Home / Cold Email Guide / Is Cold Email Legal
ComplianceIs cold email legal?
Updated August 2026 // by Mark Glazer // compliance is a checklist, not a vibe
Yes - B2B cold email is legal in most major jurisdictions, with conditions. The United States permits it under CAN-SPAM without prior consent, provided identity is honest and opt-outs are honoured. In the EU and UK it is lawful when properly grounded - for B2B, typically legitimate interest - with member-state rules varying. Canada's CASL is the strictest mainstream regime and turns on consent, express or implied.
This page is a practitioner's summary of how the rules apply to business-to-business outreach, not legal advice; for decisions with real exposure, ask a lawyer who knows your markets.
United States: CAN-SPAM
CAN-SPAM governs commercial email in the US and is an opt-out regime: you may email a business contact without prior permission, and the law regulates how. The operative requirements:
- Honest routing and identity. From-name, sending address and reply-to must identify the real sender - no forged or misleading header information.
- Truthful subject lines. The subject cannot misrepresent the message's content.
- A valid physical postal address for the sender in the message.
- A working opt-out that a recipient can exercise easily, honoured promptly - the statute allows up to ten business days - with no fee, no login and no interrogation.
- Suppression that sticks. Once someone opts out, they stay out, across your campaigns and your vendors.
Penalties are assessed per non-compliant message and reach five figures each, so violations price in fast at outbound volume. Note what CAN-SPAM does not require: prior consent, or that outreach be B2B - but the honest-identity and opt-out machinery is mandatory for everyone.
European Union: GDPR and the ePrivacy layer
GDPR regulates the personal data behind the email - a work address that identifies a person, such as dana.smith@company.com, is personal data. Sending requires a lawful basis, and for B2B outreach the commonly used one is legitimate interest: a documented balancing of your interest in reaching a relevant business contact against that person's rights. In practice that means targeting people whose role makes the message genuinely relevant, saying where their data came from when asked, honouring objections immediately, and keeping records of the reasoning.
Layered on top, the ePrivacy rules as implemented by each member state decide when unsolicited email itself is permitted - and this is where the map gets uneven. Several states distinguish corporate from individual subscribers; others, Germany prominent among them, effectively require consent for email marketing under national competition law, making cold email to German recipients a materially higher-risk activity. The UK's PECR follows the corporate-subscriber pattern: mail to limited companies' work addresses sits outside the strict consent rule that protects individuals and sole traders, while GDPR duties still apply. The operational consequence is unglamorous but simple: segment by country, and apply the strictest rule in each segment. Our own GDPR practice is documented on the GDPR page.
Canada: CASL
CASL is consent-based and the strictest regime most senders will meet. Commercial electronic messages require express consent (asked for and given) or implied consent, which for B2B most relevantly arises when a recipient's address was conspicuously published or provided, without a statement declining unsolicited messages, and the message is relevant to the recipient's business role. Every message must identify the sender, include contact information and carry a working unsubscribe. The practical posture for Canadian segments: rely on the conspicuous-publication basis only with documented relevance to the role, keep evidence of where each address came from, and suppress aggressively.
The checklist that satisfies all three
Regimes differ at the edges; the compliant operating posture is nearly universal:
- Send as a named, findable human at a real company - honest from-line, honest subject, physical address present. Never from a no-reply address that cannot receive the very opt-outs the law requires you to honour.
- Target on role relevance and document it - the same discipline that makes a list convert is the discipline regulators ask about.
- Make declining effortless, honour it immediately, and wire suppression into the cadence's stop rules so no follow-up ever chases a no.
- Segment by jurisdiction and apply the local rule - consent-first where national law demands it.
- Keep records: data sources, lawful-basis reasoning, suppression lists, opt-out timestamps.
None of this is burdensome, and all of it overlaps with what deliverability demands anyway - the law and the inbox providers are converging on the same standard: honest senders, relevant mail, working exits. The checklist also travels: when a lead generation service sends on your behalf, its compliance posture is legally yours - audit it the way you would audit your own.
Common questions
Is cold emailing illegal in the US?
No. CAN-SPAM permits unsolicited commercial email, including B2B outreach, and regulates its conduct: honest identity, truthful subject, postal address, working opt-out honoured promptly. Violating those rules is what is illegal.
Is cold email legal under GDPR?
It can be, and routinely is, when grounded in legitimate interest with a documented balancing test, role-relevant targeting and immediate handling of objections - with member-state ePrivacy rules layered on top. Germany and a few other states effectively require consent, so segment by country.
Do cold emails need an unsubscribe link?
They need a working opt-out mechanism. In B2B outreach a clear reply-to-decline can serve, and it must be honoured without friction; a one-click unsubscribe becomes mechanically required at bulk-sender thresholds - 5,000 messages a day to Gmail brings Google's bulk-sender rules into play.
Is buying an email list illegal?
The purchase itself is generally not the crime; sending to bought data is where the violations concentrate - consent bases you cannot document, decayed addresses, spam traps. We never send to purchased bulk lists, for compliance and deliverability reasons that happen to be the same reasons.
Compliant by construction, not by disclaimer
Named senders, role-relevant targeting, instant suppression and jurisdiction-aware segments are how every ReplyLead programme runs - paid mostly from revenue you close.
Our GDPR practice See the pilot