Skip to main content

The short answer

AI agents are subject to the same email laws as human senders. CAN-SPAM requires a physical address, honest subject lines, and a working unsubscribe mechanism in every commercial email. GDPR requires lawful basis for processing, data minimization, and the right to deletion. Commune handles the infrastructure parts — unsubscribe headers, data deletion API, retention policies. You handle consent management and your privacy policy.

CAN-SPAM requirements

The CAN-SPAM Act applies to any commercial email sent to US recipients. “Commercial” means any email whose primary purpose is advertising or promoting a product or service. This includes automated outreach from sales agents, marketing bots, and follow-up sequences. Penalties are up to $51,744 per violation. Each email is a separate violation.

Adding your physical address

Every commercial email your agent sends needs a physical mailing address in the footer. Build this into your email template:

Adding List-Unsubscribe headers

RFC 8058 defines a one-click unsubscribe mechanism that email providers like Gmail and Yahoo now require for bulk senders. Commune automatically adds List-Unsubscribe and List-Unsubscribe-Post headers when you include unsubscribe configuration.

Handling unsubscribe requests

When someone clicks unsubscribe, you need to record it and prevent future sends. Build a suppression list and check it before every send.
Transactional emails (order confirmations, password resets, account notifications) are exempt from most CAN-SPAM requirements except the prohibition on false headers. If your agent sends both transactional and commercial emails, classify each message and apply rules accordingly.

GDPR requirements

GDPR applies when you process personal data of EU/EEA residents. Email addresses are personal data. Email content often contains personal data. If your agent emails anyone in the EU, GDPR applies to you.

Lawful basis for processing

You need a legal reason to send email. The two most relevant bases for agent email: Consent must be freely given, specific, informed, and unambiguous. A pre-checked box is not consent. An email address submitted in a form is not consent to receive marketing.

Data minimization

Only collect and process the data your agent actually needs. If your agent doesn’t need to store the email body after processing, don’t store it.

Right to deletion

GDPR gives individuals the right to have their personal data deleted. This includes email content, metadata, and any derived data (summaries, extracted entities). Commune provides a data deletion API to remove email data from Commune’s systems:
You also need to delete data from your own systems — your database, logs, backups, vector stores, and any downstream services that received the data.

Data retention policies

Don’t keep data longer than you need it. Set retention policies and enforce them with automated cleanup:

What Commune handles vs. what you handle

Getting a DPA

If you’re processing EU personal data through Commune, you need a Data Processing Agreement. Contact support@commune.email to request one. Enterprise plans include a signed DPA by default.

Data Deletion

Full API reference for deleting email data from Commune.

Spam Prevention

How Commune prevents your agent from being flagged as a spammer.

Rate Limits

Per-plan sending limits that help keep your sending within legal bounds.

Human-in-the-Loop Approval

Approval flows that ensure compliance-sensitive emails get human review.
Last modified on March 19, 2026