Skip to content

Is Cold Email Legal? GDPR, PECR, CAN-SPAM and CASL Explained

When B2B cold email is allowed in the US, UK, EU and Canada, what CAN-SPAM, PECR, GDPR and CASL require, and a practical compliance checklist.

By the Glintscout team12 min read

On this page
  1. The short answer by country
  2. What counts as a cold email under the law
  3. United States: CAN-SPAM
  4. European Union: ePrivacy and the GDPR
  5. United Kingdom: PECR and the UK GDPR
  6. Canada: CASL
  7. Germany, Spain and France: stricter national rules
  8. Mailbox providers have rules too
  9. A practical compliance checklist
  10. FAQ

Yes, in many countries, but not everywhere and never without conditions. In the US, CAN-SPAM lets you email businesses without prior consent if you identify yourself, include a postal address and honor opt-outs. The UK allows it to companies and LLPs but not to sole traders or ordinary partnerships, Canada requires consent (a published business address can imply it for relevant messages), and in the EU the answer depends on the country.

The short answer by country

Recipient's country Main rules Consent needed for B2B email? Enforced by
United States CAN-SPAM Act No (opt-out model) FTC
United Kingdom PECR, UK GDPR Not for companies and LLPs; yes for sole traders and ordinary partnerships ICO
European Union ePrivacy Directive, GDPR Depends on the country National regulators
Germany UWG, GDPR Yes, prior express consent Courts (claims by recipients, competitors and associations), data protection authorities
Spain LSSI, GDPR Yes, unless there is a prior contractual relationship AEPD
France Postal and Electronic Communications Code, GDPR No, if the message relates to the recipient's profession CNIL
Canada CASL Yes, express or implied CRTC

As a working rule, plan for the law of the recipient's country as well as your own.

What counts as a cold email under the law

No statute uses the phrase "cold email". The laws regulate direct marketing by electronic mail (EU and UK), commercial electronic mail messages (US) and commercial electronic messages (Canada). A single personalized email whose purpose is to sell counts: none of these laws sets a minimum volume. A friendly "quick question" that aims at a sales meeting is still marketing.

Two layers of rules usually apply at once:

  1. The marketing rule decides whether you may send the email at all and what it must contain.
  2. The data protection rule (the GDPR in the EU, the UK GDPR in the UK) governs the personal data in your list, such as a named person's work address.

United States: CAN-SPAM

The US uses an opt-out model. You don't need permission before the first email, but every commercial email must follow the rules summarized in the FTC's CAN-SPAM Act compliance guide, which states plainly that "the law makes no exception for business-to-business email":

  • Accurate header information. "From", "To", "Reply-To" and routing details must identify who sent the message.
  • An honest subject line that reflects the content.
  • Disclosure that the message is an ad. The law allows leeway in how, but the disclosure must be clear and conspicuous.
  • Your valid physical postal address: a street address, a registered post office box or a registered private mailbox.
  • A clear explanation of how to opt out, with a mechanism that works for at least 30 days after you send.
  • Opt-outs honored within 10 business days. You can't charge a fee, ask for more than an email address, or require more than a reply or a visit to a single web page.
  • Oversight of anyone who sends for you. Hiring a company to send your emails doesn't transfer your responsibility.

According to the FTC's guide, each email in violation can cost up to $53,088. The guide also describes aggravated violations, such as harvesting addresses or generating them through a "dictionary attack" (combining names, letters or numbers into many permutations).

Whatever the country, a compliant campaign starts with a clean list: businesses from public listings such as Google Maps, with addresses on each company's own domain, verified before you send.

European Union: ePrivacy and the GDPR

The marketing rule: ePrivacy, country by country

Article 13 of the ePrivacy Directive requires prior consent for email marketing to individuals, with one exception: a business may email its own customers about its similar products or services, if it offered a free, easy opt-out when it collected the address and offers one in every message. Two further rules apply to every marketing email, whoever receives it: never disguise or conceal the sender's identity, and always give a valid address for opt-out requests.

