Cold email is legal in 2026 in the US, EU, UK, Australia, and most B2B markets - provided you follow the applicable regulations. The frameworks vary significantly by country: CAN-SPAM in the US does not require prior consent, GDPR allows cold email to business contacts under legitimate interest, and CASL in Canada is the outlier requiring implied or express consent. This guide breaks down each framework in plain terms so you can run compliant B2B cold outreach without needing a lawyer on retainer.
Short answer: Cold email is legal in the US under CAN-SPAM (no prior consent required), legal in the EU/UK under GDPR (legitimate interest basis for B2B), and strictly regulated in Canada under CASL (requires implied or express consent before sending). The practical minimum compliance checklist is: accurate sender info, a physical address, a working unsubscribe mechanism, and a genuine business reason for contacting the recipient. Most B2B cold outreach that is properly targeted and includes these elements is legal everywhere except Canada without prior consent.
Short Answer: Is Cold Email Legal?
Yes, with conditions. The short version:
- United States (CAN-SPAM): Legal without prior consent. You must include accurate sender info, a physical address, and a working unsubscribe mechanism. No prior opt-in required.
- European Union (GDPR): Legal for B2B under legitimate interest. Your outreach must be relevant to the recipient's professional role, you must process data minimally, and you must include an opt-out. Consent is not typically required for genuine B2B outreach.
- United Kingdom (UK GDPR + PECR): Similar to EU GDPR for business contacts. PECR (Privacy and Electronic Communications Regulations) adds requirements for marketing communications to individuals, but B2B cold email to professional email addresses is generally covered by legitimate interest.
- Canada (CASL): Strictest major framework. Requires implied or express consent before sending. Implied consent exists in specific circumstances (existing business relationship, published contact info). Express consent is best obtained explicitly.
- Australia (Spam Act 2003): Legal with consent or inferred consent (when the address is publicly published in a context consistent with receiving business messages) plus a functional unsubscribe mechanism. B2B cold email to published professional addresses is generally covered.
The takeaway: cold email is a legitimate B2B acquisition channel that millions of companies use every day. The law does not prohibit it - it regulates it. Knowing the rules takes an afternoon. Violating them takes a legal bill or a domain blacklist.
CAN-SPAM (United States): Most Permissive Framework
The CAN-SPAM Act governs commercial email in the United States. Despite what its name implies, CAN-SPAM does not prohibit commercial email - it sets conditions for sending it legally. Key requirements:
- No prior consent required. Unlike GDPR or CASL, CAN-SPAM does not require the recipient to have opted in before you send them a commercial email. You can cold email any business contact in the US without prior permission.
- Accurate header information. The "From", "To", "Reply-To", and routing information must accurately identify the person or business that sent the message. No spoofed addresses.
- No deceptive subject lines. The subject line must reflect the content of the email. A subject line that bears no relationship to the message content is a CAN-SPAM violation.
- Identify the message as an advertisement. Required if it is promotional - though this requirement is satisfied by the content context in most cases.
- Include a physical postal address. Either a street address, a PO Box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency. This must appear in the email body.
- Clear unsubscribe mechanism. Must include a way for recipients to opt out of future messages. The mechanism must remain active for at least 30 days after sending, and opt-out requests must be honored within 10 business days.
- Honor opt-out requests promptly. Once someone opts out, you cannot send them commercial email again. This applies organization-wide, not just to one campaign.
Penalty for violations: up to $50,120 per email per violation. In practice, enforcement actions target spammers and repeat offenders, not businesses running targeted B2B outreach with proper unsubscribe links. The practical risk for compliant senders is low - the reputational and deliverability risk of non-compliance is higher than the legal risk in most cases.
CAN-SPAM compliance minimum: accurate sender name + physical address in footer + working one-click unsubscribe. Most email sending platforms (including ACA) generate compliant footers automatically. If you are running cold email manually from Gmail, you need to add this yourself. A simple text block in the signature covers all three requirements.
GDPR (EU and UK): Legitimate Interest Is Your Basis
GDPR applies to any organization sending email to individuals located in the EU or UK, regardless of where the sender is based. This is the framework that makes most non-European B2B senders nervous, often unnecessarily.
The key concept is legitimate interest as a legal basis for processing personal data. Under GDPR Article 6(1)(f), you can process personal data (including professional email addresses) when you have a legitimate interest in doing so, as long as that interest is not overridden by the data subject's interests or fundamental rights.
For B2B cold email, this means:
- The contact must be a professional. You are reaching out to them in their capacity as an employee, executive, or business owner - not as a private individual. This is why GDPR treats B2B and B2C cold email differently.
- The message must be relevant to their professional role. A SaaS founder selling outreach software emailing the VP of Sales at a tech company has a plausible legitimate interest. Emailing the same VP about unrelated consumer products does not.
- Data minimization applies. Collect and process only what you need for the outreach. Do not run extensive profiling on the contact beyond what is necessary to justify the email.
