What is the CAN-SPAM Act, and who does it cover?
CAN-SPAM is the United States federal statute that governs commercial email, enforced by the Federal Trade Commission. It applies to any email whose primary purpose is to advertise or promote a product or service, whether sent to a consumer or a business inbox. Senders must identify themselves truthfully in headers and subject lines, disclose that the message is an ad when context does not make it obvious, include a valid physical postal address, and honor opt-out requests within ten business days. Penalties can reach five figures per message, and third parties who knowingly promote through non-compliant senders share liability.
Read the full answer on CAN-SPAM →
How does GDPR apply to B2B sales outreach?
The EU General Data Protection Regulation treats a business contact's name, work email, and job title as personal data, so any outbound sale into the EU or UK is a processing activity that needs a lawful basis. Most B2B outreach relies on legitimate interest, which requires a documented balancing test showing the recipient has a clear business reason to hear from you and a straightforward way to object. Senders must also provide a privacy notice, honor erasure and access requests, and record consent or interest basis per contact. Enforcement sits with national data protection authorities under European Data Protection Board guidance.
Read the full answer on GDPR for sales →
What does CCPA require from a B2B sales program?
The California Consumer Privacy Act, as amended by CPRA, gives California residents rights to know, delete, correct, and opt out of the sale or sharing of their personal information, including business contact data used for outreach. Companies that meet the revenue or data-volume thresholds must publish a privacy notice, offer a clear opt-out mechanism, honor Global Privacy Control signals, and sign data processing addenda with service providers. The California Attorney General and the California Privacy Protection Agency share enforcement, and statutory damages can apply even without a measurable breach.
Read the full answer on CCPA for sales →
What is the TCPA and when does it hit a sales team?
The Telephone Consumer Protection Act is the U.S. statute that governs sales calls, texts, and prerecorded messages, enforced by the Federal Communications Commission and private plaintiffs. It applies the moment a seller uses an autodialer, sends an SMS to a mobile number, or leaves a prerecorded voicemail. Marketing calls and texts require prior express written consent, Do Not Call registry checks, and clear identification. Settled class actions commonly land between five hundred and fifteen hundred dollars per message, so TCPA is often the single largest consent liability in an outbound stack.
Read the full answer on TCPA →
Is cold email legal in the United States, EU, and Canada?
In the United States, cold B2B email is legal under CAN-SPAM when the sender identifies themselves, uses honest headers and subject lines, lists a physical address, and honors opt-outs within ten business days. In the EU and UK, cold B2B email is allowed under GDPR legitimate interest when the recipient has an evident business reason to hear from you and can object with one click. Canada under CASL requires express or implied consent for almost every commercial electronic message. Rules differ per jurisdiction, so route sends through a system that tracks consent basis per contact.
What is double opt-in, and does it apply to outbound sales?
Double opt-in is a marketing practice where a subscriber confirms their address by clicking a link in a verification email before joining a list. It is standard for newsletters, nurture tracks, and product updates, and in Germany, Austria, and a handful of other jurisdictions it is effectively required for marketing email. It does not apply to one-to-one cold B2B outreach, which operates on legitimate interest or implied consent depending on region. A frequent mistake is uploading a double-opt-in marketing list into a cold cadence, which blurs the legal basis and complicates audits.
Read the full answer on double opt-in →
How long should we keep consent and suppression records?
Most regulators expect senders to prove consent or interest basis for as long as the contact is in active outreach, plus a defensible tail after the last message. A common pattern is to retain consent evidence for the life of the contact plus three to six years, and to retain suppression and unsubscribe records effectively forever, because reusing a suppressed address is a per-message violation under CAN-SPAM, CASL, and TCPA. Store the source, timestamp, IP address or capture context, and the exact language shown to the contact at the moment they opted in or objected.
Read the full answer on data hygiene →
What belongs in a sales privacy notice?
A sales-facing privacy notice should name the controller, describe what personal data is collected and from which sources, explain the lawful basis for each processing purpose, list the categories of recipients and any international transfers, state retention periods, and give the contact a clear path to exercise access, deletion, correction, portability, and objection rights. GDPR, CCPA, and most Latin American and Asia-Pacific regimes converge on this core. Link the notice from every outbound footer, every form, and every enrichment vendor contract, and version it so audits can show which notice was live on a given date.
How do data subject access and deletion requests work?
Under GDPR a controller has one month to confirm receipt of an access or deletion request and respond substantively, extendable by two months for complex cases. CCPA gives forty-five days with a one-time forty-five-day extension. Both require identity verification before acting, both require you to pass the request to processors and sub-processors, and both carry regulator penalties for silent refusal. Strkr logs every inbound rights request against the contact, routes it to the designated handler, and records the fulfillment action so audits can trace the full chain without a spreadsheet archaeology project.
What are the TCPA rules for sales text messaging?
Sales SMS to a mobile number requires prior express written consent that identifies the seller, discloses that messages may be sent using automated technology, and makes clear that consent is not a condition of purchase. Senders must honor STOP, END, QUIT, UNSUBSCRIBE, and CANCEL replies, keep opt-outs active permanently, respect quiet hours of 8 a.m. to 9 p.m. in the recipient's local time, and screen against internal and national Do Not Call lists. Carrier 10DLC registration adds a second compliance layer that can suspend throughput before a regulator ever notices.
What is a Data Processing Addendum, and when do we need one?
A Data Processing Addendum, or DPA, is the contract clause that binds a vendor to process personal data only on your documented instructions, with defined security obligations, breach notification timelines, sub-processor controls, and cross-border transfer safeguards. GDPR Article 28 and CCPA service provider rules both require one between a controller and every processor that touches personal data. In practice this means signing a DPA with your CRM, enrichment tools, email provider, dialer, and analytics stack before a single contact flows through. Keep the signed copies with your records of processing activities.
Does Strkr handle compliance for us?
Strkr ships the controls a compliance program depends on, including consent and interest-basis tracking per contact, jurisdiction tagging, suppression lists that cannot be bypassed, DNC and quiet-hours enforcement on SMS and voice, DPAs with every sub-processor, and audit logs that show who sent what to whom and under which basis. The platform does not replace counsel or a privacy officer, and it does not decide where legitimate interest ends or how long your retention tail should run. Those calls stay with your legal and compliance team; Strkr makes the evidence easy to produce.