Is Cold Email Legal? GDPR, CAN-SPAM and B2B
This article is general information, not legal advice. Marketing and data protection rules differ by country, change over time, and depend on the specifics of your business, your list, and your message. Before running a cold outreach programme at any scale, have a qualified lawyer in each market you target review what you plan to do.
"Is cold email legal?" is the wrong question, because the answer depends entirely on where your recipient sits. In the United States, sending an unsolicited commercial email to a business contact is lawful by default as long as you follow a short list of rules. In Germany, sending the same email without prior consent is very likely unlawful. In France, the same email to a professional address at a professional role is generally acceptable with an opt-out. Canada sits closer to Germany than to the US. Same email, three or four different legal outcomes.
This guide walks through the main regimes in plain language: what actually applies to B2B, where the carve-outs are, what your opt-out obligations look like, and which practices sit in genuinely unsettled territory rather than being clearly safe.
The two families of law you are dealing with
Almost every jurisdiction falls into one of two camps, and knowing which camp a country is in tells you most of what you need.
- Opt-out regimes. You may send a first commercial message without asking permission first, provided you identify yourself honestly, do not disguise the message, and give a working way to stop receiving further messages. The United States (CAN-SPAM) is the clearest example.
- Consent regimes. You need a lawful basis before the first message. That basis may be explicit consent, or in some cases an existing business relationship, or — in the EU — the "legitimate interests" basis under the GDPR combined with whatever the local e-marketing rule allows. Canada (CASL) and Germany are the strict end of this spectrum.
A second distinction cuts across both: the kind of address you are writing to. A generic company mailbox — info@, sales@, contact@ — is often treated more leniently than a named individual's address such as firstname.lastname@company.com, because the latter is personal data about an identifiable person in most data protection laws. That distinction matters more than the B2B/B2C label in several countries.
The EU: GDPR plus ePrivacy, and member states differ
The single most common mistake is treating "GDPR compliance" as the whole question for Europe. It is only half. Two layers stack on top of each other.
Layer one: the GDPR
The GDPR governs whether you may process someone's personal data at all — collecting a named work email, storing it in a CRM, and using it to contact them all count as processing. You need a lawful basis. For B2B cold outreach, the usual candidate is legitimate interests (Article 6(1)(f)), and direct marketing is expressly acknowledged in the GDPR's recitals as capable of being a legitimate interest. That is not a free pass. Legitimate interests requires a balancing test you can actually show:
- The interest is real and specific — you are offering something genuinely relevant to that person's professional role, not blasting a list.
- The processing is necessary and proportionate to that interest.
- The recipient's rights and reasonable expectations do not override it. A procurement manager at a logistics firm might reasonably expect vendor outreach. A junior designer whose address you scraped from a conference page probably would not.
Alongside the basis, the GDPR imposes obligations you cannot skip: transparency (people have the right to know where you got their data and how you are using it — Article 14 applies when data was not collected from them directly), the right to object to direct marketing, which is absolute and must be honoured without argument, and the usual rights of access and erasure. In practice this means your first email should be able to answer "how did you get my address?" and your systems should let you delete someone on request.
Layer two: ePrivacy, implemented differently in each country
The ePrivacy Directive governs unsolicited electronic communications specifically, and — crucially — it is a directive, so each member state wrote its own national law. Its default rule is prior consent for unsolicited email marketing to natural persons, with an exemption for existing customers being sold similar products (the "soft opt-in"). But member states were allowed to decide how to treat legal persons — companies — and they chose differently. The result is a genuine patchwork:
- Germany is the strictest major market. Under §7 UWG, unsolicited advertising email requires prior express consent, and German practice extends this to business recipients as well. There is a narrow existing-customer exception with tight conditions. Cold email into Germany without consent should be treated as legally risky, full stop — this is not a grey area you can argue your way out of comfortably.
- France takes a more workable line for B2B. The CNIL's published position is that a professional person may be contacted at their professional address about matters relating to their professional function without prior consent, provided they are informed at the point of collection and given a simple means to object. Personal-sounding addresses and messages unrelated to the person's job do not benefit from this.
- Spain layers the LSSI-CE on top of the GDPR. Commercial communications by email generally require prior consent or a pre-existing contractual relationship for similar products; the message must be clearly identifiable as commercial and must carry an opt-out. Spain also has an active national opt-out register (Lista Robinson) that direct marketers are expected to screen against.
