Nothing in this article is legal advice, and anyone who tells you a blog post can replace advice for your specific situation is selling something. What follows is a practical map of the rules, the kind you can act on while you wait for a proper answer from someone qualified.
The short version: cold email is legal in most of the world when you contact a business for a genuine business reason, say who you are, and stop when asked. The detail is where it gets interesting.
The one distinction that governs everything
Before any jurisdiction, learn this split, because it decides more outcomes than any other factor:
| You are contacting | Treatment |
|---|---|
| A corporate subscriber (a limited company, a partnership in some markets, an employee at a business address) | Permissive in most markets |
| An individual (personal address, sole trader in many markets, consumer) | Restrictive nearly everywhere |
info@acmelimited.com and sarah.jones@gmail.com are not the same thing in the eyes of any regulator, even if Sarah runs a business. Get this distinction into your list-building process and most compliance problems disappear before they start.
United States: CAN-SPAM
The most permissive of the major regimes, and the most misunderstood. CAN-SPAM is an opt-out law: you may send commercial email without prior consent, provided you follow the rules.
What it requires:
- Accurate header information. The From, Reply-To and routing details must identify who actually sent the message.
- Non-deceptive subject lines. The subject must reflect the content.
- Identification as an advertisement, where the message is commercial in nature.
- A valid physical postal address in the message.
- A clear opt-out mechanism that works.
- Opt-outs honoured within 10 business days, and no transfer or sale of an address after someone opts out.
Penalties are assessed per message, which is how modest campaigns produce eye-watering theoretical exposure. Note also that some US states layer additional requirements on top, and that separate rules govern text and phone contact.
European Union and United Kingdom: GDPR plus ePrivacy
Two overlapping regimes, which is where most of the confusion originates.
GDPR governs personal data: collecting it, storing it, using it. A business email address that identifies a person, such as sarah.jones@acme.com, is personal data. A generic info@acme.com generally is not.
ePrivacy rules (implemented as PECR in the UK, and variously across member states) govern electronic marketing specifically.
For business-to-business email in most implementations, the practical position is:
- You may rely on legitimate interests as your lawful basis for contacting a relevant business contact, rather than needing prior consent.
- You must be able to show your reasoning. A short documented assessment weighing your interest against the recipient's rights is what "legitimate interests" actually requires, and writing one takes twenty minutes.
- You must tell people what you are doing. Recipients have the right to know where you got their data, why you are processing it, and how to object. In practice this means a reachable privacy notice and an honest answer if asked.
- Individuals and, in several member states, sole traders and partnerships require consent. National implementations differ meaningfully here. Germany is notably stricter than the UK; Italy and France have their own positions.
- Objections and erasure requests must be honoured, and honoured properly, which means suppression rather than deletion (you need a record in order to keep not contacting them).
The single most common mistake is treating "GDPR" as a ban. It is not a ban. It is a requirement to have a reason, to be transparent about it, and to stop on request.
Canada: CASL
The strictest major regime, and the one people forget until they send to a .ca domain.
CASL requires consent before the first message, either express (they actively agreed) or implied. Implied consent is broader than it sounds and covers, among other things:
- an existing business relationship within the last two years;
- an enquiry from them within the last six months;
- a business email address published conspicuously without a statement refusing unsolicited messages, where your message is relevant to their role.
That last route is what makes business outreach to Canada workable. It is also narrow: the address must be published by them, publicly, and your message must be relevant to the recipient's professional function. A published address is not a general licence.
CASL also requires clear identification, contact details valid for 60 days, and a working unsubscribe honoured within 10 business days. The burden of proving consent sits with the sender, so keep a record of where each address came from.
Everywhere else, briefly
| Market | Position |
|---|---|
| Australia | Consent-based (Spam Act), with inferred consent for published business addresses relevant to the role |
| India | Sector rules for telecoms and messaging; email less strictly regulated |
| Brazil | LGPD closely mirrors GDPR, including legitimate interests |
| UAE and Gulf | Increasingly consent-based, with newer data protection laws |
| Singapore | PDPA, with a do-not-call registry covering phone and messaging |
The general direction of travel worldwide is towards consent. Building your process around the stricter standard is a hedge that costs you very little.
What actually gets people in trouble
Regulators have limited resources and they aim them at patterns, not at individuals sending thoughtful emails. In practice, enforcement and complaints cluster around:
- Ignoring opt-outs. The single most common trigger, and the most indefensible.
- Deception. Fake sender names, misleading subject lines, forged headers, false claims.
- Volume without relevance. Mass sends to purchased lists with no plausible connection to the recipient.
- Contacting individuals as though they were businesses. Personal addresses treated as fair game.
- No identification. No company name, no address, no way to work out who is writing.
Notice that none of these describe someone sending forty well-researched emails a day to relevant businesses. That is not an accident.
The commercial enforcement that arrives first
Long before a regulator notices you, three other parties will:
- Mailbox providers, who will filter or block you based on complaint rates.
- Blocklist operators, who can take your domain out of circulation across thousands of receiving servers at once.
- Your own platform, which suspends accounts that generate abuse reports, because one bad sender damages every other customer on shared infrastructure.
For a small business these are the real risks. They are faster, they need no legal process, and there is often no appeal.
Six habits that keep you clean in every jurisdiction
- Contact businesses, not individuals. Published business addresses, business context, business relevance.
- Be identifiable. Real name, real company, real address, real reply-to. If you would not put your name to it, do not send it.
- Make opting out effortless, and put the unsubscribe mechanism in every commercial message including follow-ups.
- Honour every opt-out immediately, permanently and workspace-wide. Not per campaign. Everywhere, forever.
- Record where every contact came from. Source and date. This is your defence under CASL and your evidence under GDPR, and it costs nothing to capture at the point of collection.
- Keep it relevant. Relevance is not just good marketing, it is a legal argument. "Why did you think this was appropriate to send?" is a question you want a good answer to.
Platforms can help with the mechanics: unsubscribe headers, workspace-wide suppression and verification mean the technical compliance happens whether or not anyone remembers it. But the judgement calls, who you contact and why, stay with you. No tool can hold a lawful basis on your behalf.
Do the six things above and you are, in practice, in a defensible position nearly everywhere. Skip number four and no amount of paperwork will save you.
