It depends on which law applies, who the recipient is and what the message says. “They never opted in” alone does not decide it.
For a retention team, the question is concrete: can these customer records enter this campaign or flow? Start with the basis for sending, rather than treating an address in your database as the answer.
Can you email people who never opted in? Sometimes. US federal CAN-SPAM does not require prior opt-in. UK unsolicited product marketing to individuals generally needs consent or a qualifying soft opt-in; Canada’s CASL generally needs express or valid implied consent. Other duties and exemptions apply. A customer record alone does not establish that a particular send qualifies.
This guide covers ordinary commercial email under those frameworks. It does not cover every exemption, EU/EEA country rules, US state or sector-specific privacy duties, SMS or charity fundraising. It is general information, not legal advice for a particular campaign. Resolve the applicable rules before using any example as sending permission.
How do the rules differ by country?
US federal CAN-SPAM does not require prior opt-in. UK unsolicited product marketing to individual subscribers needs consent or a qualifying products/services soft opt-in. Canadian CASL generally requires express or valid implied consent, subject to exemptions. Each framework also imposes other duties.
| Framework | Starting point for promotional email | What still needs checking |
|---|---|---|
| US federal CAN-SPAM | Prior opt-in is not required | Message requirements, earlier opt-outs and other applicable laws |
| UK PECR: unsolicited product marketing to individual subscribers | Consent or a qualifying products/services soft opt-in | Collection circumstances, what you promote and opt-out opportunities |
| Canadian CASL | Generally express or valid implied consent, subject to exemptions | Evidence, any expiry, identification and unsubscribe requirements |
The FTC explicitly says CAN-SPAM has no opt-in requirement.
Its commercial-email requirements include truthful sender information and subject lines, a valid postal address and an opt-out method. Identify advertising clearly unless the recipient gave prior affirmative consent. Honour opt-outs within 10 business days.
UK recipient type also matters. Under the ICO’s B2B guidance, corporate subscribers do not need PECR consent for email marketing, but the sender must identify itself and provide an opt-out address. Sole traders and some partnerships receive individual-subscriber protections. UK GDPR duties still apply when you process personal data, including a person’s right to object to direct marketing.
The ICO notes that its B2B guidance is under review following the Data (Use and Access) Act. Check the current guidance before relying on the corporate-subscriber position.
Does buying from you count as permission?
A purchase can support a particular exception or consent route. It does not establish every condition by itself.
For UK unsolicited product marketing to individuals, the products and services soft opt-in requires all of the following:
- You collected the address directly during a sale or sale negotiation.
- You market only your own similar products or services.
- You offered an opt-out when collecting the address.
- You offer an opt-out in every subsequent message and respect the person’s choice.
You cannot repair a missing collection-time choice by first adding it to the order confirmation. A bought list cannot qualify for this soft opt-in either.
In Canada, the CRTC’s implied-consent guidance describes qualifying purchases within the preceding two years and qualifying inquiries or applications within the preceding six months as existing-business-relationship routes. Those are specific routes, not a universal expiry rule for every contact. Check eligibility at sending time, keep proof and respect withdrawal.
Illustrative review: an imported row says “customer” and includes an order date. For a UK soft-opt-in assessment, look for the original collection form and opt-out choice. For a Canadian purchase-based assessment, check the qualifying transaction and time window. In either case, inspect the withdrawal record. Changing the row to “subscribed” would not supply the missing evidence.
Can you send abandoned-cart emails to non-subscribers?
A non-subscriber may qualify through an applicable sending route, but a checkout email address or flow label alone does not establish one. For Canadian CASL, the CRTC says an abandoned cart does not start the purchase-based two-year implied-consent period and recommends obtaining express consent at checkout.
The CRTC’s abandoned-checkout guidance warns that interpreting checkout activity as an inquiry qualifying for six-month implied consent could attract complaints. It recommends collecting express consent rather than assuming implied consent.
Nor does calling a message “transactional” settle it. Under CAN-SPAM, confirming an already-agreed transaction is a transactional category; these categories are narrow. A message mixing service information and promotion needs the primary-purpose assessment.
Keep the eligibility check beside the automation trigger. The abandoned-cart email guide explains which shopping events can trigger a flow; this permission review decides whether a particular contact should enter it.
Is a bought or cleaned list safe to use?
Neither buying a list nor checking its address quality establishes a legal sending basis. The FTC warns that purchased lists can contain previous opt-outs or addresses obtained through unlawful collection methods. Check the source and the applicable rules before sending.
Also consider whether people want the messages. Google’s sender guidance advises mailing-list operators to get opt-in, send messages people want and make leaving easy. It warns that frequent spam reports can harm domain reputation and affect later delivery.
For a retention programme, a useful default is to build a wanted subscription relationship. Check your email platform’s current policy before importing contacts.
If the immediate task is checking address quality or suppressing contacts, use the email list cleaning guide. Keep that work separate from establishing a sending basis.
What should you check before enabling the send?
Before enabling a marketing send, record the contact’s source, intended message, applicable rules and recipient type, sending basis and proof, any expiry or opt-out, and the person who checked it. Hold promotional sends where the basis is unresolved. The worksheet below is a suggested operational record, not a regulator-prescribed form.
| Record | Question to answer |
|---|---|
| Source and event | Where did this address come from, and what did the person do? |
| Intended message | What will this campaign or flow actually say? |
| Applicable rules | Which jurisdiction and recipient category have you assessed? |
| Sending basis and evidence | What supports this send: consent, a qualifying route or another applicable rule? Where is the proof? |
| Dates and withdrawals | Does the route still apply? Has the person opted out or objected? |
| Decision and owner | Send, hold for clarification or exclude from marketing—and who checked it? |
Start with representative records from each collection source. A checkout form, an old customer import and a purchased file deserve separate answers. Inspect the original form or event evidence alongside the contact record, then decide how the wider group should be handled.
For unresolved records, preserve the evidence needed to investigate instead of overwriting the uncertainty with a new subscription label.
For future contacts, put the subscription choice in the collection journey. For existing contacts, a signup opportunity on their next website visit is a practical alternative to launching an unapproved permission-request campaign.
Frequently asked questions
Does an unsubscribe link make any marketing email legal?
No. Under US federal CAN-SPAM it is only part of compliance. Under UK PECR or Canadian CASL, it does not by itself establish a required consent or qualifying exception. Assess the route for that recipient and message first.
Can legitimate interests replace email consent in the UK?
Not where PECR requires consent. Legitimate interests is a UK GDPR lawful basis, not a substitute for PECR’s email rules. Where PECR does not require consent, such as corporate-subscriber email marketing, any use of legitimate interests still needs a case-specific assessment.
Can I email a Canadian contact just to ask them to opt in?
A consent-request email is itself a commercial electronic message under CASL. The request cannot create permission to send itself. Existing valid implied consent can allow a request for express consent; without a valid sending route, do not use that email to obtain one.
Sources
- FTC — Candid answers to CAN-SPAM questions · Aug 2015
- FTC — CAN-SPAM Act: A Compliance Guide for Business · Aug 2023
- ICO — Business-to-business marketing
- ICO — How do we comply with the PECR electronic mail marketing rules?
- CRTC — CASL guidance on implied consent
- CRTC — Frequently Asked Questions about Canada's Anti-Spam Legislation
- Google — Email sender guidelines