Published 30 September 2026

Cold email laws in 2026, CAN-SPAM and GDPR for B2B outbound

Cold email laws decide what you can send, to whom and how you must behave when someone says no. B2B cold email is lawful in many markets when you follow the rules, but the rules differ between the United States, the European Union, the United Kingdom and Canada. This guide explains the main frameworks in plain language and ends with a checklist you can apply to every campaign.

This article explains the general shape of the rules as we understand them. It is not legal advice and it does not replace a lawyer who knows your company, your markets and your data. Laws, guidance and penalty amounts change, and national rules inside the EU differ. If you send at scale into several jurisdictions, get a short written opinion for your situation and review it once a year.

What CAN-SPAM requires from a B2B sender

In the United States the main federal law is the CAN-SPAM Act, enforced by the Federal Trade Commission. It applies to commercial email, meaning messages whose main purpose is to advertise or promote a product or service, and it makes no exception for business to business email. CAN-SPAM does not require prior consent. Instead it sets rules about honesty and about opting out.

  • Header information must be accurate: the from name, from address, reply to and routing must identify the sender truthfully
  • Subject lines must not be deceptive about the content of the message
  • The message must be identifiable as an advertisement; in a plain one to one style sales email this is generally satisfied by an honest commercial message, but nothing may disguise its purpose
  • Every message must include a valid physical postal address of the sender, which can be a street address, a registered post office box or a private mailbox
  • Every message must explain clearly how to opt out of future email, and the opt out mechanism must keep working for at least 30 days after sending
  • Opt out requests must be honoured within 10 business days, without charging a fee or asking for more than an email address and preferences
  • After someone opts out you may not sell or transfer their address, except to a company helping you comply
  • You stay responsible for email sent on your behalf, so agencies and their clients both carry the obligation

CAN-SPAM penalties and practical risk

Each email that breaks the law can carry a civil penalty, and the maximum amount per email is adjusted for inflation every year and is above 50 000 USD. Deceptive practices can also bring other consumer protection claims. In practice the bigger day to day risk for most B2B senders is deliverability: recipients who cannot opt out mark messages as spam, and spam complaints damage your domain long before any regulator notices you.

How GDPR applies to B2B cold email

In the European Union, and in the European Economic Area, the General Data Protection Regulation applies to personal data, and a named work email address such as [email protected] is personal data. GDPR therefore applies to B2B prospecting whenever you process information about identifiable people, even in their professional role. Generic addresses such as info@ or sales@ carry less personal data, but the email marketing rules discussed below can still apply.

GDPR does not demand consent for every use of personal data. It requires a lawful basis. For B2B outreach the basis most senders rely on is legitimate interest, and the regulation itself states that direct marketing may be regarded as a legitimate interest. That is not automatic approval: you have to show it.

  • Purpose test: identify the business interest you pursue, for example offering a relevant service to companies in a defined segment
  • Necessity test: show that processing this specific contact data is needed for that purpose and that you collect no more than you need
  • Balancing test: weigh your interest against the person's rights and reasonable expectations; a relevant offer to someone in a matching job role is easier to justify than a broad blast
  • Record the assessment in writing and keep it with your campaign documentation

Transparency, objection and deletion under GDPR

When you collect personal data from somewhere other than the person, for example from a public company website, GDPR requires you to inform them about the processing. If you use the data to contact them, that information is due at the latest at the first communication, and in any case within one month. In practice that means a short note in your email or a clear link to a privacy notice explaining who you are, where the data came from, why you use it and how to object.

People have an absolute right to object to direct marketing. Once someone objects, you must stop using their data for marketing, with no balancing test. They also have the rights of access and erasure, so you need a way to find every record about a person and delete it on request. Keep data only as long as the campaign purpose justifies, and do not keep cold prospects forever.

