You unsubscribe from a French newsletter, a US retailer, and a Canadian store in one sitting. Three senders, three countries, and the rules that protect you are not the same in any of them. Where you live, and where the sender operates, together decide how fast a company has to stop and what happens when it doesn’t.
Unsubscribe rights split into two models. The United States uses opt-out: CAN-SPAM lets a company email you until you unsubscribe, then gives it 10 business days to stop. The EU, UK, Canada, and Australia use opt-in: a sender needs your consent first and must honor withdrawal fast. Canada’s CASL is the strictest.
This is an educational overview of email marketing rules, not legal advice. For a specific situation, check the regulator linked in each section or consult a lawyer in your jurisdiction.
Do unsubscribe laws actually differ by country?
Yes, and they sort into two camps. The dividing line is whether a company may email you before you ever agree.
Under an opt-out regime, a sender can mail you first and your right kicks in only once you ask to leave. The United States runs this model through CAN-SPAM. Under an opt-in regime, a sender needs your consent up front, so an unwanted first message is already a breach. The EU, the UK, Canada, and Australia all run opt-in laws, with slightly different definitions of what counts as consent and how quickly a withdrawal must take effect.
The practical result is that the same marketing email can be perfectly legal in Texas and unlawful in Toronto. Knowing which model covers you tells you whether the sender owed you silence in the first place, or only owes you a working exit now.
How do unsubscribe rights compare across countries?
Five major regimes cover most inboxes. The table maps the consent model, the deadline a sender has to honor your opt-out, the regulator you would report to, and the ceiling on penalties.
| Region (law) | Consent model | Deadline to honor opt-out | Regulator | Maximum penalty |
|---|---|---|---|---|
| United States (CAN-SPAM) | Opt-out | 10 business days | FTC | $53,088 per email |
| European Union (GDPR + ePrivacy) | Opt-in | Without undue delay | National DPAs (EDPB) | €20M or 4% of global turnover |
| United Kingdom (PECR + UK GDPR) | Opt-in | Without undue delay | ICO | £17.5M or 4% of global turnover |
| Canada (CASL) | Opt-in (express) | 10 business days | CRTC | C$10M per violation (business) |
| Australia (Spam Act 2003) | Opt-in (express or inferred) | 5 business days | ACMA | Court civil penalties (CBA fined A$7.5M, 2024) |
Bottom line: the US gives senders the most room and you the least protection, Australia demands the fastest exit, and Canada sets the highest bar for consent and the steepest per-violation fine. The sections below unpack each one.
What are your unsubscribe rights in the United States?
CAN-SPAM gives you an exit, not a gate. A company can put you on its list without asking, and your right is to make it stop once you opt out. The FTC’s CAN-SPAM compliance guide requires every commercial email to carry a working unsubscribe mechanism and to honor your request within 10 business days.
The law also limits how hard leaving can be. A sender cannot charge a fee, cannot demand more than your email address, and cannot push you through more than one web page to opt out. Break those rules and the penalties are real: the FTC’s 2025 inflation-adjusted schedule puts the ceiling at $53,088 per non-compliant email, a figure it republishes each January and has held for 2026.
Ten business days is roughly two weeks once weekends drop out, and the counting has quirks. For the exact day math, see how long a company can email you after you unsubscribe. For the settlement record that proves the FTC enforces this, see your rights when ‘unsubscribe’ doesn’t stop the emails.
What are your rights in the European Union?
The EU flips the default. A sender needs your consent before the first marketing email lands, not just an unsubscribe link after the fact. That prior-consent rule comes from the ePrivacy Directive, which allows a narrow soft opt-in for existing customers buying similar products, and each member state writes it into national law.
GDPR sets the standard for what consent has to be. Under Article 7, it must be freely given, specific, informed, and unambiguous, and withdrawing it must be as easy as giving it was. There is no fixed deadline to stop: processing must cease without undue delay, which for an automated system means close to immediately. Force a login or a support ticket to leave, and the friction alone can breach the rule.
The penalties sit in GDPR’s top tier. Article 83 allows fines up to €20 million or 4 percent of a company’s global annual turnover, whichever is higher. You enforce these rights by filing with your national Data Protection Authority; the European Data Protection Board coordinates them across all 27 states.
What are your rights in the United Kingdom?
The UK kept the EU structure after Brexit and then raised the stakes. Marketing email to individuals needs prior consent under the Privacy and Electronic Communications Regulations (PECR), with the same soft opt-in carve-out for a company’s own existing customers. UK GDPR governs the quality of that consent and your right to withdraw it.
