Cold Email Compliance Across Jurisdictions: CAN-SPAM, GDPR, CASL and Beyond
On this page
Why Jurisdiction Matters
Cold email rules vary dramatically by country. An email that is perfectly legal under US law may violate European or Canadian law. If you send cold emails to people in multiple countries, you need to comply with the strictest rules that apply.
The key question is not where you are located. It is where the recipient is located. A company in the US sending to a prospect in Germany must comply with GDPR. A Canadian company emailing a prospect in Australia must comply with the Australian Spam Act.
United States: CAN-SPAM Act
What it covers
The CAN-SPAM Act (Controlling the Assault of Non-Solicited Pornography and Marketing Act, 2003) governs all commercial email messages sent to US recipients.
Key rules
No prior consent required. CAN-SPAM does not require opt-in consent before sending commercial email. You can email someone who has not opted in, provided you follow the other rules.
Accurate headers. The "From," "To," "Reply-To" and routing information must be accurate and identify the person or business sending the message.
No deceptive subject lines. The subject line must not mislead the recipient about the content of the message.
Identify as advertising. The message must be identified as an advertisement, though the law gives flexibility in how.
Physical address. Every commercial email must include your valid physical postal address.
Opt-out mechanism. Every email must include a clear and conspicuous way to opt out of future emails.
Honour opt-outs within 10 business days. Once someone opts out, you must stop emailing them within 10 business days.
You are responsible for third parties. If you hire someone to send email on your behalf, you are still legally responsible for compliance.
Penalties
The FTC’s compliance guide, checked on 8 October 2026, lists up to $53,088 per email in violation. Criminal penalties possible for aggravated violations.
Practical implications for cold email
CAN-SPAM is relatively permissive for cold email. You do not need prior consent. You just need accurate headers, a physical address, an opt-out mechanism and honest subject lines. This is why the US is the most active cold email market.
European Union/UK: GDPR and ePrivacy
What it covers
The General Data Protection Regulation (GDPR) governs the processing of personal data of individuals in the EU/EEA. The UK has its own version (UK GDPR) that works similarly. The ePrivacy Directive (implemented nationally, e.g., PECR in the UK) adds specific rules for electronic communications.
Key rules
Legal basis required. You need a legal basis to process someone's personal data (including their email address). For B2B cold email, the most commonly cited basis is "legitimate interest."
Legitimate interest test. To use legitimate interest, you must demonstrate:
- You have a legitimate reason to contact them (business purpose).
- The processing is necessary for that purpose.
- The individual's rights do not override your interest.
Data minimisation. Collect only the data you need.
Right to object. Recipients can object to processing at any time, and you must stop.
Right to erasure. Recipients can request deletion of their data.
Transparency. You must be clear about who you are, why you are emailing and how you obtained their data.
Record-keeping. Document your legal basis, data sources and processing activities.
B2B vs B2C distinction
Some EU member states (and the UK's PECR) distinguish between B2B and B2C email:
- B2B: Cold email may be allowed under legitimate interest, depending on the member state's implementation.
- B2C: Generally requires prior opt-in consent (not just legitimate interest).
This distinction varies by country. Germany is stricter than the UK. France has different rules than the Netherlands.
Penalties
Up to 20 million EUR or 4% of global annual turnover, whichever is higher.
Practical implications for cold email
GDPR makes cold email to EU/UK prospects possible but more restrictive than CAN-SPAM. You need a documented legitimate interest, transparency about data sourcing, easy opt-out, and you must honour data deletion requests promptly.
See GDPR Email Marketing Checklist.
Canada: CASL
What it covers
Canada's Anti-Spam Legislation (CASL, 2014) governs commercial electronic messages (email, SMS, social media messages) sent to or from Canadian computer systems.
Key rules
Express or implied consent required. This is the critical difference from CAN-SPAM. You cannot email someone in Canada without some form of consent.
Express consent: The recipient explicitly opted in to receive your emails. Must be documented.
Implied consent exists in limited situations:
- Existing business relationship (purchased from you within the last 2 years, or had a contract within the last 2 years).
- Existing non-business relationship (membership, volunteer, donation within the last 2 years).
- Publicly available email address (published in a directory, on a website, in an advertisement) AND your message is relevant to their business or role. This is the narrow opening for B2B cold email in Canada.
- Referral (someone gave you their contact, but you can only send one message).
Identification. The message must clearly identify you, include your physical mailing address and include contact information.
Unsubscribe mechanism. Must include a working unsubscribe mechanism that remains functional for at least 60 days after sending.
Honour unsubscribes within 10 business days.
Penalties
The CRTC’s current CASL enforcement guidance states maximum administrative monetary penalties of CAD $1 million per violation for individuals and CAD $10 million for businesses. The Government of Canada suspended implementation of CASL’s private right of action; do not describe that proposed lawsuit mechanism as an active right under CASL.
