
Is it illegal to send marketing emails without permission?
Key Facts
- The U.S. is the only major jurisdiction allowing marketing emails without prior consent under CAN-SPAM's opt-out model per FTC guidance.
- Canada's CASL imposes penalties up to CAD $10 million per day for organizations sending unsolicited commercial emails according to compliance research.
- GDPR fines reach €20 million or 4% of global annual turnover, whichever is higher, for non-compliant email marketing per international compliance data.
- The UK ICO fined Boost Finance Ltd £90,000 for 4 million emails sent on generic 'third party marketing' consent per enforcement records.
- CAN-SPAM violations carry penalties up to $53,088 per individual email as of January 2025 per FTC compliance guide.
- Washington state law allows up to $500 per email for misleading subject lines like manufactured urgency claims per class action reporting.
- Consent laws apply based on where contacts live, not where your business operates per practitioner guidance.
The Short Answer: It Depends on Where Your Contacts Live
If you're waiting for a simple yes or no, here it is: in most of the world, yes — sending marketing emails without permission is flatly illegal. But in the United States, the answer is no, and that split is exactly where businesses get into trouble.
The U.S. is the global outlier. Under the CAN-SPAM Act, according to the FTC's compliance guide, you don't need prior consent to send commercial email. The law operates on an opt-out model: you can email someone until they tell you to stop, provided you meet strict requirements — accurate headers, truthful subject lines, a valid physical address, and a working unsubscribe honored within 10 business days. Even so, violations carry penalties of up to $53,088 per separate email.
Nearly everywhere else flips that model on its head. As compliance research from Usercentrics confirms, regulations including GDPR (EU), CASL (Canada), PECR (UK), and Australia's Spam Act all require explicit opt-in consent before a single marketing email goes out. The penalties reflect how seriously these jurisdictions take it:
- Canada's CASL: up to CAD $10 million per day for organizations
- GDPR and UK-GDPR: €20 million / £20 million or 4% of global annual turnover, whichever is higher
- Brazil's LGPD: up to BRL 50 million or 2% of Brazilian annual revenue per violation
- Australia's Spam Act: up to AUD 220,000 for repeat offenders
This isn't theoretical enforcement. The UK ICO fined Boost Finance Ltd £90,000 for sending over 4 million unsolicited funeral-plan marketing emails, ruling the underlying consent was "inadequate, generic, vague and misleading" — affiliate-level "third party marketing" consent didn't transfer because the specific sender was never identified.
That's why "it depends" is a dangerous answer for any business emailing across borders. Consent laws apply based on where your contacts live, not where your business sits. A Texas company emailing a list that includes Canadian or European addresses inherits CASL and GDPR obligations the moment it hits send. And as practitioner guidance on 2026 email compliance puts it: if you sell internationally, follow the strictest standard you touch — GDPR is usually the highest bar.
Size offers no shelter either. The same guidance notes that these laws apply based on who you email and what you do with their data, not how big your operation is.
This jurisdictional reality is why My AI Call Center — operating from both Halifax, Nova Scotia and Austin, Texas — builds every campaign around approved, permissioned, or reviewed contact lists, with list source and consent records checked before anything launches. When your footprint spans CAN-SPAM and CASL territory simultaneously, the strictest applicable standard isn't a courtesy. It's the only workable baseline.
The sections ahead break down what each major framework actually requires — and what "consent" must look like to hold up when a regulator asks.
What the Law Actually Demands — and What Violations Cost
The penalties for getting email compliance wrong are not theoretical — they scale per message, per day, and per percentage point of global revenue. Here is what each major framework demands, and what violations actually cost.
CAN-SPAM (United States) is the most permissive regime, but "permissive" does not mean optional. According to the FTC's compliance guide, every commercial email must meet specific obligations:
- Accurate header information — no false or misleading "from" or routing data
- Truthful subject lines that reflect the message content
- A valid physical postal address in every message
- Opt-out requests honored within 10 business days, with the unsubscribe mechanism working for at least 30 days after sending
- No fees, no multi-step hurdles, and no selling or transferring opted-out addresses
Violations carry penalties of up to $53,088 per individual email — the inflation-adjusted figure effective January 17, 2025. A single campaign to 10,000 contacts with a broken unsubscribe link is not a slap on the wrist; it is existential exposure.
CASL (Canada) is far stricter. It requires express consent before sending commercial electronic messages, with penalties reaching CAD $10 million per day for organizations and CAD $1 million for individuals, per Usercentrics' overview of email marketing laws. For any business operating in Canada, the U.S.-style opt-out model is simply not available.
The GDPR raises the ceiling further: fines of up to €20 million or 4% of global annual turnover, whichever is higher. Consent must be voluntary, informed, and given through an unambiguous confirming action — pre-checked boxes do not count.
Enforcement is active, not hypothetical. The UK ICO fined Boost Finance Ltd £90,000 for sending over 4 million unsolicited funeral-plan emails because the underlying consent was deemed "inadequate, generic, vague and misleading," as the National Law Review's enforcement write-up details. Meanwhile, Washington state's CEMA allows damages up to $500 per email for misleading subject lines, and class actions have already targeted brands like Southwest Airlines and Nike over manufactured urgency, according to industry reporting on the litigation wave.
Two rules catch businesses off guard. First, shared liability: the FTC states plainly that "even if you hire another company to handle your email marketing, you can't contract away your legal responsibility." Both the promoted company and the sender can be held liable. Second, size is no shield — as practitioner guidance on 2026 compliance puts it, laws apply based on who you email and what you do with their data, not how big your business is.
