TL;DR

Cold B2B email is legal in the US under CAN-SPAM with no prior consent required, is legal in the UK to corporate addresses under PECR with no consent but is restricted to individuals, is legal in the EU only with a lawful basis under GDPR (usually legitimate interest for B2B), requires express or implied consent in Canada under CASL, and is regulated in Australia under the SPAM Act 2003. In every jurisdiction you must identify yourself, provide a physical address, and honour opt-outs.

Last reviewed: 2026-09

Sources and jurisdictional rules on this page were re-checked in September 2026. We revisit this post quarterly. Enforcement guidance can shift between reviews, so treat this as a current-quarter map, not a permanent one.

Not legal advice

This post is a starting map, written by operators for operators. It is not legal advice. Rules change, enforcement changes, and edge cases matter. If your outreach is at scale or crosses borders, talk to a lawyer in each relevant jurisdiction.

How do the five jurisdictions compare?

Rules by jurisdiction at a glance

  • Jurisdiction
    US (CAN-SPAM)
    Consent needed?
    No prior consent needed
    Opt-out required?
    Yes, honour within 10 business days
    Physical address in email?
    Yes, valid postal address
    Enforcement body
    FTC
    Max penalty
    Up to USD 51,744 per email
  • Jurisdiction
    UK (PECR + UK GDPR)
    Consent needed?
    No for corporate subscribers, yes (or soft opt-in) for individuals
    Opt-out required?
    Yes
    Physical address in email?
    Yes, identity + how to contact
    Enforcement body
    ICO
    Max penalty
    Up to GBP 17.5m or 4% of global turnover
  • Jurisdiction
    EU (GDPR + ePrivacy)
    Consent needed?
    Lawful basis required (legitimate interest for B2B is common)
    Opt-out required?
    Yes
    Physical address in email?
    Yes, controller identity + contact
    Enforcement body
    National DPAs, EDPB coordinates
    Max penalty
    Up to EUR 20m or 4% of global turnover
  • Jurisdiction
    Canada (CASL)
    Consent needed?
    Express or implied consent required
    Opt-out required?
    Yes, functional within 10 business days
    Physical address in email?
    Yes, sender identification + address
    Enforcement body
    CRTC
    Max penalty
    Up to CAD 10m per violation (org)
  • Jurisdiction
    Australia (SPAM Act 2003)
    Consent needed?
    Consent required (express or inferred)
    Opt-out required?
    Yes, functional and free
    Physical address in email?
    Yes, accurate sender info
    Enforcement body
    ACMA
    Max penalty
    Up to AUD 2.22m per day for repeat offenders
Cold email rules by jurisdiction, 2026.

Is cold email legal in the United States?

CAN-SPAM (15 USC 7701 et seq., implementing rule 16 CFR Part 316) does not require prior consent for commercial email. It does require truthful headers, a non-deceptive subject line, clear identification as an ad if applicable, a valid physical postal address, and a working opt-out that you honour within 10 business days. Every recipient is counted separately for penalties.

FTC CAN-SPAM compliance guide (primary source) FTC.

Is cold email legal in the United Kingdom?

The Privacy and Electronic Communications Regulations (PECR) treat B2B corporate subscribers differently from individuals. You can email a role address at a company (info@, sales@, or a named employee at a corporate domain) without prior consent, provided you identify yourself and offer opt-out. Sole traders and non-limited partnerships in England, Wales, and Northern Ireland are treated as individuals and generally need consent or the soft opt-in. UK GDPR still applies to any personal data you process.

ICO direct marketing guidance (primary source) ICO.

Is cold email legal in the European Union?

GDPR requires a lawful basis for processing personal data. For B2B cold outreach the usual basis is legitimate interest (Article 6(1)(f)), which requires a documented three-part balancing test: purpose, necessity, and the recipient's rights. National ePrivacy rules layer on top and vary. Germany, for example, is stricter than Ireland. If you send at scale into the EU, run a per-country analysis rather than a single EU-wide policy.

EDPB (European Data Protection Board) EDPB.

Is cold email legal in Canada?

Canada's Anti-Spam Legislation is one of the strictest regimes. Any commercial electronic message to a Canadian recipient needs express consent, or a defined implied consent (existing business relationship, published business address without a "no unsolicited email" notice, and other narrow cases). Every message needs sender identification, a physical address, and a functional unsubscribe. Enforcement by the CRTC is active.

CRTC CASL requirements (primary source) CRTC.

Is cold email legal in Australia?

The SPAM Act 2003 requires consent (express or inferred from an existing relationship), clear sender identification, and a functional, free, working-for-30-days unsubscribe. The regulator is ACMA and fines have been substantial for repeat corporate offenders.

ACMA spam rules (primary source) ACMA.

What is a safe baseline that works everywhere?

If you want one policy that covers most B2B outreach across these five jurisdictions without a lawyer on every send, adopt this baseline. It is stricter than CAN-SPAM and looser than CASL, and it will keep you inside the guardrails for the majority of B2B cases.

The seven-point baseline

  • Only email business addresses at businesses (no personal Gmail, Yahoo, iCloud).
  • Only email people whose role plausibly cares about your offer (documented legitimate interest).
  • Identify yourself, your company, and your postal address in every message.
  • Include a plain-text unsubscribe line and a one-click List-Unsubscribe header.
  • Honour opt-outs immediately and permanently. Store the suppression list forever.
  • Do not email known Canadian recipients without express or valid implied consent.
  • Keep a record of why you contacted each recipient (source, date, reasoning).

Deliverability guide: why cold emails go to spam Deliverability.

The one thing to remember

Cold B2B email is legal across every major English-speaking jurisdiction when you identify yourself honestly, publish a real postal address, honour opt-outs immediately, and can point to why you contacted each recipient. The variance across borders is in consent thresholds and enforcement appetite, not the fundamentals.

FAQ

Is cold email legal in the US?

Yes, under CAN-SPAM, without prior consent, provided you follow the header, address, and opt-out rules.

Do I need consent to email a business in the EU?

You need a lawful basis under GDPR. For B2B outreach that is usually legitimate interest, documented with a three-part balancing test. Some member states add stricter ePrivacy rules on top.

Can I email Canadian prospects at all?

Yes, but only with express consent or a defined implied consent (existing business relationship or a publicly listed business address with no "no unsolicited email" notice).

What must every cold email include?

Your real identity, your company name, a valid physical address, and a working way to opt out. In practice, put a footer that covers all four every time.