email-compliance

Audit commercial email campaigns for CAN-SPAM, GDPR, and CASL compliance.

2|Updated Mar 30, 2026
One-click install
npx skills add https://github.com/chunkydotdev/email-skills --skill email-compliance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: email-compliance
Source: https://github.com/chunkydotdev/email-skills/tree/main/skills/compliance/email-compliance
Command: npx skills add https://github.com/chunkydotdev/email-skills --skill email-compliance

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Sending commercial or bulk email across multiple jurisdictions exposes you to heavy penalties for non-compliance with conflicting regulations like CAN-SPAM (US), GDPR (EU/EEA), and CASL (Canada), which have differing consent, unsubscribe, and record-keeping requirements that are easy to get wrong.

Core Features & Use Cases

  • Multi-jurisdiction compliance guidance: Clear, side-by-side breakdown of requirements for the three major global email laws, with practical rules of thumb for senders targeting multiple regions.
  • Consent and suppression management support: Guidance for building valid opt-in flows, tracking consent records, handling implied consent expiry for CASL, and maintaining compliant suppression lists for unsubscribes and bounces.
  • Pre-send and operational checklists: Actionable checklists for auditing email practices, implementing RFC 8058 one-click unsubscribe, and responding to GDPR data subject erasure requests. Use case: For example, a marketing team launching a new newsletter to EU and US recipients can use this skill to verify their signup flow meets GDPR explicit consent requirements, add required unsubscribe headers to their emails, and build a process to honor erasure requests within the required 30-day window.

Quick Start

Use the email-compliance skill to review your upcoming promotional email campaign for compliance with CAN-SPAM, GDPR, and CASL requirements before sending to your recipient list.

Frequently Asked Questions about email-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I ensure bulk email compliance with GDPR, CAN-SPAM, and CASL when sending to multiple regions?

Bulk email compliance across GDPR, CAN-SPAM, and CASL requires navigating conflicting consent, unsubscribe, and record-keeping rules. You can apply side-by-side regulatory breakdowns and pre-send checklists to verify that your campaigns meet multi-jurisdictional requirements before sending.

What is RFC 8058 one-click unsubscribe and do I need it for GDPR and CASL compliance?

RFC 8058 one-click unsubscribe is a standard for handling email opt-outs directly from the email client. Implementing it is a key operational checklist item for complying with global email regulations like GDPR and CASL, ensuring recipients can easily suppress future sends.

How do I build a GDPR compliant consent flow and maintain audit-ready email records?

Building a GDPR compliant consent flow involves capturing explicit opt-in and tracking consent records to maintain audit-ready proof. You can use guidance for designing valid opt-in flows and establishing processes to handle data subject erasure requests within the required 30-day window.

How do I manage suppression lists and CASL implied consent expiry for commercial email?

Managing suppression lists and CASL implied consent expiry requires tracking consent durations and maintaining compliant unsubscribe and bounce records. You can apply operational checklists to handle implied consent expiration and ensure suppressed recipients are excluded from future commercial sends.

What's the best way to audit email practices before sending a promotional campaign to US and EU recipients?

The best way to audit email practices is using pre-send compliance checklists that verify signup flows against GDPR explicit consent and CAN-SPAM requirements. This process ensures your promotional emails meet multi-jurisdictional regulations before hitting your recipient list.

How do I handle GDPR data subject erasure requests for my email marketing list?

Handling GDPR data subject erasure requests involves building a process to identify and remove subscriber data from your email lists within the required 30-day window. You can use operational checklists to establish a compliant workflow for responding to these suppression and deletion requests.