15 U.S.C. §§ 7701-7713

Controlling the Assault of Non-Solicited Pornography And Marketing Act

Statute — United States Federal
Effective: January 1, 2004 100 platforms tracked 4475 provisions indexed Enforced by: Federal Trade Commission (FTC), State Attorneys General, Internet Service Providers (private right of action) Last reviewed May 9, 2026

Overview

The CAN-SPAM Act establishes the rules for commercial email communications in the United States. Despite its name suggesting anti-spam legislation, the law primarily regulates commercial messaging rather than banning unsolicited email outright.

The Act requires that commercial emails must not use deceptive subject lines, must identify the message as an advertisement, must include the sender's valid physical postal address, must tell recipients how to opt out of future messages, and must honor opt-out requests within 10 business days. The law prohibits selling or transferring email addresses of individuals who have opted out.

For platform governance, CAN-SPAM is relevant because platform terms of service frequently reference email communication practices, marketing consent, and user notification preferences. Many platforms' privacy policies disclose email data sharing and marketing practices that must comply with CAN-SPAM requirements.

Penalties

Up to $50,120 per violation (each separate email is a potential violation). Criminal penalties for aggravated violations: up to 5 years imprisonment. No private right of action for individual consumers.

Key Articles & Sections

Platforms We Track Subject to CAN-SPAM

Recent Changes Related to CAN-SPAM

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by CAN-SPAM (4475 across 100 platforms)

Account Deletion Right 23andMe
Medium
International Data Transfers 23andMe
Medium
Sharing Features Participation (DNA Relatives and Connections) 23andMe
Medium
Restriction on Insurance Companies and Employers 23andMe
Medium
DNA Relatives and Sharing Features Consent 23andMe
Medium
Account Deletion and Sample Discard 23andMe
Medium
Prohibition on Insurance Company and Employer Use 23andMe
Medium
Telehealth Services and Separate Medical Record Privacy Notice 23andMe
Medium
Terms Modification with Continued Use as Acceptance 23andMe
Medium
Age Restriction and Minimum Age Requirement 23andMe
Medium
Sample Storage Choice 23andMe
Medium
Intellectual Property License 23andMe
Medium
Data Sharing with Third-Party Service Providers 23andMe
Medium
Telehealth and Medical Record Privacy Notice 23andMe
Medium
Genetic Data Research Use 23andMe
Medium
California Consumer Privacy Rights 23andMe
Medium
CCPA Rights for California Residents 23andMe
Medium
Separate Medical Record Privacy Notice for Telehealth 23andMe
Medium
Data Sharing with Affiliates and Service Providers Acorns
Medium
Data Collection from Third-Party Sources Including Data Brokers Acorns
Medium
Incorporation by Reference of Product-Specific Agreements Acorns
Medium
California Resident Privacy Rights (CCPA) Acorns
Medium
Geolocation and Device Data Collection Acorns
Medium
Custodial Account Terms — Minors (Acorns Early) Acorns
Medium
Behavioral Analytics and Tracking Technologies Acorns
Medium
Collection of Sensitive Financial and Identity Data Acorns
Medium
Business Transfer Data Disclosure Acorns
Medium
California Resident Privacy Rights Acorns
Medium
California Consumer Privacy Rights Acorns
Medium
Account Linking and Third-Party Data Aggregator Access Acorns
Medium

Showing 30 of 4475 provisions. View all →

Official Source

View official regulation text →

Get alerted when platforms change their policies — including CAN-SPAM-relevant provisions.

Subscribe to Monitor — $19/mo

Frequently Asked Questions

What does CAN-SPAM require?

Which platforms does CAN-SPAM apply to?

ConductAtlas tracks CAN-SPAM-relevant provisions across 100 platforms. Each platform's specific provisions are classified by severity and mapped to CAN-SPAM requirements.

How does ConductAtlas monitor CAN-SPAM compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect CAN-SPAM obligations. Every change is archived with cryptographic verification.