The EU email marketing rules sit next to GDPR

GDPR is not the only rule. Electronic marketing is also covered by the ePrivacy Directive as implemented in each member state's national law, and member states treat B2B email differently. Some allow unsolicited email to business addresses under conditions, others expect prior consent even for business recipients. Germany is commonly treated as one of the strictest markets for unsolicited commercial email, while other countries are more permissive for messages relevant to the recipient's professional role. Before you scale into a specific EU country, check its national rule, not only GDPR.

GDPR fines can reach 20 million EUR or 4 percent of worldwide annual turnover for the most serious infringements, whichever is higher. Regulators usually start with complaints, and complaints usually start with an email someone could not stop.

UK PECR in brief

The United Kingdom has its own versions of these rules: UK GDPR for personal data and the Privacy and Electronic Communications Regulations, PECR, for electronic marketing. PECR distinguishes corporate subscribers, such as limited companies, limited liability partnerships and public bodies, from individual subscribers, such as sole traders and some partnerships. Marketing email to corporate subscribers does not require prior consent under PECR, but you must identify yourself and give a valid way to opt out. Sole traders and some partnerships are treated like individuals and generally need consent or the soft opt in, which only applies to existing customers. Because named employees are still people, UK GDPR applies to their data in the same way GDPR does in the EU.

Canada CASL in brief

Canada's Anti-Spam Legislation, CASL, is stricter than CAN-SPAM because it is a consent based law. A commercial electronic message to a Canadian address needs consent, express or implied, and this includes B2B email. Implied consent can come from an existing business relationship or from a person who conspicuously published their business address without stating they do not want unsolicited messages, provided your message is relevant to their business role. Every message must identify the sender, include contact information and offer an unsubscribe mechanism that is processed within 10 business days. Penalties for organisations can reach 10 million CAD per violation, so Canadian lists deserve extra care and a record of where each consent came from.

The four frameworks side by side

CAN-SPAM, United States

Consent needed for B2B cold email
No
Key duties
Honest headers and subject, postal address, working opt out honoured within 10 business days

GDPR and national ePrivacy rules, EU

Consent needed for B2B cold email
Depends on the country; personal data needs a lawful basis such as legitimate interest
Key duties
Legitimate interest assessment, transparency at first contact, right to object, deletion

PECR and UK GDPR, United Kingdom

Consent needed for B2B cold email
Not for corporate subscribers; yes for sole traders and some partnerships
Key duties
Identify sender, opt out, UK GDPR duties for named people

CASL, Canada

Consent needed for B2B cold email
Yes, express or implied
Key duties
Sender identification, contact details, unsubscribe processed within 10 business days, consent records

A practical cold email compliance checklist

Use this list before every new campaign. It is written for B2B outbound and covers the common ground between the frameworks above. For the way OutreachAuto handles these points in the product, see our page on cold email compliance.

  • Send only to business contacts in a role your offer is relevant to, never to consumer lists
  • Write down where each contact came from: public company website, your own CRM, an event, a purchased list
  • Keep a short legitimate interest assessment for each segment you contact in the EU and UK
  • Check the national rule for each EU country before you scale there, and treat Canadian contacts as consent based
  • Use a truthful from name, from address and subject line
  • Put your business's physical postal address in every campaign email
  • Include a working unsubscribe link and a one click unsubscribe header in every campaign email
  • Honour every opt out immediately, and in any case within the legal deadline
  • Keep one suppression list for the whole company, so an opt out from one campaign stops all of them
  • Explain who you are and how you got the contact, in the email or a linked privacy notice
  • Answer access and deletion requests and actually delete the data
  • Remove contacts that bounce, do not respond for a long time or no longer match your segment
  • Make sure agencies and contractors who send on your behalf follow the same rules

Compliance and deliverability point the same way

The habits that keep you compliant also keep you out of spam folders. Mailbox providers watch complaint rates, and the easiest way to avoid complaints is to let people leave easily and to email only people who have a reason to care. Sending from your own authenticated domains, warming new inboxes and keeping a modest daily volume per inbox protect both your reputation and your legal position. Our guide on cold emails per inbox per day covers the sending side, and the email warmup tool page explains how new inboxes earn trust.

Compliance built into every campaign