There’s always a common question- Is Cold Email Legal? Yes, Cold email is legal in 2026 in the United States, European Union, United Kingdom, Canada, Australia and most major markets. The law does not ban cold email. It bans non-compliant email. The difference is consent requirements, disclosure rules and opt-out processing. These vary significantly depending on whose inbox you are reaching.
The four regulations every B2B sender needs to understand are CAN-SPAM (US), GDPR (EU and UK), UK GDPR with PECR (UK post-Brexit) and CASL (Canada). Each treats cold B2B email differently. Getting the distinctions right determines whether your outreach is legal, risky or outright prohibited, particularly for campaigns reaching Canadian recipients, where CASL is among the strictest email laws in the world.
This article covers legal frameworks, not legal advice. For compliance decisions specific to your business situation, consult a qualified legal professional.
The Short Answer: Is Cold Email Illegal?
No. Cold email is not illegal in the US, EU, UK, Canada or Australia, provided the sender complies with the applicable regulations. The common misconception that all unsolicited email is illegal confuses spam (bulk, indiscriminate, non-compliant email) with cold email, which is targeted, personalised outreach to a specific business contact with a legitimate reason for reaching out. Every major regulatory framework carves out a legal pathway for compliant B2B prospecting.
What differs across jurisdictions is whether you need consent before sending, what disclosures are required in each email and how quickly you must honour opt-out requests. Understanding those differences, particularly the CASL/GDPR distinction, is where compliance work actually begins.
CAN-SPAM (United States): The Most Permissive Framework
The CAN-SPAM Act governs commercial email in the United States. It is an opt-out law: no prior consent is required before sending a commercial email to a US recipient, including cold outreach to business contacts the sender has never spoken to.
What CAN-SPAM requires
- Accurate sender information: The “From,” “To” and “Reply-To” fields must accurately identify the sender. No misleading header information.
- Non-deceptive subject line: The subject line must reflect the content of the email. Deceptive subject lines are a direct CAN-SPAM violation.
- Clear commercial identification: The email must be identifiable as an advertisement or solicitation, though this can be integrated naturally into the message rather than as an explicit label.
- Physical postal address: Every commercial email must include a valid physical address — a registered office, a P.O. box or a registered mailing address.
- Working opt-out mechanism: Every email must include a clear, conspicuous way for the recipient to opt out of future messages. The opt-out mechanism must work for at least 30 days after the email was sent.
- Opt-outs honoured within 10 business days: Once a recipient opts out, you must stop sending to that address within 10 business days. You cannot charge a fee for opt-outs, require personal information beyond an email address or make the opt-out process complicated.
CAN-SPAM penalties
Penalties under CAN-SPAM reach up to $53,088 per individual non-compliant email as of January 2025, following the FTC’s periodic adjustment for inflation. Multiple violations in a single campaign compound quickly. Enforcement is carried out by the FTC, state attorneys general and (in some cases) private parties with standing to sue.
What CAN-SPAM does not require
CAN-SPAM does not require prior consent. It does not require that the recipient has any existing relationship with the sender. A legitimate B2B cold email to a prospect who has never heard of the sender is fully legal under CAN-SPAM as long as the six requirements above are met. The law explicitly makes no B2B exception to its coverage but also creates no consent prerequisite — which is why US-based cold email campaigns operate freely relative to other jurisdictions.
GDPR (European Union and UK): Legitimate Interest for B2B
The General Data Protection Regulation governs personal data processing in the EU. In the UK, the equivalent framework is UK GDPR, maintained post-Brexit and substantively identical for cold email purposes. Cold B2B email is legal under both frameworks under the legitimate interest legal basis, but with conditions that require documentation and ongoing process discipline.
