Email signature compliance gets invoked as a single idea, but it is really six different rulebooks, each with its own scope, requirements, and common myths: CAN-SPAM, GDPR, PECR, UK trading disclosures, HIPAA, and FINRA-style supervision. This series covers each on its own page, in plain English, sourced to the regulator's own text where one exists. None of it is legal advice - see the note at the top of every page.
Each page in this series covers one regulatory theme - what it actually requires, the myths that circulate about it, and a fictional worked example. Nothing here is generic "best practices"; each page names its source.
A recurring pattern across all six themes is a belief that a disclaimer sentence satisfies a requirement that is really about a process, a safeguard, or a specific piece of information. Each page states the myth plainly, then what the source actually says.
This series explains general concepts for a reader trying to understand what a rule is about. It is not a substitute for advice from a lawyer who knows your company's specific facts, jurisdiction, and industry.
The US CAN-SPAM Act requires a valid physical postal address and a working opt-out mechanism on commercial email. It does not require those two things to sit inside a personal reply signature, and a confidentiality disclaimer is not the same requirement and does not satisfy it. What counts as "commercial" is about the message's primary purpose, not who is CC'd.
Read: CAN-SPAM and your email signatureUnder the GDPR and UK GDPR, an employee's name, job title, direct phone number, and photo in an email signature are typically personal data, and a company processes that data every time it sets a signature template. GDPR does not prescribe exact signature content; it regulates how that data is collected, used, and minimized, with a lawful basis behind it.
Read: GDPR and your email signatureThe UK Privacy and Electronic Communications Regulations (PECR), sitting alongside UK GDPR, require that marketing email clearly identify the sender and offer a simple way to opt out, with no exception for small businesses or B2B recipients. A narrow 'soft opt-in' lets a company market similar products to its own existing customers without prior consent, provided every message still offers an opt-out.
Read: PECR and marketing email signaturesUnder the Companies Act 2006 and the Companies (Trading Disclosures) Regulations 2008, UK companies and LLPs must show their registered name, company number, place of registration, and registered office address on business email, in characters readable with the naked eye. This applies to every team member sending external business email on the company's behalf, not only directors.
Read: UK company email signature requirementsHIPAA governs how covered entities and business associates protect protected health information (PHI), and its Privacy and Security Rules focus on safeguards like access control, encryption, and authorization - not on the wording of an email footer. A confidentiality disclaimer may signal good intent, but it does not itself secure a message or excuse an improper disclosure.
Read: HIPAA email disclaimer mythsFINRA Rule 2210 requires that communications with the public be fair, balanced, and not misleading, and firms must supervise and retain those communications - including email - under related record-keeping obligations. Pasting a long, generic disclaimer block into every signature is neither what the rule requires nor a substitute for actual review and supervision of content.
Read: FINRA email disclaimer mythsSignatoro puts your name, title and contact details on every signature, free for one person. From the Up to 15 plan, a company adds one compliance footnote to everyone's signature.
Each page below cites the regulator's own text or guidance where one exists (the FTC, the EDPB and ICO, UK legislation, HHS, and FINRA), and labels any secondary commentary as commentary rather than as the rule itself. Open a page for its full source list.