It is a Thursday and you are setting up a newsletter blast for a client. Their list is 6,000 people, imported from a spreadsheet they swear is “all opted in.” You load it and hit send. Three weeks later the client forwards a complaint: someone got the email, never signed up, and is threatening to report it. Now you are on the phone with the client’s lawyer, explaining why an agency you run has their name on a message that broke the rules.
Here is the part most agency owners never get told. When you send email on a client’s behalf, the law does not treat you as a neutral pipe. It treats you as a sender, right alongside the client, and both of you can be held liable. CAN-SPAM says so plainly, GDPR pulls you in as a data processor, and the Gmail and Yahoo sender rules will quietly kill your deliverability long before any regulator shows up. This guide is the compliance layer for every client send, with copy you can lift into your footers, forms and contracts.
What this article covers
- Why the liability lands on your agency
- What one bad send actually costs
- CAN-SPAM: the seven rules, in agency terms
- GDPR: when one EU lead changes everything
- CASL: the Canada rule US agencies miss
- Deliverability is compliance now (Gmail and Yahoo)
- Review-request emails and the FTC
- Three agencies, three compliance setups
- Steal this: the footer, consent and contract copy
- Objections
- FAQ
Why the liability lands on your agency
Most agency owners assume the client owns the list, so the client owns the risk. That is not how these laws are written: they attach responsibility to whoever sends the message and whoever it promotes, and an agency running a client’s email is usually both.
CAN-SPAM is clearest on this. The FTC states that a business cannot contract away its responsibility to comply, and that both the company being promoted and the company that sends the message can be held legally responsible (FTC CAN-SPAM guide). A “the client provided the list” clause does not move liability off your desk. It decides who you argue with after the fact.
GDPR reaches you through a different door: handle personal data on a client’s instructions and you are a “processor” with your own obligations and exposure. CASL targets anyone who sends or causes a commercial message to be sent. The theme is consistent: the send is the act, and you perform it. None of this makes email dangerous. It makes the safe version a system you build once and bake into every sub-account, so the rules become a checklist instead of a threat.
What one bad send actually costs
The numbers behind a sloppy send are large. Start with CAN-SPAM, where the penalty is assessed per email, not per campaign. After the FTC’s 2025 inflation adjustment, each message that violates the Act can carry a civil penalty of up to $53,088 (FTC). Regulators rarely charge the maximum, but the math multiplies by volume: one non-compliant blast to a few thousand people is, in theory, a statutory-maximum exposure in the tens of millions.
“Per email” is the phrase that should make you build a system. The chart shows the statutory maximum, not a prediction.
Statutory-maximum CAN-SPAM exposure by number of non-compliant emails, in USD, at the 2025 per-email penalty. Source: FTC CAN-SPAM Compliance Guide.
GDPR’s top tier reaches €20 million or 4% of global annual turnover, whichever is higher (GDPR Art. 83), and CASL allows up to $10 million per violation for a business (CRTC). For a small agency, though, the realistic risk is not a headline fine but a client relationship that ends the day their brand is named in a complaint, plus the hours you burn cleaning up a mess a five-minute setup would have prevented.
CAN-SPAM: the seven rules, in agency terms
CAN-SPAM applies to every commercial email your agency sends in the US. The FTC boils it into a short list (FTC CAN-SPAM guide), translated here for the agency behind the send.
1. Don’t lie in the header. The “From,” “To,” “Reply-To” and routing must accurately identify who sent the message. For an agency this is the trickiest one: the client’s brand belongs in the From name, but the sending domain and authentication must match reality. Send as the client, authenticated as the client.
2. Don’t use a deceptive subject line. The subject must reflect the content. A fake “Re:” or a false “Your invoice is ready” to lift opens is a straight violation.
3. Say it’s an ad. Commercial messages must disclose that they are advertisements, clearly and conspicuously.
4. Give a real physical address. Every commercial email needs a valid physical postal address, the client’s, not yours. A PO box or registered agent address is fine.
5. Offer a clear way to opt out, with a working unsubscribe in every message.
6. Honor opt-outs fast. Process an unsubscribe within 10 business days, with no fee, no forced login, and nothing asked beyond an email address.
7. Monitor what is sent on your behalf. This is the rule written for you. Even when a client or subcontractor triggers the send, you remain responsible.
How it breaks for agencies: unsubscribes get logged in one sub-account but not synced across a client’s other lists, so someone who opted out of the newsletter still gets the promo. That single gap violates rules 5 and 6 at once. The fix is one suppression list per client that every send checks against, not a per-list opt-out that leaks.
GDPR: when one EU lead changes everything
Agencies love to think GDPR is a European problem. It is not a geography problem, it is a data problem. GDPR applies whenever you process the personal data of people in the EU or UK, wherever your agency sits. The moment a client’s list contains one person in Berlin or Dublin, your send falls under it.
