Back to blog
Cold Email August 4, 2026 11 min read Thomas Ryan Oakes

Is Cold Email Legal? GDPR and CAN-SPAM

Is cold email legal? Yes for B2B in most countries, if you follow rules that change by jurisdiction. A country-by-country guide to CAN-SPAM, GDPR, CASL and more.

Yes, cold email is legal in most countries, including the United States, the United Kingdom and the European Union, when you send business-to-business and follow the specific rules of the recipient’s jurisdiction. Those rules differ enough that a single global policy cannot make you compliant everywhere. The question is not whether you may send, but under which conditions.

Disclosure: This guide mentions GTM Bud alongside general outreach practice. We have a bias toward our own product, but the compliance guidance here is vendor-neutral and applies whatever tools you use.

We are not writing this from theory. Our outbound agency, Referral Program Pros, has booked over 7,000 meetings for clients across dozens of industries and jurisdictions, and we built GTM Bud on the playbook that agency runs every day. Running campaigns into North America, the UK, the EU and Australia forces you to learn where the lines sit, because the same message can be routine in one market and a problem in another.

This is general information, not legal advice. We are outbound operators, not lawyers. Cold email law varies by country, by the type of recipient, and by how you obtained the data, and it changes. Nothing here is a guarantee that any particular campaign is lawful. Before you send at scale, and especially before you send into the EU, Canada or Germany, consult a qualified lawyer in the relevant jurisdiction.

Is cold email legal in the United States?

Cold email is legal in the United States, and the country runs the most permissive major regime among the large markets. CAN-SPAM is an opt-out law, not a consent law. The Federal Trade Commission is explicit that the Act covers all commercial messages, is not limited to bulk email, and applies to business-to-business email. You do not need permission before you send. You need to be honest about who you are, and you need to let people leave. Two operational details carry most of the risk. Opt-out requests must be honoured within 10 business days, and your opt-out mechanism must stay able to process requests for at least 30 days after the message goes out. You may not charge a fee, demand information beyond an email address, or make someone take more than one step to unsubscribe.

The FTC sets out seven requirements: no false or misleading headers, no deceptive subject lines, clear identification of the message as an advertisement, a valid physical postal address, a clear explanation of how to opt out, opt-outs honoured promptly, and responsibility for anything an agency does on your behalf. That last point catches a lot of companies. Hiring a vendor does not transfer the liability.

The penalty is assessed per email, which is what makes carelessness expensive at volume. Following the FTC’s inflation adjustment published in January 2025, the maximum civil penalty stands at $53,088 per non-compliant email. Older figures still circulating online, including $16,000 and $46,517, are superseded. Read the FTC CAN-SPAM compliance guide directly; it is short and written for business owners rather than lawyers.

United States permissiveness is a trap for teams that expand internationally. A campaign that is entirely lawful when sent to Chicago can breach the law when the same list includes Toronto, Berlin and Sydney. Segment your sending by recipient country before you scale, not after.

Does GDPR allow cold email to businesses in the EU?

GDPR does not ban B2B cold email, but it changes what you must be able to prove. Article 6(1)(f) allows processing that is necessary for the legitimate interests of the controller, unless those interests are overridden by the rights of the individual. Recital 47 states that direct marketing may be regarded as a legitimate interest. That word “may” is the whole story. Legitimate interest is a case you have to make, document and be able to defend, not a box you tick. Two factors push the balance toward you for genuine B2B outreach: corporate role-based data sits further from a person’s private life than a personal address does, and a message about their actual professional responsibilities falls closer to what they would reasonably expect to receive. Two push against you: irrelevant messages, and data from a source you cannot explain.

The UK Information Commissioner’s Office describes a three-part assessment that regulators across Europe apply in substance: the purpose test, whether there is a real and specific interest rather than a vague commercial one; the necessity test, whether the processing is genuinely needed or whether a less intrusive route exists; and the balancing test, whether the person’s rights and reasonable expectations override your interest. The ICO advises recording that assessment in writing.

Separately from GDPR, the ePrivacy Directive (2002/58/EC) governs unsolicited electronic marketing in the EU, and Article 13(5) leaves each member state to decide how far to protect subscribers who are not natural persons. That is why there is no single “EU rule” for B2B email. Implementation varies country by country, and Germany sits at the strict end.

The exposure is significant. Article 83 sets two tiers: up to 10 million euros or 2 percent of worldwide annual turnover for the lower tier, and up to 20 million euros or 4 percent for the upper tier, whichever is higher. Read the full GDPR Article 6 text and our complete guide to cold email before you build an EU campaign.

The UK carve-out that most senders miss

The UK is friendlier to B2B outreach than most people assume. Under PECR, the rules on unsolicited electronic marketing do not apply to corporate subscribers. The ICO defines corporate subscribers as limited companies, limited liability partnerships, Scottish partnerships and public bodies. Email one of those, and you do not need PECR consent.

