Is cold email legal?
Updated 25 September 2026 // by Mark Glazer, ReplyLead // compliance is a checklist, not a vibe
- 10business days to honour a US opt-out (FTC)
- $53,088maximum FTC civil penalty per violating email
- 0B2B exceptions in CAN-SPAM
- 4regimes compared: US, UK, EU, Canada
Yes - B2B cold email is legal in most major jurisdictions, with conditions. The United States permits it under CAN-SPAM without prior consent, provided identity is honest and opt-outs are honoured. In the EU and UK it is lawful when properly grounded - for B2B, typically legitimate interest - with member-state rules varying. Canada's CASL is the strictest mainstream regime and turns on consent, express or implied. The US rules carry weight: the FTC puts penalties at up to $53,088 for each email that breaks them, and opt-outs must be honoured within 10 business days.
This page is a practitioner's summary of how the rules apply to business-to-business outreach, not legal advice; for decisions with real exposure, ask a lawyer who knows your markets.
United States: CAN-SPAM
CAN-SPAM governs commercial email in the US and is an opt-out regime: you may email a business contact without prior permission, and the law regulates how. The operative requirements:
- Honest routing and identity. From-name, sending address and reply-to must identify the real sender - no forged or misleading header information.
- Truthful subject lines. The subject cannot misrepresent the message's content.
- A valid physical postal address for the sender in the message.
- Identified as an ad. The FTC says "you must disclose clearly and conspicuously that your message is an advertisement", and allows "a lot of leeway in how to do this".
- A working opt-out that a recipient can exercise easily, honoured promptly - the statute allows up to ten business days - with no fee, no login and no interrogation.
- Suppression that sticks. Once someone opts out, they stay out, across your campaigns and your vendors.
Penalties are assessed per non-compliant message and can reach five figures each, so violations price in fast at outbound volume. Note what CAN-SPAM does not require: prior consent, or that outreach be B2B - but the honest-identity and opt-out machinery is mandatory for everyone.
European Union: GDPR and the ePrivacy layer
GDPR regulates the personal data behind the email - a work address that identifies a person, such as dana.smith@company.com, is personal data. Sending requires a lawful basis, and for B2B outreach the commonly used one is legitimate interest: a documented balancing of your interest in reaching a relevant business contact against that person's rights. In practice that means targeting people whose role makes the message genuinely relevant, saying where their data came from when asked, honouring objections immediately, and keeping records of the reasoning.
Layered on top, the ePrivacy rules as implemented by each member state decide when unsolicited email itself is permitted - and this is where the map gets uneven. Several states distinguish corporate from individual subscribers; others, Germany prominent among them, effectively require consent for email marketing under national competition law, making cold email to German recipients a materially higher-risk activity. The UK's PECR follows the corporate-subscriber pattern: mail to limited companies' work addresses sits outside the strict consent rule that protects individuals and sole traders, while GDPR duties still apply. The operational consequence is unglamorous but simple: segment by country, and apply the strictest rule in each segment. Our own GDPR practice is documented on the GDPR page.
Canada: CASL
CASL is consent-based and the strictest regime most senders will meet. Commercial electronic messages require express consent (asked for and given) or implied consent, which for B2B most relevantly arises when a recipient's address was conspicuously published or provided, without a statement declining unsolicited messages, and the message is relevant to the recipient's business role. Every message must identify the sender, include contact information and carry a working unsubscribe. The practical posture for Canadian segments: rely on the conspicuous-publication basis only with documented relevance to the role, keep evidence of where each address came from, and suppress aggressively.
The operating checklist across all four
Regimes differ at the edges; the compliant operating posture is nearly universal:
- Send as a named, findable human at a real company - honest from-line, honest subject, physical address present, message identified as an ad. Never from a no-reply address that cannot receive the very opt-outs the law requires you to honour.
- Target on role relevance and document it - the same discipline that makes a list convert is the discipline regulators ask about.
- Make declining effortless, honour it immediately, and wire suppression into the cadence's stop rules so no follow-up ever chases a no.
- Segment by jurisdiction and apply the local rule - consent-first where national law demands it.
- Keep records: data sources, lawful-basis reasoning, suppression lists, opt-out timestamps.
None of this is burdensome, and all of it overlaps with what deliverability demands anyway - the law and the inbox providers are converging on the same standard: honest senders, relevant mail, working exits. The checklist also travels: when a lead generation service sends on your behalf, its compliance posture is legally yours - audit it the way you would audit your own.
What the regulators actually say
The summary above is ours. These are the lines it rests on, quoted from each regulator or statute and checked against the source when this page was built.
United States (FTC, CAN-SPAM)
"The law makes no exception for business-to-business email."FTC, CAN-SPAM compliance guide
"You must honor a recipient's opt-out request within 10 business days."FTC, CAN-SPAM compliance guide
"Your message must include your valid physical postal address."FTC, CAN-SPAM compliance guide
United Kingdom (ICO, PECR)
"You can send marketing emails or texts to companies."ICO, electronic mail marketing
"Sole traders and some partnerships are treated as individuals - so you can only email or text them if they have specifically consented"ICO, electronic mail marketing
European Union and UK (GDPR)
"The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."GDPR Recital 47 (gdpr-info.eu, unofficial reproduction)
The ICO's legitimate-interests guidance asks "Can we use legitimate interests for our business-to-business contacts?" and answers that you "must apply the three-part test". GDPR also gives the recipient "the right to object at any time to processing of personal data concerning him or her for such marketing" (Article 21), and requires "the identity and the contact details of the controller" to be given "at the latest at the time of the first communication to that data subject" (Article 14). Member-state ePrivacy rules then decide when an unsolicited email is allowed at all, which is why the checklist below treats Germany separately.