- Include an opt-out mechanism. EU recipients must be able to object to receiving future emails, and that objection must be respected immediately.
- Your privacy policy must cover this processing. If you are a data processor under GDPR (which you are if you store EU contact data), your privacy policy needs to acknowledge it.
The legitimacy test: would the recipient reasonably expect to receive this kind of message given their professional role? A cold email from a B2B software vendor to a B2B buyer in the relevant industry passes this test. Mass email blasts to scraped personal email addresses do not.
The practical compliance steps: include your company name, a physical address, a clear opt-out link, and a brief sentence indicating why you are reaching out. The GDPR purists will add a sentence like "We believe this email is relevant to your role at [company] based on [specific reason]. You can unsubscribe at any time below." This is not legally required but reduces the risk of a legitimate interest challenge.
CASL (Canada): The Strictest Framework
Canada's Anti-Spam Legislation (CASL) is the strictest major email compliance framework in any developed economy. Unlike CAN-SPAM, CASL requires some form of consent before you can send a commercial electronic message (CEM) to a Canadian recipient.
There are two types of consent under CASL:
- Express consent: The recipient explicitly opted in to receive commercial messages from you. This is the cleanest form - they signed up for something, checked a box, replied affirmatively to an outreach.
- Implied consent: Consent can be implied in specific circumstances without an explicit opt-in. The most relevant for B2B cold outreach: (1) the recipient has conspicuously published their electronic address (business cards, company website, LinkedIn) without a "do not contact" statement, and the message is relevant to their business role or function; (2) you have an existing business relationship in the past 2 years; (3) the recipient has an inquiry, application, or written contract with you in the past 6 months.
The published-address implied consent is the most commonly used basis for cold email to Canadian contacts. If a Director of Marketing has their email on their company's website and LinkedIn, and you are emailing them about a relevant B2B product, CASL likely covers it under implied consent. The key qualifier is that the message must be relevant to the role - spray-and-pray cold email to Canadian contacts without relevance is a violation.
Penalties for CASL violations are serious: up to $1 million CAD per violation for individuals, $10 million CAD per violation for organizations. CASL enforcement is real and active. If you send at volume to Canadian lists, invest in a proper consent audit before launching campaigns.
CCPA (California): What It Means for Cold Email
The California Consumer Privacy Act (CCPA) and its successor CPRA are primarily data privacy laws focused on consumer data rights, not email marketing regulations. They do not directly prohibit cold email but impose data handling obligations relevant to your outreach practice.
The CCPA applies if your organization collects personal information from California residents and meets at least one of: annual gross revenue over $25M, buys/sells/shares personal info of 100,000+ consumers/households per year, or derives 50%+ of annual revenue from selling personal information.
For most B2B cold email senders, the CCPA impact is: honor deletion requests from California contacts (if someone asks to be removed from your database, you must comply), do not sell the contact's personal data without disclosing it, and maintain a privacy policy that covers your data collection practices.
CCPA does not create a consent requirement for cold email the way CASL does. A California business contact with their email published on their company website can still be cold emailed without prior consent, provided you follow CAN-SPAM requirements and honor opt-out requests. The CCPA layer adds the deletion right on top.
Country-by-Country Quick Reference
| Country / Region | Framework | Prior consent required? | B2B cold email legal? | Key requirements |
|---|---|---|---|---|
| United States | CAN-SPAM | No | Yes | Accurate sender, physical address, working unsubscribe |
| EU (all member states) | GDPR | No (legitimate interest basis) | Yes, for B2B | Relevant to role, opt-out, data minimization |
| United Kingdom | UK GDPR + PECR | No (legitimate interest basis) | Yes, for B2B | Same as EU GDPR for business contacts |
| Canada | CASL | Yes (express or implied) | Conditional | Implied consent via published address + role relevance |
| Australia | Spam Act 2003 | Inferred consent OK | Yes, with conditions | Inferred consent for published addresses, functional unsubscribe |
| Brazil | LGPD | No (legitimate interest basis) | Yes, for B2B | Similar to GDPR; opt-out must be honored |
| India | IT Act + DPDPA | No explicit requirement for B2B | Yes, generally | Evolving regulation; basic sender accuracy and opt-out |
Legitimate interest (GDPR definition): A legal basis for processing personal data under GDPR Article 6(1)(f) that does not require consent. It applies when the data controller has a genuine, real, and present interest in processing the data, the processing is necessary for that interest, and the interest is not overridden by the data subject's fundamental rights. For B2B cold email, this means: you have a genuine reason to contact this specific person based on their professional role, your message is relevant to that role, and a reasonable person in their position would not be surprised or objectively harmed by receiving it.
