Cold Email Laws by Country

Cold email is legal in most places, provided you follow the rules, and the rules differ by jurisdiction. This is a neutral reference to how cold email is regulated in the United States, the EU and UK, Canada, and Australia, with a comparison table and a compliance checklist. It is general information, not legal advice.

Cold email versus spam

Cold email is a message sent to a business contact you have no prior relationship with, for a legitimate business purpose. Spam, by contrast, is bulk, unsolicited, and frequently deceptive email sent indiscriminately. The distinction matters legally, because every major framework below is aimed at the behaviors that define spam rather than at outreach as such. Three behaviors separate the two in practice:

  • Targeting. Compliant cold email is sent to a specific person because their role or business makes the message relevant. Spam is sent to whoever appears on a purchased or scraped list, with no selection at all.
  • Honesty. Compliant cold email uses the sender's real name, real domain, and a subject line that reflects the content. Spam routinely forges headers, spoofs domains, and baits with misleading subjects, which is what most statutes prohibit first.
  • Opt-out. Compliant cold email includes a working way to say no, and the sender stops when asked. Spam offers no such mechanism, or a fake one.

None of the laws described here bans cold email outright. They set conditions: tell the truth about who you are, make the message identifiable as commercial, respect the recipient's ability to refuse, and, in consent-based jurisdictions, have a lawful reason to email that person in the first place.

Key terms

  • Opt-out regime: senders may email first, but must stop when the recipient objects (the US model).
  • Opt-in regime: senders need permission, or another legally recognized basis, before the first message (the broad EU, UK, Canadian, and Australian model).
  • Express consent: the recipient actively agreed to receive messages, for example by ticking a box or signing up.
  • Implied or inferred consent: consent a law deems to exist from circumstances, such as an existing business relationship or a relevantly published business address.
  • Legitimate interest: a lawful basis under GDPR that lets an organization process personal data without consent when its documented interest is not overridden by the individual's rights.
  • Suppression list: the sender's record of everyone who has opted out, checked before every send so no one who refused is emailed again.

United States: the CAN-SPAM Act

The Controlling the Assault of Non-Solicited Pornography And Marketing Act, known as CAN-SPAM, was signed into law in 2003 and took effect on January 1, 2004. It was the first national US standard for commercial email and it preempted a patchwork of state anti-spam laws. The Federal Trade Commission (FTC) is the primary enforcer, with additional authority for other federal agencies over the sectors they regulate and a limited right of action for internet service providers. It applies to commercial email generally: business-to-business messages are covered just as consumer messages are.

The seven core requirements

The FTC's compliance guide for business distills the statute into seven obligations for any commercial message:

  • Do not use false or misleading header information: the "From," "To," "Reply-To," and routing details must accurately identify the sender.
  • Do not use deceptive subject lines: the subject must reflect the content of the message.
  • Identify the message as an advertisement, in a clear and conspicuous way, where it is one.
  • Tell recipients where you are located: every message needs a valid physical postal address (a street address, or a registered post office box or private mailbox).
  • Tell recipients how to opt out of future email, in a way an ordinary person can notice and use.
  • Honor opt-out requests promptly: within 10 business days, without charging a fee, requiring anything beyond an email address, or making the recipient do more than send a reply or visit a single page. The mechanism must keep working for at least 30 days after the message is sent.
  • Monitor what others do on your behalf: hiring an agency does not transfer the legal responsibility.
Anatomy of a compliant cold emailAnatomy of a compliant cold emailFrom: Jane Doe <jane@acmecorp.com>Subject: Question regarding your hiring plansHi Alex,Jane Doe, Head of PartnershipsAcme Corp100 Main Street, Springfield, USAUnsubscribeor reply "no thanks" to opt out1Accurate sender identityReal name, real domain, no spoofing2Honest subject lineReflects the actual content3Clear identificationWho is sending, and for whom4Physical postal addressRequired by CAN-SPAM and CASL5Working opt-outEasy to use, honored promptly
Figure 1. The elements most cold email laws require in the message itself. The first five callouts map directly to CAN-SPAM obligations; identification and a working opt-out are also required under GDPR and ePrivacy rules, CASL, and the Australian Spam Act.

