Back to docs
Research Operations

Is It Legal to Email or Text Someone for Research? CAN-SPAM, TCPA, CASL and PECR Rules for Recruitment

Research invitations are governed by marketing communications law, not just privacy law. Here is how CAN-SPAM, the TCPA, CASL and PECR treat genuine research outreach — and the one mistake that strips the exemption.

Short answer: in the US, Canada, and the UK/EU, a genuine research invitation is generally not treated as marketing — and therefore sits outside the strictest rules of CAN-SPAM, CASL and PECR. But that exemption is fragile. The moment your invitation promotes a product, or the moment the research is really a route to a future sales list, the message becomes marketing and the full rules apply retroactively.

Most research teams check the wrong law. They ask their privacy counsel about GDPR lawful basis and consent forms, get a green light, and send 4,000 recruitment emails — never realising that a separate body of law governs whether that email could be sent at all. Data protection law governs what you do with the answers. Marketing communications law governs the invitation itself. They are different regimes, with different regulators and different penalties.

This guide covers the second one. It is written for research and insights teams running their own recruitment — in-product prompts, customer email lists, CRM outreach, SMS reminders — rather than for teams buying panel sample, where the panel provider carries the outreach obligation.

This is practitioner guidance, not legal advice. Communications law is jurisdiction-specific and moves quickly; have your counsel confirm anything that will scale.

The distinction that decides everything

Every regime on this page turns on the same question: is the primary purpose of this message commercial?

A message that says "We are redesigning the billing screen and would like 20 minutes of your time — here is a £40 voucher" is a request for information. A message that says "We are redesigning the billing screen and would like 20 minutes of your time — and by the way, have you seen our new Pro plan?" is an advertisement wearing a lab coat.

The industry has a name for the second one: suggingselling under the guise of research. It is the single behaviour that collapses the research exemption in every jurisdiction below, and it is usually introduced not by researchers but by a well-meaning marketing colleague adding a footer to the invitation email.

United States: CAN-SPAM and the primary purpose test

CAN-SPAM regulates commercial electronic mail — messages whose primary purpose is the commercial advertisement or promotion of a product or service. The FTC applies a primary purpose test to mixed messages: a message is judged commercial if a reasonable recipient would conclude from the subject line that it is commercial, or if the non-commercial content is buried below the promotional content.

Research and opinion survey emails generally fall outside the definition, because they advertise nothing. But the FTC's own guidance is explicit that a message containing a survey plus advertising can be primarily commercial and therefore fully in scope.

What that means in practice:

If your invitation...StatusWhat you must do
Only asks the recipient to take part in a studyNot commercialNo CAN-SPAM obligations, but honour opt-outs anyway
Mentions a product launch, offer, or upgradeCommercialPhysical postal address, clear identification as an ad, working opt-out honoured within 10 business days
Uses a subject line implying a deal or offerCommercialSame — the subject line alone can flip the test
Is sent to build a list for later sales outreachCommercial in substanceTreat as marketing regardless of the wording

The safest posture is to comply with the operational parts of CAN-SPAM anyway — accurate headers, honest subject lines, a real reply address, an unsubscribe that works — because those are also the things that keep your invitations out of spam folders and your response rates alive.

United States: TCPA rules for calls and texts

Phone and SMS outreach is governed by the TCPA, and this is where the exemption is genuinely valuable. The FCC has consistently treated research and survey calls that do not also carry a telemarketing message as non-telemarketing, which means they escape the heightened prior express written consent standard reserved for telemarketing, and they are not "solicitations" for National Do Not Call Registry purposes.

That is not a free pass. Three constraints still bite:

  1. Autodialed or prerecorded calls and texts to a mobile number still require prior express consent, even when non-telemarketing. Having the number in your CRM because someone bought from you is not automatically consent to be robotexted.
  2. Revocation must be honoured. A recipient can revoke consent by any reasonable means that clearly communicates "stop" — including replying STOP to an SMS or telling a live agent.
  3. The legal ground is moving. In January 2025 the Eleventh Circuit vacated the FCC's "one-to-one consent" rule before it took effect, and in February 2026 the Fifth Circuit held in Bradford v. Sovereign Pest Control that the TCPA's "prior express consent" covers oral as well as written consent — undercutting the FCC's long-standing written-consent interpretation. Those rulings bind their circuits, not the country, so a national programme still faces conflicting standards. Document consent in writing regardless: the fight you want to avoid is evidentiary, not doctrinal.

If your study is voice-based, note that recording rules are a separate question again — see Interview Recording Consent Laws for one-party, all-party, and biometric requirements.

Canada: CASL and the DNCL

CASL is the strictest anti-spam regime of the three, with penalties running to CAD 10 million for organisations — so the research carve-out matters.