What Compliance Looks Like in Practice
Reading the frameworks is useful. Knowing what they mean for your actual outreach process is more useful. Here is what a compliant B2B cold email operation looks like in 2026:
Every email you send should include:
- Your real name and company name in the "From" field or signature
- A physical mailing address (company address works)
- A working one-click unsubscribe link
- A subject line that matches the email's content
Your process should include:
- A suppression list that grows with every opt-out and is honored across all campaigns
- A decision not to re-email anyone who has unsubscribed from previous campaigns
- Email addresses collected from legitimate B2B sources (company websites, LinkedIn, business databases) rather than scraped personal data
- Targeting that links message relevance to the recipient's professional role - the "why this person" test
For Canadian outreach specifically:
- Use only contacts who have published their business email address in a professional context (company website, LinkedIn, speaking bio)
- Ensure the message is clearly relevant to the recipient's professional function
- Keep records of how each Canadian contact's implied consent was established
Most email outreach platforms handle the technical compliance side automatically - footer generation, unsubscribe processing, suppression list management. The judgment call you make as a sender is the targeting and relevance side: why are you emailing this specific person, and would they consider it a reasonable business communication.
Our complete cold email deliverability guide covers the technical infrastructure that keeps compliant email out of the spam folder. Compliance with law and compliance with inbox providers are related but distinct - our SPF, DKIM, and DMARC setup guide covers the authentication layer that affects deliverability. And if you are looking for a platform that handles compliance infrastructure for you, our cold email software comparison evaluates tools by compliance feature set alongside channel coverage and deliverability tooling. The email deliverability guide covers the reputation and technical side, and our cold email outreach guide puts it all together in a campaign workflow.
In our experience running outreach campaigns across EU, US, LATAM, and SEA markets, the companies that get into trouble with compliance are usually not running targeted B2B outreach - they are spraying unsegmented lists at consumer-mixed contacts without unsubscribe mechanisms. If you are doing real B2B sales outreach to professional contacts with genuine relevance, the legal risk is low across all major markets. The deliverability risk of running non-compliant email is higher than the legal risk anyway - Gmail, Outlook, and their peers enforce compliance more aggressively than any regulatory agency.
Frequently Asked Questions
Does GDPR ban cold email to EU contacts?
No. GDPR does not ban B2B cold email. It requires that processing of personal data (which includes holding and emailing a business contact's email address) has a legal basis. For B2B cold outreach to professional contacts, legitimate interest under Article 6(1)(f) provides that basis, provided your message is relevant to the recipient's professional role and they have an easy way to opt out. GDPR bans consent-free cold email to private individuals in a consumer context - it does not ban targeted B2B outreach to business contacts.
What is the minimum required in every cold email for compliance?
The minimum that satisfies CAN-SPAM (and covers most other frameworks): (1) accurate "From" name and address matching real sender identity, (2) a physical postal address in the email body or signature, (3) a working unsubscribe link or reply-to opt-out instruction, (4) a subject line that reflects the content of the message. Adding "I'm reaching out because [specific professional reason]" also helps satisfy the GDPR legitimate interest and CASL relevance requirements.
Can you cold email Canadian addresses?
Yes, under CASL's implied consent provision, if the contact has published their email address in a professional context (company website, LinkedIn profile, business card) without a "do not contact" statement, and your message is relevant to their business role. This is the basis most B2B senders use for Canadian outreach. Express consent is better if you can get it - it removes any ambiguity. Do not cold email Canadian consumer addresses without express consent.
Is scraping email addresses for cold email legal?
It depends on where the addresses come from and how they are used. Scraping professional email addresses from company websites and LinkedIn profiles for legitimate B2B outreach is generally considered lawful in the US (CAN-SPAM applies to the email, not to how you found the address) and arguable under GDPR legitimate interest for relevant B2B outreach. Scraping consumer addresses, personal social media profiles, or databases where scraping is prohibited by terms of service adds both legal and ethical risk. Most B2B email databases (Apollo, ZoomInfo, Cognism) use disclosed data collection methods and provide GDPR-compliant data under their own legal bases.
What happens if you violate CAN-SPAM?
The legal maximum is $50,120 per email sent in violation - but enforcement actions at this scale target large-scale spammers, not businesses sending targeted outreach with minor technical violations. The FTC brings a handful of cases per year against egregious violators. The more immediate risk for most senders is deliverability: ISPs and email providers enforce CAN-SPAM-adjacent rules more aggressively than federal regulators. A domain that generates spam complaints, lacks unsubscribe processing, or uses deceptive headers gets blacklisted before it gets sued.
Do I need a privacy policy for cold email?
Yes, for any meaningful outreach operation. If you are emailing EU contacts under GDPR legitimate interest, you must have a privacy policy that covers your processing of personal data, including prospecting. GDPR technically requires you to inform data subjects about the processing - the most practical way to satisfy this for cold email is a link to your privacy policy in the email footer. For US-only outreach under CAN-SPAM, a privacy policy is not legally required for cold email itself, but most business contexts expect one.