The carve-out has limits. It does not extend to individual subscribers, which the ICO treats as including consumers, sole traders and most ordinary partnerships. Emailing a named contact at a registered company is therefore treated differently from emailing a freelance consultant trading under their own name, even though both look like business addresses.

UK GDPR still applies to the personal data of the named individual behind the corporate address. You need a lawful basis, you need to tell people how you are using their data, and the right to object to direct marketing is absolute. The ICO also recommends maintaining a corporate suppression list. Note that the old PECR penalty ceiling of 500,000 pounds has been raised toward UK GDPR levels by the Data (Use and Access) Act 2025, so treat that figure as out of date. The ICO guidance on business-to-business marketing is the authoritative source and is written for non-lawyers.

Where the rules get stricter: Canada, Germany and Australia

Three markets flip the model from opt-out to consent, and they catch teams that assume a US-style approach travels.

Canada runs CASL, the strictest of the major regimes. A commercial electronic message requires consent, sender identification and an unsubscribe mechanism. Consent can be express, which does not expire and which the sender must be able to prove, or implied. The implied route that matters for outbound is conspicuous publication: where a business address is published openly without a statement refusing unsolicited messages, and your message is relevant to that person’s business role. The other implied route is an existing business relationship, which runs for two years from the relevant transaction. Unsubscribes must stay valid for at least 60 days and be processed within 10 business days. Maximum administrative penalties reach 1 million Canadian dollars for an individual and 10 million for an organisation. The CRTC CASL guidance sets out both consent routes.

Germany is why “we follow GDPR” is not a sufficient answer for Europe. Section 7 of the UWG treats email advertising without the addressee’s prior express consent as an unacceptable nuisance, and that provision refers simply to the addressee. It does not carve out business recipients the way the UK does. Unsolicited B2B cold email into Germany carries real risk, and enforcement often comes from competitors and industry associations rather than a data protection regulator.

Australia applies the Spam Act 2003, which requires consent, accurate sender identification and a working unsubscribe facility. Consent can be express or inferred, with inferred consent arising from an existing business relationship or a conspicuously published work address where the message is relevant to that role. Unsubscribe requests must be honoured within five business days, and ACMA has issued penalties in the millions of Australian dollars against large senders. See ACMA’s spam guidance for current figures.

JurisdictionConsent modelKey requirement beyond opt-outPenalty exposure
United StatesOpt-out, no prior consentValid physical postal address in every messageUp to $53,088 per non-compliant email
United KingdomNo consent needed for corporatesDocumented lawful basis, absolute right to objectRaised toward UK GDPR levels by the 2025 Act
EU (general)Legitimate interest, case by caseWritten legitimate interests assessment on fileUp to 20 million euros or 4 percent of turnover
GermanyPrior express consentConsent before sending, including to businessesInjunctions and competitor-driven claims
CanadaConsent, express or impliedProvable consent, 60-day valid unsubscribeUp to CAD 10 million per violation for a business
AustraliaConsent, express or inferredUnsubscribe honoured within five business daysMulti-million dollar ACMA penalties on record

What does a compliant cold email actually contain?

A cold email that satisfies the strictest common requirements across these regimes is not complicated, and building to that standard costs you nothing in reply rate. Every message we send carries the same structural elements regardless of where it lands, because varying the message format by country is where mistakes get made. The list below is the practical floor, not a legal opinion.

  • Accurate from name, from address and reply-to. No spoofed headers, no aliases hiding who is sending.
  • A subject line that reflects the content. Deceptive subject lines are explicitly prohibited in the United States.
  • A real, identifiable sender. A named person at a named company, identifiable from the message itself.
  • A valid physical postal address. Required under CAN-SPAM, harmless everywhere else.
  • A clear opt-out route. A one-line “reply STOP and I will not contact you again” works; an unsubscribe link works better.
  • Immediate suppression on request. Do not use the full ten business days the law allows.
  • Relevance to the recipient’s professional role. This carries the legitimate interests argument and earns the replies.
  • A record of where the data came from. Source, date and method, for every contact.

That last point is the one most teams skip. Keep records of your data sources, your suppression list, the date each opt-out arrived, and, for EU sending, your written legitimate interests assessment. If a complaint comes, the records are the defence. Targeting properly from the start makes this easier, which is why we push people to build a real ICP for outbound before they buy any data.

Legal and deliverable are two different tests

Passing the legal test does not get you into the inbox. Gmail and Yahoo enforce their own bulk sender requirements, and those are platform policy, not law. Break them and nothing happens in court; your mail gets filtered, throttled or rejected instead, which commercially is worse than a warning letter.

