Skip to content
OmniLeadDocs
Sign in

Understand cold email laws by region

What CAN-SPAM, GDPR, PECR, CASL and the Australian Spam Act ask of you, in plain English, and what OmniLead handles for you.

5 min readLast updated

Cold email is legal in most places, but every region sets its own conditions. Some only ask you to be honest and stop when someone says no. Others require the person's permission before the first email. This article explains the main rules in plain English so you know what applies to your list before you launch.

The short version

  • United States: you can email businesses without permission, as long as the email is honest, includes your postal address and an unsubscribe link, and you stop when asked.
  • European Union and UK: work emails are personal data. You need a lawful basis (usually legitimate interest), you must tell people where you got their details, and some countries require consent before the first email.
  • Canada: you need consent. Implied consent covers a work address that was published openly, when your email is relevant to the person's job.
  • Australia and New Zealand: you need consent, with a similar exception for published work addresses.

OmniLead enforces the parts software can enforce: postal address, one-click unsubscribe, suppression, and per-country rules. The judgment calls, such as whether your message is relevant to someone's role, stay with you.

United States: CAN-SPAM

The CAN-SPAM Act covers every commercial email, including business-to-business email. It doesn't require permission before you send. It does require that:

  1. Your From, To and Reply-To details are accurate and identify you.
  2. Your subject line reflects what's in the email.
  3. The email is identifiable as a commercial message.
  4. The email includes a valid physical postal address.
  5. The email tells people how to opt out, and the opt-out works for at least 30 days after sending.
  6. You honor opt-outs within 10 business days and never sell or transfer the address afterwards.

Each email that breaks the rules can be fined more than $50,000, and you stay responsible for email that someone sends on your behalf.

OmniLead blocks a sequence from launching until your postal address is set and every email step carries an unsubscribe link. Unsubscribes take effect immediately, well within the 10-day limit. See Add your postal address to every email and Handle unsubscribes and suppression.

European Union: GDPR and ePrivacy

Two layers of law apply to email sent to people in the EU.

GDPR applies because a named work email, such as anna.schmidt@firma.de, is personal data. That means:

  • You need a lawful basis for processing it. For B2B outreach this is usually legitimate interest, backed by a written Legitimate Interest Assessment.
  • You must tell the person, at the latest in your first email, who you are, where you got their details and how to object. A short line plus a link to your privacy notice is the common approach.
  • The person can object to direct marketing at any time, and that objection is absolute: you must stop.
  • Fines reach €20 million or 4% of worldwide annual turnover, whichever is higher.

The ePrivacy Directive governs electronic marketing itself, and each country implements it differently. Germany, Austria, Poland, Italy, Denmark, Spain and several others require prior consent even for email to businesses. France, the Netherlands, Ireland and Sweden allow B2B email with an opt-out, provided the message relates to the person's job.

OmniLead stores a lawful basis on every lead and keeps a Legitimate Interest Assessment template in settings. Its country rules block or warn before sending to countries that require consent. See Set country sending rules and Respond to GDPR data requests.

United Kingdom: UK GDPR and PECR

The UK kept GDPR as UK GDPR, so the lawful basis and transparency rules above still apply. Electronic marketing falls under PECR:

  • Corporate subscribers (limited companies, LLPs, public bodies) can be emailed without consent, as long as you identify yourself and offer a simple way to opt out.
  • Sole traders and some partnerships count as individuals. Emailing them needs consent unless they are existing customers.

When you target UK sole traders or small partnerships, record consent first or leave them out of the sequence.

Canada: CASL

Canada's Anti-Spam Legislation (CASL) is one of the strictest laws. Every commercial electronic message needs consent:

  • Express consent: the person agreed to receive your emails, and you can show when and how.
  • Implied consent: for example, an existing business relationship in the last two years, or a work address that was conspicuously published without a "no solicitation" statement, when your message is relevant to the person's role.

Every message must identify you, include your contact details and offer an unsubscribe that works within 10 business days. Penalties reach CAD $10 million per violation for a company.

OmniLead blocks every send to a Canadian recipient unless a consent record exists for that address. A consent record stores the basis, where you found it and your evidence, such as the page where the address was published.

Australia: Spam Act

The Spam Act 2003 also requires consent, either express or inferred. Inferred consent can come from a work address that was conspicuously published, when your email relates to the person's role and the page doesn't say they refuse marketing. Every message must identify the sender and include a working unsubscribe, honored within five business days. New Zealand's Unsolicited Electronic Messages Act works in a similar way.

OmniLead treats Australia and New Zealand as consent countries, so they follow your workspace's block-or-warn setting.

Other countries

OmniLead keeps a maintained list of country rules, including Switzerland, Norway, Belgium, Japan, South Korea and South Africa. You can see every country, the law it's based on and a plain-English note in Settings → Compliance → Country rules. Countries not on the list follow the standard opt-out rules: honest headers, your postal address, an unsubscribe link and an immediate stop on opt-out.

Compliance settings with the postal address field, country rules and the suppression list
Settings → Compliance holds your postal address, country rules and suppression list.

What OmniLead handles and what you handle

RequirementOmniLeadYou
Postal address in every emailAdds it to the footer and blocks launch without itEnter a real address
One-click unsubscribeAdds RFC 8058 headers and a footer link to every emailKeep the link in custom templates
Stop on opt-outImmediate, across every sequence and mailboxDon't re-import opted-out people elsewhere
Consent countriesBlocks or warns before sendingCollect and record consent
Honest subject linesFlags misleading phrases in the pre-launch checklistWrite honest copy
Lawful basis and sourceStores both on every leadComplete your Legitimate Interest Assessment
Is cold email legal at all in Germany?

Unsolicited marketing email to German businesses generally needs prior consent under UWG §7. OmniLead blocks these sends by default. Use other channels to start the conversation, or record consent before you enroll someone.

Does GDPR apply if my company is in the US?

Yes, if you email people in the EU or UK. GDPR follows the person, not the sender. You may also need an EU or UK representative.

What's next