New law targets unwanted e-mail; gets mixed review
After more than six years of kicking around Congress, while inboxes around the country continued to fill with pleas from Nigerian widows and offers for everything from free prescriptions to pornography, the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-Spam) Act at last became law on Dec. 16.
Building a Strong Data Foundation in the Age of AI
Artificial intelligence (AI) has become a key priority in the boardroom and across management —…
Learn More
Beginning New Year’s Day, the CAN-Spam Act will replace laws already in place in more than 35 states, many of which had much tougher penalties and a few of which allowed individual consumers to sue spammers. The federal law only extends the opportunity for prosecution to Internet service providers, who’ve argued for years that their bandwidth is being unfairly hampered by the millions of messages a single spammer can generate in a day.
The law also authorizes the Federal Trade Commission to establish a “do-not-spam” registry, a provision which has received mixed reviews. Opponents of the registry say it would set a new Holy Grail for hackers by compiling the sensitive information in one area, while others argue a registry would finally give account holders control of their own inbox.
“Honestly, it’s not terrific stuff,” said David Rice, a law professor at Roger Williams University, of the legislation. From a legal standpoint, Rice said that it’s always tougher to enforce “opt-out” policies as opposed to “opt-in” and said the least the federal government could have done was mandate the FCC to create the do-not-spam list.
“If they did that, there’d be some measure of protection to citizens,” Rice said. “As opposed to this taking everything on a case-by-case basis.”
Technically, the law actually legalizes sending non-fraudulent spam in some states that already prohibit the practice. Both Washington, D.C. and Washington state have granted e-mail recipients the right to sue spammers and California and Delaware have already passed “opt-in” approaches that prohibited unsolicited commercial e-mail without a prior business relationship.
Regardless, the bill, after more than six years in the making, was a popular one in Congress – passing through the House in early December by a 392-5 vote after a similar bill passed the Senate in October 97-0.
State laws on Rhode Island’s books since the summer of 1999 made it illegal to send unsolicited commercial e-mails when violating a Rhode Island Internet service provider’s policies. A separate law requires mass e-mails to include opt-out instructions and contact information, and prohibits false routing information and third-party domain names from being used without permission. The laws applied to messages sent both from the state and into the state, if the sender could “reasonably” have known that the e-mail recipient was a Rhode Islander.
U.S. companies testified that spam costs them billions in lost productivity and software. The bill text incorporates findings that unsolicited commercial electronic mail is estimated to account for more than half of all electronic mail traffic, up from an estimated 7 percent in 2001, with the volume continuing to rise.
Besides Internet service providers, the bill says a wide range of businesses and institutions carry and receive e-mail and there is a finite volume that such providers, businesses and institutions can handle without spending more on their infrastructure.
Justin Gill, marketing programs director at Providence systems-integration firm Entrepid, said e-mail has quickly become a huge part of the business day. Whether spam can ever be stopped entirely is a valid question, he said, but added that the legislation will hopefully bring back some morals to mass e-mail marketing.
“I think some spammers are always going to find a way to send it,” Gill said. “A few people, just like the hackers, are going to find a way to make you miserable.”
Gill said like the illegal online trading of copyrighted music and video files, a few people will probably have to be made an example of before anyone takes the law seriously.
“Over time, I think it’ll be tough to remove all spam,” Gill said. “It’s really a cheap way of targeting and marketing a prospect. Because it doesn’t cost anything is part of why it’s become so widespread and so out of control. Hopefully this law will place some ethics on it.”
Rep. Brian Patrick Kennedy, a Hopkington Democrat, was one of the five representatives who sponsored Rhode Island’s state spam legislation. At the time, Kennedy said he had just started really using a computer himself and quickly found spam to be “quite an annoyance.” His bill originally proposed banning falsified headers and mandated that the subject lines for pornography and other advertisements clearly identify themselves.
But Kennedy said complaints from the American Civil Liberties Union about the freedoms of spammers led to a watering-down of the law. Over the years he hasn’t heard of anyone being punished under the law and said that most people probably don’t even realize there is a law on the books.
“I’m not convinced this is a total solution to the problem,” said Kennedy of the federal legislation. “But hopefully we’ll start seeing less of those e-mails out of Nigeria that start off with, ‘Permit me to introduce myself.’ It’s good to have something on the books.”
For Rhode Island at least, Kennedy thinks the new federal law is “definitely a step up over what we have today,” and added his hopes that a do-not-spam list will be eventually enacted to “give a little bit of privacy back to the people.”
The bill’s text says federal legislation is necessary because state-enacted laws have failed to regulate or reduce unsolicited commercial electronic mail while imposing wide-ranging standards and requirements. As the bill states, part of the problem is that “since an electronic mail address does not specify a geographic location, it can be extremely difficult for law-abiding businesses to know with which of these disparate statutes they are required to comply.”
With the Internet making the business world increasingly global, Rice, the law professor, said anti-spam measures raise interesting questions about finding international limits and boundaries where none exist. He added that the law should allow Internet service providers to seek jurisdiction to prosecute international spammers outside of the country by arguing that a spammer is using U.S. facilities and infrastructure. If nothing else, Rice said the CAN-Spam Act will at least set a common ground throughout the country, even if that means scrapping some of the more progressive state laws, such as the new California provisions to have taken effect Jan. 1.
“Part of me feels bad that this takes basically all legislation down to this
level, which is basically minimal,” Rice said. “It could be worse, but it could
be a lot, lot better.”












