscribe flow broke during a platform migration. Notably, neither company intended to break the law; these were operational blind spots that quietly developed when nobody was watching for compliance gaps.

The law also follows your recipient, not your office address. A U.S. business emailing someone in Germany triggers GDPR for that contact, as the same analysis points out. And per the FTC, you cannot contract away responsibility by outsourcing your sends — both the advertiser and the sending company can be held liable.

This is why consent verification matters so much. At My AI Call Center, every campaign begins with a list and consent review before anything launches, and opt-outs are logged and honored immediately. That discipline reflects a simple reality: compliance experts recommend following the stricter standard everywhere, because doing so satisfies nearly every framework at once.

What the Law Actually Requires: Unsubscribe Rules Across Jurisdictions

So you clicked "unsubscribe" and the emails keep coming. Here's what the law actually says about that — and it's more specific than most companies realize.

The FTC's CAN-SPAM compliance guide is blunt: the law "gives recipients the right to have you stop emailing them." That right comes with hard deadlines and technical requirements that apply to every commercial message, not just bulk newsletters.

The core rules are consistent across CAN-SPAM, Canada's CASL, and other major frameworks:

  • Opt-out requests must be honored within 10 business days of receipt, a timeline shared across CAN-SPAM, CASL, and other frameworks.
  • The unsubscribe mechanism must stay functional for at least 30 days after the email is sent — a broken link is a violation, not a glitch.
  • Opt-out requests never expire. They must be honored in perpetuity unless the recipient voluntarily opts back in.
  • Once someone opts out, you cannot sell or transfer their email address, except to a company hired to help with compliance.

The stakes are real. Violations of CAN-SPAM can draw penalties of up to $53,088 per violating email, according to the U.S. Chamber of Commerce. And since February 2024, Gmail has permanently rejected bulk senders who skip one-click unsubscribe — platform enforcement layered on top of legal exposure.

Two misconceptions get companies into trouble. First, many assume the law depends on where their office sits. It doesn't. As compliance experts put it, "the law follows your recipient, not your company address." A U.S. business emailing someone in Germany triggers GDPR for that contact.

Second, there is no B2B exception. The FTC states plainly that CAN-SPAM has "no exception for business-to-business email." If it's a commercial message, the rules apply — full stop. Prior consent doesn't erase these obligations either; under GDPR, recipients always retain "a straightforward way to withdraw consent at any time."

This is why consent verification matters before any campaign launches, not after. At My AI Call Center, list source and consent records are reviewed before a single call goes out, and opt-outs are logged and honored immediately — because a missing or ignored opt-out isn't a minor oversight. It's a breach of consent law, with penalties that scale per message, per recipient.

The simplest path, per compliance analysts: adopt the strictest standard (GDPR) everywhere, and you'll satisfy most other frameworks automatically.

The Same Rules Apply to Phone Calls — Not Just Email

If a company won't let you stop the calls, the law is just as unforgiving as it is for email — and in some ways, stricter. The Telephone Consumer Protection Act treats AI-generated voices as artificial voices, which means every call requires prior express consent before it is placed, not just an opt-out after the fact.

The consent logic mirrors what email law already establishes: once someone says stop, stopping is a legal obligation, not a courtesy. Under CAN-SPAM, the FTC requires that opt-out requests be honored within 10 business days, and opt-out requests never expire — they must be respected in perpetuity unless the recipient opts back in. On the phone side, the same principle plays out through keyword opt-outs like STOP and REVOKE, and through do-not-call requests that must be logged and honored across every campaign a company runs.

For AI calling specifically, the practical requirements are concrete:

  • AI-generated voices are artificial voices under the TCPA — prior express consent is required before dialing.
  • Keyword opt-outs such as STOP and REVOKE must be recognized immediately, and honored.
  • Do-not-call requests must be respected across all campaigns and carried into permanent DNC records.
  • Recipients can ask whether a call is AI-assisted, request a human, or opt out — and those requests must be handled.

Here is the part that catches many businesses off guard: hiring someone else to make the calls does not transfer the legal risk. The FTC is explicit on this point in the email context, stating that you cannot contract away your legal responsibility — both the promoted company and the sending company can be held liable. Opt-out obligations extend to third parties acting on the advertiser's behalf, meaning if an agency or vendor mishandles a request, the brand that commissioned the campaign is exposed too.

That shared liability is why consent verification has to happen before a campaign launches, not after a complaint arrives. A vendor that checks list sources and consent records up front — and flags lists without clear permission records — is doing exactly what the law effectively demands of both parties. This is how My AI Call Center approaches every campaign: opt-outs are logged and honored immediately, DNC requests carry into client records, and nothing launches until the list and consent documentation are reviewed.

The financial stakes make the discipline worthwhile. CAN-SPAM violations alone can reach $53,088 per violating message, and TCPA exposure follows a similar pattern of per-call liability. Whether the message travels by email or by voice, consent is the legal foundation — and an unsubscribe option is how you prove you respect it.

How Operational Blind Spots Create Violations

How Operational Blind Spots Create Violations

Most compliance failures aren't the result of deliberate defiance but rather systemic oversights that emerge during routine business changes. As industry experts note, "Neither company was intentionally breaking the law. These were operational blind spots, the type that quietly develop during a redesign or ESP switch when nobody's specifically watching for compliance gaps" according to research analyzing major enforcement cases. This pattern appears consistently in regulatory settlements where unsubscribe mechanisms fail not due to malice but through neglected process monitoring.