Who is liable

Liability under CAN-SPAM is deliberately broad. Both the company whose product or service is promoted and the company that actually transmits the message can be legally responsible, so a business cannot outsource its exposure to a lead generation agency or a sending vendor. More than one party can be on the hook for the same email.

What CAN-SPAM does not require

CAN-SPAM is often misread as an opt-in law. It is not. It does not require prior consent before the first email, does not require permission to be documented, and does not restrict who may be emailed. It also does not require that the opt-out be a link: a monitored reply address can satisfy the statute. What it polices is deception and the refusal to let recipients say no. This is the key structural difference between the US regime and the consent-based regimes described below.

Penalties: a worked example

Penalties are assessed per email, not per campaign. The statutory civil penalty is adjusted for inflation and currently exceeds $50,000 per violating message. The arithmetic is what makes the statute bite: a single send of 1,000 emails that all omit a postal address is, on paper, 1,000 separate violations, so the theoretical ceiling for that one campaign runs to eight figures. Actual FTC settlements are far below theoretical ceilings, but the per-email structure explains why bulk senders treat even small template mistakes as serious. Deceptive practices can also trigger aggravated penalties, and certain conduct (such as harvesting addresses or falsifying headers at scale) can carry criminal consequences under related provisions.

European Union and United Kingdom: GDPR and ePrivacy / PECR

In Europe two layers of law apply at once. The General Data Protection Regulation (GDPR), in force since May 2018, governs any processing of personal data. The ePrivacy Directive of 2002 governs electronic marketing specifically, and each EU member state implements it in national law; the UK implementation is the Privacy and Electronic Communications Regulations (PECR), which continue to apply alongside the UK GDPR after Brexit. A cold email campaign into the EU or UK must satisfy both layers, and the marketing layer differs slightly from country to country.

Personal data includes business email

GDPR defines personal data as any information relating to an identified or identifiable natural person. A generic inbox such as info@company.com is generally not personal data, but jane.doe@company.com identifies a person and therefore is. That means finding, storing, and emailing a named prospect's work address is processing personal data, and the sender needs a lawful basis for it, a privacy notice that covers it, and processes to honor rights such as access, erasure, and objection.

Lawful bases and legitimate interest

GDPR offers six lawful bases; for cold outreach the realistic candidates are consent and legitimate interest. Recital 47 of the GDPR notes that direct marketing may be a legitimate interest, but relying on it is not automatic. Regulators expect a documented three-part assessment: identify the interest (for example, marketing a relevant product to businesses), show that emailing this person is necessary for it, and balance it against the recipient's rights and reasonable expectations. A sales director being contacted about sales software sits very differently in that balance than a consumer being contacted from a scraped list. Recipients always retain an absolute right to object to direct marketing, and an objection must stop the emails.

Soft opt-in and the corporate subscriber exception

The ePrivacy layer adds two practically important carve-outs. The first is the soft opt-in: an organization may email marketing to its own existing customers about similar products without fresh consent, provided the address was collected during a sale or sale negotiation and every message offers an opt-out. The second, in the UK, is the corporate subscriber exception: PECR's consent rule for unsolicited marketing email protects individual subscribers, so email sent to a corporate subscriber (a company's own domain) is outside that specific consent requirement. This is the main reason B2B cold email is workable in the UK. The exception has limits: sole traders and some partnerships count as individuals, the UK GDPR still governs the personal data of a named employee, and several EU member states apply consent rules to business recipients too, so the position varies across Europe.

Enforcement and fines

GDPR fines can reach 20 million euros or 4 percent of worldwide annual turnover, whichever is higher, with a lower tier for less serious infringements. In the UK, the Information Commissioner's Office (ICO) enforces both regimes and can currently fine up to 500,000 pounds under PECR in addition to UK GDPR penalties. In practice, ICO enforcement against email marketers has concentrated on senders who bought lists, ignored objections, or could not evidence consent; documented, targeted, low-volume B2B outreach with a clean opt-out has drawn far less action. That is an observation about enforcement patterns, not a safe harbor.

Canada: CASL

Canada's Anti-Spam Legislation (CASL) came into force on July 1, 2014 and is generally regarded as the strictest general-purpose email law in the world. It covers commercial electronic messages of any kind sent to or from Canada, and its starting position is a prohibition: no commercial message may be sent without consent plus prescribed identification and unsubscribe content. Enforcement is led by the Canadian Radio-television and Telecommunications Commission (CRTC), with roles for the Competition Bureau and the Privacy Commissioner.

