Cold email compliance in 2026: CAN-SPAM, GDPR and CASL in plain English
What the main cold email laws actually require, where they differ, and a checklist you can run before every campaign. Not legal advice, but a clear place to start.
- compliance
- cold email
- CAN-SPAM
- GDPR
- CASL
Cold email sits in a grey zone in many people's minds: common, useful, and vaguely illegal. The truth is more specific. In the United States, business cold email is legal if you follow a handful of rules. In the EU and UK it depends on the country and on who you're writing to. In Canada, it mostly needs consent.
This guide walks through the three regimes that matter most for B2B senders, what they have in common, and a checklist you can apply to every campaign.
The United States: CAN-SPAM
The CAN-SPAM Act covers "commercial electronic mail messages", meaning email whose primary purpose is to advertise or promote a product or service. It applies to business-to-business email just as much as to consumer email. It does not require prior consent. Instead, it sets rules for how you send.
The Federal Trade Commission's guidance boils it down to these requirements:
- Don't use false or misleading header information. Your From, To and Reply-To, and the routing information, must accurately identify you.
- Don't use deceptive subject lines. The subject must reflect the content of the message.
- Identify the message as an ad where required. The law is flexible about how, but the disclosure must be clear.
- Tell recipients where you're located. Include a valid physical postal address: a street address, a post office box registered with the USPS, or a private mailbox registered with a commercial mail receiving agency.
- Tell recipients how to opt out. The opt-out must be clear and easy to spot, and it must work for at least 30 days after you send.
- Honor opt-outs promptly. You have 10 business days. You can't charge a fee, ask for anything beyond an email address, or make people do more than reply or visit one page.
- Monitor what others do on your behalf. If an agency or tool sends for you, you're both responsible.
Penalties are per email. The FTC adjusts the maximum civil penalty for inflation each year, and it is currently more than $50,000 for each violating message. That's why a single bad campaign can become a serious liability.
The EU: GDPR plus ePrivacy
In Europe, two sets of rules overlap.
GDPR: can you use the data at all?
The GDPR governs processing personal data, and a work email like jane.doe@company.com is personal data. To use it you need a lawful basis. For B2B prospecting that is usually legitimate interest under Article 6(1)(f), which requires you to:
- Have a genuine, specific interest (for example, offering a product relevant to someone's job).
- Show the processing is necessary for that interest.
- Balance it against the person's rights and expectations. Document this in a short legitimate interest assessment.
The GDPR also has transparency duties. When you collect data from somewhere other than the person, Article 14 says you must tell them who you are, why you're processing their data, where the data came from, and their rights. You must do this within a reasonable time, and at the latest when you first contact them. In practice, a short line in your first email plus a link to your privacy notice covers much of this.
Finally, people have an absolute right to object to direct marketing (Article 21). If someone says stop, you stop, everywhere.
ePrivacy: can you send the email?
Separately, the ePrivacy Directive, implemented differently by each member state, controls unsolicited electronic marketing. For emails to individuals, it generally requires prior consent. For emails to businesses, member states choose, and they don't agree:
- Germany treats unsolicited marketing email as requiring prior consent, including in most B2B situations, and courts apply this strictly.
- Austria and Poland also generally require prior consent for marketing email, including to businesses.
- France allows B2B prospecting without prior consent if the message relates to the recipient's profession and includes a way to object.
- Several other countries take a similar professional-relevance approach to France.
That patchwork is why a one-size-fits-all EU campaign is risky. The safe approach is to decide, country by country, whether you'll send, and enforce that before emails go out.
The UK: UK GDPR and PECR
The UK kept the GDPR as the UK GDPR, and its version of the ePrivacy rules is PECR. Under PECR, you can send marketing email to corporate subscribers, such as limited companies and LLPs, without prior consent, as long as you identify yourself and give a valid way to opt out. Sole traders and some partnerships count as individuals, so they need consent. The UK GDPR's lawful-basis and transparency rules still apply to the personal data in the address.
Canada: CASL
Canada's Anti-Spam Legislation is the strictest of the four. A commercial electronic message generally needs consent, either express or implied.
Implied consent covers some useful cases, including:
- An existing business relationship, such as a purchase in the last two years.
- Conspicuous publication: the person published their address, didn't say they don't want commercial messages, and your message is relevant to their business role.
Every message must also identify the sender, include contact information including a mailing address, and have an unsubscribe mechanism that you honor within 10 business days. Penalties can reach $10 million per violation for businesses. Because proving implied consent is on you, many senders simply don't cold email Canadian recipients without a recorded basis for consent.
What the regimes have in common
Look past the differences and a shared core appears:
- Be honest about who you are. Real name, real company, accurate subject line.
- Be relevant. Write to people in their professional role about something that relates to it.
- Say where you got their details and how to learn more.
- Make stopping easy, and make it stick across every campaign and teammate.
- Keep records: where each contact came from, your basis for contacting them, and when they opted out.
A pre-send checklist
Run through this before every campaign:
- Every contact has a recorded source and, for EU and UK recipients, a lawful basis.
- You've checked the recipient countries against your policy, and removed countries that require consent you don't have.
- The From name and address are real and consistent with your domain.
- The subject line matches the body.
- The footer includes your postal address.
- There is a one-click unsubscribe header and a visible opt-out link, and both work.
- Your list has been checked against your suppression list, including past unsubscribes and bounces.
- Your first message says why you're writing to this person and where you found their details.
- Your volume is reasonable for your mailbox, and your domain has SPF, DKIM and DMARC in place.
You can paste any draft into our free compliance checker to catch common gaps.
How OmniLead handles this
We built OmniLead so these rules are enforced by default rather than remembered:
- Every contact stores its source URL, the date it was found, and a lawful basis.
- Every send includes RFC 8058 List-Unsubscribe headers and a footer link, and unsubscribes apply instantly across the workspace.
- A sequence can't launch without a postal address and healthy mailbox authentication.
- Per-country rules let admins allow, warn or block by recipient country, with defaults for countries that expect prior consent, and Canadian recipients need a consent record.
- Anyone can remove or suppress their data through our public opt-out portal.
None of that replaces your judgement or a lawyer's advice, but it makes the right thing the easy thing.
Send outreach that respects the rules
Unsubscribe headers, suppression and per-country rules come standard on every plan, including Free.