Is Cold Email Legal? A Small-Team Guide to CAN-SPAM and GDPR

Is Cold Email Legal? A Small-Team Guide to CAN-SPAM and GDPR

Dumebi Okolo

Founder and CEO of Ozigi. Writes about go-to-market, content strategy, and the tooling small teams rely on.

June 18, 202610 min readBy Dumebi OkoloMarketing, Compliance, Outreach

TL;DR: Yes, cold email is legal. B2B cold outreach is permitted in the US, EU, UK, Australia, and most major markets when you follow the rules, and Canada's CASL is the strict exception that wants consent first. In the US, CAN-SPAM uses an opt-out model: no prior consent needed, but you must be honest about who you are, include a physical address, and honor opt-outs. In the EU and UK, GDPR allows B2B cold email under a documented legitimate interest, as long as the message is relevant to the person's job. The line is simple: cold email is legal, spam is not. This is a plain-language guide, not legal advice.

One quick note before anything else: I am a founder, not a lawyer, and this is general information, not legal advice. For your specific situation, especially at scale or in a regulated industry, talk to a qualified attorney. With that said, the rules are far less scary than the rumors, and most of cold email compliance is common sense written down.

The fear that cold email is somehow illegal stops a lot of founders before they start. It should not. Here is what the actual laws say, in plain terms.

Yes. Cold email is legal in 2026 across the US, EU, UK, Australia, and most major markets, provided you follow each region's rules. The distinction that matters is not cold versus warm. It is compliant versus spam.

Regulators do not ban unsolicited business email. What they regulate is honesty, relevance, and the recipient's ability to opt out. A relevant, honest message to a decision-maker who fits your product, with a working unsubscribe and your real identity attached, is on solid ground almost everywhere. A deceptive mass blast to a purchased list is not. Same channel, opposite sides of the law.

So the question is never really "is cold email legal." It is "is my cold email compliant." Three frameworks cover most of where you will be sending.

What Does CAN-SPAM Require in the US?

CAN-SPAM runs on an opt-out model, which means you can send B2B cold email in the US without prior consent, as long as you meet its conditions. It is the most permissive of the major laws.

The requirements are straightforward:

  • Use accurate "from," "to," and routing information, so the recipient knows who is contacting them
  • Do not use deceptive or misleading subject lines, including fake "Re:" threads
  • Identify the message as an outreach email where relevant
  • Include a valid physical postal address for your business
  • Provide a clear way to opt out, and honor opt-outs within 10 business days
  • Do not email people who have already opted out

That is the whole list. The penalties for ignoring it are not small, with violations running up to roughly $53,000 per email as of early 2025, so the cheap insurance is to simply include your address and a working unsubscribe in every send.

What Does GDPR Require in the EU and UK?

GDPR requires a lawful basis before you contact someone, and for B2B cold email that basis is almost always "legitimate interest." It is stricter than CAN-SPAM on documentation and purpose, but it does not ban cold email.

Legitimate interest, under Article 6(1)(f), is a three-part test you should document before a campaign:

  • Purpose: do you have a real business reason to contact this person?
  • Necessity: is email a reasonable way to achieve it?
  • Balance: does your reason outweigh the recipient's privacy?

A relevant pitch to a decision-maker at a well-matched company usually passes. A mass blast to a scraped consumer list does not. A written Legitimate Interest Assessment is not strictly mandatory, but without one you lose the argument by default if a regulator ever asks. Beyond the basis, every GDPR-compliant cold email needs your identity, a physical address, an easy opt-out honored quickly (treat it as 24 to 48 hours, not the 10 days CAN-SPAM allows), a link to your privacy policy, and data minimization, meaning you only hold what you need.

One nuance worth knowing: enforcement varies by country. The UK ICO and France's CNIL are relatively permissive for genuine B2B outreach, Germany is stricter, and some countries such as Poland tend to expect consent even for business contacts. The UK applies its own UK GDPR post-Brexit, but for cold email purposes you can treat UK recipients the same as EU ones.

What About Canada, Australia, and Elsewhere?

Canada's CASL is the strict outlier and requires consent before you send, not just an opt-out afterward. Australia's Spam Act is closer to an opt-out model for most B2B. Most other major markets fall somewhere between the US and EU approaches.

