Cold Email Strategy

    Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English

    Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.

    CAN-SPAM, EU and UK privacy law, and CASL compared on consent model, enforcer, headline maximum penalty and unsubscribe deadline
    August 10, 2026Updated August 10, 20266 min read
    Share:
    The short answer

    Cold email is legal in the United States with no prior consent, provided you identify yourself, include a physical address, and honour opt-outs within 10 business days. Canada requires consent or an exemption under CASL. The EU and UK permit business-to-business outreach under legitimate interest, with rules varying by country.

    Key takeaways

    • CAN-SPAM requires no consent to send, but sets a maximum civil penalty of $53,088 per violating email following the FTC adjustment effective 17 January 2025.
    • CAN-SPAM opt-outs must be honoured within 10 business days and the opt-out mechanism must stay functional for at least 30 days after sending.
    • EU B2B cold email typically relies on legitimate interest under GDPR Article 6(1)(f), but the ePrivacy Directive is implemented per country and Germany generally expects consent even between businesses.
    • The UK Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global turnover, in force from 5 February 2026.
    • In January 2026 the ICO fined Allay Claims £120,000 for over 4 million unlawful marketing texts and ZMLUK £105,000 for over 67 million emails sent without valid consent.
    • CASL maximum penalties are $1 million for an individual and $10 million for any other person, and the burden of proving consent sits with the sender.

    Reviewed and updated August 10, 2026

    Yes, in most places, if you do specific things. Cold email is legal in the United States without any prior consent. It is legal in Canada only with consent or a qualifying exemption. It is legal for business contacts across most of the EU and the UK under legitimate interest, with real exceptions by country.

    The rules are not complicated. They are just three different rulebooks that people try to satisfy with one process.

    This is not legal advice. It is an operator's summary of published law and regulator guidance. If you are running outbound at scale into regulated markets, have counsel review your process.

    The three regimes at a glance

    United States (CAN-SPAM)EU and UK (GDPR, ePrivacy, PECR)Canada (CASL)
    Consent modelOpt-out. No consent needed to send.Legitimate interest for business contacts, with country variationOpt-in. Consent required unless an exemption applies.
    Who enforcesFederal Trade CommissionNational data protection authorities; the ICO in the UKCRTC, with the Competition Bureau and Privacy Commissioner
    Headline maximum$53,088 per violating emailUp to 20 million euro or 4% of global turnover under GDPR; up to £17.5 million or 4% under UK PECR$1 million for an individual, $10 million for any other person
    Unsubscribe deadline10 business daysWithout undue delay10 business days

    United States: CAN-SPAM

    CAN-SPAM is the most permissive of the three. It does not require consent, it does not distinguish B2B from B2C, and it does not ban cold email. It regulates how you send.

    The FTC's requirements:

    1. No false or misleading header information. From, To, Reply-To, and routing data must accurately identify the sender.
    2. No deceptive subject lines. The subject must reflect the content.
    3. Identify the message as an advertisement, clearly and conspicuously.
    4. Include your valid physical postal address.
    5. Include a clear and conspicuous explanation of how to opt out of future marketing email.
    6. Honour opt-out requests within 10 business days.
    7. Keep the opt-out mechanism working for at least 30 days after the message is sent.

    You are also responsible for what a vendor sends on your behalf. Hiring an agency does not transfer liability.

    Penalties. The maximum civil penalty is $53,088 per violating email, following the FTC's inflation adjustment effective 17 January 2025. Read that as per email, not per campaign. A 1,000-address send with a broken unsubscribe link is theoretically a nine-figure exposure, which is why the FTC's actual settlements are negotiated rather than calculated.

    The practical takeaway: a compliant US cold email needs a real physical address, a working opt-out, an honest subject line, and a suppression process that runs inside ten business days. That is achievable in a template.

    European Union: GDPR plus ePrivacy

    Two laws stack here, and skipping the second is the usual mistake.

    GDPR governs whether you may process someone's personal data. A work email address that identifies a person is personal data. The lawful basis most B2B senders rely on is legitimate interest under Article 6(1)(f), and Recital 47 explicitly names direct marketing as a possible legitimate interest. Relying on it means documenting a legitimate interest assessment: your purpose, why the processing is necessary, and why it does not override the recipient's rights. You also owe transparency (a privacy notice the recipient can reach), the right to object, and the right of access and erasure.

    The ePrivacy Directive governs whether you may send an unsolicited electronic message at all, and it is implemented separately by each member state. Article 13(5) lets member states decide how far protections extend to legal persons, meaning companies. Most states carved out room for B2B messaging on that basis. Some did not, and Germany is the strict end of the range: consent is generally expected even between businesses. France and several others are more permissive for corporate addresses.

    There is no single EU answer. A message that is lawful in one member state can be unlawful in another, which means country-level segmentation rather than an EU-wide send.