The regulator is the Information Commissioner’s Office. Until recently the ICO could fine a PECR breach no more than £500,000, a cap that made spam a cost of doing business for some senders. That changed on 5 February 2026, when the Data (Use and Access) Act 2025 lifted the ceiling to £17.5 million or 4 percent of global turnover, whichever is higher. PECR now carries the same financial weight as a UK GDPR breach.
If a UK sender keeps mailing you after you opt out, the ICO takes reports through a dedicated spam-email form. The filing walkthrough covers the ICO, the FTC, and EU DPAs step by step.
What are your rights in Canada under CASL?
Canada sets the highest bar of the five. CASL requires express, opt-in consent before a company sends any commercial electronic message, and a pre-checked box, a bought list, or an assumption of interest does not count. Consent has to be a deliberate action you took.
Once you unsubscribe, the CRTC’s CASL guidance gives the sender 10 business days to stop, and the unsubscribe link has to keep working for at least 60 days after the message was sent. Implied consent exists only in narrow cases, such as an existing business relationship, and it expires, typically two years after the triggering event.
The penalties match the strictness. Under section 20(4) of CASL, the CRTC can impose administrative monetary penalties up to C$10 million per violation for a business and C$1 million for an individual. That is the steepest per-violation ceiling among the major regimes, which is why Canada is the jurisdiction marketers watch most carefully.
What are your rights in Australia?
Australia demands the fastest exit. Under the Spam Act 2003, a business must action your unsubscribe request within 5 business days, the shortest fixed deadline of any regime here. The ACMA’s guidance on avoiding spam also requires consent before sending, which can be express or reasonably inferred from an existing relationship, and bars a sender from making you log in or hand over extra details to leave.
The Australian Communications and Media Authority enforces the Act, and it has been active. Penalties run as court-ordered civil sums tied to penalty units, which climb steeply for repeat corporate offenders. The concrete numbers show the reach: ACMA fined Commonwealth Bank A$7.5 million in October 2024 for sending more than 170 million marketing messages without working unsubscribe arrangements, one of the largest spam penalties the regulator has secured.
For an Australian resident, the takeaway is simple: a sender has five business days, not ten, and no consent means no email in the first place.
Which country has the strictest unsubscribe law?
Canada, on the two measures that matter most. It demands the hardest form of consent and it backs the demand with the highest per-violation fine.
CASL treats consent as something you must actively give, so a sender cannot rely on inaction, a pre-ticked box, or a purchased address. The EU, UK, and Australia also require consent, but each allows a soft opt-in or inferred-consent path for existing customers that CASL keeps narrower. On penalties, Canada’s C$10 million per-violation ceiling and the EU and UK turnover-based fines all dwarf the US per-email figure once a campaign scales. The United States is the most permissive of the five, because it never required consent to begin with.
Australia earns a mention for speed. Its 5-business-day deadline is the shortest anywhere, so an Australian recipient waits the least time for a compliant sender to stop.
Which law protects you, your country or the sender’s?
The law of your location generally governs, not the sender’s. A company mailing an EU resident must meet EU rules even if its office sits in Nevada, and CAN-SPAM covers commercial email to US recipients regardless of where the sender operates. The protection follows the inbox, not the outbox.
Enforcement reach is the catch. A regulator acts most easily against a sender with a legal presence, customers, or assets in its jurisdiction. A US resident reporting a small overseas sender to the FTC has a weaker practical remedy than a Canadian reporting a domestic retailer to the CRTC. The rights on paper are broad; the ability to force a stranger abroad to comply is narrower. That gap is exactly why blocking the sender at your email provider, which works no matter where the company sits, is always the first move before you file anything.
How do you act on these rights without tracking every sender by hand?
Knowing your rights is one thing. Proving a sender broke them across dozens of lists is the tedious part. You unsubscribe from thirty senders in an afternoon, and two weeks later you cannot recall who honored it and who kept mailing, which is the exact record a complaint to the FTC, a DPA, the ICO, the CRTC, or ACMA rests on.
That record is what the Email Unsubscriber app keeps. It scans your inbox in your browser, so your email content never reaches our servers, dispatches one-click unsubscribes, logs every action with its date in an audit history, and flags any sender still mailing you after you opted out with a “Still Emailing” marker. The senders who ignored your request stop being invisible, which is the timeline you paste into a complaint. It is a one-off payment, with nothing to cancel.
No jurisdiction requires you to track violations yourself. It just helps to have the dates ready when you decide to act.
