Skip to content
Your Rights

Unsubscribe laws by country: your email rights by region

Your unsubscribe rights split into two models: opt-out in the US under CAN-SPAM, opt-in across the EU, UK, Canada, and Australia. Here is the map.

Email Unsubscriber Team 9 min read
Flat vector illustration of a folded world map with a pinned unsubscribe envelope at its center, ringed by five stamped legal cards, a gavel, and a small scale of justice.

You unsubscribe from a French newsletter, a US retailer, and a Canadian store in one sitting. Three senders, three countries, and the rules that protect you are not the same in any of them. Where you live, and where the sender operates, together decide how fast a company has to stop and what happens when it doesn’t.

Unsubscribe rights split into two models. The United States uses opt-out: CAN-SPAM lets a company email you until you unsubscribe, then gives it 10 business days to stop. The EU, UK, Canada, and Australia use opt-in: a sender needs your consent first and must honor withdrawal fast. Canada’s CASL is the strictest.

This is an educational overview of email marketing rules, not legal advice. For a specific situation, check the regulator linked in each section or consult a lawyer in your jurisdiction.

Do unsubscribe laws actually differ by country?

Yes, and they sort into two camps. The dividing line is whether a company may email you before you ever agree.

Under an opt-out regime, a sender can mail you first and your right kicks in only once you ask to leave. The United States runs this model through CAN-SPAM. Under an opt-in regime, a sender needs your consent up front, so an unwanted first message is already a breach. The EU, the UK, Canada, and Australia all run opt-in laws, with slightly different definitions of what counts as consent and how quickly a withdrawal must take effect.

The practical result is that the same marketing email can be perfectly legal in Texas and unlawful in Toronto. Knowing which model covers you tells you whether the sender owed you silence in the first place, or only owes you a working exit now.

How do unsubscribe rights compare across countries?

Five major regimes cover most inboxes. The table maps the consent model, the deadline a sender has to honor your opt-out, the regulator you would report to, and the ceiling on penalties.

Region (law)Consent modelDeadline to honor opt-outRegulatorMaximum penalty
United States (CAN-SPAM)Opt-out10 business daysFTC$53,088 per email
European Union (GDPR + ePrivacy)Opt-inWithout undue delayNational DPAs (EDPB)€20M or 4% of global turnover
United Kingdom (PECR + UK GDPR)Opt-inWithout undue delayICO£17.5M or 4% of global turnover
Canada (CASL)Opt-in (express)10 business daysCRTCC$10M per violation (business)
Australia (Spam Act 2003)Opt-in (express or inferred)5 business daysACMACourt civil penalties (CBA fined A$7.5M, 2024)

Bottom line: the US gives senders the most room and you the least protection, Australia demands the fastest exit, and Canada sets the highest bar for consent and the steepest per-violation fine. The sections below unpack each one.

What are your unsubscribe rights in the United States?

CAN-SPAM gives you an exit, not a gate. A company can put you on its list without asking, and your right is to make it stop once you opt out. The FTC’s CAN-SPAM compliance guide requires every commercial email to carry a working unsubscribe mechanism and to honor your request within 10 business days.

The law also limits how hard leaving can be. A sender cannot charge a fee, cannot demand more than your email address, and cannot push you through more than one web page to opt out. Break those rules and the penalties are real: the FTC’s 2025 inflation-adjusted schedule puts the ceiling at $53,088 per non-compliant email, a figure it republishes each January and has held for 2026.

Ten business days is roughly two weeks once weekends drop out, and the counting has quirks. For the exact day math, see how long a company can email you after you unsubscribe. For the settlement record that proves the FTC enforces this, see your rights when ‘unsubscribe’ doesn’t stop the emails.

What are your rights in the European Union?

The EU flips the default. A sender needs your consent before the first marketing email lands, not just an unsubscribe link after the fact. That prior-consent rule comes from the ePrivacy Directive, which allows a narrow soft opt-in for existing customers buying similar products, and each member state writes it into national law.