This is why My AI Call Center checks list source and consent records before any campaign launches, flagging or declining bought lists without clear permission records. When liability cannot be outsourced, the vendor's list discipline becomes part of your legal defense.
Enforcement Is Real: Generic Consent and Misleading Subject Lines
It's easy to read consent rules as paperwork — until a regulator turns them into a six-figure fine. The enforcement record shows these aren't theoretical risks, and the cases reveal exactly where companies go wrong.
In the UK, the Information Commissioner's Office fined Boost Finance Ltd £90,000 for sending more than 4 million unsolicited funeral-plan marketing emails, according to a National Law Review account of the enforcement action. The company believed it had consent — recipients had agreed to "third party marketing" through affiliates.
The ICO disagreed. It ruled the consent "inadequate, generic, vague and misleading" because the specific sender was never clearly identified. The principle that emerges is blunt: consent must name who will contact the person and for what purpose. A vague checkbox covering unnamed partners doesn't transfer.
This is precisely why disciplined outbound operations check list source and consent records before anything launches. At My AI Call Center, bought lists without clear permission records are flagged and in most cases declined — because as the Boost Finance case shows, "someone opted in somewhere" is not a defense.
The second enforcement front is content honesty. Washington state's Commercial Electronic Mail Act (CEMA) bans false or misleading subject lines, with damages of up to $500 per email — and class actions are now targeting major brands over "manufactured urgency," per industry reporting on the litigation wave.
Southwest Airlines, Nike, and Tim Hortons have all faced suits over subject lines like "Last Day" and "Ending Soon" when the promotions weren't actually ending. At $500 per email across a list of thousands, a single campaign's creative shortcut becomes serious legal exposure.
The practical takeaways from these cases:
- Consent must be specific — naming the actual sender and purpose, not a generic "third party" category
- Subject lines must be literally true — urgency claims require a real deadline behind them
- Documentation matters — if you can't prove consent when challenged, regulators treat it as absent
- Liability can't be outsourced — under FTC guidance on CAN-SPAM, both the sender and the promoted company can be held responsible, with penalties up to $53,088 per email
The deeper shift is that truthful content has moved from a deliverability concern to a legal one. As the analysis of the CEMA cases puts it, a subject line that bends the truth might drive short-term clicks, but it risks fines, lawsuits, and reputational damage.
The same logic applies across channels. Whether it's an email subject line or an outbound call script, invented claims and manufactured urgency create the same exposure. That's why "no invented numbers" — reporting what actually happened, with real scripts and real disclosures — functions as a legal safeguard, not just a brand value.
Enforcement agencies and plaintiffs' attorneys are reading marketing messages closely. The safest posture is the boring one: permissioned lists, named consent, and content that tells the plain truth.
The Practical Playbook: Default to the Strictest Standard You Touch
The U.S. lets you email first and ask questions later. Almost everywhere else — Canada, the EU, the UK, Australia, Brazil — you need explicit opt-in consent before a single marketing email lands in an inbox. The FTC confirms CAN-SPAM requires no prior consent, while major frameworks like CASL and GDPR treat unsolicited commercial email as unlawful. For a company operating from both Halifax and Austin, the strictest standard you touch becomes your operational floor.
Practitioners put it plainly: follow the strictest standard you touch. That means adopting CASL- or GDPR-style opt-in as your default, even for U.S.-only sends. Document consent so it names the specific sender and purpose — the UK ICO fined £90,000 when "third party marketing" consent failed to identify the actual company behind 4 million funeral-plan emails. Build opt-out handling to the tightest spec: honor requests within 10 business days, keep the mechanism live for 30+ days, and never sell or transfer opted-out addresses. Treat subject-line accuracy as a compliance requirement, not a copywriting tactic — Washington state law allows up to $500 per email for manufactured urgency claims.
- Default to express opt-in (CASL/GDPR standard) for every list, every campaign
- Record consent with sender name and specific purpose attached
- Honor opt-outs fast — within 10 business days, mechanism functional 30+ days
- Never sell, share, or transfer addresses that have opted out
- Write subject lines that would hold up in court
This is the posture My AI Call Center bakes into every campaign. Lists are approved, permissioned, reviewed before launch — source and consent records checked, bought lists without clear permission declined. Opt-outs are logged and honored immediately. The first campaign review is free, and the full number is known before you approve launch. Plan a campaign that starts on the right side of every inbox law that applies to you.
Frequently Asked Questions
Is it illegal to send marketing emails without permission in the U.S.?
What about sending marketing emails to people in Canada or the EU?
If my business is based in the U.S., do I still have to follow Canadian or EU email laws?
What counts as valid consent under laws like GDPR and CASL?
Can I avoid liability by hiring another company to send my marketing emails?
Are misleading subject lines actually a legal risk, or just a deliverability issue?
Permission Isn't Paperwork — It's Your Legal Baseline
So, is it illegal to send marketing emails without permission? In most of the world, yes. The U.S. stands nearly alone with its opt-out model — everywhere from Canada to the EU to Australia demands explicit consent before the first send, with penalties reaching CAD $10 million per day under CASL and 4% of global turnover under GDPR. And because liability follows your contacts' location — not yours — and can't be outsourced to a vendor, the only safe posture is the strictest standard you touch. The practical path is simple: default to express opt-in, document consent naming the sender and purpose, honor opt-outs fast, and keep every subject line literally true. That's the same discipline My AI Call Center applies to outbound calling — approved, permissioned, reviewed lists, consent records checked before launch, and bought lists without clear permission declined. If you're planning an outbound campaign and want the list review handled before you spend anything, the first campaign review is free — plan your campaign at myaicallcenter.app/campaigns.