15 U.S.C. §§ 7701-7713

Controlling the Assault of Non-Solicited Pornography And Marketing Act

Statute — United States Federal
Effective: January 1, 2004 100 platforms tracked 11954 provisions indexed Enforced by: Federal Trade Commission (FTC), State Attorneys General, Internet Service Providers (private right of action) Last reviewed May 9, 2026

Overview

The CAN-SPAM Act establishes the rules for commercial email communications in the United States. Despite its name suggesting anti-spam legislation, the law primarily regulates commercial messaging rather than banning unsolicited email outright.

The Act requires that commercial emails must not use deceptive subject lines, must identify the message as an advertisement, must include the sender's valid physical postal address, must tell recipients how to opt out of future messages, and must honor opt-out requests within 10 business days. The law prohibits selling or transferring email addresses of individuals who have opted out.

For platform governance, CAN-SPAM is relevant because platform terms of service frequently reference email communication practices, marketing consent, and user notification preferences. Many platforms' privacy policies disclose email data sharing and marketing practices that must comply with CAN-SPAM requirements.

Penalties

Up to $50,120 per violation (each separate email is a potential violation). Criminal penalties for aggravated violations: up to 5 years imprisonment. No private right of action for individual consumers.

Key Articles & Sections

Platforms We Track Subject to CAN-SPAM

Recent Changes Related to CAN-SPAM

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by CAN-SPAM (11954 across 100 platforms)

User controls participation in sharing features 23andMe
Medium
Research participation is voluntary with IRB consent 23andMe
Medium
User choice to store biological sample 23andMe
Medium
Product development uses de-identified information 23andMe
Medium
Eligible users invited to participate in 23andMe Research 23andMe
Medium
Personal information used for compliance and fraud prevention Acorns
Medium
Third-party sign-in data used solely for account management Acorns
Medium
Personal information shared with corporate affiliates Acorns
Medium
Customer right to limit affiliate marketing sharing Acorns
Medium
California residents information not shared beyond state law Acorns
Medium
Sensitive personal information processed only as described in policy Acorns
Medium
California opt-out applies only to submitting browser and device Acorns
Medium
Aggregated or deidentified data disclosed to third parties Acorns
Medium
Sensitive personal information not used for CCPA-limitable purposes Acorns
Medium
New customer sharing begins after 30 days Acorns
Medium
Affiliates marketing to you can be limited Acorns
Medium
User Warrants Authority To Share Client Information Acorns
Medium
Federal law limits consumer sharing rights Acorns
Medium
Vermont residents information sharing restricted to law or authorization Acorns
Medium
Affiliates share transaction and experience information Acorns
Medium
Session replay data not shared with third parties Acorns
Medium
Personal information used to send direct marketing communications Acorns
Medium
Acorns shares for own marketing purposes Acorns
Medium
Sensitive personal information not used to infer characteristics Acorns
Medium
Personal information used for service delivery purposes Acorns
Medium
Service providers contractually bound on personal information handling Acorns
Medium
Acorns does not sell personal information under CCPA Acorns
Medium
Promotional programs use personal information Acorns
Medium
Session replay sensitive information automatically masked Acorns
Medium
Acorns collects information from other companies Acorns
Medium

Showing 30 of 11954 provisions. View all →

Official Source

View official regulation text →

Get alerted when platforms change their policies, including CAN-SPAM-relevant provisions.

Subscribe to Monitor, $19/mo

Frequently Asked Questions

What does CAN-SPAM require?

Which platforms does CAN-SPAM apply to?

ConductAtlas tracks CAN-SPAM-relevant provisions across 100 platforms. Each platform's specific provisions are classified by severity and mapped to CAN-SPAM requirements.

How does ConductAtlas monitor CAN-SPAM compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect CAN-SPAM obligations. Every change is archived with cryptographic verification.