CASL regulates commercial electronic messages (CEMs): messages that, having regard to content, links and contact information, would reasonably be concluded to have as one of their purposes encouraging participation in a commercial activity. A genuine survey invitation does not encourage commercial activity, so it is not a CEM. The parallel Do Not Call rules in the Telecommunications Act contain an explicit carve-out for telecommunications "made for the sole purpose of collecting information for a survey of members of the public."

The interesting Canadian question is incentives, because a gift card looks a lot like an inducement. The CRTC addressed this directly in Compliance and Enforcement Decision CRTC 2016-107, recognising that incentives are a legitimate research practice and that offering one does not by itself turn an invitation into a CEM. The factors that matter include the value of the incentive, whether it is connected to the sender's own products or services, whether it is offered to all participants, whether it is tied to a specific survey rather than general participation, and the promotional tone of the message.

The practical translation: a $25 prepaid card for completing one specific study is fine. "$25 off your next order, and while you are here, tell us what you think" is a CEM.

UK and EU: PECR, ePrivacy and the GDPR layer

In the UK, PECR governs electronic mail marketing — email, SMS, voicemail, in-app messages and direct messages. The underlying definition comes from section 11(3) of the Data Protection Act 2018: direct marketing is "the communication, by whatever means, of any marketing material which is directed to particular individuals."

The ICO's position on research is clear and quotable: contacting people to conduct genuine market research is not direct marketing. The example the ICO gives of genuine research is research used to make commercial or public policy decisions. But the guidance is equally clear about where it breaks:

  • if the messages include promotional material, they are direct marketing;
  • if the research is being carried out so that you or someone else can subsequently send direct marketing to those individuals, it is direct marketing;
  • if a survey collects details to use in future marketing campaigns, the survey is for direct marketing purposes.

That second bullet is the one that catches product teams. A study whose stated internal goal is "identify accounts to target for the enterprise upsell" is not genuine research in the ICO's sense, no matter how neutral the questionnaire looks.

Two things remain true even when the exemption applies. First, you still need a UK/EU GDPR lawful basis for processing the contact data to send the invitation — legitimate interests is the usual route for existing customers, supported by a legitimate interests assessment, and it must be paired with transparency and a genuine right to object. Second, participants retain their data subject rights over anything you collect; see DSARs for Research Data for handling access and deletion requests, and Research Consent Form Templates for the consent layer that sits inside the study itself.

Across the EU, the ePrivacy Directive is implemented nationally, so the detail varies: several member states apply the marketing rules more broadly than the UK, and B2B exemptions differ sharply between, for example, Germany and the Netherlands. If you recruit across the EU, scope the strictest market you operate in and apply that standard everywhere — it is cheaper than maintaining twelve variants.

A compliance checklist for a research invitation

Run every recruitment message through this before it goes out:

  1. Purpose test. Would a reasonable recipient say the primary purpose is to gather information? If a colleague has added a product mention, remove it.
  2. No downstream targeting. Confirm the participant list will not be handed to sales or marketing on the basis of who responded. If it will, you are running a marketing campaign.
  3. Honest subject line. It should describe the study, not a benefit.
  4. Identification. Say who is running the research, who the client is if you are an agency, and how to reach a human.
  5. A working opt-out on every channel, honoured promptly, including STOP handling on SMS.
  6. Consent evidence for automated calls and texts to mobile numbers, with a timestamp and source.
  7. Incentive framing tied to one specific study, not to your own products.
  8. Suppression lists that persist. Someone who opted out of research last quarter should not receive this quarter's invitation.
  9. A record of the lawful basis and, where relevant, the legitimate interests assessment.
  10. A retention rule for the recruitment list itself, separate from the study data.

How this works in Koji

Koji is built so that the compliant path is the default one.

  • Personalised interview links let you send one invitation per participant from your own CRM or email platform, so your existing consent and suppression logic stays in force — you are not handing your list to a third-party sender. See Personalized Interview Links.
  • In-product recruiting sidesteps the outbound-communications question almost entirely: an intercept shown to a logged-in user is not electronic mail marketing, which is why it is the fastest compliant channel for most product teams. See In-Product Research Recruiting.
  • The interview itself is neutral by design. Koji's AI interviewer probes what the participant actually said rather than steering toward a product pitch — the structural opposite of sugging. Follow-up questions are generated from the response, not from a marketing script.
  • Structured questions keep the study genuinely analytical. Koji supports six types — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no — so you can produce decision-grade quantitative output alongside conversational depth, which is exactly the evidence that demonstrates your research was genuine research. See Structured Questions Guide.
  • Consent and intake are captured in the flow, timestamped per participant, so the record you need if a regulator or a customer asks is already there.

