Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English
Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.

Cold email is legal in the United States with no prior consent, provided you identify yourself, include a physical address, and honour opt-outs within 10 business days. Canada requires consent or an exemption under CASL. The EU and UK permit business-to-business outreach under legitimate interest, with rules varying by country.
Key takeaways
- CAN-SPAM requires no consent to send, but sets a maximum civil penalty of $53,088 per violating email following the FTC adjustment effective 17 January 2025.
- CAN-SPAM opt-outs must be honoured within 10 business days and the opt-out mechanism must stay functional for at least 30 days after sending.
- EU B2B cold email typically relies on legitimate interest under GDPR Article 6(1)(f), but the ePrivacy Directive is implemented per country and Germany generally expects consent even between businesses.
- The UK Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global turnover, in force from 5 February 2026.
- In January 2026 the ICO fined Allay Claims £120,000 for over 4 million unlawful marketing texts and ZMLUK £105,000 for over 67 million emails sent without valid consent.
- CASL maximum penalties are $1 million for an individual and $10 million for any other person, and the burden of proving consent sits with the sender.
Reviewed and updated August 10, 2026
Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English
Yes, in most places, if you do specific things. Cold email is legal in the United States without any prior consent. It is legal in Canada only with consent or a qualifying exemption. It is legal for business contacts across most of the EU and the UK under legitimate interest, with real exceptions by country.
The rules are not complicated. They are just three different rulebooks that people try to satisfy with one process.
This is not legal advice. It is an operator's summary of published law and regulator guidance. If you are running outbound at scale into regulated markets, have counsel review your process.
The three regimes at a glance
| United States (CAN-SPAM) | EU and UK (GDPR, ePrivacy, PECR) | Canada (CASL) | |
|---|---|---|---|
| Consent model | Opt-out. No consent needed to send. | Legitimate interest for business contacts, with country variation | Opt-in. Consent required unless an exemption applies. |
| Who enforces | Federal Trade Commission | National data protection authorities; the ICO in the UK | CRTC, with the Competition Bureau and Privacy Commissioner |
| Headline maximum | $53,088 per violating email | Up to 20 million euro or 4% of global turnover under GDPR; up to £17.5 million or 4% under UK PECR | $1 million for an individual, $10 million for any other person |
| Unsubscribe deadline | 10 business days | Without undue delay | 10 business days |
United States: CAN-SPAM
CAN-SPAM is the most permissive of the three. It does not require consent, it does not distinguish B2B from B2C, and it does not ban cold email. It regulates how you send.
The FTC's requirements:
- No false or misleading header information. From, To, Reply-To, and routing data must accurately identify the sender.
- No deceptive subject lines. The subject must reflect the content.
- Identify the message as an advertisement, clearly and conspicuously.
- Include your valid physical postal address.
- Include a clear and conspicuous explanation of how to opt out of future marketing email.
- Honour opt-out requests within 10 business days.
- Keep the opt-out mechanism working for at least 30 days after the message is sent.
You are also responsible for what a vendor sends on your behalf. Hiring an agency does not transfer liability.
Penalties. The maximum civil penalty is $53,088 per violating email, following the FTC's inflation adjustment effective 17 January 2025. Read that as per email, not per campaign. A 1,000-address send with a broken unsubscribe link is theoretically a nine-figure exposure, which is why the FTC's actual settlements are negotiated rather than calculated.
The practical takeaway: a compliant US cold email needs a real physical address, a working opt-out, an honest subject line, and a suppression process that runs inside ten business days. That is achievable in a template.
European Union: GDPR plus ePrivacy
Two laws stack here, and skipping the second is the usual mistake.
GDPR governs whether you may process someone's personal data. A work email address that identifies a person is personal data. The lawful basis most B2B senders rely on is legitimate interest under Article 6(1)(f), and Recital 47 explicitly names direct marketing as a possible legitimate interest. Relying on it means documenting a legitimate interest assessment: your purpose, why the processing is necessary, and why it does not override the recipient's rights. You also owe transparency (a privacy notice the recipient can reach), the right to object, and the right of access and erasure.
The ePrivacy Directive governs whether you may send an unsolicited electronic message at all, and it is implemented separately by each member state. Article 13(5) lets member states decide how far protections extend to legal persons, meaning companies. Most states carved out room for B2B messaging on that basis. Some did not, and Germany is the strict end of the range: consent is generally expected even between businesses. France and several others are more permissive for corporate addresses.
There is no single EU answer. A message that is lawful in one member state can be unlawful in another, which means country-level segmentation rather than an EU-wide send.
Penalties. GDPR Article 83 sets two tiers: up to 10 million euro or 2 percent of worldwide annual turnover, and up to 20 million euro or 4 percent for breaches of core principles and data subject rights, whichever is higher in each case.