Under GDPR you are almost always the processor, acting on the client’s instructions, while the client is the controller who decides why the data is used. Processors are not off the hook: you must process data only on documented instructions, keep it secure, and help the controller answer data-subject requests.
Two things follow. First, you need a lawful basis for every EU contact you email, which for marketing usually means consent or a defensible legitimate-interest assessment, not “the client gave me a spreadsheet.” Second, you and the client need a data-processing agreement (a DPA) that names you as the processor and spells out what you may do with the data. Most small agencies have never signed one. The clause is in Steal this.
How it breaks for agencies: a client hands you a purchased or scraped list of EU contacts with no consent trail, and you send. Now you are processing personal data with no lawful basis, on instructions you should have questioned. The safe move is to refuse an EU send you cannot document, and to build consent capture into the client’s own forms so the trail exists before anyone hits send.
CASL: the Canada rule US agencies miss
If any of your client’s contacts are in Canada, CASL applies, and it is stricter than CAN-SPAM in the way that matters most: it is consent-first. Where the US lets you email until someone opts out, Canada generally requires express or valid implied consent before you send a commercial electronic message. CASL is enforced by the CRTC and carries penalties up to $10 million per violation for a business (CRTC).
CASL also demands clear sender identification and a working unsubscribe, like CAN-SPAM, but the consent standard is the trap. An agency used to US-style “opt-out is enough” will import a Canadian list and blast it, and that is exactly the send CASL punishes.
How it breaks for agencies: you treat a mixed North American list as one audience under a single US ruleset. Segment by country at intake and apply the strictest rule that touches the list. If Canadian contacts are in the mix, you need express consent on record first.
Deliverability is compliance now (Gmail and Yahoo)
This rule change hits agencies fastest, because it does not need a regulator. Since February 2024, Gmail and Yahoo treat anyone sending more than about 5,000 messages a day to their users as a bulk sender, and they enforce a short list of requirements or your mail stops arriving (Google sender guidelines).
The requirements: authenticate your mail with SPF, DKIM and DMARC; include a one-click unsubscribe (the RFC 8058 header) on marketing mail; and keep your user-reported spam-complaint rate under 0.3%, ideally closer to 0.1%. Miss these and Gmail starts rejecting or foldering your client’s mail, and enforcement has ramped up through 2025.
For an agency, the spam-rate threshold is the sneaky one: it is measured per sending domain and per client, so one client with a stale, angry list can drag deliverability down for every other client. That is why serious agencies isolate sending by client domain and watch complaint rates like they watch lead attribution. Clean authentication and honest lists are the price of the inbox now.
Review-request emails and the FTC
If your agency sends review-request emails, one more rulebook applies. The FTC’s revised Endorsement Guides (2023) prohibit fake and incentivized reviews and removed the old “results not typical” safe harbor (FTC Endorsement Guides). In plain terms, the email cannot offer a discount or prize for a positive review, and it cannot nudge only happy customers while suppressing unhappy ones (review gating). If you run review automation for clients, the request copy is a compliance surface: write it to ask for honesty, and the FTC problem disappears.
Three agencies, three compliance setups
The rules are the same for everyone. The setup that satisfies them scales with your book of business.
The solo operator with US-only clients
Five or six local clients, all US lists. Your exposure is almost entirely CAN-SPAM plus deliverability. The setup is light: authenticate each client’s sending domain (SPF, DKIM, DMARC), put the client’s real address and a working unsubscribe in every template, keep one suppression list per client, and never import a list you cannot vouch for. GDPR and CASL are edge cases you handle with one intake question: are any contacts outside the US?
The 12-person agency with mixed US and EU clients
Now GDPR is live, because at least one client sells into Europe. You need a DPA on file with every client, a documented lawful basis for EU contacts, and consent capture built into the forms you manage. Sending is isolated per client domain so one bad list cannot sink the rest. This is the size where a repeatable process stops being optional: you can no longer hold every list’s history in your head.
The 20-plus-person agency across every jurisdiction
At scale, compliance is infrastructure. You send for clients with US, EU and Canadian contacts, so you segment by country and apply the strictest rule per segment automatically. Authentication, suppression, consent records and DPAs are standardized across every sub-account, and complaint rates sit on a dashboard so a rising number gets caught before Gmail reacts. Every new client inherits a compliant setup by default.
Steal this: the footer, consent and contract copy
Here is the scaffolding, ready to adapt. Run it past your own legal advisor before you rely on it, but this is the shape.
The compliant email footer (CAN-SPAM, for a client send).
[Client Business Name] [Client’s real physical street address, city, state, ZIP] You are receiving this because you signed up with [Client]. [Unsubscribe] · [Update preferences] This is an advertisement.
The consent checkbox (for the client’s opt-in forms).
☐ Yes, I’d like to receive marketing emails from [Client Business Name]. I can unsubscribe at any time using the link in every email. (Unchecked by default. Log the date, time, IP and form URL with every opt-in.)
