Live data from Hacker News

Email marketing regulations around the world

github.com

1–10 of 30 posts

Re: Email marketing regulations around the world

#2
CAN-SPAM is unenforced afaict. You can still take action against bad actors by signing up with old abandoned email address(es) though. ISP's will have converted them into spam traps and will subtract a higher amount from their sender reputation.

Re: Email marketing regulations around the world

#3
post #2

CAN-SPAM is unenforced afaict. You can still take action against bad actors by signing up with old abandoned email address(es) though. ISP's will have converted them into spam traps and will subtract a higher amount from their sender reputation.

CAN-SPAM is still somewhat enforced. The problem is the type of spam it targeted is now sent from foreign bad actors and there's not much they can do to enforce it.

Re: Email marketing regulations around the world

#4
GDPR (EU and UK) is much more nuanced than this makes out. For example, there are a number of legal bases that can be used to process someone's personal data.

For example, "Legitimate Interest" can be used if there is a reasonable way that the usage could be foreseen like sending a "How did we do" email after somebody buys something. Unfortaunately, this is not well-defined in the regulations so, for example, one company I came across got my information from Linked In, sold it to other businesses and those directly contacted me to sell something on the basis that the vacuuming company had a "legitimate interest" in selling my data i.e. it's how they made their money.

Re: Email marketing regulations around the world

#5
post #4

GDPR (EU and UK) is much more nuanced than this makes out. For example, there are a number of legal bases that can be used to process someone's personal data. For example, "Legitimate Interest" can be used if there is a reasonable way that the usage could be foreseen like sending a "How did we do" email after somebody buys something. Unfortaunately, this is not well-defined in the regulations so, for example, one com…

Additionally I would say it creates a barrier for entering the market by small companies and startups. The idea is good but the execution is kinda off I would say, but that's usually how it goes with politicians and bureaucrats.

Re: Email marketing regulations around the world

#6
This is missing out a lot of subtleties that a legal team might care about.

I have been a part of multiple companies trying to make a "harmonized" global opt-in policy: basically figure out any set of marketing preferences where we could get away with collecting information without first knowing the user's country - even if that meant more conservative marketing opt-ins.

In each case, we could never figure out a single-method for collecting explicit opt-in that worked worldwide. The standout countries always being some combination of South Korea, Germany, Russia, or Brazil.

Re: Email marketing regulations around the world

#7
post #4

GDPR (EU and UK) is much more nuanced than this makes out. For example, there are a number of legal bases that can be used to process someone's personal data. For example, "Legitimate Interest" can be used if there is a reasonable way that the usage could be foreseen like sending a "How did we do" email after somebody buys something. Unfortaunately, this is not well-defined in the regulations so, for example, one com…

It's pretty well defined for the Netherlands and "making your money" as a legitimate interest could result in a hefty fine. Imho rightfully so.

Re: Email marketing regulations around the world

#8
post #4

GDPR (EU and UK) is much more nuanced than this makes out. For example, there are a number of legal bases that can be used to process someone's personal data. For example, "Legitimate Interest" can be used if there is a reasonable way that the usage could be foreseen like sending a "How did we do" email after somebody buys something. Unfortaunately, this is not well-defined in the regulations so, for example, one com…

At our company, we are actually required to timestamp and enumerate the legitimate interest on all new marketing leads.

I think the issue is here that GDPR is a fairly poorly written cudgel of a law, and regulators are really only using it to go after larger foreign tech companies. Smaller, local companies can get away with much more malfeasance because it would be such a pain to enforce.

Re: Email marketing regulations around the world

#10
post #4

GDPR (EU and UK) is much more nuanced than this makes out. For example, there are a number of legal bases that can be used to process someone's personal data. For example, "Legitimate Interest" can be used if there is a reasonable way that the usage could be foreseen like sending a "How did we do" email after somebody buys something. Unfortaunately, this is not well-defined in the regulations so, for example, one com…

Additionally, individual US states have started passing laws on data privacy, and these laws sometimes impact email marketers who do business in those states. For instance, California has the CCPA (recently amended by the CPRA), and Colorado, Connecticut, Utah, and Virginia recently passed their own laws. Still, credit to OP for raising awareness of data privacy issues.
Post reply on HN