Practical implications for cold email
CASL is significantly stricter than CAN-SPAM. The "publicly available email + relevant message" implied consent provision is the only practical path for cold B2B email in Canada, and it is narrow. Many companies choose to avoid cold email to Canadian prospects entirely unless they have a clear implied or express consent basis.
See CASL Guide.
Australia: Spam Act 2003
What it covers
The Spam Act 2003 governs commercial electronic messages with an Australian link (sent from Australia, originating from an Australian server, or sent to an Australian address).
Key rules
Consent required. Either express consent (opt-in) or inferred consent (existing business relationship, or conspicuously published email address in a business context).
Identify the sender. The message must clearly identify the sender with accurate information.
Include an unsubscribe facility. Must be functional for at least 30 days after sending.
Honour unsubscribes within 5 business days.
Penalties
Up to AUD $2.22 million per day for individuals, AUD $11.1 million per day for companies.
Practical implications
Similar to CASL. B2B cold email is possible when the recipient's email address is conspicuously published in a business context and the message relates to their business, but the law is stricter than CAN-SPAM.
Other Jurisdictions
Brazil: LGPD
Brazil's Lei Geral de Protecao de Dados (LGPD) is similar to GDPR. Requires a legal basis for processing personal data. Consent or legitimate interest can apply to B2B cold email.
India: IT Act and proposed DPDP Act
India's digital privacy framework is evolving. The Digital Personal Data Protection Act (DPDP) requires consent for processing personal data, with some exceptions for "legitimate uses." B2B cold email rules are still being clarified.
Japan: Act on Regulation of Transmission of Specified Electronic Mail
Requires prior opt-in consent for commercial email. Exceptions for existing business relationships and business cards exchanged at events.
South Korea: Information and Communications Network Act
Requires prior express consent for advertising emails. Stricter than most jurisdictions.
Singapore: Spam Control Act
Allows unsolicited commercial email but requires unsubscribe mechanisms, accurate sender identification and honouring opt-outs within 10 business days. More similar to CAN-SPAM than GDPR.
China: Personal Information Protection Law (PIPL)
Requires consent for processing personal data. Strict data localisation requirements. Cold email to Chinese prospects requires careful compliance assessment.
Jurisdiction Comparison
| Jurisdiction | Consent required? | B2B exception? | Max penalty |
|---|---|---|---|
| US (CAN-SPAM) | No | N/A (no consent needed) | $53,088/email |
| EU (GDPR/ePrivacy) | Legitimate interest or consent | Varies by member state | 4% of global revenue |
| UK (GDPR/PECR) | Legitimate interest for B2B, consent for B2C | Yes | 4% of global revenue |
| Canada (CASL) | Yes (express or implied) | Narrow (publicly available + relevant) | Up to CAD $1M individual / $10M business per violation |
| Australia (Spam Act) | Yes (express or inferred) | Narrow (published business email) | AUD $11.1M/day |
| Brazil (LGPD) | Legitimate interest or consent | Possible via legitimate interest | 2% of revenue |
| Japan | Yes (opt-in) | Business card exchange | JPY 1M+ |
| Singapore | No | N/A | SGD $25/message |
Multi-Jurisdiction Compliance Checklist
If you send cold emails internationally, follow these rules to comply with the strictest common requirements:
Before sending:
- Document your legal basis. For each country you email, document why you are allowed to email that recipient (CAN-SPAM compliance, GDPR legitimate interest assessment, CASL implied consent basis).
- Record data sources. Document where you obtained each email address and when.
- Verify addresses. Invalid addresses waste your effort and hurt deliverability. See Best Email Verification Services.
- Segment by country. Apply the appropriate rules for each recipient's country.
In every email:
- Accurate sender identity. Your real name or company name in the "From" field.
- Honest subject line. No misleading or deceptive subject lines.
- Physical address. Include your business mailing address.
- Clear unsubscribe mechanism. One-click or easy-to-use opt-out.
- Identify as commercial. Make it clear this is a business communication.
- State how you found them. For GDPR compliance, briefly mention how you obtained their contact (e.g., "I found your contact on your company website").
After sending:
- Honour opt-outs immediately. Do not wait the maximum allowed period. Process opt-outs the same day.
- Handle data requests. Respond to deletion, access and correction requests within the required timeframes.
- Maintain suppression lists. Cross-reference all future sends against your suppression list.
- Keep records. Archive all consent records, opt-out requests and data processing documentation.
When in Doubt
If you are unsure whether cold email is legal for a specific recipient or jurisdiction:
- Consult a lawyer with expertise in the relevant country's data protection and electronic communications law.
- Default to the strictest standard. If you cannot determine which rules apply, follow CASL or GDPR (the strictest major frameworks).
- Consider alternatives. LinkedIn outreach, content marketing, paid advertising and referrals may be more appropriate for jurisdictions with strict cold email rules.
- Use professional tools. Tools that filter by geography can help you avoid sending to jurisdictions where you lack a legal basis.