CAN-SPAM, CASL and PECR: B2B email rules for the US, UK and Canada
One campaign, three very different laws. A plain-English guide to what each market requires before you hit send.
BootSoc team

If your campaigns reach buyers in the US, UK and Canada, you're working under three different rulebooks. The good news is that one well-designed process can satisfy all of them. This guide summarises the essentials. It isn't legal advice, so check your specific program with counsel.
United States: CAN-SPAM
CAN-SPAM applies to commercial email, including business-to-business messages. It doesn't require prior consent, but it sets firm rules for every message:
- Accurate header information and a subject line that isn't misleading
- A valid physical postal address for the sender
- A clear way to opt out, honored within 10 business days
- Responsibility for what vendors send on your behalf
Penalties can exceed $50,000 per violating email. State privacy laws add another layer: many now cover business contact data and give people the right to opt out of the sale or sharing of their information.
Canada: CASL
Canada's Anti-Spam Legislation is stricter. You need consent before sending a commercial electronic message. Consent can be express (the person opted in) or implied in specific situations, such as an existing business relationship or a business address that was conspicuously published without a “no unsolicited messages” statement, where your message is relevant to the person's role.
- Identify the sender and include contact information
- Include an unsubscribe mechanism that works for at least 60 days after sending
- Process unsubscribes within 10 business days
- Keep records that prove consent
Penalties reach up to CA$10 million per violation for organisations. In Quebec, Law 25 adds requirements around tracking technologies and a named person responsible for personal information.
United Kingdom: PECR and UK GDPR
Under PECR, you can email corporate subscribers (limited companies, LLPs and government bodies) without prior consent, as long as you identify yourself and offer a simple opt-out in every message. Sole traders and some partnerships count as individual subscribers, so they need consent or a valid soft opt-in.
Named business emails are still personal data under UK GDPR, so you need a lawful basis, usually legitimate interests backed by a documented assessment. The Data (Use and Access) Act 2025 raised maximum PECR fines to match UK GDPR levels, so the stakes are now much higher.
One process that works everywhere
- Record consent or lawful basis per contact, with source and timestamp
- Identify the sender and include a postal address in every message
- Offer one-click unsubscribe and sync it to a global suppression list
- Honor opt-outs within 10 business days at the latest
- Treat Canadian and UK sole-trader contacts as opt-in only unless an exemption clearly applies
Our Email and outreach policy explains exactly how BootSoc applies these rules to the programs we run for clients.