What makes GDPR cold email lawful
Under Article 6(1)(f) of GDPR, processing personal data (including someone’s business email address) is lawful if it serves the legitimate interests of the data controller, provided those interests are not overridden by the rights and interests of the data subject. For B2B cold email, the legitimate interest framework works when:
- The email is relevant to the recipient’s professional role, not sent to their personal address
- The sender has a genuine, documented commercial interest in reaching this specific type of prospect
- A Legitimate Interest Assessment (LIA) has been completed and retained on file
- The email discloses how the recipient’s data was obtained and how they can opt out
- Opt-out requests are processed promptly — in practice, 24–48 hours, not the 10-business-day window CAN-SPAM allows
GDPR requirements in each cold email

- Clear identification of the sender and their organisation
- A brief disclosure of where the recipient’s email address was sourced (“I found your contact details on LinkedIn” or “via your company website”)
- A simple, easy opt-out mechanism in every email
- No use of personal data beyond what is necessary for the outreach purpose
The UK PECR addition
The UK’s Privacy and Electronic Communications Regulations (PECR) explicitly allows unsolicited commercial emails to corporate subscribers (people using a business email address) without prior consent, provided the sender’s identity is clear and an opt-out mechanism is included. This makes the UK relatively permissive for B2B cold email, in line with the EU legitimate interest framework.
The Germany exception
Germany applies stricter requirements under its Unfair Competition Act (UWG). Cold email without prior consent is effectively prohibited for both consumer and professional recipients in Germany, even under the GDPR legitimate interest basis. Teams targeting German business contacts should seek specific legal guidance before sending.
GDPR penalties
GDPR fines reach up to €20 million or 4% of global annual revenue, whichever is higher. The largest cold email-related GDPR enforcement actions have involved significant fines for processing personal data without a valid legal basis. Documenting your Legitimate Interest Assessment before campaigns send is the operational protection against this risk.
CASL (Canada): The World’s Strictest Commercial Email Law

Canada’s Anti-Spam Legislation is the most restrictive commercial email law among major economies. Unlike CAN-SPAM (opt-out model) and GDPR (legitimate interest for B2B), CASL requires consent, express or implied, before sending any commercial electronic message to a Canadian recipient. The burden sits with the sender, not the recipient.
What CASL governs
CASL applies to any “commercial electronic message” sent to an electronic address located in Canada, regardless of where the sender is based. A US company sending a cold email to a Canadian business contact must comply with CASL. The law applies to email, SMS and some social media messages. The “electronic address in Canada” standard means the recipient’s location, not the sender’s, determines applicability.
Express consent under CASL
Express consent requires the recipient to have explicitly opted in to receiving commercial electronic messages from the sender. This is a positive, affirmative action: a checkbox ticked, a form submitted, a request made. Pre-ticked boxes and buried consent language do not constitute express consent under CASL. Express consent must be separate from other terms and conditions and must clearly describe what the person is consenting to receive.
Implied consent under CASL: the B2B pathway
CASL provides two implied consent pathways that create a legal basis for cold B2B email without prior express consent:
- Existing business relationship: A prior commercial relationship within the past two years — a completed purchase, an active contract, an inquiry the person initiated, a membership or subscription — creates implied consent for commercial messaging within that two-year window.
- Conspicuously published business email address: If a Canadian professional’s business email address has been conspicuously published in a public context that suggests they welcome business contact — a company website, LinkedIn profile, business directory, trade publication bio — implied consent exists for outreach directly relevant to their professional role at that organisation. This is the primary pathway for B2B cold email to Canadian recipients.
CASL requirements for every message sent
- Sender identification: Full name and contact information of the sender and any organisation on whose behalf the message is sent
- Unsubscribe mechanism: A clear, easy way to opt out that works for at least 60 days after the message was sent (longer than CAN-SPAM’s 30-day requirement)
- Opt-outs honoured within 10 business days: Once a recipient opts out, all sending to that address must stop within 10 business days
- Consent records: The burden of proving consent rests with the sender. Maintain records of how and when consent was obtained or the basis for implied consent
CASL penalties
CASL penalties reach up to $1 million CAD per violation for individuals and $10 million CAD per violation for organisations. Private rights of action allow recipients to sue directly for CASL violations, a feature not present in CAN-SPAM. Enforcement has been active: the CRTC (Canadian Radio-television and Telecommunications Commission) has issued multi-million dollar penalties against companies sending non-compliant commercial electronic messages.