Google applies its bulk sender requirements to anyone sending more than 5,000 messages a day to Gmail accounts. Those senders must support one-click unsubscribe using the List-Unsubscribe and List-Unsubscribe-Post headers, include a visible unsubscribe link in the body, and process unsubscribe requests within two days. Google also tells every sender to keep the Postmaster Tools spam rate below 0.3 percent and ideally under 0.1 percent.

Note the mismatch. United States law gives you ten business days to honour an opt-out. Google gives you two. The platform rule is tighter than the statute, and the platform decides whether your next campaign lands. Our cold email deliverability guide covers the authentication and reputation side in full.

Compliance and deliverability point the same direction. Honest headers, relevant targeting, easy opt-outs and clean lists are what regulators ask for and what mailbox providers reward.

Four myths about cold email legality

“Cold email is spam by definition.” No. Spam has a legal meaning in each of these regimes, and it turns on consent, deception and identification, not on whether the recipient knew you beforehand. A relevant, identified, opt-out-respecting message to a business contact is not spam under United States or United Kingdom law.

“A purchased list is automatically illegal.” It depends where you send. Under CAN-SPAM there is no consent requirement, so the source of an address is not the deciding factor. Under GDPR it matters enormously, because you must be able to explain where the data came from. The stronger argument against bought lists is commercial: they are stale, they carry spam traps, and they hurt your reputation long before a regulator notices you.

“An unsubscribe link makes anything legal.” It satisfies one requirement of several. It does nothing about consent in Canada, Germany or Australia, nothing about your lawful basis under GDPR, and nothing about deceptive headers or subject lines.

“GDPR killed cold email in Europe.” It raised the standard of proof. Teams that target precisely and document their reasoning still run European campaigns; teams that blast bought lists cannot defend themselves.

Frequently asked questions about cold email legality

Is cold calling subject to the same rules as cold email?

No, cold calling sits under a separate regime almost everywhere. The United States uses the Telephone Consumer Protection Act and the National Do Not Call Registry rather than CAN-SPAM. The UK uses different PECR provisions and the Telephone Preference Service, with a Corporate TPS for business numbers. Canada runs its own Do Not Call List separately from CASL. A contact who opted out of email is not automatically covered on the phone, so suppress across both.

Are LinkedIn messages covered by cold email law?

Generally no. Statutes such as CAN-SPAM and the Spam Act are written for electronic mail, and platform messaging sits outside them. LinkedIn outreach is governed by the platform’s terms of service, which restrict automation and set connection and messaging limits, while data protection law still covers how you collect and store profile data. Fewer statutory constraints, tighter platform ones, which is why multichannel outreach for B2B services needs a policy per channel.

Who is liable if my agency sends the emails?

You usually are, alongside them. The FTC states plainly that both the company whose product is promoted and the company that sends the message can be held legally responsible, and the same principle runs through the other regimes. If you outsource outreach, put the compliance obligations in the contract, ask which jurisdictions the agency sends into, and review their suppression process. Agencies running client campaigns should read our guidance on cold email for agencies.

How long should I keep unsubscribe records?

Keep them indefinitely and treat the suppression list as permanent. There is no upper limit on retaining a record that someone asked not to be contacted, and that record is what proves you honoured the request. The mistake to avoid is holding suppression per campaign or per mailbox instead of globally. If someone opts out of one sequence and hears from a different mailbox two months later, you have a complaint waiting to happen.

Does compliance change if I am a solo consultant rather than a company?

Your obligations as a sender do not change with your size. No jurisdiction exempts small senders from CAN-SPAM, PECR, GDPR, CASL or the Spam Act. What changes is the recipient side: in the UK a sole trader or ordinary partnership counts as an individual subscriber rather than a corporate one, so emailing other freelancers carries stricter requirements than emailing limited companies. Solo operators comparing tools can start with our roundup of the best cold email software.

Send confidently instead of cautiously

Uncertainty about the law costs more pipeline than the law does. Teams sit on outbound for months because nobody can answer whether it is allowed, when for most B2B senders in most markets the answer is yes, with conditions you can meet in an afternoon. Build the compliant message once, segment your list by recipient country, keep your records, suppress globally and immediately, and the legal question stops being a blocker.

Then the work becomes execution, which is where campaigns actually fail. GTM Bud runs LinkedIn and email outreach for small teams, agencies and consultants, built on the same playbook our agency Referral Program Pros used to book over 7,000 meetings. If you want the sending, sequencing and follow-up handled while you keep control of who gets contacted and how they opt out, start with our cold email automation tool.

Thomas Ryan Oakes

Co-Founder & Outbound Strategist

Outbound expert behind 7,000+ booked meetings. Co-founder of Referral Program Pros and GTM Bud.

is cold email legalcold email complianceGDPR cold emailCAN-SPAMB2B outreach law

Ready to automate your outreach?

GTM Bud finds Leads, writes personalized messages, and sends them, all on autopilot.