CAN-SPAM Flashcards
Sector
Marketing
Year passed/amended
2003
Original purpose
Provide a mechanism for legitimate email solicitations, while allowing consumers to opt out of unwanted solicitations
Primary requirements
Email solicitations must identify the sender, including a return address; not be misleading; and provide a conspicuous, free way to opt out.
Specifically, must:
(a) not use misleading headers or subject lines;
(b) contain a functioning, conspicuous return email address, and a valid physical postal address;
(c) contain a conspicuous, free mechanism to opt out;
(d) state clearly and conspicuously that the email is commercial;
(e) not use address-harvesting, automated creation of multiple email accounts, or retransmission through multiple accounts;
(f) if message is sexually explicit, contain a warning label
Entities subject to the law
Anyone who advertises products or services by email originating in the U.S.
Covers commercial email whose primary purpose is advertising or promoting a product or service.
Term for relevant PII or regulated data
Commercial email messages and text messages
Definition of relevant PII or regulated data
“Commercial” is not defined, but the law does not apply to commercial messages which primary purpose is to:
(a) facilitate or confirm an agreed-upon commercial transaction, or deliver goods or services pursuant to an agreed-upon commercial transaction;
(b) provide warranty or safety information about a product purchased or used by the recipient;
(c) provide certain information regarding an ongoing commercial relationship;
(d) provide information related to employment or a related benefit plan
Civil or criminal?
Both
Enforcing authority - civil
FTC, FCC (for texts), state attorneys general, ISPs
Penalties - civil
Injunctive relief; up to $250 per violation to a max of $2 million. Triple for willful or aggravated violations
Enforcing authority - criminal
DOJ?
Penalties - criminal
Egregious conduct punishable by up to 5 years imprisonment
Preemption?
Yes, except to the extent state anti-spam laws prohibit false or deceptive activity
Private right of action?
No
FIP Individual Rights addressed
Choice and consent (not notice or access, whatever those would mean in this context)