Is Cold Email Legal? CAN-SPAM, GDPR and CASL
Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.

Cold email is legal in the United States with no prior consent, provided you identify yourself, include a physical address, and honour opt-outs within 10 business days. Canada requires consent or an exemption under CASL. The EU and UK permit business-to-business outreach under legitimate interest, with rules varying by country.
Key takeaways
- CAN-SPAM requires no consent to send, but sets a maximum civil penalty of $53,088 per violating email following the FTC adjustment effective 17 January 2025.
- CAN-SPAM opt-outs must be honoured within 10 business days and the opt-out mechanism must stay functional for at least 30 days after sending.
- EU B2B cold email typically relies on legitimate interest under GDPR Article 6(1)(f), but the ePrivacy Directive is implemented per country and Germany generally expects consent even between businesses.
- The UK Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global turnover, in force from 5 February 2026.
- In January 2026 the ICO fined Allay Claims £120,000 for over 4 million unlawful marketing texts and ZMLUK £105,000 for over 67 million emails sent without valid consent.
- CASL maximum penalties are $1 million for an individual and $10 million for any other person, and the burden of proving consent sits with the sender.
Reviewed and updated September 5, 2026
Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English
Yes, in most places, if you do specific things. Cold email is legal in the United States without any prior consent. It is legal in Canada only with consent or a qualifying exemption. It is legal for business contacts across most of the EU and the UK under legitimate interest, with real exceptions by country.
The rules are not complicated. They are just three different rulebooks that people try to satisfy with one process.
Asked the other way round, is cold email illegal, the answer is the same and the exceptions are where it lives: unsolicited business email is not illegal in the United States, it becomes illegal when it lacks the things below, and in Canada it is illegal by default until an exemption applies.
This is not legal advice. It is an operator's summary of published law and regulator guidance. If you are running outbound at scale into regulated markets, have counsel review your process.
If you are reading this as one of the professional-services firms it is written for, the persona-specific version of this playbook lives in our guide to outbound for professional-services firms.
The three regimes at a glance
| United States (CAN-SPAM) | EU and UK (GDPR, ePrivacy, PECR) | Canada (CASL) | |
|---|---|---|---|
| Consent model | Opt-out. No consent needed to send. | Legitimate interest for business contacts, with country variation | Opt-in. Consent required unless an exemption applies. |
| Who enforces | Federal Trade Commission | National data protection authorities; the ICO in the UK | CRTC, with the Competition Bureau and Privacy Commissioner |
| Headline maximum | $53,088 per violating email | Up to 20 million euro or 4% of global turnover under GDPR; up to £17.5 million or 4% under UK PECR | $1 million for an individual, $10 million for any other person |
| Unsubscribe deadline | 10 business days | Without undue delay | 10 business days |
United States: CAN-SPAM
The transactional exemption is the one people reach for by mistake: a receipt, a password reset or a shipping notice is exempt from the opt-out requirement because it serves an existing relationship, and cold outbound is by definition not that, so the exemption never reaches it.
CAN-SPAM is the most permissive of the three. It does not require consent, it does not distinguish B2B from B2C, and it does not ban cold email. It regulates how you send.
The FTC's requirements:
- No false or misleading header information. From, To, Reply-To, and routing data must accurately identify the sender.
- No deceptive subject lines. The subject must reflect the content.
- Identify the message as an advertisement, clearly and conspicuously.
- Include your valid physical postal address.
- Include a clear and conspicuous explanation of how to opt out of future marketing email.
- Honour opt-out requests within 10 business days.
- Keep the opt-out mechanism working for at least 30 days after the message is sent.
You are also responsible for what a vendor sends on your behalf. Hiring an agency does not transfer liability.
Penalties. The maximum civil penalty is $53,088 per violating email, following the FTC's inflation adjustment effective 17 January 2025. Read that as per email, not per campaign. A 1,000-address send with a broken unsubscribe link is theoretically a nine-figure exposure, which is why the FTC's actual settlements are negotiated rather than calculated.
The practical takeaway: a compliant US cold email needs a real physical address, a working opt-out, an honest subject line, and a suppression process that runs inside ten business days. That is achievable in a template.
European Union: GDPR plus ePrivacy

Two laws stack here, and skipping the second is the usual mistake.
GDPR governs whether you may process someone's personal data. A work email address that identifies a person is personal data. The lawful basis most B2B senders rely on is legitimate interest under Article 6(1)(f), and Recital 47 explicitly names direct marketing as a possible legitimate interest. Relying on it means documenting a legitimate interest assessment: your purpose, why the processing is necessary, and why it does not override the recipient's rights. You also owe transparency (a privacy notice the recipient can reach), the right to object, and the right of access and erasure.
The ePrivacy Directive governs whether you may send an unsolicited electronic message at all, and it is implemented separately by each member state. Article 13(5) lets member states decide how far protections extend to legal persons, meaning companies. Most states carved out room for B2B messaging on that basis. Some did not, and Germany is the strict end of the range: consent is generally expected even between businesses. France and several others are more permissive for corporate addresses.
There is no single EU answer. A message that is lawful in one member state can be unlawful in another, which means country-level segmentation rather than an EU-wide send.
Penalties. GDPR Article 83 sets two tiers: up to 10 million euro or 2 percent of worldwide annual turnover, and up to 20 million euro or 4 percent for breaches of core principles and data subject rights, whichever is higher in each case.
United Kingdom: PECR and the corporate subscriber exemption
The UK kept a version of the ePrivacy rules in PECR, and its most useful feature for outbound is the corporate subscriber exemption. PECR's consent requirement for unsolicited marketing email applies to individual subscribers, meaning people contacted in a personal capacity. Email to a corporate subscriber, which covers limited companies, LLPs, and Scottish partnerships, generally falls outside that consent requirement. Sole traders and most partnerships are treated as individual subscribers, so they are not covered by the exemption.
UK GDPR still applies on top: lawful basis, transparency, and the right to object do not go away.
Penalties changed recently and significantly. The Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4 percent of global annual turnover, whichever is higher, with those provisions commencing 5 February 2026.
Enforcement is real but has concentrated on high-volume consumer marketing. In January 2026 the ICO fined two companies £225,000 between them: £120,000 against Allay Claims Ltd for more than 4 million unlawful marketing texts, and £105,000 against ZMLUK Limited for more than 67 million marketing emails sent without valid consent.
Canada: CASL