CASL compliance summary for B2B cold email
| Situation | CASL basis | Documentation needed |
|---|---|---|
| Email found on company website or LinkedIn | Implied consent (conspicuous publication) | Record the source URL and date of acquisition |
| Prior purchase or active contract in past 2 years | Implied consent (existing business relationship) | Record of the transaction, date and nature of relationship |
| Prospect submitted an inquiry or demo request | Implied consent (recipient initiated contact) | Record of the inquiry, date and method |
| Email sourced from a purchased list with no public profile | No valid CASL basis | Do not send — seek express consent or alternative sourcing |
Jurisdiction Comparison: CAN-SPAM vs GDPR vs CASL
| Rule | CAN-SPAM (US) | GDPR (EU/UK) | CASL (Canada) |
|---|---|---|---|
| Prior consent required | No | No (legitimate interest) | Yes (express or implied) |
| Opt-out timeframe | 10 business days | Without undue delay (24–48 hours in practice) | 10 business days |
| Unsubscribe mechanism duration | 30 days | Ongoing | 60 days |
| Physical address required | Yes | Yes (sender identification) | Yes |
| Documentation requirement | Minimal | Legitimate Interest Assessment | Consent records mandatory |
| Maximum penalty | $53,088 per email | €20M or 4% global revenue | $10M CAD per violation |
| Private right of action | Limited | Yes (via data protection authorities) | Yes (direct civil suits) |
Practical Compliance Checklist for Cold Email Campaigns
This checklist applies across all three major frameworks. For campaigns targeting Canadian recipients, apply CASL requirements specifically. EU/UK recipients need the GDPR layer in addition to the baseline requirements.
Before the campaign sends
- Verify the legal basis for each recipient segment (opt-out/CAN-SPAM, legitimate interest/GDPR, implied or express consent/CASL)
- Document the source of every contact — company website, LinkedIn, business directory, referral. Record the date of acquisition.
- For EU/UK recipients: complete a Legitimate Interest Assessment and retain it on file
- For Canadian recipients: confirm implied consent basis exists before adding to any send list
- Verify all email addresses before sending — purchased or scraped lists create immediate GDPR and CASL compliance gaps and high bounce rates from unverified data signal non-compliance to email providers
- Build a suppression list: all prior opt-outs must be excluded from every campaign before it sends
In every email
- Accurate sender name and organisation in the From field
- Non-deceptive subject line that reflects the email’s content
- Physical postal address in the email footer
- Clear, functional opt-out mechanism (unsubscribe link or reply-to instruction)
- For GDPR campaigns: brief data sourcing disclosure (“I found your details via your company’s LinkedIn page”)
After a recipient opts out
- Process the opt-out within 24–48 hours for GDPR campaigns, within 10 business days for CAN-SPAM and CASL campaigns
- Add the address to your suppression list before the next campaign sends
- Do not send any follow-up messages after an opt-out is received — even automated sequences already in motion
Common Compliance Myths

“Cold email is illegal under GDPR”
False. B2B cold email under legitimate interest is permitted under GDPR. The error comes from conflating GDPR’s requirements for B2C email (which generally requires consent) with B2B professional outreach, which can proceed under legitimate interest provided the contact is relevant to the recipient’s professional role and proper documentation exists.
“I need consent for every cold email”
False under CAN-SPAM (US). True for CASL (Canada) in most circumstances. Depends on the legal basis and jurisdiction for GDPR. Consent is the most conservative approach and the simplest to document, but it is not universally required for B2B professional outreach.
“An unsubscribe link hurts deliverability”
False. Unsubscribe links are legally required under CAN-SPAM, GDPR and CASL. They actually improve deliverability by giving recipients a legitimate way to opt out rather than marking the email as spam. Spam complaints damage sender reputation far more than unsubscribes do.
“If they don’t reply, I can keep emailing indefinitely”
Technically lawful under CAN-SPAM until an opt-out is received, but harmful to sender reputation and inconsistent with GDPR best practices. Limit follow-up sequences to 3–4 touches per contact. Continued sending after a reasonable sequence window without a response generates spam complaints that damage deliverability regardless of legal compliance.