The Verkada and Experian settlements exemplify how system transitions create vulnerability. Verkada paid $2.95 million in 2024—the largest CAN-SPAM settlement in FTC history—after failing to provide functional unsubscribe options during a platform migration as documented in regulatory filings. Similarly, Experian's $650,000 settlement in 2023 stemmed from a broken unsubscribe flow during their own system redesign per official enforcement records. These cases reveal that compliance gaps typically surface when teams focus on technical migration while overlooking consent mechanics.

  • System migrations and ESP switches
  • Website or email template redesigns
  • Process handoffs between marketing and technical teams
  • Unmonitored automated workflows
  • Consent record synchronization failures

Today's enforcement reality operates on dual tracks: regulatory penalties alongside platform-level deliverability consequences. Since February 2024, Gmail has permanently rejected bulk senders who skip one-click unsubscribe functionality based on published policy updates, creating immediate business impact beyond potential fines. This convergence means that maintaining proper unsubscribe mechanics isn't just about avoiding legal risk—it's fundamentally about ensuring messages reach intended recipients. As industry analysis confirms, "Good compliance habits and strong deliverability practices are basically the same thing" per expert consensus on email operations. For organizations managing permissioned contact lists, this alignment simplifies compliance: honoring unsubscribe requests protects both legal standing and email reputation simultaneously.

Running compliant campaigns starts before the first message sends. The FTC makes clear that CAN-SPAM applies to every commercial email — including B2B — and that "subscribers/members retain opt-out rights" regardless of prior consent. Violations carry penalties up to $53,088 per email, and Gmail now permanently rejects bulk senders lacking one-click unsubscribe. FTC guidance confirms the law gives recipients the right to stop messages at any time.

  • Verify list source and consent records before any campaign launches
  • Build working opt-out mechanisms into every channel — calls, texts, emails
  • Honor opt-outs immediately and log them across all campaigns
  • Test unsubscribe flows during every system change or migration
  • Adopt the stricter GDPR standard globally to simplify compliance

The 10-business-day honor window and 30-day mechanism durability are non-negotiable baselines. Industry analysis shows operational blind spots during platform switches caused the Verkada and Experian settlements — failures that monitoring catches. Opt-out requests never expire and must be honored in perpetuity unless the recipient opts back in. Regulatory overviews confirm this applies to third parties sending on your behalf too.

My AI Call Center reviews consent records and honors opt-outs across all campaigns before anything launches. The managed service checks list source, calling windows, and disclosure scripts — then routes every disposition, including opt-outs, back into your CRM. Compliance experts recommend following GDPR's stricter opt-in standard universally; doing so satisfies most CAN-SPAM and CASL requirements automatically.

Frequently Asked Questions

Is it actually illegal for a company to keep emailing me after I unsubscribe?
Yes. Under the U.S. CAN-SPAM Act, every commercial email must include a working opt-out mechanism, and companies must honor your request within 10 business days — the FTC states plainly that the law gives recipients the right to make a company stop emailing them. Violations carry penalties of up to $53,088 per individual email, a figure the FTC updated in January 2025.
How long does a company legally have to stop emailing me once I unsubscribe?
Companies have 10 business days to honor your opt-out request, and the unsubscribe mechanism itself must stay functional for at least 30 days after the email is sent, according to the FTC's CAN-SPAM compliance guide. A broken unsubscribe link isn't a glitch — it's a violation.
Can a company email me just because I'm a customer or gave my email at signup?
Yes, they can email you, but you always keep the right to stop them. Prior consent or an existing business relationship does not erase your opt-out rights, and under GDPR, recipients must always have a straightforward way to withdraw consent at any time. Once you opt out, the request never expires unless you voluntarily opt back in.
Does the unsubscribe law apply to B2B emails too?
Yes. Many B2B teams assume CAN-SPAM doesn't apply to them, but the FTC is explicit that there is no exception for business-to-business email. If it's a commercial message, the unsubscribe rules apply — full stop.
What happens to companies that don't honor unsubscribes?
The fines are steep and enforcement is real. Security camera maker Verkada paid a $2.95 million settlement in 2024 — the largest CAN-SPAM settlement in FTC history — and Experian paid $650,000 after its unsubscribe flow broke during a platform migration. Outside the U.S., GDPR fines can reach €20 million or 4% of global revenue, and Canada's CASL allows up to $10 million CAD per violation.
Can a company avoid liability by outsourcing their emails or calls to an agency?
No. The FTC makes clear that you cannot contract away legal responsibility — both the company advertising and the company sending can be held liable. That's why My AI Call Center reviews list source and consent records before any campaign launches, and logs and honors every opt-out immediately across all campaigns.

The Bottom Line: Consent Is Not Optional — and Neither Is the Unsubscribe

The answer to the question is clear: yes, it is illegal to deny someone a working way to opt out. Every major framework — CAN-SPAM, GDPR, CASL, and CCPA — requires a functional unsubscribe mechanism, with penalties reaching up to $53,088 per violating email. The enforcement record shows most violations come from operational blind spots, not bad intent: broken links during migrations and redesigns cost Verkada $2.95 million and Experian $650,000. The practical takeaway is simple. Adopt the strictest standard everywhere — GDPR's — and you satisfy most other frameworks automatically. Test your unsubscribe flows during every system change. Remember the law follows your recipient, not your office, and there is no B2B exception. If you run outbound campaigns and want that discipline handled for you, My AI Call Center reviews list source and consent records before anything launches, and logs and honors every opt-out immediately. Your next step: audit your own opt-out flow this week — or book a free campaign review at myaicallcenter.app and let the consent review happen before you spend anything.

Get campaign planning tips