The short version, by market
Different countries take fundamentally different approaches, and the split that matters most is opt-out versus consent:
- United States (CAN-SPAM): opt-out. Cold email is legal without prior consent, subject to clear rules.
- EU and UK (GDPR): legal for B2B under the legitimate-interest basis, with conditions and an easy opt-out.
- Canada (CASL): consent-based and the strictest. You generally need express or implied consent before sending.
- Australia (Spam Act): broadly opt-out for most B2B, with identification and unsubscribe requirements.
Because your list often spans several of these, the safe operating standard is to meet the strictest rule that applies to anyone you are emailing, then layer on the specifics per market.
United States: CAN-SPAM
CAN-SPAM is an opt-out law, which is why US cold email is legal without asking permission first. What it requires in exchange is honesty and an exit. In practice:
- Accurate From, To, and header information that identifies who actually sent the message.
- No deceptive subject lines. The subject must reflect the content.
- A valid physical postal address in every message.
- A working opt-out mechanism, with requests honoured within ten business days.
Get those right and a US cold email is compliant. Violations can carry penalties reaching tens of thousands of dollars per message, so the list is not optional polish; it is the law.
EU and UK: GDPR
GDPR treats an email address as personal data, which makes people assume cold email is banned in Europe. It is not. GDPR permits processing under several legal bases, and for B2B outreach the standard basis is legitimate interest under Article 6(1)(f), not consent. Relying on it means, in plain terms:
- A genuine commercial reason to contact this specific person.
- Relevance to their role. Their job should plausibly match what you are offering, so the contact is something they would reasonably expect.
- An easy opt-out in every message, honoured promptly.
- Documented reasoning, often called a legitimate-interest assessment, showing you weighed your interest against their rights.
Two cautions. Emailing individuals or sole traders, rather than a corporate role at a company, can pull you into stricter ePrivacy rules (PECR in the UK) that lean toward consent, so professional, role-based addresses are safer. And GDPR penalties are severe, up to the well-known 20 million euro or 4% of global turnover ceiling, so European lists deserve genuine care rather than a copy-paste of your US approach.
Canada: CASL
CASL is the outlier and the strictest of the major regimes. It uses a consent model, so you generally need express or implied consent before sending a commercial electronic message, the reverse of CAN-SPAM. The workable path for cold outreach is usually implied consent, which can arise from an existing business relationship, or where someone has conspicuously published a business email address without saying they do not want unsolicited mail, and your message is relevant to their role. Every message must still clearly identify you and carry a working unsubscribe. With penalties that can reach millions of dollars per violation, Canadian recipients are the ones to treat most conservatively, or to route through a consent-based approach entirely.
The universal safe practices
Regardless of jurisdiction, a cold email that does all of the following is in good shape almost everywhere, and doing them also happens to help deliverability:
- Identify yourself honestly in the From line, headers, and body, and include a real physical address.
- Write honest subject lines that match the content.
- Include a clear, working unsubscribe, and honour it fast. This overlaps directly with the one-click unsubscribe now required by Gmail's bulk sender rules.
- Email business roles, not consumers, and only people your offer is genuinely relevant to.
- Keep records of your reasoning and your suppression list, so you can show a good-faith, documented process.
Where legitimate outreach becomes a violation
The lines are consistent across regimes: deception and ignoring opt-outs. Falsifying identity or headers, misleading subject lines, missing a required address, a broken or absent unsubscribe, or emailing someone after they opted out will put you offside almost anywhere. Emailing consumers instead of business contacts, or emailing Canadian recipients with no consent basis, are the other common ways a legal campaign tips into an illegal one. Notably, none of these are things a good cold sender wants to do anyway, which is why compliance and effective outreach mostly point the same direction.
Common questions
Is cold email legal?
In most major markets, yes, provided you follow that market's rules. B2B cold email is legal in the United States under CAN-SPAM (an opt-out model needing no prior consent), in the EU and UK under GDPR (using the legitimate-interest legal basis for relevant business contacts), and in Australia under the Spam Act. Canada is the strict exception: CASL generally requires consent before you send. So the real question is not whether cold email is legal but whether your specific email meets the requirements of the recipient's jurisdiction. This is general information, not legal advice.
Do I need consent to send a cold email under GDPR?
Not necessarily. GDPR treats an email address as personal data, but it allows processing under several legal bases, and for B2B cold outreach the usual basis is legitimate interest under Article 6(1)(f) rather than consent. To rely on it you need a genuine commercial reason to contact the person, their role should plausibly match what you are offering, the contact should reasonably expect business email of that kind, and you must offer an easy opt-out and be able to document your reasoning. Consumer (B2C) contacts are a stricter matter and generally need consent.
What does CAN-SPAM require for cold email?
CAN-SPAM, the US law, permits cold email without prior consent but sets clear rules: use accurate From and header information, do not use deceptive subject lines, include a valid physical postal address in every message, provide a working opt-out mechanism, and honour opt-out requests within ten business days. Meeting those is what keeps a US cold email compliant. Penalties for violations can reach tens of thousands of dollars per email, so the requirements are worth taking literally.
Why is Canada's CASL stricter than other cold email laws?
CASL uses a consent model rather than an opt-out model, so it generally requires express or implied consent before you send a commercial electronic message, which is the opposite of CAN-SPAM. Implied consent can exist, for example through an existing business relationship or where a person has conspicuously published a business email address without a statement that they do not want unsolicited mail, and the message is relevant to their role. Every message must still identify the sender and include a working unsubscribe. Penalties can be very high, so Canadian recipients warrant extra care.
What makes a cold email actually illegal?
The consistent lines across jurisdictions are deception and ignoring opt-outs. Falsifying your identity or headers, using misleading subject lines, omitting a physical address where required, failing to provide a working unsubscribe, or continuing to email someone after they opted out will put you offside almost anywhere. Emailing consumers rather than business contacts, or emailing Canadian recipients without a consent basis, are the other common ways legitimate outreach tips into a violation.