Subscribe
Learn Library

One Email, a $2.95 Million Fine

An educational article on digital marketing compliance, using a $2.95 million fine over a missing unsubscribe link to explain email, advertising, and data rules, and outlining consent-first practices such as double opt-in, fast unsubscribes, data mapping, and privacy ownership.

ai-marketingworkflow
2026-08-30SupaMarketers7 min read

Let me start with a story.

In 2024, a company was fined $2.95 million. The charge may sound hard to believe: the marketing emails it blasted out had no "unsubscribe" link.

Yes, you read that right. No fraud. No stolen data. The unsubscribe line at the bottom of the email was simply missing — users wanted out and had nowhere to click.

One link. $2.95 million.

Some will say: tough luck. Wrong place, wrong time.

No. This isn't bad luck. This is the new normal.

Let me give you a few numbers. By 2024, 144 countries had privacy laws on the books, and more than 80% of the world's population lives under some form of privacy regulation. The United States still has no unified federal privacy law, but California, Virginia, Colorado, Connecticut, Utah... every state writes its own rules. In 2023 alone, new laws took effect in five states at once.

Among companies doing business in the US, nearly 60% admit it: they can't keep up. They truly can't.

So what are marketers supposed to do?

What Is Digital Marketing Compliance?

Don't let the phrase intimidate you. Break it down and it's three plain statements.

Email has its rules: your subject line is honest, your sender identity is real, and if users want to leave, they can leave at any time.

Ads have their rules: no deceiving, no hiding, and you follow the platform's policies.

Data has its rules: for every piece of personal information — how you collected it, where it's kept, what you use it for — you have to be able to explain it clearly, and you need the user's consent.

That's it. Understanding isn't the hard part. Taking it seriously is.

When someone doesn't, the price shows up on the fine itself. In Europe, since GDPR (General Data Protection Regulation) took effect, regulators had racked up €5.88 billion in cumulative fines by the end of 2024. In 2023, Meta was hit with a single €1.2 billion fine — for transferring European users' data to servers in the United States.

Now look at email. A single non-compliant email can cost you up to about $50,000.

Now imagine you send 100,000 of them...

Right — I don't need to finish that math. You already know how multiplication works.

What Do Users Actually Care About?

Some still hold out hope: fines are a long shot, and users don't really care about any of this.

A survey tells a different story. Cisco asked a group of companies: if your data protection is poor, will customers still buy from you? 94% said no.

Those companies' instincts are right. Because the numbers on the consumer side are even harsher.

Nearly half of Americans have stopped buying from a company outright over privacy concerns. Four in ten consumers don't trust businesses to use their data properly at all. More than six in ten users believe most companies simply aren't transparent: what did you do with my data? I have no idea.

Picture a customer who already finds your ads annoying — and then hears you've been passing their data around. How are they going to treat you?

They won't just tune you out. They'll cut you off for good.

Tune you out, and you can still reach someone else tomorrow. Cut you off, and that person is never coming back.

There's another side to this, though — and it's good news.

Google and Ipsos ran a study: when users feel in control of how their data gets used, they're three times as likely to feel positive about the ads they see.

Three times. Same people, same ads. The only thing that changed was the sense of control.

Why Playing by the Rules Makes You More Money

Let's be blunt: compliance isn't buying peace of mind. Compliance is good business in its own right.

Here are the numbers. 95% of companies believe the benefits of privacy compliance outweigh the costs. 80% say privacy regulations have actually made their business better.

And I came across an even more striking set. Companies that deliberately collect first-party data — the data users hand over themselves, with clear and explicit consent — and market with it: customer acquisition costs down 83%, conversion rates up 73%, marketing ROI up 72%.

Those numbers are not typos. Down 83%, up 73%, up 72%.

Why? Think about one simple truth.

Which is more real: behavior you silently logged behind users' backs, or the preferences they volunteer on their own social feed? Which converts more easily?

The latter, every time. Data given willingly arrives with intent. If someone opts into your emails, they actually want to read them. If they fill out your survey, they actually have a need. Market with data like that, and every shot is aimed.

Data quietly stockpiled, on the other hand, looks impressive — but half of it is noise, and the other half is risk.

78% of companies have already figured this out and ranked first-party data as their most valuable source of customer insight. 93% of marketers say consent-based data matters more than ever.

Put simply: It used to be about who held the most data. From here on, it's about who's allowed to know the most.

So What Do You Actually Do?

The playbook comes down to one sentence: build permission into your process.

Where to start? With your email list.

Marketing's old default was: send first, and annoyed users will unsubscribe on their own. The new default is the reverse: consent first, then send. The whole logic has flipped. And reality is pushing you to flip with it: between 2021 and 2023, user requests to have their data deleted by companies rose 246%. Don't fight that current.

A few concrete things — none of them hard.

The most basic: send only after the user says yes. Don't buy lists, don't scrape lists. If you can, use double opt-in: users submit their email, then click a confirmation message — only then do they count. A little more friction, but if a dispute ever comes up, that's your evidence.

Go one step further: make unsubscribing fast. The law gives you ten business days, but don't use them — when a user clicks unsubscribe, make it effective on the spot. Think about it: someone who's already decided to leave — what good is clutching their email address?

One small thing gets overlooked the most: map the data you hold. Which systems it lives in, who can see it, what it's used for. Sounds basic? Only 34% of companies worldwide have finished that map. The ones who have are the ones who know exactly where they stand.

Then, name someone in charge. Data privacy can't be "everyone's job." If it's everyone's job, it's no one's job. In the US and UK, 70% of companies have already appointed a dedicated privacy lead.

And finally: if there's a tool for it, skip the manual grunt work. Roughly half of companies have already adopted privacy management software, and 70% of them say compliance clearly improved once the tools were in place.

Notice something? Not one of these takes a genius. All it takes is putting "did the user say yes?" before every action.

The Last Word

Back to that email from the beginning.

Adding an unsubscribe link before hitting send — how long does that take? About five minutes.

$2.95 million, divided by five minutes. No job on Earth pays an hourly rate like that.

I kept turning this over afterwards, and the more I did, the clearer it got: the expensive thing was never compliance. It's gambling on luck.

What users give you was never just data — it's permission. Permission builds up slowly, and it takes only once to bring it all down.

Oh, and one more thing: may you never have to learn this lesson through a fine.