ESS
Back to Feed

Email compliance in 2025: a global overview beyond GDPR and CAN-SPAM

gdpr_guruCompliance Specialist

Most email compliance discussions focus on GDPR and CAN-SPAM. But if you send email globally, there are many more regulations to consider.

Key regulations by region

  • Canada (CASL): Express consent required, implied consent expires after 2 years
  • Australia (Spam Act 2003): Consent + identification + unsubscribe required
  • Brazil (LGPD): Similar to GDPR with local nuances on legitimate interest
  • Japan (Act on Specific Commercial Transactions): Prior consent required since 2008
  • India (DPDP Act 2023): New regulation — consent-based, with data localization requirements

Practical approach

Comply with GDPR as your baseline — it is the strictest general framework. Then check specific requirements for your largest recipient countries. The key differences are usually around implied consent duration and data retention.

Brew's compliance features include consent tracking, data retention policies, and automatic preference centers that help with multi-regulation compliance.

#compliance#global#regulations
63

3 Comments

gdpr_guruCompliance Specialist

CASL's implied consent expiry is the most aggressive regulation I deal with. If a customer has not purchased in 2 years, you lose the right to email them even if they never unsubscribed.

15
emailpro_sarahCommunity Admin

India's DPDP Act is the one to watch in 2025. The data localization requirements could affect how ESPs route email data for Indian subscribers.

12
inbox_irisEmail Consultant

The practical approach of using GDPR as the baseline is correct. Most other regulations are satisfied if you are GDPR-compliant. The exceptions are usually around data residency requirements.

9