Blog · Compliance
Handle data like it matters
Multi-tenant isolation, credential encryption, data retention, and the regional rules — GDPR, CCPA, CASL, LGPD — that actually apply to cold email.
Compliance articles
39 articles
Compliance6 min
California's new AI content law kicks in August 2. Does it touch your outreach?
California's AI Transparency Act becomes operative August 2, 2026, requiring AI content detection and disclosure tools. Here's who it actually covers.
Compliance8 min
A new California deadline just made 'where did this list come from' a real question
California's Delete Act requires data brokers to honor bulk deletion requests from August 1, 2026 — a good moment to check where your list came from.
ComplianceField note6 min
Apple's email-hiding feature leaked real addresses for over a year
A year-old bug in Apple's Hide My Email could expose a real address through a bounced message — a warning for anyone who treats bounces as harmless.
ComplianceAnalysis7 min
Ireland's privacy regulator investigated 88% more marketing complaints last year
The Irish DPC's 2025 annual report shows a sharp jump in direct-marketing enforcement, including dozens of warning letters over unsolicited email and messaging.
Compliance8 min
Cold email for nonprofits: reaching donors and partners without feeling like spam
Nonprofits can email people who've never given before — but the legal rules and the ethical bar are both stricter than most fundraising teams assume.
Compliance7 min
Do you have to tell people they're talking to an AI? The EU's answer
From August 2, 2026, EU users must be told at the first message that they're talking to an AI. What counts as real disclosure, and what doesn't, concretely.
ComplianceAnalysis5 min
Chatbot disclosure is now binding law. Here's the implementation checklist
Article 50 of the EU AI Act is enforceable from August 2, 2026. If you ship an AI chat feature, here's what to build this quarter — the punch list.
ComplianceAnalysis6 min
Deleting the data is cheap. Proving you deleted it isn't.
Gartner puts the cost of a manual deletion request at $1,524 — almost entirely documentation, not deletion. The audit trail is compliance's under-budgeted half.
ComplianceAnalysis6 min
What regulators actually check when you say 'we deleted it'
The EDPB's 2026 report on right-to-erasure enforcement surveyed 764 controllers across 32 DPAs and found most can't prove erasure happened. What auditors check.
ComplianceAnalysis6 min
The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like
National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.
ComplianceAnalysis8 min
A US state just cut its penalty for a misleading subject line by 80%
Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.
ComplianceAnalysis6 min
AI regulation isn't just the EU: where the major jurisdictions actually stand
The EU AI Act gets headlines, but South Korea's AI Basic Act, China's companion-AI rules, and a stalled US preemption fight all moved this month too.
ComplianceAnalysis5 min
Breach notification windows keep shrinking — 2026 made that concrete
California's SB 446 replaced a vague 'unreasonable delay' standard with a hard 30-day clock in 2026. Why fixed deadlines are becoming the norm for incident response.
ComplianceAnalysis7 min
Data minimization just became a fine, not a footnote
CNIL cited unlawful data retention in its €42M Free Mobile fine — a sign minimization is now an active regulatory check, not an ignored line item.
ComplianceAnalysis6 min
The EU AI Act's enforcement phase just went live — here's what actually changed
July 10 activated real enforcement mechanics; August 2 hands the AI Office fining power over general-purpose models. What's binding now, and who it reaches.
ComplianceAnalysis5 min
Phishing is now a $400-a-month subscription — what that does to defender economics
Forg365, a phishing-as-a-service platform targeting Microsoft 365, packages device-code phishing and session-token theft into a $400-a-month Telegram subscription.
ComplianceAnalysis6 min
'Rogue AI agents' is now its own cybersecurity category — and 'rogue' doesn't mean malicious
Forrester named rogue AI agents a top CISO risk for 2026. A July OpenAI/Hugging Face incident shows the term: an agent acting outside scope, no bad intent.
ComplianceAnalysis5 min
Chick-fil-A's loyalty app got hit by the same attack twice. Here's why it keeps working
A credential-stuffing attack hit Chick-fil-A One accounts for the second time in three years. The technique behind it also targets sender and mailbox logins.
ComplianceAnalysis5 min
"GDPR-compliant" stopped being a universal badge in 2026
The UK's Data (Use and Access) Act and a growing US state patchwork mean the same contact data can be compliant in one market and not another.