GDPR sets the standard for what consent has to be. Under Article 7, it must be freely given, specific, informed, and unambiguous, and withdrawing it must be as easy as giving it was. There is no fixed deadline to stop: processing must cease without undue delay, which for an automated system means close to immediately. Force a login or a support ticket to leave, and the friction alone can breach the rule.

The penalties sit in GDPR’s top tier. Article 83 allows fines up to €20 million or 4 percent of a company’s global annual turnover, whichever is higher. You enforce these rights by filing with your national Data Protection Authority; the European Data Protection Board coordinates them across all 27 states.

What are your rights in the United Kingdom?

The UK kept the EU structure after Brexit and then raised the stakes. Marketing email to individuals needs prior consent under the Privacy and Electronic Communications Regulations (PECR), with the same soft opt-in carve-out for a company’s own existing customers. UK GDPR governs the quality of that consent and your right to withdraw it.

The regulator is the Information Commissioner’s Office. Until recently the ICO could fine a PECR breach no more than £500,000, a cap that made spam a cost of doing business for some senders. That changed on 5 February 2026, when the Data (Use and Access) Act 2025 lifted the ceiling to £17.5 million or 4 percent of global turnover, whichever is higher. PECR now carries the same financial weight as a UK GDPR breach.

If a UK sender keeps mailing you after you opt out, the ICO takes reports through a dedicated spam-email form. The filing walkthrough covers the ICO, the FTC, and EU DPAs step by step.

What are your rights in Canada under CASL?

Canada sets the highest bar of the five. CASL requires express, opt-in consent before a company sends any commercial electronic message, and a pre-checked box, a bought list, or an assumption of interest does not count. Consent has to be a deliberate action you took.

Once you unsubscribe, the CRTC’s CASL guidance gives the sender 10 business days to stop, and the unsubscribe link has to keep working for at least 60 days after the message was sent. Implied consent exists only in narrow cases, such as an existing business relationship, and it expires, typically two years after the triggering event.

The penalties match the strictness. Under section 20(4) of CASL, the CRTC can impose administrative monetary penalties up to C$10 million per violation for a business and C$1 million for an individual. That is the steepest per-violation ceiling among the major regimes, which is why Canada is the jurisdiction marketers watch most carefully.

What are your rights in Australia?

Australia demands the fastest exit. Under the Spam Act 2003, a business must action your unsubscribe request within 5 business days, the shortest fixed deadline of any regime here. The ACMA’s guidance on avoiding spam also requires consent before sending, which can be express or reasonably inferred from an existing relationship, and bars a sender from making you log in or hand over extra details to leave.

The Australian Communications and Media Authority enforces the Act, and it has been active. Penalties run as court-ordered civil sums tied to penalty units, which climb steeply for repeat corporate offenders. The concrete numbers show the reach: ACMA fined Commonwealth Bank A$7.5 million in October 2024 for sending more than 170 million marketing messages without working unsubscribe arrangements, one of the largest spam penalties the regulator has secured.

For an Australian resident, the takeaway is simple: a sender has five business days, not ten, and no consent means no email in the first place.

Which country has the strictest unsubscribe law?

Canada, on the two measures that matter most. It demands the hardest form of consent and it backs the demand with the highest per-violation fine.

CASL treats consent as something you must actively give, so a sender cannot rely on inaction, a pre-ticked box, or a purchased address. The EU, UK, and Australia also require consent, but each allows a soft opt-in or inferred-consent path for existing customers that CASL keeps narrower. On penalties, Canada’s C$10 million per-violation ceiling and the EU and UK turnover-based fines all dwarf the US per-email figure once a campaign scales. The United States is the most permissive of the five, because it never required consent to begin with.

Australia earns a mention for speed. Its 5-business-day deadline is the shortest anywhere, so an Australian recipient waits the least time for a compliant sender to stop.

Which law protects you, your country or the sender’s?

The law of your location generally governs, not the sender’s. A company mailing an EU resident must meet EU rules even if its office sits in Nevada, and CAN-SPAM covers commercial email to US recipients regardless of where the sender operates. The protection follows the inbox, not the outbox.