United Kingdom: PECR and the corporate subscriber exemption
The UK kept a version of the ePrivacy rules in PECR, and its most useful feature for outbound is the corporate subscriber exemption. PECR's consent requirement for unsolicited marketing email applies to individual subscribers, meaning people contacted in a personal capacity. Email to a corporate subscriber, which covers limited companies, LLPs, and Scottish partnerships, generally falls outside that consent requirement. Sole traders and most partnerships are treated as individual subscribers, so they are not covered by the exemption.
UK GDPR still applies on top: lawful basis, transparency, and the right to object do not go away.
Penalties changed recently and significantly. The Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global annual turnover, whichever is higher, with those provisions commencing 5 February 2026.
Enforcement is real but has concentrated on high-volume consumer marketing. In January 2026 the ICO fined two companies £225,000 between them: £120,000 against Allay Claims Ltd for more than 4 million unlawful marketing texts, and £105,000 against ZMLUK Limited for more than 67 million marketing emails sent without valid consent.
Canada: CASL
CASL inverts the default. You need consent, express or implied, before sending a commercial electronic message to a Canadian recipient, and the burden of proving it sits with you.
Implied consent covers conspicuously published business addresses (with conditions), and existing business relationships within defined windows. There is also a business-to-business exemption, which is narrower than it sounds. Maximum penalties are $1 million for an individual and $10 million for any other person, per violation.
CASL deserves its own read because the exemptions are where the detail lives. See CASL compliance for cold email for the full breakdown.
An operating standard that satisfies all three

Rather than maintaining three processes, run one that clears the highest bar in each dimension:
- Target roles, not people at home. Business addresses, business-relevant messages, no consumer domains.
- Identify yourself honestly. Real sender name, real company, real physical address, accurate subject line.
- One-click opt-out in every message, working for at least 60 days after send, honoured within 10 business days at the absolute latest and same-day in practice.
- Suppress permanently and globally. An unsubscribe from one campaign suppresses across every campaign and every domain you own.
- Document your basis. A legitimate interest assessment for EU and UK contacts; consent or exemption evidence for Canadian contacts.
- Segment by jurisdiction before you send, not after a complaint.
- Keep records. CASL in particular puts the evidentiary burden on the sender.
Where people actually get caught
Not on the technicalities of legitimate interest. On purchased consumer lists, missing physical addresses, unsubscribe links that fail, suppression that does not carry across campaigns, and sending into strict jurisdictions with a process built for CAN-SPAM.
Compliance and deliverability pull in the same direction here. The behaviours that keep regulators away (accurate identity, honest subjects, easy opt-out, no consumer addresses) are the same behaviours that keep complaint rates low, and complaint rate is what Google Postmaster Tools measures and what spam rate benchmarks track. Pair this with correct authentication records, proper list verification so you are not mailing dead addresses, and the fundamentals in the deliverability guide. If sending is already failing, check your blacklist status first.
Want outbound run on a process that clears all three regimes? Get a free campaign plan and we will walk through how the compliance layer is built.
Frequently asked questions.
Frequently asked questions- Do I need permission before sending a cold email in the United States?
- No. CAN-SPAM is an opt-out law, so you may send commercial email to someone who never asked for it. What you must do is use accurate header information and subject lines, disclose that the message is an advertisement, include a valid physical postal address, provide a working opt-out, and honour opt-out requests within 10 business days.
- Is cold email allowed under GDPR?
- Business-to-business cold email is generally permitted using legitimate interest as the lawful basis under Article 6(1)(f), with direct marketing named in Recital 47. The complication is the ePrivacy Directive, implemented differently by each member state. Some countries protect corporate addresses lightly, others require consent, so segment your sends by country.
- What is the fine for violating CAN-SPAM?
- Up to $53,088 per violating email, set by the FTC's inflation adjustment effective 17 January 2025. The figure is per message rather than per campaign, so a single non-compliant send to a large list carries theoretical exposure far beyond what the FTC typically settles for in practice.
- Can I cold email UK businesses without consent?
- Usually yes. PECR's consent requirement for marketing email applies to individual subscribers, and email to corporate subscribers such as limited companies, LLPs, and Scottish partnerships generally falls outside it. Sole traders and most partnerships count as individual subscribers, so they are not covered. UK GDPR obligations still apply on top.
- What happens if someone unsubscribes from one campaign but not another?
- Treat every unsubscribe as global. Suppress the address across every campaign, every sending domain, and every brand you operate. Regulators and mailbox providers both look at whether the person kept receiving mail, not at which campaign sent it. A per-campaign suppression list is the most common avoidable compliance failure.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
CASL Compliance for Cold Email: What Canadian Law Actually Requires
Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.
Email Blacklist Check and Recovery: How to Delist and Stay Off
How to check Spamhaus, Barracuda, and Microsoft for a listing, the exact delisting path for each, and the sending habits that prevent a second listing.