The efficiency argument matters here too. Traditional recruitment gets its scale by sending more messages, which is precisely what increases legal exposure. Koji gets scale from the interview side — every participant who accepts gets a full moderated-depth conversation, automatically analysed — so a team can learn more from 60 invitations than a survey programme learns from 6,000. Fewer messages, better data, smaller compliance surface.

Frequently asked questions

Do I need consent to email my own customers about a research study? In the UK and EU you need a lawful basis to process their contact data, which for existing customers is usually legitimate interests rather than consent — provided the study is genuine research and you offer a clear way to object. In the US, a non-commercial research email is outside CAN-SPAM's consent-style requirements entirely. The answer changes the moment the invitation includes promotional content.

Does offering a gift card turn my research invitation into marketing? Not by itself. The CRTC addressed this directly in Decision CRTC 2016-107, recognising incentives as a legitimate research practice. What matters is that the incentive is tied to participation in one specific study, is offered to all participants, and is not a discount on your own products — a voucher for your own store looks like promotion.

Can I text customers to invite them to an interview? Under the TCPA, survey and research messages that carry no telemarketing content are not treated as telemarketing, so the heightened written-consent standard and Do Not Call Registry restrictions do not apply. But autodialed or prerecorded messages to mobile numbers still need prior express consent, and STOP requests must be honoured immediately.

Is B2B research outreach exempt? Partly, and only in some places. UK PECR applies the electronic mail marketing rules to individual subscribers, with corporate subscribers treated differently, and several EU member states are stricter than the UK. Genuine research is outside the marketing rules regardless of B2B or B2C — but you cannot rely on the B2B label to rescue a message that is actually promotional.

What happens if marketing adds a product mention to our invitation? The message becomes commercial and the full marketing rules apply — physical address and opt-out under CAN-SPAM, CEM status under CASL, consent or soft opt-in under PECR. It also damages the research: participants who read the invitation as a sales approach answer differently, which is one reason sugging is banned by professional research codes as well as by regulators.

Does using an AI interviewer change any of this? The outreach rules are about the invitation, not the moderator, so they apply identically. Where an AI platform helps is downstream: consent capture, timestamps, suppression and retention are handled as data rather than as a spreadsheet someone maintains by hand. Where you must take care is disclosure — tell participants they will be speaking with an AI interviewer, both because it is the ethical default and because it is increasingly expected under AI transparency rules.

Related Resources

Ready to run research that is easy to defend? Start free with 10 credits — no credit card, and only conversations that pass Koji's quality bar consume them.

Related Articles

DSARs for Research Data: Handling Access, Deletion, and Portability Requests from Participants

A participant asks what you hold on them, or asks you to delete it. The clock is one month under GDPR and 45 days under CCPA. Here is what counts as their data in an interview study, why the research exemption rarely saves you, and a seven-step runbook.

Interview Recording Consent Laws: One-Party, All-Party, and Biometric Rules (2026)

Federal law allows one-party consent recording, but roughly a dozen US states require all-party consent - and biometric laws like Illinois BIPA add a separate written-consent duty for voiceprints. Here is how research teams stay on the safe side of both.

Paying Doctors and Nurses for Research: Sunshine Act Reporting, EFPIA Disclosure and Fair Market Value

When you pay a physician or nurse to take part in research, transparency law may require the payment to be published under their name. In both the US and the EU, the deciding factor is not the amount — it is whether the sponsor learns who took part.

In-Product Research Recruiting: Recruit Customer Interview Participants From Inside Your App

Stop paying recruiting panels for participants you already have. Learn how to recruit research participants directly from your product using embedded prompts, in-app banners, email triggers, and personalized AI interview links. Faster, cheaper, and more representative than external panels — with zero scheduling friction.

Research Consent Form Templates: GDPR-Compliant Forms for Every Study

Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.

Research Contact Policy: Frequency Caps, Suppression Lists and Who Owns the Customer Inbox

A research contact policy governs how often any single customer can be asked for feedback, by whom, and with what cooling-off period. Here is how to set the cap, run a suppression list, rotate your sample, and stop five teams from independently surveying the same 200 accounts.

Research Ethics and Informed Consent: A Practical Guide for UX Teams

A practical guide to ethical UX research — covering the Belmont Report's three principles, GDPR informed consent requirements, how to handle AI tools responsibly, and how to build ethical maturity in your research practice.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.

User Research Recruitment Emails: Templates and Scripts That Get Responses

Ready-to-use email templates for recruiting user research participants, with proven subject lines, body copy, and follow-up sequences that achieve 7–15% response rates.