Express versus implied consent

Express consent means the recipient actively agreed to receive commercial messages, with a clear request that named the sender and the purpose; it does not expire. Implied consent exists only in defined situations, chiefly an existing business relationship (for example a purchase within the previous two years, or an inquiry within the previous six months). A third route matters for B2B senders: the conspicuous publication exception. If a person has conspicuously published their business email address, or given it to the sender, without a statement that they do not want unsolicited messages, and the message is relevant to their business role, consent can be implied. The burden of proving consent always sits with the sender, which is why CASL compliance in practice means keeping records of where every address came from and when.

Identification and unsubscribe rules

Every message must identify the sender (and anyone on whose behalf it is sent) by name, include a current mailing address plus a phone number, email address, or web address, and contain an unsubscribe mechanism that can be used in no more than two clicks. The unsubscribe must remain functional for at least 60 days after the message is sent, and requests must be honored within 10 business days.

Penalties

Administrative monetary penalties under CASL can reach 1 million Canadian dollars per violation for individuals and 10 million Canadian dollars per violation for organizations. The CRTC has issued multimillion-dollar penalties and negotiated substantial settlements since 2014. Directors and officers can be personally liable in some circumstances, which is unusual among email laws and adds to CASL's reputation for strictness.

Australia, and everywhere else

Australia: the Spam Act 2003

Australia's Spam Act 2003 predates CAN-SPAM by a few weeks and takes the opposite approach: it is consent-based. A commercial electronic message may be sent only with the recipient's consent, which may be express or inferred. Consent can be inferred from an existing business relationship, or from a business email address that was conspicuously published, provided the message is relevant to the recipient's role and the publication did not say unsolicited messages were unwanted. Every message must accurately identify the sender and include a functional unsubscribe facility that works for at least 30 days and is honored within 5 business days. The Australian Communications and Media Authority (ACMA) enforces the Act and has imposed penalties on major brands; for repeated contraventions, penalties can run to millions of Australian dollars.

Other jurisdictions in brief

Most developed economies now have an analogous regime, usually closer to the consent-based model than to CAN-SPAM. Examples include Singapore's Spam Control Act and Personal Data Protection Act, Japan's Act on Regulation of Transmission of Specified Electronic Mail, Brazil's LGPD data protection law, and South Africa's POPIA. The recurring pattern across nearly all of them is the same triad: identify yourself truthfully, have some justification for the contact, and provide a working opt-out. A sender who builds for that triad, and then layers the stricter consent rules on top for the jurisdictions that demand them, is aligned with most of the world's rules by default.

Jurisdictions at a glance

JurisdictionMain lawRegime typeKey requirementsEnforcement body
United StatesCAN-SPAM Act (2003)Opt-outTruthful headers and subject lines, ad identification, physical postal address, opt-out honored within 10 business daysFederal Trade Commission (FTC)
European UnionGDPR + ePrivacy DirectiveConsent-based, with legitimate interest available for some B2BLawful basis for personal data, consent for individuals, sender identification, right to objectNational data protection authorities
United KingdomUK GDPR + PECRConsent-based, with a corporate subscriber exceptionConsent for individual subscribers, soft opt-in for existing customers, identification, opt-out in every messageInformation Commissioner's Office (ICO)
CanadaCASL (2014)Consent-requiredExpress or implied consent, full sender identification, unsubscribe honored within 10 business daysCRTC (with the Competition Bureau and Privacy Commissioner)
AustraliaSpam Act 2003Consent-requiredExpress or inferred consent, sender identification, functional unsubscribe honored within 5 business daysAustralian Communications and Media Authority (ACMA)
Cold email consent regimes by jurisdictionCold email consent rules by jurisdictionRegime type under each country's main statute, ordered from least to most consent requiredUnited StatesCAN-SPAM Act (2003)Opt-outNo prior consentneeded; honoropt-outs within10 business daysEU and UKGDPR + ePrivacy / PECRConsent-leaningConsent is thedefault for people;legitimate interestfor some B2BAustraliaSpam Act 2003Consent-requiredExpress or inferredconsent; unsubscribehonored within5 business daysCanadaCASL (2014)Consent-requiredExpress or impliedconsent; sendermust prove consentif challengedFewer consent requirementsMore consent requirements
Figure 2. The four major regimes on a consent spectrum. The United States allows email first and requires an opt-out; the EU and UK default to consent with a legitimate interest path for some B2B email; Australia and Canada require consent before the first message, with Canada placing the burden of proof on the sender.

