C
4 termsCAN-SPAM Act
The CAN-SPAM Act is the 2003 US federal law that sets rules for commercial email, including honest headers and subject lines, a working opt-out, and a valid physical postal address. It applies to business-to-business email and is enforced by the FTC.
CASL
CASL, Canada's Anti-Spam Legislation, is the federal law that has regulated commercial electronic messages since July 1, 2014. It requires consent before sending, sender identification and a working unsubscribe mechanism, and it is one of the strictest email marketing laws in the world.
CCPA / CPRA
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is California's main privacy law. It gives California residents rights over their personal information and applies to for-profit businesses that meet revenue or data-volume thresholds.
Consent
In data protection and email law, consent is a person's freely given, specific, informed and unambiguous agreement to have their data processed or to receive messages. It must be a clear affirmative action, and it can be withdrawn at any time.
D
2 termsData Minimization
Data minimization is the principle that you should collect and keep only the personal data that is adequate, relevant and limited to what is necessary for your purpose. It is one of the core GDPR principles in Article 5(1)(c).
Data Processing Agreement (DPA)
A data processing agreement (DPA) is a contract between a controller and a processor that sets out how the processor may handle personal data on the controller's behalf. GDPR Article 28 makes such a contract mandatory and lists the terms it must contain.
G
1 termL
1 termO
1 termP
4 termsPECR
PECR, the Privacy and Electronic Communications Regulations 2003, is the UK law that sets specific rules for electronic marketing, including email, texts, calls and cookies. It sits alongside the UK GDPR and is enforced by the Information Commissioner's Office (ICO).
Personal Data
Personal data is any information relating to an identified or identifiable living person. Under GDPR that includes names, work email addresses, job titles, online identifiers and any combination of details that could single someone out, even in a business context.
Physical Address Requirement
The physical address requirement is the rule, found in CAN-SPAM and CASL, that every commercial email must include the sender's valid postal address. Under CAN-SPAM this can be a street address, a registered PO box or a registered private mailbox.
Publicly Available Data
Publicly available data is information anyone can access without special permission, such as a company website, press coverage or a public register. When it relates to an identifiable person it usually remains personal data under GDPR, even though it is public.