CASL inverts the default. You need consent, express or implied, before sending a commercial electronic message to a Canadian recipient, and the burden of proving it sits with you.
Implied consent covers conspicuously published business addresses (with conditions), and existing business relationships within defined windows. There is also a business-to-business exemption, which is narrower than it sounds. Maximum penalties are $1 million for an individual and $10 million for any other person, per violation.
CASL deserves its own read because the exemptions are where the detail lives. See CASL compliance for cold email for the full breakdown.
An operating standard that satisfies all three

Rather than maintaining three processes, run one that clears the highest bar in each dimension:
- Target roles, not people at home. Business addresses, business-relevant messages, no consumer domains.
- Identify yourself honestly. Real sender name, real company, real physical address, accurate subject line.
- One-click opt-out in every message, working for at least 60 days after send, honoured within 10 business days at the absolute latest and same-day in practice.
- Suppress permanently and globally. An unsubscribe from one campaign suppresses across every campaign and every domain you own.
- Document your basis. A legitimate interest assessment for EU and UK contacts; consent or exemption evidence for Canadian contacts.
- Segment by jurisdiction before you send, not after a complaint.
- Keep records. CASL in particular puts the evidentiary burden on the sender.
Where people actually get caught
- No: Purchased consumer lists
- No: Missing physical addresses
- No: Unsubscribe links that fail
- No: Suppression that does not carry across campaigns
- No: Sending into strict jurisdictions with a process built for CAN-SPAM
Not on the technicalities of legitimate interest. On purchased consumer lists, missing physical addresses, unsubscribe links that fail, suppression that does not carry across campaigns, and sending into strict jurisdictions with a process built for CAN-SPAM.
Compliance and deliverability pull in the same direction here. The behaviours that keep regulators away (accurate identity, honest subjects, easy opt-out, no consumer addresses) are the same behaviours that keep complaint rates low, and complaint rate is what Google Postmaster Tools measures and what spam rate benchmarks track. Pair this with correct authentication records, proper list verification so you are not mailing dead addresses, and the fundamentals in the deliverability guide. If sending is already failing, check your blacklist status first.
Want outbound run on a process that clears all three regimes? Get a free campaign plan and we will walk through how the compliance layer is built.
Frequently asked questions.
Frequently asked questions- Do I need permission before sending a cold email in the United States?
- No. CAN-SPAM is an opt-out law, so you may send commercial email to someone who never asked for it. What you must do is use accurate header information and subject lines, disclose that the message is an advertisement, include a valid physical postal address, provide a working opt-out, and honour opt-out requests within 10 business days.
- Is cold email allowed under GDPR?
- Business-to-business cold email is generally permitted using legitimate interest as the lawful basis under Article 6(1)(f), with direct marketing named in Recital 47. The complication is the ePrivacy Directive, implemented differently by each member state. Some countries protect corporate addresses lightly, others require consent, so segment your sends by country.
- What is the fine for violating CAN-SPAM?
- Up to $53,088 per violating email, set by the FTC's inflation adjustment effective 17 January 2025. The figure is per message rather than per campaign, so a single non-compliant send to a large list carries theoretical exposure far beyond what the FTC typically settles for in practice.
- Can I cold email UK businesses without consent?
- Usually yes. PECR's consent requirement for marketing email applies to individual subscribers, and email to corporate subscribers such as limited companies, LLPs, and Scottish partnerships generally falls outside it. Sole traders and most partnerships count as individual subscribers, so they are not covered. UK GDPR obligations still apply on top.
- What happens if someone unsubscribes from one campaign but not another?
- Treat every unsubscribe as global. Suppress the address across every campaign, every sending domain, and every brand you operate. Regulators and mailbox providers both look at whether the person kept receiving mail, not at which campaign sent it. A per-campaign suppression list is the most common avoidable compliance failure.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
CASL Compliance for Cold Email: What Canadian Law Requires
Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.
CAN-SPAM Act Compliance for B2B Cold Email: The Rules
The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.
Transactional Email: The Class That Needs Its Own Domain
A transactional email is triggered by the recipient's own action and expected by them. The reason it needs separating from marketing and cold mail is reputation.
Cold Email in HubSpot: What Its Anti-Spam Policy Says
Whether HubSpot can send cold email is a feature question. What it permits is a contract question, and HubSpot answers it in writing on a page most buyers never open.
How to Write a New Year Outreach Email, Line by Line
A new year outreach email works only where January is a fact about the account. Who that is, the structure line by line, and two worked examples.
How to Write a Third Follow Up Email, Line by Line
A third follow up email belongs only in a thread where the person replied or agreed to something. When to send one, and how to write it line by line.