    Penalties. GDPR Article 83 sets two tiers: up to 10 million euro or 2 percent of worldwide annual turnover, and up to 20 million euro or 4 percent for breaches of core principles and data subject rights, whichever is higher in each case.

    United Kingdom: PECR and the corporate subscriber exemption

    The UK kept a version of the ePrivacy rules in PECR, and its most useful feature for outbound is the corporate subscriber exemption. PECR's consent requirement for unsolicited marketing email applies to individual subscribers, meaning people contacted in a personal capacity. Email to a corporate subscriber, which covers limited companies, LLPs, and Scottish partnerships, generally falls outside that consent requirement. Sole traders and most partnerships are treated as individual subscribers, so they are not covered by the exemption.

    UK GDPR still applies on top: lawful basis, transparency, and the right to object do not go away.

    Penalties changed recently and significantly. The Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global annual turnover, whichever is higher, with those provisions commencing 5 February 2026.

    Enforcement is real but has concentrated on high-volume consumer marketing. In January 2026 the ICO fined two companies £225,000 between them: £120,000 against Allay Claims Ltd for more than 4 million unlawful marketing texts, and £105,000 against ZMLUK Limited for more than 67 million marketing emails sent without valid consent.

    Canada: CASL

    CASL inverts the default. You need consent, express or implied, before sending a commercial electronic message to a Canadian recipient, and the burden of proving it sits with you.

    Implied consent covers conspicuously published business addresses (with conditions), and existing business relationships within defined windows. There is also a business-to-business exemption, which is narrower than it sounds. Maximum penalties are $1 million for an individual and $10 million for any other person, per violation.

    CASL deserves its own read because the exemptions are where the detail lives. See CASL compliance for cold email for the full breakdown.

    An operating standard that satisfies all three

    Six operating rules that clear the strictest requirement in each regime, from targeting roles to segmenting by jurisdiction

    Rather than maintaining three processes, run one that clears the highest bar in each dimension:

    • Target roles, not people at home. Business addresses, business-relevant messages, no consumer domains.
    • Identify yourself honestly. Real sender name, real company, real physical address, accurate subject line.
    • One-click opt-out in every message, working for at least 60 days after send, honoured within 10 business days at the absolute latest and same-day in practice.
    • Suppress permanently and globally. An unsubscribe from one campaign suppresses across every campaign and every domain you own.
    • Document your basis. A legitimate interest assessment for EU and UK contacts; consent or exemption evidence for Canadian contacts.
    • Segment by jurisdiction before you send, not after a complaint.
    • Keep records. CASL in particular puts the evidentiary burden on the sender.

    Where people actually get caught

    Not on the technicalities of legitimate interest. On purchased consumer lists, missing physical addresses, unsubscribe links that fail, suppression that does not carry across campaigns, and sending into strict jurisdictions with a process built for CAN-SPAM.

    Compliance and deliverability pull in the same direction here. The behaviours that keep regulators away (accurate identity, honest subjects, easy opt-out, no consumer addresses) are the same behaviours that keep complaint rates low, and complaint rate is what Google Postmaster Tools measures and what spam rate benchmarks track. Pair this with correct authentication records, proper list verification so you are not mailing dead addresses, and the fundamentals in the deliverability guide. If sending is already failing, check your blacklist status first.

    Want outbound run on a process that clears all three regimes? Get a free campaign plan and we will walk through how the compliance layer is built.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Do I need permission before sending a cold email in the United States?
    No. CAN-SPAM is an opt-out law, so you may send commercial email to someone who never asked for it. What you must do is use accurate header information and subject lines, disclose that the message is an advertisement, include a valid physical postal address, provide a working opt-out, and honour opt-out requests within 10 business days.
    Is cold email allowed under GDPR?
    Business-to-business cold email is generally permitted using legitimate interest as the lawful basis under Article 6(1)(f), with direct marketing named in Recital 47. The complication is the ePrivacy Directive, implemented differently by each member state. Some countries protect corporate addresses lightly, others require consent, so segment your sends by country.
    What is the fine for violating CAN-SPAM?
    Up to $53,088 per violating email, set by the FTC's inflation adjustment effective 17 January 2025. The figure is per message rather than per campaign, so a single non-compliant send to a large list carries theoretical exposure far beyond what the FTC typically settles for in practice.
    Can I cold email UK businesses without consent?
    Usually yes. PECR's consent requirement for marketing email applies to individual subscribers, and email to corporate subscribers such as limited companies, LLPs, and Scottish partnerships generally falls outside it. Sole traders and most partnerships count as individual subscribers, so they are not covered. UK GDPR obligations still apply on top.
    What happens if someone unsubscribes from one campaign but not another?
    Treat every unsubscribe as global. Suppress the address across every campaign, every sending domain, and every brand you operate. Regulators and mailbox providers both look at whether the person kept receiving mail, not at which campaign sent it. A per-campaign suppression list is the most common avoidable compliance failure.
    Cold EmailComplianceCAN-SPAMGDPRCASLEmail Law
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.