For businesses and other legal persons, the Directive leaves the choice to each country, which must only ensure their legitimate interests are "sufficiently protected". That is why B2B cold email needs consent in some EU countries and only an opt-out in others (Germany, Spain and France are covered below).

The data protection rule: the GDPR

The GDPR applies whenever your list holds personal data. A named work address such as [email protected] is personal data. A role address such as info@ usually isn't, unless it identifies a person, as the address of a one-person business can.

For named contacts, the GDPR expects:

  • A lawful basis. For B2B prospecting, that is usually legitimate interests (Article 6(1)(f)). Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest", but you still have to weigh your interest against the person's and document that assessment. Legitimate interests never override a national rule that requires consent for the email itself.
  • Transparency. When you didn't get the data from the person, Article 14 requires you to tell them who you are, what data you hold, where it came from and what their rights are, at the latest in your first message to them.
  • Respect for the right to object. Under Article 21, once someone objects to direct marketing, you must stop, without exception. Your first message must mention this right explicitly, clearly and separately from other information.
  • Minimization and retention limits. Keep only the fields you need, and delete prospects who never engage.

For the most serious infringements, GDPR fines can reach EUR 20 million or 4% of worldwide annual turnover, whichever is higher (Article 83(5)).

United Kingdom: PECR and the UK GDPR

The Privacy and Electronic Communications Regulations (PECR) split recipients into two groups, and the split decides whether you need consent:

  • Corporate subscribers (limited companies, LLPs, Scottish partnerships, government bodies): no consent needed. Regulation 23 still forbids disguising or concealing your identity and requires a valid address for opt-out requests.
  • Individual subscribers (individuals, sole traders and ordinary partnerships in England, Wales and Northern Ireland): you need prior consent under regulation 22, unless the soft opt-in for your own customers applies.

The ICO's guidance on business-to-business marketing adds two practical points. If you can't tell whether a contact is a sole trader or a company, treat them as an individual subscriber. And although PECR doesn't explicitly require it for corporate email, you should honor a company's opt-out request.

To tell the two apart, search the free Companies House register: limited companies and LLPs are registered there, and their names usually end in "Ltd", "Limited", "PLC" or "LLP". A trading name with no registered company behind it may belong to a sole trader.

The UK GDPR still applies to named employees at companies: you need a lawful basis (usually legitimate interests), you must provide privacy information, and you must respect their absolute right to object. Since 5 February 2026, PECR fines can reach £17.5 million or 4% of global turnover, the same ceiling as the UK GDPR, according to the ICO's statement on the Data (Use and Access) Act.

Canada: CASL

Canada's Anti-Spam Legislation (CASL) uses a consent model: you may send a commercial electronic message only with the recipient's express or implied consent. It applies whenever a computer system in Canada is used to send or access the message (section 12), so it covers senders abroad who email people in Canada.

Section 10(9) implies consent in three situations:

  • An existing business relationship, such as a purchase within the past two years or an inquiry within the past six months.
  • Conspicuous publication: the person published their address (or had it published), the publication doesn't say they refuse unsolicited commercial messages, and your message is relevant to their business role or duties.
  • Disclosure: the person gave you the address, for example on a business card, without saying they refuse such messages, and your message is relevant to their role.

Most B2B cold email relies on conspicuous publication, and the CRTC's CASL guidance reads it narrowly: an address that merely appears somewhere online isn't enough; it must be published in a way that makes consent to your type of message reasonable to infer. Example (fictional): the owner of Example Plumbing Co. lists her address on the company's contact page. An email offering her scheduling software for plumbers is relevant to her role; an email selling her a vacation package isn't.

You carry the burden of proof (section 13). Record where and when you found each address, and check that the page had no "no solicitations" notice.

Every message must also identify the sender (and anyone on whose behalf it is sent), give a mailing address plus a phone number, email address or web address, and include an unsubscribe mechanism that works for at least 60 days and is honored within 10 business days (section 11 and the Electronic Commerce Protection Regulations). Penalties can reach C$1 million per violation for an individual and C$10 million for a company (section 20(4)).