Email authentication: SPF, DKIM, and DMARC

Three technical standards sit alongside the legal rules. SPF (Sender Policy Framework) lets a domain publish which servers may send email on its behalf. DKIM (DomainKeys Identified Mail) adds a cryptographic signature that proves a message was not altered and really comes from the signing domain. DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together, telling receiving servers what to do with mail that fails and reporting abuse back to the domain owner.

Authentication connects to the law in two ways. First, laws such as CAN-SPAM prohibit false or misleading header information, and properly configured SPF, DKIM, and DMARC are how a sender demonstrates at the protocol level that its headers are genuine. Second, authentication has become a de facto sending requirement regardless of law: in 2024 Google and Yahoo began requiring bulk senders to authenticate with SPF, DKIM, and DMARC, to support one-click unsubscribe, and to keep spam complaint rates low. A legally compliant cold email that is not authenticated will increasingly never reach an inbox, so in practice the legal checklist and the deliverability checklist have converged.

Common misconceptions

  • "B2B email is unregulated." False everywhere. CAN-SPAM, CASL, and the Spam Act all cover business recipients. The UK's corporate subscriber exception narrows one specific consent rule; it does not remove the identification, honesty, or opt-out duties, and the UK GDPR still applies to a named person's work address.
  • "One opt-out link is enough everywhere." The mechanics differ. CAN-SPAM allows any workable mechanism, honored within 10 business days and live for 30 days after sending. CASL requires a two-click maximum, a 60-day working window, and 10 business days to honor. Australia requires the facility to work for 30 days and to be honored within 5 business days. A sender operating globally has to meet the strictest applicable set.
  • "GDPR banned cold email." It did not. GDPR regulates personal data and provides lawful bases, including legitimate interest, that documented B2B outreach can rely on in many member states and the UK. What GDPR ended is undocumented emailing of scraped consumer lists.
  • "The sender's location decides which law applies." These laws protect recipients (and, for CASL, messages routed through Canada), so a US sender emailing prospects in Toronto or Berlin is inside CASL or GDPR territory regardless of where the sending server sits.
  • "Small senders are ignored." Enforcement does skew toward large or egregious operations, but regulators in the UK and Canada have penalized small firms, and per-message penalty structures mean exposure scales with volume, not with company size.

A practical compliance checklist

  • Use truthful sender, subject, and header information, and authenticate the sending domain with SPF, DKIM, and DMARC.
  • Include a real, monitored way to opt out in every message, honor requests within 10 business days at the latest (5 for Australia), and keep the mechanism working for at least 60 days to satisfy the strictest rule.
  • Maintain a suppression list of everyone who has opted out and check it before every send.
  • Provide a valid physical mailing address and full sender identification, including anyone on whose behalf the message is sent.
  • Segment lists by recipient country and apply consent rules where the recipient is located: express or implied consent for Canada, express or inferred consent for Australia, consent or a documented legitimate interest assessment for the EU and UK.
  • Record where every address came from and when, so consent or the basis for contact can be evidenced later.
  • Do not use harvested or scraped lists in ways the applicable law prohibits, and be cautious with purchased lists generally, since the seller's consent records rarely transfer cleanly.
  • Target by role relevance, keep volumes reasonable, and stop on any objection, which is both the legal floor and the behavior that keeps complaint rates low.
  • When a list mixes jurisdictions or locations are unknown, apply the strictest applicable standard.
Consent decision flow by recipient jurisdictionWhich rules apply? Start with the recipientWhere is the recipient based?United StatesEU and UKCanadaAustraliaNo consent needed.Truthful headers andsubject, postal address,working opt-out(CAN-SPAM)Consent, or documentedlegitimate interest forB2B, plus identificationand a right to object(GDPR + ePrivacy)Express or impliedconsent before sending,full identification,working unsubscribe(CASL)Express or inferredconsent, identification,unsubscribe honoredwithin 5 business days(Spam Act 2003)The recipient's location decides which rules apply.When the location is unknown or lists are mixed, meet the strictest standard.
Figure 3. A simplified decision flow. The recipient's location, not the sender's, determines which regime applies; mixed or unknown lists should be held to the strictest applicable standard. This is a summary, not legal advice.

