TL;DR
Cold B2B email is legal in the US under CAN-SPAM with no prior consent required, is legal in the UK to corporate addresses under PECR with no consent but is restricted to individuals, is legal in the EU only with a lawful basis under GDPR (usually legitimate interest for B2B), requires express or implied consent in Canada under CASL, and is regulated in Australia under the SPAM Act 2003. In every jurisdiction you must identify yourself, provide a physical address, and honour opt-outs.
Last reviewed: 2026-09
Sources and jurisdictional rules on this page were re-checked in September 2026. We revisit this post quarterly. Enforcement guidance can shift between reviews, so treat this as a current-quarter map, not a permanent one.
Not legal advice
This post is a starting map, written by operators for operators. It is not legal advice. Rules change, enforcement changes, and edge cases matter. If your outreach is at scale or crosses borders, talk to a lawyer in each relevant jurisdiction.
How do the five jurisdictions compare?
Rules by jurisdiction at a glance
| Jurisdiction | Consent needed? | Opt-out required? | Physical address in email? | Enforcement body | Max penalty |
|---|---|---|---|---|---|
| US (CAN-SPAM) | No prior consent needed | Yes, honour within 10 business days | Yes, valid postal address | FTC | Up to USD 51,744 per email |
| UK (PECR + UK GDPR) | No for corporate subscribers, yes (or soft opt-in) for individuals | Yes | Yes, identity + how to contact | ICO | Up to GBP 17.5m or 4% of global turnover |
| EU (GDPR + ePrivacy) | Lawful basis required (legitimate interest for B2B is common) | Yes | Yes, controller identity + contact | National DPAs, EDPB coordinates | Up to EUR 20m or 4% of global turnover |
| Canada (CASL) | Express or implied consent required | Yes, functional within 10 business days | Yes, sender identification + address | CRTC | Up to CAD 10m per violation (org) |
| Australia (SPAM Act 2003) | Consent required (express or inferred) | Yes, functional and free | Yes, accurate sender info | ACMA | Up to AUD 2.22m per day for repeat offenders |
- Jurisdiction
- US (CAN-SPAM)
- Consent needed?
- No prior consent needed
- Opt-out required?
- Yes, honour within 10 business days
- Physical address in email?
- Yes, valid postal address
- Enforcement body
- FTC
- Max penalty
- Up to USD 51,744 per email
- Jurisdiction
- UK (PECR + UK GDPR)
- Consent needed?
- No for corporate subscribers, yes (or soft opt-in) for individuals
- Opt-out required?
- Yes
- Physical address in email?
- Yes, identity + how to contact
- Enforcement body
- ICO
- Max penalty
- Up to GBP 17.5m or 4% of global turnover
- Jurisdiction
- EU (GDPR + ePrivacy)
- Consent needed?
- Lawful basis required (legitimate interest for B2B is common)
- Opt-out required?
- Yes
- Physical address in email?
- Yes, controller identity + contact
- Enforcement body
- National DPAs, EDPB coordinates
- Max penalty
- Up to EUR 20m or 4% of global turnover
- Jurisdiction
- Canada (CASL)
- Consent needed?
- Express or implied consent required
- Opt-out required?
- Yes, functional within 10 business days
- Physical address in email?
- Yes, sender identification + address
- Enforcement body
- CRTC
- Max penalty
- Up to CAD 10m per violation (org)
- Jurisdiction
- Australia (SPAM Act 2003)
- Consent needed?
- Consent required (express or inferred)
- Opt-out required?
- Yes, functional and free
- Physical address in email?
- Yes, accurate sender info
- Enforcement body
- ACMA
- Max penalty
- Up to AUD 2.22m per day for repeat offenders
Is cold email legal in the United States?
CAN-SPAM (15 USC 7701 et seq., implementing rule 16 CFR Part 316) does not require prior consent for commercial email. It does require truthful headers, a non-deceptive subject line, clear identification as an ad if applicable, a valid physical postal address, and a working opt-out that you honour within 10 business days. Every recipient is counted separately for penalties.
FTC CAN-SPAM compliance guide (primary source) FTC.
Is cold email legal in the United Kingdom?
The Privacy and Electronic Communications Regulations (PECR) treat B2B corporate subscribers differently from individuals. You can email a role address at a company (info@, sales@, or a named employee at a corporate domain) without prior consent, provided you identify yourself and offer opt-out. Sole traders and non-limited partnerships in England, Wales, and Northern Ireland are treated as individuals and generally need consent or the soft opt-in. UK GDPR still applies to any personal data you process.
ICO direct marketing guidance (primary source) ICO.
Is cold email legal in the European Union?
GDPR requires a lawful basis for processing personal data. For B2B cold outreach the usual basis is legitimate interest (Article 6(1)(f)), which requires a documented three-part balancing test: purpose, necessity, and the recipient's rights. National ePrivacy rules layer on top and vary. Germany, for example, is stricter than Ireland. If you send at scale into the EU, run a per-country analysis rather than a single EU-wide policy.
EDPB (European Data Protection Board) EDPB.
Is cold email legal in Canada?
Canada's Anti-Spam Legislation is one of the strictest regimes. Any commercial electronic message to a Canadian recipient needs express consent, or a defined implied consent (existing business relationship, published business address without a "no unsolicited email" notice, and other narrow cases). Every message needs sender identification, a physical address, and a functional unsubscribe. Enforcement by the CRTC is active.
CRTC CASL requirements (primary source) CRTC.
Is cold email legal in Australia?
The SPAM Act 2003 requires consent (express or inferred from an existing relationship), clear sender identification, and a functional, free, working-for-30-days unsubscribe. The regulator is ACMA and fines have been substantial for repeat corporate offenders.
ACMA spam rules (primary source) ACMA.
What is a safe baseline that works everywhere?
If you want one policy that covers most B2B outreach across these five jurisdictions without a lawyer on every send, adopt this baseline. It is stricter than CAN-SPAM and looser than CASL, and it will keep you inside the guardrails for the majority of B2B cases.
The seven-point baseline
- Only email business addresses at businesses (no personal Gmail, Yahoo, iCloud).
- Only email people whose role plausibly cares about your offer (documented legitimate interest).
- Identify yourself, your company, and your postal address in every message.
- Include a plain-text unsubscribe line and a one-click List-Unsubscribe header.
- Honour opt-outs immediately and permanently. Store the suppression list forever.
- Do not email known Canadian recipients without express or valid implied consent.
- Keep a record of why you contacted each recipient (source, date, reasoning).
Deliverability guide: why cold emails go to spam Deliverability.
The one thing to remember
Cold B2B email is legal across every major English-speaking jurisdiction when you identify yourself honestly, publish a real postal address, honour opt-outs immediately, and can point to why you contacted each recipient. The variance across borders is in consent thresholds and enforcement appetite, not the fundamentals.
FAQ
Is cold email legal in the US?
Yes, under CAN-SPAM, without prior consent, provided you follow the header, address, and opt-out rules.
Do I need consent to email a business in the EU?
You need a lawful basis under GDPR. For B2B outreach that is usually legitimate interest, documented with a three-part balancing test. Some member states add stricter ePrivacy rules on top.
Can I email Canadian prospects at all?
Yes, but only with express consent or a defined implied consent (existing business relationship or a publicly listed business address with no "no unsolicited email" notice).
What must every cold email include?
Your real identity, your company name, a valid physical address, and a working way to opt out. In practice, put a footer that covers all four every time.