Btw, how specific is the American CAN-SPAM act in terms of how the unsubscribe link should work? In my country I sometimes get emails with unsubscribe links that require you to log in first, which can be a pain to pull out the credentials when you don't really remember signing up for it in the first place. Does CAN-SPAM specify, say, that an unsubscribe link 1)must not require a login? 2)must lead to completion of the subscribe process within x steps?
§ 316.5 Prohibition on charging a fee or imposing other requirements on recipients who wish to opt out.
Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page, in order to:
(a) Use a return electronic mail address or other Internet-based mechanism, required by 15 U.S.C. 7704(a)(3), to submit a request not to receive future commercial electronic mail messages from a sender;
Interesting. That means that Twitter's implementation is one that is against the law, as it required me to log in before I could unsubscribe. It also only unsubscribed me from "that type of email", so lo and behold, more spam arrived a few days later.
The clause only applies to certain email. Applicable? "The term “commercial electronic mail message” means any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service". Probably not.
§ 316.5 Prohibition on charging a fee or imposing other requirements on recipients who wish to opt out.
Tell that to eBay. I cannot got them to leave me alone.
There is no unsubscribe link. Only “To change which emails you receive from eBay, go to Communication Preferences in My eBay.” But there is no such option in My eBay.
There is a “Communications Preferences” elsewhere, but there’s nothing in there to stop eBay spam. I have everything set to off, but they still keep coming.
I think he's talking about signing into a preexisting account. It maybe be illegal to require you to sign up, but I don't think it's proven that requiring preexisting customers to sign in to a preexisting account to adjust their communication settings.
Personally I'm all for requiring an automation enabled unsubscribe header and double opt in (requiring a response from a subscription confirmation email to subscribe in the first place).
The wording is very clear, you can NOT require login to change subscription settings. A password would classify as additional information outside of email address and preferences. Otherwise someone could sign up with your email and you would have no recourse to end the spam, or the company could just bulk create accounts for you without any way to log in (i.e. Facebook).
> The wording is very clear, you can NOT require login to change subscription settings.
You’re right that wording is clear, though you might have misunderstood or skipped over the scope of this CFR, which is “Non-solicited” messages (https://www.law.cornell.edu/cfr/text/16/316.1), and excludes transactional email (https://www.law.cornell.edu/cfr/text/16/316.3). Since the parent was explicitly talking about any email communication coming from accounts you’ve signed up for, it is important to note that the CFR you’re citing does not always apply.
You absolutely can legally require a password to change some subscription and communication settings relating directly to someone’s account, to require otherwise would be a glaring and massive security hole. It’s quite easy to spoof email addresses, and being able to unsubscribe someone else from transactional email subscriptions would be extremely dangerous.
I recently opted out of one where they gave me a list of opt-out choices, with the default being "I still wish to receive this information". If I was on autopilot I would have submitted it. It seems to follow the letter of the law but feels pretty sleazy.
If you did log in, whether you remember your credentials or not, a company can send you transactional emails, marketing emails, or both. CAN-SPAM does not cover emails that are “primarily” transactional, even if the email is part marketing. Companies are legally allowed to require authentication for updating the subscription settings of transactional email. And you wouldn’t want it any other way, otherwise someone could easily spoof you and unsubscribe you from notifications from your bank about your bank account, or other important email you depend on.
On top of that, rather often other people sign up for accounts using my email address, which is my first name + my last name at gmail. I'm guessing they missed a number or middle initial. I could password reset their account, but that seems legally/morally dubious.
Fortunately nobody's signed up for an account for anything I'd actually care to sign up for myself. It's usually some grocery store in Malaysia or something.