(888) 278-3433contact@rampedup.io
Count build — August 2026Opt outLog in
RampedUp
Sign Up for Free

Blog

Marketing in the Americas - Privacy Laws and Languages

· 3 min read

Marketing in the Americas – Many countries in North and South America have taken strides to protect their citizens' privacy that marketers need to understand before campaigning. Some countries have different requirements or considerations depending on the state or province - so understanding locality is important too. Lastly, most countries require marketers to share their opt out procedure in the language spoken in that country so we have associated the languages with the countries below

Brazil (Portuguese) : The LGDP is Brazil’s version of the General Data Protection Regulation for the European Union. The LGDP is a much more comprehensive law that distinguishes between data controllers and data processors with responsibilities for both. Data Controllers (direct marketers) usually work under legitimate business interest to process personal data and ask for their permission for solicitation. Data Processors must allow for a consumer right to be forgotten or understand how their data is processed.

Argentina (Spanish): RampedUp abides by the Argentine Model Clauses (Controller to Processor) which allows Argentine citizens to be removed from our database.

Canada (English / French): Canada is governed by CASL or the Canadian Ant-Spam Legislation passed in 2014. In short, the legislation requires a business to have consent from the recipient before sending a solicitation. It is important to note the law protects Canadians but can impact businesses outside of Canada.

United States (English): The United States is governed by the CAN-SPAM Act and is occasionally referred to as the "You-Can-Spam" Act because it allows marketers to send solicitations until the recipient “Opts Out.” In particular, it does not require marketers to obtain permission before they send marketing messages. It also pre-empts individual states like from requiring an Opt-In but some states have requirements that are more stringent than others:

  • California created the (CCPA) to give consumers more control over the personal information that businesses collect about them. In particular, the CCPA guarantees the consumer’s right to know about the personal information a business collects about them, the right to delete personal information collected, and the right to opt-out of the sale of their personal information. It does not however, require a business to collect an Opt-In before solicitation.
  • New York passed the Stop Hacks and Improve Electronic Data Security (SHIELD) Act. This law creates data security requirements for companies that collect information on New York residents and provides protection from data breaches of their personal information
  • Michigan requires companies to provide notice of a data security breach to each resident of Michigan if the resident’s unencrypted and unredacted information was accessed and acquired by an unauthorized person. An example of this type of data breach we see on a daily basis is when a company uses an email signatures to add to a commercial database when the data was never intended for that purpose.
  • Maine bars broadband internet access providers from “using, disclosing, selling or permitting access to customer personal information unless the customer expressly consents to that use, disclosure, sale or access." An example of implied consent is when a social media user "chooses" to make their information publicly available or a company will provide a press release about one of their employees.
  • HIPPA Healthcare Insurance Protection and Portability Act states a company may not sell protected health information or lists to a business associate or any other third party for that party’s own purposes without obtaining authorization from each person on the list, Businesses that create lists from emails and emails signatures that have protected health information are in violation of this provision of HIPPA.

More on Global