For a US store, the email law you must follow is CAN-SPAM. GDPR applies through your EU customers. CCPA can apply below its $26.6M revenue line if your site shares data on 100,000 or more Californians a year.
For a US store, the email law you must follow is CAN-SPAM. GDPR applies through your EU customers. CCPA can apply below its $26.6M revenue line if your site shares data on 100,000 or more Californians a year.
This is not legal advice. It is a map of which rules reach a US ecommerce brand, so you know what to ask a lawyer.
Which privacy law applies to your store?
Most guides on GDPR and CCPA compliance for ecommerce explain both laws in full. They skip the question a founder needs answered first: which one applies to me?
Law Who it covers What triggers it Penalty CAN-SPAM Anyone sending commercial email to US inboxes Sending a marketing email Up to $53,088 per email GDPR Stores outside the EU that sell to, or track, people in the EU Offering goods to people in the EU, or monitoring their behavior there Set by EU regulators CCPA Businesses handling data on California residents Over $26,625,000 in revenue, OR buying, selling or sharing data on 100,000+ consumers or households a year, OR 50%+ of revenue from selling or sharing data Up to $2,663 per violation, $7,988 if intentionalThe CAN-SPAM figure comes from the FTC. The CCPA figures come from the California Privacy Protection Agency, effective 1 January 2025. The GDPR trigger is Article 3(2) of the regulation.
Read the CCPA row twice. The revenue line is the one everyone quotes. The second test is the one that catches smaller brands.
Do you need consent to email customers in the US?
No. CAN-SPAM works on opt-out, not opt-in. The FTC's own guide says you do not need consent to send marketing emails.
What you do need, on every marketing email:
- Honest "From" and header details.
- A subject line that matches what is inside.
- A valid physical postal address. A registered PO box or private mailbox counts.
- A clear way to unsubscribe that keeps working for at least 30 days after you send.
- Opt-outs honored within 10 business days.
Transactional emails, like order and shipping confirmations, are exempt from most of these rules. They still need honest routing details.
Check that the unsubscribe link and your address are in every template. That includes the ones an agency or a designer built for you.
So for US subscribers, the real risk is sloppy footers and slow unsubscribes.
Does CCPA apply if you're under $26.6M?
It can. This is the part most founders get wrong.
The revenue test is over $26,625,000. Most brands between $1M and $10M stop reading there. But CCPA also covers any business that "buys, sells, or shares the personal information of 100,000 or more consumers or households" in a year. That test has nothing to do with revenue.
So what counts as selling or sharing? The Sephora case is the clearest answer. In August 2022, California's attorney general announced a $1.2 million settlement with Sephora. The state said Sephora let ad tech and analytics companies place "cookies, pixels, and other tracking technologies" on its site. Those companies collected data like the products people viewed and bought. California treated that as a sale Sephora had not disclosed. The order also required Sephora to honor Global Privacy Control, a browser setting that tells sites "do not sell my data".
Now look at your own store. You probably run an ad pixel or two. If 100,000 California visitors a year load your site, you may be in scope, whatever your revenue.
Two things to do this week:
- Pull a year of site traffic from your analytics, filtered to California. Note the number.
- List every pixel and tracking script on the site. Your theme and apps may have added some you forgot.
Take both to a lawyer. They will tell you if you need a "Do Not Sell or Share" link and how to honor Global Privacy Control.
Does GDPR apply to a US online store?
Only through your EU customers.
Article 3(2) says GDPR applies to a business outside the EU when it processes data linked to "the offering of goods or services" to people in the EU. It also applies to "the monitoring of their behaviour" in the EU. If you ship to Germany, or run a pixel that tracks visitors in France, it can reach you for those people.
It does not mean every US subscriber needs GDPR consent. So skip the site-wide consent wall. Treat the EU as its own group:
- Build a segment of subscribers located in the EU.
- On signup forms shown to EU visitors, add an unticked consent checkbox.
- For past EU customers, EU rules allow a "soft opt-in". You can email them about products like the ones they bought. You must have told them so, and every email must let them opt out.
If you do not ship to the EU at all, check whether your store lets EU visitors order. If it does not, the "offering goods" test falls away. Tracking EU visitors can still count.
What to set up in Klaviyo
Most of the work lives where your list lives. One pass through this list covers the basics:
- Footer. Physical address and unsubscribe link in every template.
- Unsubscribes. Test one yourself. Make sure the profile gets suppressed, not only removed from one list.
- Requests. When someone asks you to delete or stop using their data, suppress or delete the profile the same week.
- EU segment. Build it. Show EU visitors a signup form with an unticked consent checkbox.
- Signup forms. The form is where consent is captured. Your welcome email flow starts there, so get the wording right once.
- Tracking. Your browse abandonment flow depends on tracking visitors. Include Klaviyo's tracking in the pixel list from the CCPA section.
This work lets you keep emailing the people who want to hear from you.
Where this sits in the system
Compliance sits under every flow. Every flow sends to people who signed up through a form. Every one depends on an unsubscribe that works.
For the order to build the flows themselves, start at the ecommerce customer retention hub.
Get the whole system
Once the basics are clean, the next job is the flows that bring customers back.
12 flows, 37 emails, one job: repeat purchases. Every trigger, every send delay, every exit condition, written out so you can build them this month.