The double opt-in confirmation email (recommended for EU and Canadian contacts).
Subject: Please confirm your subscription You recently asked to receive emails from [Client Business Name]. Click below to confirm. If you did not request this, ignore this message and you will not be added. [Confirm my subscription]
The data-processing clause (for your client service agreement).
“For personal data Agency processes on Client’s behalf, Client is the data controller and Agency is the data processor. Agency will process it only on Client’s documented instructions, keep it secure, assist with data-subject requests, and not send to any contact for whom Client cannot evidence a lawful basis and, where required, express consent. Client is responsible for the accuracy and lawful sourcing of all contact lists it provides.”
Pair this with the matching SMS opt-in script, and the automation side of running these lists cleanly lives in the GoHighLevel email playbook.
The risky send vs the compliant send
| Plan | The risky send | The compliant sendRecommended |
|---|---|---|
| Price | One complaint from trouble | Boring, by design |
| Feature 1 | List imported, origin unknown | Consent trail captured at intake |
| Feature 2 | Agency's own address in the footer | Client's real physical address in every email |
| Feature 3 | Opt-out logged per list, leaks across sends | One suppression list per client, checked every send |
| Feature 4 | No DPA with the client | DPA on file naming agency as processor |
| Feature 5 | Same setup for US, EU and Canada | Segmented by country, strictest rule applied |
| Feature 6 | No SPF/DKIM/DMARC on the domain | Authenticated domain, spam rate under 0.3% |
| See how it's built → |
Objections, answered
“The client owns the list, so this is their problem.” Not under the law. CAN-SPAM says both the promoter and the sender are responsible, and you are the sender (FTC). A “the client provided the list” clause decides who you sue later, not whether you are liable now.
“We only have US clients, so GDPR and CASL don’t apply.” They apply based on where the contacts are, not where the client is. A US client with one customer in Toronto or Paris pulls that send under CASL or GDPR. Ask at intake: are any contacts outside the US?
“Double opt-in will tank our sign-up numbers.” It trims the top of the funnel and improves everything below it. A confirmed list complains less, which protects the 0.3% Gmail threshold that decides whether your mail arrives at all (Google). A smaller list that lands beats a bigger one in spam.
“This is a lot to set up and I’m a small shop.” It is a one-time setup, not a per-send chore. Authenticate the domains, drop in the footer and consent copy, wire one suppression list per client, and the compliant version runs itself. Small is exactly when a single complaint hurts most.
FAQ
Agency email compliance: quick answers
Is my agency liable for a client's email list, or is the client?
Both. CAN-SPAM makes the business being promoted and the business that sends the message legally responsible, and the FTC says you cannot contract that away. As the agency running the send, you are a sender, so a clause blaming the client's list does not remove your liability.
How much is the penalty for a CAN-SPAM violation?
Up to $53,088 per individual email that violates the Act, after the FTC's 2025 inflation adjustment. Because it is assessed per email rather than per campaign, one non-compliant blast can carry a very large statutory-maximum exposure, even though regulators rarely charge the maximum.
Does GDPR apply if my agency is based in the US?
Yes, if you process the personal data of people in the EU or UK. GDPR is about where the contacts are, not where your agency sits. The moment a client's list includes one EU contact, your send falls under it, and you act as the data processor.
What do the 2024 Gmail and Yahoo rules require of agencies?
Authenticate mail with SPF, DKIM and DMARC, add a one-click unsubscribe to marketing messages, and keep the user-reported spam rate under 0.3%. They apply to bulk senders sending over about 5,000 messages a day to Gmail or Yahoo. Miss them and your client's mail gets rejected or sent to spam.
Do I need a data-processing agreement with every client?
If you handle contact data for any client with EU or UK contacts, yes. A DPA names the client as controller and your agency as processor and sets out what you may do with the data. Even for US-only clients it is good practice, because it documents who owns the list's lawful sourcing.
Can I offer a discount for leaving a review in an email?
No. The FTC's revised Endorsement Guides prohibit incentivized and fake reviews and removed the old 'results not typical' safe harbor. A compliant request asks every customer for an honest review with no incentive attached, and does not filter out unhappy customers before asking.
The bottom line
Go back to that Thursday send. The version that ends in a lawyer’s phone call and the version that ends in a clean report look identical when you hit the button. The difference was decided weeks earlier, in the setup: whether the list had a consent trail, whether the footer carried the client’s real address and a working unsubscribe, whether the domain was authenticated, and whether you had asked the one question that tells you which country’s rules apply.
Compliance is not the exciting part of running an agency. It is the part that decides whether your best client stays after their name shows up in a complaint. Build it once, into every sub-account and every send, and it becomes a quiet advantage: you are the agency whose mail lands, whose lists are clean, and whose contracts already answer the question a nervous client is about to ask.
Related reading: the SMS opt-in script every agency needs, A2P 10DLC registration for agencies, and the GoHighLevel email marketing playbook.