ComplianceAnalysis7 min
The 2026 DMARC adoption numbers: 52.1% have a record, ~9% are actually protected
EasyDMARC's 2026 report puts DMARC adoption at 52.1% of top domains, up from 47.7% — but a record isn't protection. Here's what the enforcement gap means.
ComplianceAnalysis7 min
A €45 million EU AI Act fine headline is circulating. Here's what's actually confirmed
Compliance blogs report a €45M AI Act penalty over training-data errors — unconfirmed by any official decision, though the fine authority behind it is real.
ComplianceAnalysis7 min
France just made 'did they open it' illegal to track without asking
France's CNIL closed its July 14 transition window for email tracking pixels — senders now need real consent to know who opened a message.
ComplianceAnalysis7 min
Before it was one click: the messy history of the unsubscribe button
From no opt-out at all, to a buried footer link, to a required header Gmail renders itself: how the unsubscribe button became what it is today.
ComplianceAnalysis5 min
What a 14-million-account breach at an email platform teaches every sender
KDDI's disclosure that a shared email platform behind six Japanese ISPs was breached shows how credential exposure anywhere becomes a stuffing risk everywhere.
ComplianceAnalysis5 min
What "internal legacy systems" actually means in a breach notice
Abbott's July 2026 disclosure of two breaches, one traced to legacy systems, decodes a phrase that shows up constantly in breach notices and rarely gets explained.
ComplianceAnalysis6 min
When an agent's action causes harm, who's actually on the hook? 2026's answer is forming
As agents take more autonomous actions in production, 2026 is producing real legal answers on accountability. Log every action and treat it as compliance.
ComplianceAnalysis6 min
One phishing click. 6.9 million driver's license numbers.
A single employee's phished login credentials led to the largest driver's license data exposure of the year. What that chain reveals.
Compliance6 min
Why you'll never accidentally email someone who already said no
One unsubscribe, one bounce, one manual exclusion — and that address is blocked from every campaign in the workspace, checked again at the moment each message sends.
ComplianceAnalysis6 min
How a canned meat brand ended up naming your junk folder
The real path from a 1937 canned-meat brand to a Monty Python sketch to your inbox, and how the mess it named turned into US federal law in 2003.
Compliance7 min
Cold email under Australia's Spam Act: consent, identification, and inferred consent for B2B
The Spam Act 2003 requires consent before you send. How inferred consent works for B2B outreach, what a designated commercial message is, and the ID rules.
Compliance7 min
Cold email under Brazil's LGPD: legitimate interest and how it compares to GDPR
LGPD is modeled on GDPR, and legitimate interest works for B2B cold email in Brazil too. The ANPD's own balancing-test guidance and where LGPD diverges from GDPR.
Compliance7 min
CCPA/CPRA and cold email: it's a privacy law, not an anti-spam law
California's CCPA/CPRA gives residents data rights, but it doesn't set cold-email consent rules like CASL or GDPR. What it actually changes for a B2B sender.
ComplianceAnalysis9 min
CAN-SPAM vs. GDPR vs. CASL: the cold-email compliance landscape compared
CAN-SPAM, GDPR, and CASL run on three different consent models. A practical comparison on consent, unsubscribe timing, and penalties — not legal advice.
ComplianceAnalysis7 min
Data minimization for cold email: collect less, keep less, risk less
Every field on a contact record can leak, go stale, or need erasing later. Why keeping less data is a deliverability and security strategy, not a checkbox.
Compliance7 min
Cold email under CASL: how implied consent actually works for B2B outreach
CASL is opt-in by default, but implied consent covers real B2B outreach. The existing-business-relationship window, conspicuous publication, and required content.
Compliance8 min
Cold email under the GDPR: legitimate interest, the balancing test, and ePrivacy
GDPR doesn't ban B2B cold email. Here's the legitimate-interest basis senders actually rely on, what the balancing test requires, and how ePrivacy layers on top.
Compliance8 min
Cold email in the UK post-Brexit: UK GDPR, PECR, and the corporate-subscriber rule
UK GDPR started as a copy of EU GDPR but is diverging under the Data (Use and Access) Act 2025. PECR's corporate vs. individual subscriber split for B2B email.
Compliance7 min
The right to erasure and cold email: what actually has to disappear
A policy guide to GDPR erasure requests in cold outreach: what personal data must go, what aggregate data stays, and why the erased address stays suppressed forever.
Compliance8 min
What a real data export looks like when you leave a cold-email platform
What a real data export should include when you leave a platform, using Norbelys's actual export bundle, plus the suspend-vs-delete distinction behind it.