Skip to content

CAN-SPAM, CASL and PECR: B2B email rules for the US, UK and Canada

One campaign, three very different laws. A plain-English guide to what each market requires before you hit send.

BootSoc team

A marketer reviewing an email campaign on a laptop and phone

If your campaigns reach buyers in the US, UK and Canada, you're working under three different rulebooks. The good news is that one well-designed process can satisfy all of them. This guide summarises the essentials. It isn't legal advice, so check your specific program with counsel.

United States: CAN-SPAM

CAN-SPAM applies to commercial email, including business-to-business messages. It doesn't require prior consent, but it sets firm rules for every message:

  • Accurate header information and a subject line that isn't misleading
  • A valid physical postal address for the sender
  • A clear way to opt out, honored within 10 business days
  • Responsibility for what vendors send on your behalf

Penalties can exceed $50,000 per violating email. State privacy laws add another layer: many now cover business contact data and give people the right to opt out of the sale or sharing of their information.

Canada: CASL

Canada's Anti-Spam Legislation is stricter. You need consent before sending a commercial electronic message. Consent can be express (the person opted in) or implied in specific situations, such as an existing business relationship or a business address that was conspicuously published without a “no unsolicited messages” statement, where your message is relevant to the person's role.

  • Identify the sender and include contact information
  • Include an unsubscribe mechanism that works for at least 60 days after sending
  • Process unsubscribes within 10 business days
  • Keep records that prove consent

Penalties reach up to CA$10 million per violation for organisations. In Quebec, Law 25 adds requirements around tracking technologies and a named person responsible for personal information.

United Kingdom: PECR and UK GDPR

Under PECR, you can email corporate subscribers (limited companies, LLPs and government bodies) without prior consent, as long as you identify yourself and offer a simple opt-out in every message. Sole traders and some partnerships count as individual subscribers, so they need consent or a valid soft opt-in.

Named business emails are still personal data under UK GDPR, so you need a lawful basis, usually legitimate interests backed by a documented assessment. The Data (Use and Access) Act 2025 raised maximum PECR fines to match UK GDPR levels, so the stakes are now much higher.

One process that works everywhere

  • Record consent or lawful basis per contact, with source and timestamp
  • Identify the sender and include a postal address in every message
  • Offer one-click unsubscribe and sync it to a global suppression list
  • Honor opt-outs within 10 business days at the latest
  • Treat Canadian and UK sole-trader contacts as opt-in only unless an exemption clearly applies

Our Email and outreach policy explains exactly how BootSoc applies these rules to the programs we run for clients.

Let's plan next quarter's pipeline.

A 30-minute call with a strategist. You leave with a target spec, audience size and a program plan, whether or not we work together.

Privacy choices

Choose which optional cookies we may use. You can change this any time from “Your privacy choices” in the footer.