Canada (CASL)
"whether the consent is express or implied"Canada's Anti-Spam Legislation, section 6(1)(a)
Implied consent covers an electronic address the person "has conspicuously published", without saying they do not want such messages, when "the message is relevant to the person's business, role, functions or duties in a business or official capacity" (CASL, section 10(9)(b)).
Build the checklist for your markets
Tick the jurisdictions a campaign will send into and this assembles the operating checklist from the sections above: the universal posture every regime expects, plus each market's specific additions, with the strictest rule surfaced first. It restates this page's practitioner summary - it is not legal advice, and it runs entirely in your browser.
- Send as a named, findable human at a real company - honest from-line, honest subject; never from a no-reply address that cannot receive the opt-outs the law requires you to honour.
- Target on role relevance and document it.
- Make declining effortless, honour it immediately, and wire suppression into the cadence's stop rules so no follow-up ever chases a no.
- Keep records: data sources, lawful-basis reasoning, suppression lists, opt-out timestamps.
- Segment by jurisdiction and apply the local rule in each segment.
- No forged or misleading header information; from-name, sending address and reply-to identify the real sender.
- Subject line must not misrepresent the message's content.
- Include a valid physical postal address for the sender in the message.
- Identify the message as an ad, clearly and conspicuously - the FTC allows a lot of leeway in how.
- Working opt-out, exercisable easily, honoured promptly - the statute allows up to ten business days - with no fee, no login, no interrogation.
- Suppression that sticks across campaigns and vendors. Penalties assess per message and can reach five figures each.
Practitioner summary of the sections above, not legal advice; for decisions with real exposure, ask a lawyer who knows your markets.
When this page does not apply
- You need legal advice. This is a practitioner's summary with the regulators' own words attached; for decisions with real exposure, ask a lawyer who knows your markets.
- You send to consumers. Consumer email is stricter almost everywhere; the ICO, for example, treats individuals and sole traders differently from companies.
- You send outside these four regimes. Australia, other APAC markets and Latin America have their own rules; check the local regulator before sending.
- The rules changed after the date above. Regulators update guidance (the ICO marks its PECR guidance "under review and may be subject to change"); the quotes were checked on the date shown in the sources.
How this page was built and checked
The summary sections are ReplyLead's practitioner reading. The quotes are copied from the FTC's CAN-SPAM compliance guide, the ICO's PECR and legitimate-interests guidance, the text of Canada's Anti-Spam Legislation and GDPR Recital 47, and each was checked word for word against its source on 25 September 2026. The checklist tool restates the sections above and runs in your browser. ReplyLead runs cold email and LinkedIn outbound, and every programme follows these rules; see how ReplyLead runs outbound.
Common questions
Is cold emailing illegal in the US?
No. CAN-SPAM permits unsolicited commercial email, including B2B outreach, and regulates its conduct: honest identity, truthful subject, postal address, identification as an ad, working opt-out honoured promptly. Violating those rules is what is illegal.
Is cold email legal under GDPR?
It can be, and routinely is, when grounded in legitimate interest with a documented balancing test, role-relevant targeting and immediate handling of objections - with member-state ePrivacy rules layered on top. Germany and a few other states effectively require consent, so segment by country.
Do cold emails need an unsubscribe link?
They need a working opt-out mechanism. In B2B outreach a clear reply-to-decline can serve, and it must be honoured without friction; a one-click unsubscribe becomes mechanically required at bulk-sender thresholds - 5,000 messages a day to Gmail brings Google's bulk-sender rules into play.
Is buying an email list illegal?
The purchase itself is generally not the crime; sending to bought data is where the violations concentrate - consent bases you cannot document, decayed addresses, spam traps. We never send to purchased bulk lists, for compliance and deliverability reasons that happen to be the same reasons.
Sources and check dates
ReplyLead's own pages behind this one:
- GDPR at ReplyLead: how our programmes handle personal data.
- Cold email guide: the six systems of a campaign, compliance included.
- No-reply email: why a no-reply address cannot take the opt-outs the law requires.
Outside primary sources, each read on the date shown:
- FTC: CAN-SPAM Act, a compliance guide for business: no B2B exception; honest headers and subject lines; a physical postal address; opt-outs honoured within 10 business days; penalties per email. checked 25 September 2026.
- ICO: electronic mail marketing (PECR): companies may be emailed without consent; sole traders and some partnerships are treated as individuals. checked 25 September 2026.
- Canada's Anti-Spam Legislation (S.C. 2010, c. 23), full text, Justice Laws: consent express or implied; implied consent for a conspicuously published business address when the message is relevant to the role. checked 25 September 2026.
- ICO: when can we rely on legitimate interests?: UK GDPR legitimate interests for direct marketing and business-to-business contacts, and the balancing test. checked 25 September 2026.
- GDPR Recital 47 (unofficial reproduction of the official text, gdpr-info.eu): direct marketing may be regarded as a legitimate interest. checked 25 September 2026.
- FTC: CAN-SPAM Rule (16 CFR Part 316): the rule the compliance guide summarises. checked 25 September 2026.
- GDPR Article 21 (unofficial reproduction of the official text, gdpr-info.eu): the right to object at any time to direct marketing. checked 25 September 2026.
- GDPR Article 14 (unofficial reproduction of the official text, gdpr-info.eu): the sender's identity and contact details, at the latest at the first communication. checked 25 September 2026.
Compliant by construction, not by disclaimer
Named senders, role-relevant targeting, instant suppression and jurisdiction-aware segments are how every ReplyLead cold email and LinkedIn programme runs - paid mostly from revenue you close.
Our GDPR practice See the pilot