Frequently asked questions

Is cold email legal?

In most countries cold email is legal for legitimate business purposes if you follow the applicable rules: identify yourself, tell the truth, and give a working way to opt out. The United States uses an opt-out model (CAN-SPAM), while Canada (CASL), Australia (Spam Act 2003), and, for most individual recipients, the EU and UK (GDPR and ePrivacy rules) require some form of consent or another lawful basis before sending.

Does CAN-SPAM require consent before emailing?

No. The US CAN-SPAM Act is an opt-out regime: it does not require prior consent, but it does require accurate header and sender information, a non-deceptive subject line, a valid physical postal address, and a working opt-out that is honored within 10 business days.

What is the difference between cold email and spam?

Spam is bulk, unsolicited, and often deceptive email sent indiscriminately. Compliant cold email is targeted, identifies the sender truthfully, is relevant to the recipient's role or business, and offers a clear way to opt out. The legal frameworks in most countries are designed to police deception and disregard for consent, not to ban one-to-one business outreach.

Is cold email legal under GDPR?

It can be. GDPR does not name email channels; it requires a lawful basis for processing personal data, and a work email that identifies a person counts as personal data. Many B2B senders rely on the legitimate interest basis, which requires a documented balancing of the sender's interest against the recipient's rights, plus the ePrivacy or PECR marketing rules of the recipient's country. Marketing to individual consumers generally requires consent.

Is B2B cold email exempt from email marketing laws?

No. CAN-SPAM applies to commercial email regardless of whether the recipient is a business or a consumer. CASL and Australia's Spam Act apply to commercial electronic messages generally. In the UK, PECR's consent rule targets individual subscribers rather than corporate subscribers, which gives B2B senders more room, but GDPR still governs any personal data involved, including a named person's work email address.

What penalties can cold email senders face?

Ceilings vary widely. Under CAN-SPAM, each non-compliant email can carry a civil penalty that currently exceeds $50,000. Under GDPR, fines can reach 20 million euros or 4 percent of worldwide annual turnover, whichever is higher. Under CASL, administrative penalties can reach 10 million Canadian dollars per violation for organizations. Actual enforcement outcomes are usually far below these ceilings, but the ceilings shape risk.

Do SPF, DKIM, and DMARC affect legal compliance?

Indirectly. SPF, DKIM, and DMARC are technical standards that let receiving servers verify a message really comes from the domain it claims. They support the accurate-header requirements found in laws like CAN-SPAM, and since 2024 Google and Yahoo have required bulk senders to authenticate with them, so unauthenticated cold email increasingly fails on deliverability before any legal question arises.

Which country has the strictest cold email law?

Canada's CASL is widely considered the strictest general regime: it requires express or narrowly defined implied consent before sending, places the burden of proving consent on the sender, and carries administrative penalties of up to 10 million Canadian dollars per violation for organizations. The EU and UK rules are also strict for individual recipients, with more flexibility for business-to-business messages.

References

  • U.S. Federal Trade Commission, "CAN-SPAM Act: A Compliance Guide for Business."
  • U.S. Federal Trade Commission, CAN-SPAM Rule (16 CFR Part 316) and annual civil penalty inflation adjustments.
  • UK Information Commissioner's Office, guidance on PECR and direct marketing; EU General Data Protection Regulation (Regulation 2016/679), including Recital 47.
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR); EU ePrivacy Directive 2002/58/EC.
  • Government of Canada, "Canada's Anti-Spam Legislation (CASL)"; CRTC guidance on express and implied consent.
  • Australian Communications and Media Authority (ACMA), guidance on the Spam Act 2003.
  • Google, "Email sender guidelines" (bulk sender requirements, 2024); RFC 7208 (SPF), RFC 6376 (DKIM), RFC 7489 (DMARC).
  • "Cold email," "CAN-SPAM Act of 2003," and "Canada's Anti-Spam Legislation," Wikipedia.

This reference page is maintained by Emailchaser, a cold email platform. It is general information and not legal advice; consult qualified counsel for your situation.