Skip to content
← BlogComplianceAnalysis8 min read

A US state just cut its penalty for a misleading subject line by 80%

Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

Most US state email law gets less strict scrutiny than CAN-SPAM, GDPR or CASL because it rarely makes headlines outside legal trade press. Washington’s Commercial Electronic Mail Act, or CEMA, is the exception, and this year it went through a genuine back-and-forth: a 2025 state Supreme Court ruling broadened what counts as a violation, a wave of litigation followed, and in March 2026 the legislature responded by narrowing the penalty. If you send commercial email to US recipients and haven’t specifically checked whether any of it reaches Washington residents, this is worth five minutes, because CEMA doesn’t care where you’re sending from.

What CEMA actually prohibits, and why it’s unusual

CEMA has existed since 1998, and its core prohibition is simple: don’t send a commercial email with false or misleading information in the subject line. What makes it unusual among state email laws is the enforcement mechanism — a private right of action with statutory damages that don’t require proving actual harm. Historically, that meant $500 per violation, and “violation” meant per email, per Washington recipient, regardless of where the sender was located. A federal court separately upheld CEMA against a challenge that CAN-SPAM should preempt it, which matters because CAN-SPAM’s own private right of action is much narrower — CEMA has real teeth precisely because it isn’t just a state mirror of the federal law.

The ruling that changed the stakes

In 2025, the Washington Supreme Court issued an opinion expanding the interpretation of CEMA’s misleading-subject-line provision, broadening its reach beyond the narrower reading some senders had relied on. The practical effect, according to legal commentary tracking the fallout, was a surge in CEMA litigation against retailers and other commercial senders — a predictable outcome once a court makes a strict-liability, no-damages-required statute easier to trigger. Any subject line that a plaintiff’s attorney could plausibly characterize as misleading became a viable claim, and at $500 per email per recipient with no cap tied to actual harm, the math on a list of any real size gets serious fast.

What HB 2274 actually changes

Washington’s legislature moved in 2026 to narrow the statute’s practical bite without repealing it. Governor Bob Ferguson signed House Bill 2274 on March 23, 2026, and it took effect June 11, 2026. The headline change: statutory damages for a CEMA violation dropped from $500 per violation to $100 per violation — an 80% reduction. That’s a meaningful de-escalation for the retailers and marketers who’d been facing the earlier ruling’s broadened liability, but it’s worth being precise about what didn’t change: the underlying prohibition on misleading subject lines is still there, the private right of action is still there, and $100 per email per Washington recipient is still real money at any list size that matters for a cold-outreach or retail-marketing program.

Before HB 2274After HB 2274 (June 11, 2026)
Statutory damages per violation$500$100
Proof of actual damages requiredNoNo
Private right of actionYesYes
Scope: misleading subject lines prohibitedYes (broadly, post-2025 ruling)Yes, unchanged
Applies regardless of sender locationYesYes

How CEMA stacks up against the law you’re probably already thinking about

Most US-based senders build their compliance mental model around CAN-SPAM and stop there, because CAN-SPAM is the federal baseline and, for a long time, the assumption was that federal law occupies the field. Washington’s federal court ruling upholding CEMA against a CAN-SPAM preemption challenge closed that door specifically for Washington — the two laws coexist, and complying with one doesn’t automatically satisfy the other:

CAN-SPAM (federal)Washington CEMA
Who can sueFTC, state AGs, ISPsFTC, state AGs, plus any individual recipient
Damages without proof of harmNo — enforcement-driven penaltiesYes — statutory damages per violation
Per-violation exposureSet by FTC enforcement action$100 (post-HB 2274), no cap on count
Subject line standardNo false or misleading header infoNo false or misleading subject line info
Applies based onSender conduct broadlyRecipient's Washington residency

The private right of action is the whole story here. CAN-SPAM’s enforcement runs almost entirely through the FTC and state attorneys general — an individual recipient generally can’t sue you directly over a misleading subject line under federal law. CEMA lets any Washington recipient do exactly that, which is the mechanical reason a single state law generated enough litigation to force a legislative response, while CAN-SPAM enforcement actions against small and mid-size senders remain comparatively rare.

What this actually means if you send cold email

The reform doesn’t change your compliance obligation — it changes your exposure if you get it wrong, and $100 per violation is still not a number worth testing. The real takeaway is that CEMA is a live example of a pattern worth internalizing generally: state-level email law can move fast, in both directions, and it moves in response to actual litigation volume, not in response to a compliance calendar. A subject line that felt like reasonable marketing language a year ago can become expensive after a single state supreme court ruling reinterprets a decades-old statute, and the fix a legislature applies afterward doesn’t retroactively protect anything sent before the reform took effect.

The practical standard to hold subject lines to hasn’t changed: don’t imply a relationship, offer, or urgency that isn’t real. “Following up” when you’ve never previously contacted the recipient, a fake reply-thread subject line, or a subject line implying a personal connection that doesn’t exist are exactly the kind of thing CEMA — and honestly, most recipients’ spam-report reflex — was built to catch. That’s not a new standard cold email specifically needs to invent; it’s the same honesty bar specific, verifiable claims already outperform on for reply rates, independent of any legal exposure at all.

Why this matters even if you’ve never been sued

It’s easy to read a story about a state statutory-damages reform and conclude it’s only relevant to companies large enough to attract plaintiff’s-attorney attention — big retailers with list sizes in the millions, running programs at a scale where $100 per violation becomes a boardroom conversation. That’s true as far as it goes, but it undersells the actual lesson. CEMA litigation didn’t emerge because retailers were doing something unusually deceptive; it emerged because a court reinterpreted an existing statute more broadly, and ordinary marketing language that nobody had previously flagged as risky suddenly carried real exposure. Any cold-email operator sending into the US, at any scale, is one similarly-timed court ruling away from the same situation in whatever state they’re least paying attention to — and unlike a deliverability problem, which shows up in your bounce rate, a compliance exposure like this one can sit invisible until the first demand letter arrives.

Frequently asked questions

Does CEMA apply to my business if I'm not based in Washington?

Yes, if your commercial email reaches Washington residents. CEMA's scope is based on the recipient's location, not the sender's — a company with no Washington presence can still be subject to a CEMA claim over a misleading subject line sent to a Washington-based recipient.

Is $100 per violation still worth worrying about?

Yes. At any meaningful list size, $100 per email per Washington recipient with no cap and no requirement to prove actual damages adds up quickly. The reform reduced exposure by 80% from the prior $500 figure — it didn't eliminate it.

What actually counts as a misleading subject line under CEMA?

The statute prohibits subject lines containing false or misleading information, and a 2025 Washington Supreme Court ruling broadened how that's interpreted. The safest practical standard is a subject line that accurately reflects the message content and doesn't imply a relationship, prior contact, or urgency that isn't genuinely there.

Compliance you don’t have to track state by state

CEMA is one state’s law, but the underlying lesson generalizes to every jurisdiction your list touches: suppression lists, unsubscribe handling, and audience segmentation built into your sending platform matter more than any individual statute’s specific dollar figure, because the number you actually control is whether your subject lines and targeting are honest in the first place. Norbelys keeps suppression enforcement and honest, verified analytics running on every send, so a subject line that’s misleading enough to trigger a state law is also, not coincidentally, the kind of send that tanks your real reply rate — the two problems share the same fix. See it running on your own domain and stop treating compliance risk and deliverability risk as two separate problems, because they’re the same problem measured two different ways.