Cold email compliance for B2B outbound

B2B cold email is lawful in most markets when it follows a few clear rules: tell people who you are, write to them in their business role, give them an easy way out and respect it. This page sums up the main rules, shows what OutreachAuto does in every campaign, and lists what remains your responsibility as the sender.

This page is general information, not legal advice. Rules differ by country and change over time, so check your own situation with a lawyer, especially before you write to a new market.

The main cold email laws in brief

CAN-SPAM Act

Where
United States
What it asks of B2B cold email
Truthful sender and subject, identify the message as an ad where required, a valid physical postal address, a working opt-out honoured within 10 business days

GDPR

Where
European Union and UK
What it asks of B2B cold email
A lawful basis for processing personal data, usually legitimate interest for B2B outreach, a privacy notice, the right to object and the right to erasure

PECR

Where
United Kingdom
What it asks of B2B cold email
Corporate subscribers may receive marketing email, while sole traders and some partnerships are treated like individuals and need consent

CASL

Where
Canada
What it asks of B2B cold email
Consent is required, implied consent covers a published business address when the message is relevant to the role, identification and an unsubscribe in every message

For a longer walk through each law, read our guide on cold email laws.

CAN-SPAM in the United States

CAN-SPAM allows unsolicited commercial email but sets conditions. Headers and subject lines must not mislead, the message must include the sender's valid physical postal address, and every message needs a clear way to opt out that works for at least 30 days after sending. Opt-outs must be honoured within 10 business days, and the sender stays responsible even when a tool or an agency sends on its behalf.

GDPR in the EU and the UK

GDPR applies to business contacts too, because a named work email is personal data. Most B2B outreach relies on legitimate interest, which requires a documented assessment: a real business interest, outreach that is necessary for it, and a balance with the person's reasonable expectations. People must be told where their data came from, can object at any time, and can ask for their data to be erased.

PECR in the United Kingdom

PECR sits alongside UK GDPR. Marketing email to employees of limited companies and other corporate bodies is allowed without prior consent, provided you identify yourself and offer an opt-out. Sole traders and some partnerships count as individual subscribers and need consent first.

CASL in Canada

CASL is stricter than the US rules. You need express or implied consent before you send. Implied consent can apply when a person publishes their business email without a statement that they do not want messages, and your email relates to their role. Every message must identify the sender and include an unsubscribe that works.

What OutreachAuto does in every campaign

  • Adds an unsubscribe link and a List-Unsubscribe header to every campaign email, with one-click unsubscribe for mailbox providers that support it
  • Processes unsubscribes at once and adds them to one suppression list for the whole account, so no sequence or teammate can email that address again
  • Stops a sequence on reply, bounce or unsubscribe, and pauses it on out-of-office replies
  • Writes to business contacts only, by role, and does not build lists of private consumer addresses
  • Gives you a physical address field for your own business, which is inserted into your campaign emails for CAN-SPAM
  • Records where each contact came from, such as public company data, your CSV upload or your CRM import, so you can answer the question "where did you get my details"
  • Provides notes for your legitimate interest assessment that you can adapt to your offer and keep on file
  • Deletes a person's data on request and keeps only a suppression entry so they are not contacted again
  • Sends only from your own domains and inboxes, with warmup, per-inbox daily limits and an SPF, DKIM and DMARC check, so identification is truthful and traceable

Deletion and objection requests

When a prospect asks you to delete their data or objects to processing, you can remove the contact from the account in one step. OutreachAuto deletes their personal data from your workspace and keeps only a minimal suppression record, which is the usual way to make sure an objection is respected in future campaigns. The way we protect stored data is described on outbound data security.

What remains your responsibility

OutreachAuto gives you the tools, and you remain the sender. That means you:

  • Decide whom to contact and confirm that each market's rules allow it, for example consent for Canadian recipients or for UK sole traders
  • Complete and keep your own legitimate interest assessment and provide a privacy notice that covers prospecting
  • Enter a truthful sender name, subject lines and a valid physical address for your business
  • Answer access, objection and deletion requests within the legal time limits
  • Upload only lists you are allowed to use, and do not import contacts who have opted out elsewhere without adding them to suppression
  • Keep message content honest and relevant to the recipient's role

Outbound with the rules built in