Enforcement reach is the catch. A regulator acts most easily against a sender with a legal presence, customers, or assets in its jurisdiction. A US resident reporting a small overseas sender to the FTC has a weaker practical remedy than a Canadian reporting a domestic retailer to the CRTC. The rights on paper are broad; the ability to force a stranger abroad to comply is narrower. That gap is exactly why blocking the sender at your email provider, which works no matter where the company sits, is always the first move before you file anything.

How do you act on these rights without tracking every sender by hand?

Knowing your rights is one thing. Proving a sender broke them across dozens of lists is the tedious part. You unsubscribe from thirty senders in an afternoon, and two weeks later you cannot recall who honored it and who kept mailing, which is the exact record a complaint to the FTC, a DPA, the ICO, the CRTC, or ACMA rests on.

That record is what the Email Unsubscriber app keeps. It scans your inbox in your browser, so your email content never reaches our servers, dispatches one-click unsubscribes, logs every action with its date in an audit history, and flags any sender still mailing you after you opted out with a “Still Emailing” marker. The senders who ignored your request stop being invisible, which is the timeline you paste into a complaint. It is a one-off payment, with nothing to cancel.

No jurisdiction requires you to track violations yourself. It just helps to have the dates ready when you decide to act.

Frequently asked questions

Are unsubscribe laws the same in every country?

No. They split into two models. The United States uses opt-out under CAN-SPAM: a company can email you until you unsubscribe, then has 10 business days to stop. The EU, UK, Canada, and Australia use opt-in: a sender needs your consent before mailing you at all and must honor withdrawal fast. The deadlines, penalties, and regulators differ in each.

What is the difference between opt-in and opt-out email marketing?

Opt-out means a company may email you without asking first, and your only right is to leave once messages start. That is the US model. Opt-in means the sender needs your consent before the first message, so silence is not permission. The EU, UK, Canada, and Australia all run opt-in regimes, which makes marketing without consent a violation from the start.

Which country has the strictest anti-spam law?

Canada. CASL requires express, opt-in consent before any commercial message, treats a pre-checked box or bought list as no consent, and gives a sender 10 business days to honor an unsubscribe. The CRTC can impose administrative penalties up to 10 million Canadian dollars per violation for a business, the highest per-violation ceiling among the major regimes.

How long does a company have to honor an unsubscribe request?

It depends on the region. Australia is fastest at 5 business days. The United States and Canada both allow 10 business days. The EU and UK set no fixed number: withdrawal must be honored without undue delay, which a modern automated system should treat as near-immediate. Gmail and Yahoo separately require their bulk senders to process a one-click unsubscribe within 48 hours.

Does GDPR require opt-in for marketing emails?

Yes, in effect. The EU ePrivacy Directive requires prior consent before marketing email reaches an individual, with a narrow soft opt-in exception for existing customers. GDPR sets the standard for that consent: freely given, specific, informed, and as easy to withdraw as it was to give. A sender that keeps mailing after you withdraw breaches the rule.

What is the maximum fine for ignoring an unsubscribe request?

Ceilings vary widely. US CAN-SPAM reaches $53,088 per non-compliant email. EU GDPR allows up to 20 million euros or 4 percent of global turnover. UK PECR now matches that at 17.5 million pounds or 4 percent. Canada's CASL caps at 10 million Canadian dollars per violation for a business. Australia levies court-ordered civil penalties per day of breach.

Which unsubscribe law applies if the sender is in another country?

The law of the recipient's location generally governs. A company mailing an EU resident must meet EU rules even if the company sits in the US, and CAN-SPAM covers commercial email to US recipients regardless of where the sender operates. Enforcement reach is the harder part: a regulator acts most easily against senders with a presence or customers in its jurisdiction.

Is CAN-SPAM opt-in or opt-out?

Opt-out. CAN-SPAM does not require a company to get your consent before sending commercial email. It requires every message to carry a working unsubscribe mechanism, honor your opt-out within 10 business days, use accurate sender and subject information, and demand nothing more than your email address to process the request.