CASL stands apart because it requires express or implied consent before the first message. For B2B, implied consent can exist through a "conspicuously published" business contact, for example an email address a company lists publicly without a note saying it does not want outreach, but the bar is higher than CAN-SPAM's opt-out model, and penalties reach into the millions per violation. If you send into Canada at any volume, read CASL specifically rather than assuming your US approach transfers.

The practical takeaway for a small team selling globally: build to the stricter standard. If your process satisfies GDPR's legitimate interest and documentation, it comfortably clears CAN-SPAM, and you only need to layer CASL's consent rule on top for Canadian contacts.

What Makes a Cold Email Compliant in Practice?

A compliant cold email is honest about who sent it, relevant to the recipient's job, sourced from a professional context, and easy to opt out of. Hit those four and you satisfy most of what every framework asks.

A checklist that works across jurisdictions:

  • Your real name, company, and a physical postal address are present
  • The subject line is honest and not a fake reply
  • The message is clearly relevant to the person's professional role
  • The contact was sourced from a professional context, such as a company site, a public profile, or a directory, and you can say where
  • There is a one-click way to opt out, honored fast
  • A link to your privacy policy is included for EU and UK recipients
  • You do not re-email anyone who opts out

Sourcing from professional context matters more than people realize. Pulling a developer's public profile from GitHub or a professional directory is defensible. Buying or scraping a non-contextual consumer list is the practice that draws fines. This is one reason sourcing leads from public professional platforms sits on firmer ground than a bought list.

Where Do Small Teams Usually Slip Up?

The common mistakes are mundane: a missing physical address, a deceptive subject line, ignored opt-outs, and no documented basis for emailing EU contacts. None of these require a lawyer to avoid.

For US senders, the most frequent oversight is leaving out the postal address and mimicking reply threads to boost opens. For anyone emailing the EU, it is having no documented legitimate interest in the privacy policy and failing to process deletion requests in time. And across the board, the quiet reputation killer is continuing to email people who never engaged or who opted out, which is both a compliance risk and a deliverability one. A tool that tracks opt-outs and stops sequences on reply, like the Ozigi GTM engine, removes most of these slip-ups by making the compliant behavior the default, though the legal responsibility still sits with you. You can see how a compliant email reads by generating one for free with Ozigi's cold email generator, no signup required.

Frequently Asked Questions

Is cold email legal? Yes. B2B cold email is legal in the US, EU, UK, Australia, and most major markets when you follow each region's rules. The US uses an opt-out model under CAN-SPAM, the EU and UK allow it under GDPR's legitimate interest basis, and Canada's CASL is the strict exception that requires consent first. Cold email is legal; spam is not.

Do I need consent to send cold email? In the US under CAN-SPAM, no. You can send without prior consent as long as you include a physical address, an honest subject, and a working opt-out. In the EU and UK, you need a lawful basis, usually documented legitimate interest. In Canada under CASL, you generally do need consent before the first message.

Is cold email illegal under GDPR? No, this is a common myth. GDPR permits B2B cold email under the legitimate interest basis when the message is relevant to the recipient's professional role and you have documented a three-part assessment. Personal, consumer-facing cold email is a different matter and generally requires consent.

What must every compliant cold email include? Your real identity and company, a physical postal address, an honest subject line, a clear and quick opt-out, and, for EU and UK recipients, a link to your privacy policy. The message should be relevant to the person's job and sent to a contact sourced from a professional context, not a purchased consumer list.

Can I email leads I found on GitHub or LinkedIn? Generally yes for B2B outreach, because those are professional contexts and the contact relates to the person's work, which supports a legitimate interest basis. Keep the message relevant, include an opt-out and your address, and record where you sourced the contact. Buying or scraping non-contextual lists is the practice that draws regulatory attention.

What happens if I break these rules? Penalties are real: CAN-SPAM violations run up to about $53,000 per email, GDPR fines reach into the millions or a percentage of global revenue, and CASL penalties are similarly steep. Most enforcement targets deceptive or large-scale operations, but a small team should still include the basics in every send and document its basis.

Sources and Further Reading

External references used in this article:

Related Ozigi reading:


This article is general information, not legal advice. Confirm the rules for your jurisdiction and situation with a qualified attorney. Ozigi builds compliant defaults into outreach, one-click unsubscribe, opt-out tracking, and sending from your own accounts, so the basics are handled while the responsibility stays yours. Try the free cold email generator — no signup required.

About the author

Dumebi Okolo

Founder and CEO of Ozigi. Writes about go-to-market, content strategy, and the tooling small teams rely on.