Frequently Asked Questions
Is cold email legal?
Yes, cold email is legal in the United States, European Union, United Kingdom, Canada, Australia and most major markets, provided the sender complies with the applicable regulations. The US (CAN-SPAM) is the most permissive: no prior consent required, opt-out model. The EU and UK (GDPR/PECR) allow cold B2B email under legitimate interest with documentation. Canada (CASL) is the strictest — express or implied consent is required before the first send. Compliance requirements vary by jurisdiction; the law bans non-compliant email, not cold email itself.
Is cold emailing illegal under GDPR?
No. B2B cold email is permitted under GDPR via the legitimate interest legal basis (Article 6(1)(f)). The email must be relevant to the recipient’s professional role, the sender must complete a Legitimate Interest Assessment, the data source must be disclosed in the email and opt-outs must be processed promptly (within 24–48 hours in practice). B2C cold email to personal addresses without consent is not permitted under GDPR. Germany applies stricter national requirements that effectively prohibit cold email without consent for all recipients.
Is cold email legal in Canada under CASL?
Cold email to Canadian recipients is legal under CASL only when implied or express consent exists. Implied consent applies when the recipient’s business email address was conspicuously published on a company website, LinkedIn profile or business directory and the outreach is relevant to their professional role, or when an existing business relationship exists within the past two years. Cold email to Canadian recipients sourced from purchased or scraped lists with no public profile typically has no valid CASL basis. Penalties reach $10 million CAD per violation.
What are the CAN-SPAM requirements for cold email?
CAN-SPAM requires: accurate sender identification in the From field, a non-deceptive subject line, a physical postal address in every email, a clear and working opt-out mechanism and opt-outs honoured within 10 business days. No prior consent is required. Penalties for non-compliance reach $53,088 per email (as of January 2025). The law applies to any commercial email sent to US recipients regardless of where the sender is located.
What is CASL and how does it differ from CAN-SPAM?
CASL (Canada’s Anti-Spam Legislation) requires either express consent or implied consent before any commercial electronic message is sent to a Canadian recipient. This is a consent-first model, the opposite of CAN-SPAM’s opt-out model. CAN-SPAM requires no prior consent and gives recipients the right to opt out after receiving a message. CASL requires consent to be established before the first send. Penalties under CASL are also significantly higher ($10M CAD per violation vs $53,088 per email under CAN-SPAM) and CASL allows direct private lawsuits against senders.
Do I need an unsubscribe link in cold emails?
Yes, under all three major frameworks. CAN-SPAM requires a working opt-out mechanism in every commercial email. GDPR requires a way for recipients to withdraw from future communications. CASL requires an unsubscribe mechanism that remains functional for at least 60 days after the message was sent. Including an unsubscribe link also reduces spam complaints, which damage sender reputation — making it both a legal requirement and a deliverability best practice.
Compliance Is the Baseline, Not the Ceiling
Meeting the legal minimum is not the same as running an effective cold email operation. CAN-SPAM compliance keeps you out of legal trouble. Relevant, targeted, personalised outreach keeps you out of the spam folder and in the primary inbox.
The practical approach for teams sending across multiple jurisdictions: apply the strictest standard (CASL) to your entire operation and build compliance systems that work universally. Document the source of every contact, process opt-outs within 24 hours across all campaigns and never send from purchased or scraped lists. That approach satisfies all three frameworks simultaneously and protects sender reputation in markets where regulatory scrutiny is growing.
- Cold Email Infrastructure Setup — the technical setup that keeps campaigns compliant and deliverable
- Cold Email Deliverability — how spam complaint rates affect inbox placement and what to watch
- Cold Email Best Practices 2026 — the full system from targeting to reply management
- Cold Email Lead Generation — how to build lists that are compliant from the source
This article provides general information about legal frameworks governing cold email. It does not constitute legal advice. For compliance decisions specific to your jurisdiction and business situation, consult a qualified legal professional.