Germany, Spain and France: stricter national rules

In general terms, Germany and Spain require consent even for business recipients, and France sets conditions of its own:

  • Germany: under § 7 of the Act against Unfair Competition (UWG), advertising by email without the recipient's prior express consent counts as an unacceptable nuisance, and this applies to business recipients too. The exception in § 7(3) is narrow and covers only your own customers. In practice, cold email to German businesses carries real legal risk; research, phone calls within the rules for business calls, post and consent-based email are the usual alternatives.
  • Spain: article 21 of the LSSI prohibits advertising emails that the recipient didn't request or expressly authorize beforehand, and it doesn't exempt company recipients. The exception is a prior contractual relationship, for similar products and with an opt-out. The AEPD enforces these rules and can impose fines.
  • France: article L34-5 of the Postal and Electronic Communications Code requires prior consent for email marketing to individuals. For professionals, the CNIL accepts email prospecting without prior consent when the message relates to the recipient's profession, the person was informed when the address was collected, and every message offers a simple way to object. Generic addresses such as contact@ belong to the company, not to a person.

Other EU countries transpose the ePrivacy Directive in their own way, so read the national regulator's guidance before you email a new market.

Mailbox providers have rules too

Separately from the law, Gmail and Yahoo decide whether your emails reach the inbox. Google's email sender guidelines ask every sender to set up SPF or DKIM and keep the spam rate reported in Postmaster Tools below 0.3%; senders of more than 5,000 messages a day to Gmail accounts also need SPF, DKIM, DMARC and one-click unsubscribe for marketing messages. Yahoo's requirements are similar, and our cold email deliverability rules cover the setup.

A practical compliance checklist

Before you build the list

  1. Decide which countries you will email and check each one's rule in the table above. Store the country with every lead.
  2. Leave out recipients who need consent you don't have, such as most businesses in Germany and Spain and sole traders in the UK. Reach them another way.
  3. Target by role and relevance. Relevance to the recipient's business is a legal condition in Canada and France, and it earns replies everywhere.
  4. Record the source of every address: the page, the date and whether it carried a "no solicitations" notice. CASL's burden of proof and GDPR transparency both depend on it.
  5. Document your legitimate interests assessment and publish a privacy notice that covers prospect data (EU and UK).

In every message

  1. Say who you are: your real name, your company and a working reply address.
  2. Include your postal address (required in the US and Canada; Canada also requires a phone number, email address or web address).
  3. Write an honest subject line that matches the content.
  4. Offer a simple opt-out, such as "reply 'stop'" or an unsubscribe link. For named contacts in the EU and UK, also mention the right to object and link to your privacy notice.

After you send

  1. Honor opt-outs fast: within 10 business days at the latest in the US and Canada, and without undue delay in the EU and UK.
  2. Keep one suppression list across every inbox, domain and tool, so one opt-out covers every campaign.
  3. Delete stale prospect data on a schedule, and hold anyone who sends on your behalf to the same rules.

Which addresses you collect matters too: our guide on finding a company's email address explains which ones suit B2B outreach, and verifying them without sending an email keeps dead addresses off your list.

FAQ

Yes. CAN-SPAM doesn't require consent before the first commercial email, including to businesses. Every message still needs accurate headers, an honest subject line, an ad disclosure, your postal address and an opt-out you honor within 10 business days.

Yes for corporate subscribers such as limited companies and LLPs, as long as you identify yourself and give a valid opt-out address. Sole traders and ordinary partnerships need consent first. When you email a named person, the UK GDPR applies as well.

Is a generic address like info@ personal data?

Usually not, because it doesn't identify a person, so the GDPR's rules on personal data don't apply to it. The marketing rules still do: in Germany or Spain, the consent requirement covers info@ just as it covers a named address.

The rules in this guide were checked against the official texts in September 2026.

This article is general information, not legal advice.

Keep reading

All articles