- The Netherlands, Ireland, Belgium and several others permit B2B email to corporate addresses with an opt-out, subject to local conditions. Italy applies GDPR strictly and is closer to a consent posture.
The practical takeaway: there is no single "EU rule" for cold email. If your list spans eight countries, you are running under eight national implementations. Segmenting your list by country and applying the strictest applicable rule per segment is the only reliably defensible approach.
The UK after Brexit
The UK retained a near-identical framework: UK GDPR plus PECR (Privacy and Electronic Communications Regulations). PECR's consent requirement applies to "individual subscribers" — consumers and, importantly, sole traders and most partnerships. Emails to corporate subscribers, meaning limited companies and public bodies, do not require prior consent, but UK GDPR still applies to any named individual's data, so you still owe transparency and must honour objections. A named person at a limited company is therefore in an in-between position that is often misdescribed as fully permitted.
The United States: CAN-SPAM
The US is the most permissive major market and the most misunderstood. CAN-SPAM does not require prior consent for commercial email — not for B2C and not for B2B. It requires that you behave honestly. The core duties:
- No false or misleading header information. The From, To, Reply-To, and routing details must accurately identify who sent the message.
- No deceptive subject lines. The subject must reflect what is actually in the email.
- Identify the message as an advertisement where it is one — the law allows flexibility in how, but it must be clear.
- Include a valid physical postal address for your business. A registered post office box that meets the relevant requirements can qualify.
- Provide a clear, working opt-out mechanism, functioning for at least 30 days after sending, and requiring nothing more than a reply or a single-click page. You may not require a login, a fee, or the disclosure of information beyond an email address and opt-out preferences.
- Honour opt-outs within 10 business days, and do not sell or transfer the address of someone who opted out.
Two things people miss. First, liability runs to the company whose product is promoted, not only to the agency that pressed send — outsourcing does not outsource responsibility. Second, individual US states have their own rules, and California's CCPA/CPRA governs the underlying personal data even when the sending itself is CAN-SPAM-compliant. CAN-SPAM being permissive is not the same as US email being unregulated.
Canada: CASL, the strict one
CASL applies to commercial electronic messages sent to or accessed from Canada, and it is consent-based. You need either express consent (a clear, recorded opt-in) or implied consent, which is where most B2B outreach tries to live. Implied consent arises in limited situations, including:
- An existing business relationship — for example a purchase or contract — generally giving a two-year window from the relevant event, or six months from an inquiry.
- Conspicuous publication: the recipient's address is published publicly (say, on the company website) without a statement that they do not wish to receive unsolicited messages, and your message is relevant to their business role. Both conditions must hold.
Every CASL message must also identify the sender, include contact information valid for 60 days, and carry a working unsubscribe that is actioned within 10 business days. CASL puts the burden of proving consent on the sender, so if you cannot document why a given Canadian contact was on your list, you are exposed. Treat Canada as consent-first and keep records per contact.
Beyond Europe and North America
Brazil — LGPD
The LGPD closely mirrors the GDPR, including a legitimate interests basis and a strong transparency requirement. Brazil has no single dedicated anti-spam statute equivalent to CAN-SPAM; the Consumer Protection Code and self-regulatory codes sit alongside the LGPD. B2B outreach relying on legitimate interests is workable in principle, but you must be able to explain your data source, provide clear opt-out, and respond to data subject requests. The regulator, the ANPD, has been progressively more active.
India — the DPDP Act
India's Digital Personal Data Protection Act, 2023 is materially stricter in structure than the GDPR on one point: it is built around consent plus a narrow set of "legitimate uses", and it does not contain a broad legitimate-interests basis of the European kind. Corporate contact details of an identified person are still personal data. The Act's operational rules and enforcement have been phasing in, so exact obligations for B2B marketing are still settling. The conservative reading is that unsolicited email to named individuals in India should rest on consent or a clearly documented pre-existing relationship. Separately, India's telecom regulator enforces strict rules on commercial SMS and calls, which are a different regime from email.
UAE and Saudi Arabia
The UAE's federal Personal Data Protection Law and Saudi Arabia's Personal Data Protection Law are both consent-oriented and both explicitly address direct marketing, generally requiring consent and an opt-out mechanism. The UAE additionally has free-zone regimes (DIFC and ADGM) with their own data protection laws, so which law applies can depend on where the recipient entity is established. The Gulf markets have been tightening rather than loosening; assume consent is required for messaging named individuals and lean on generic company channels and legitimate business enquiry rather than bulk sending.
Russia — 152-ФЗ and the advertising law
Two laws apply together. Federal Law 152-ФЗ governs personal data and requires a basis — in practice consent — for processing, with data localisation obligations for Russian citizens' data. Separately, the Federal Law "On Advertising" (Article 18) prohibits distributing advertising via telecommunications networks without the prior consent of the subscriber or addressee, and places the burden of proving consent on the advertiser. The combination means unsolicited commercial email to Russian recipients is on weak legal footing without documented consent.
Australia and elsewhere
Australia's Spam Act is consent-based but recognises inferred consent where a work address is conspicuously published and the message is relevant to the person's role — similar in shape to CASL's conspicuous publication rule. Many other markets have adopted variants of one of the models above; the two-family framing at the top of this article is a reasonable starting hypothesis, to be checked locally.
Where it is genuinely a grey area
Honest answers matter more than confident ones here. Several common practices are unsettled rather than clearly permitted:
- Scraping named work emails at scale for EU recipients. Legitimate interests can support targeted, relevant outreach. It supports mass collection poorly, and regulators have shown limited patience with "we found it publicly" as a standalone justification. Public availability is not a lawful basis.
- Email-pattern guessing (deriving firstname.lastname@ from a naming convention). You are creating personal data by inference and cannot claim it was published. Treat this as higher risk than using a published address.
- Whether an Article 14 notice can be folded into the first email. Common practice is a short "where we got your data" line plus a privacy policy link. Whether that fully discharges the obligation in every case has not been definitively settled in the way practitioners would like.
- LinkedIn and other platform messages. Data protection law applies to the data; platform terms of service apply separately and can be enforced by account termination regardless of legality.
- Automated enrichment of scraped contacts. Combining sources to build a profile of an individual raises the intrusiveness of the processing, which weighs directly against you in a legitimate-interests balancing test.
If a vendor tells you any of these is definitively fine everywhere, that is a sales claim, not a legal opinion.
A practical compliance checklist
None of this makes cold outreach impossible. It makes sloppy cold outreach expensive. The following holds up across most regimes:
- Segment your list by country and apply the strictest rule that applies to that segment. One global policy set to the most permissive market is the failure mode that gets companies in trouble.
- Prefer role-based company addresses (info@, sales@, purchasing@) over named individuals in consent regimes. They carry meaningfully lower personal-data risk.
- Identify yourself completely in every message: real sender name, real company, real physical address, honest subject line, honest From field.
- Include a working opt-out in every message — one click or one reply, no login, no fee, no form asking why.
- Honour opt-outs fast. The legal maximum is often 10 business days; aim for immediate and automatic. Never sell or share an address that opted out.
- Maintain a permanent suppression list that survives CRM changes, tool migrations, and list re-imports. Re-contacting someone who opted out is the single most common way a minor issue becomes a complaint.
- Record the source of every contact — where the address came from, when, and why you believed it was relevant. Under CASL and the GDPR the burden of explanation is on you, and a record created after a complaint is worth much less than one created at collection.
- Say where you got the data in your first message and link to a privacy notice that explains your processing and rights.
- Do not use scraped personal addresses in consent regimes — Germany, Canada, India, the Gulf states, Russia. Restrict those markets to consented contacts, inbound leads, or genuinely public corporate channels.
- Keep volumes human. Small, relevant, well-targeted sends are both more defensible legally and more effective commercially. Volume is what turns a compliance question into a complaint pattern.
Most of that checklist is also simply good practice: a clean, well-sourced list of relevant businesses, with a record of where each contact came from, is both easier to defend and more likely to get replies than a scraped pile of addresses. If you are building lists from maps data, business registries, and public company websites, tools like JustLeadIt keep the source of each record visible, which is exactly what you need when someone asks where you got their details.
The short version
Cold email is legal in the United States if you are honest and provide a real unsubscribe. It is legal in much of the EU for genuine B2B outreach under legitimate interests, but Germany is a hard no without consent and each member state differs. Canada, India, the Gulf and Russia should be treated as consent-first. The UK sits in between depending on whether your recipient is a corporate subscriber. Everywhere, transparency, a working opt-out, fast suppression, and records of where your data came from are the baseline — and everywhere, a lawyer familiar with your target market is worth more than an article, including this one.