Cold email and the law: CAN-SPAM, GDPR and CASL without the myths

· 12 min read · Web Involved

Is cold email legal, and what are the rules?

Cold email is legal in the US, the EU, the UK and Canada if you follow the rules — the widespread belief that GDPR bans it is a myth. What changes across borders is the consent model, and the three regimes work almost oppositely. CAN-SPAM (US) is opt-out: send without prior consent, but identify yourself honestly, include a physical postal address, and honour unsubscribes within 10 business days. GDPR (EU and UK) permits B2B cold email under a documented “legitimate interest” basis, provided the message is relevant to the recipient’s professional role. And CASL — Canada’s Anti-Spam Legislation, the strictest email law in the world — flips the default to opt-in, requiring express or implied consent before the first message, with B2B cold email surviving mainly through a “conspicuous publication” test and penalties up to CAD $10 million per violation. The insight that ties it all together is that compliance and deliverability are built from the same parts: the behaviours regulators punish — hiding your identity, burying opt-outs, blasting stale or purchased lists — are exactly the ones mailbox providers punish with spam placement. So the practical move is to build one program to the strictest standard, which almost always satisfies the looser regimes automatically and lands you in the inbox at the same time. As a Canadian studio, we build to CASL by default. One caveat throughout: this is an operational overview, not legal advice — check your specific situation with a qualified professional.

The first thing to clear up is the myth that cold email is inherently illegal, because it stops a lot of legitimate outreach that regulators never intended to ban. Cold email is legal in the US, EU, UK and Canada as long as you follow the applicable rules; the line the law draws isn’t between “cold” and “warm” but between compliant, relevant outreach and spam (InboxKit, 2026). What makes a message defensible is that it goes to the right person for a genuine reason, from a real identity, with an easy way out.

There’s a deliverability reason to care beyond the legal one, which our pillar on reaching the inbox sets up: cold outreach has an inherently harder profile. Recipients didn’t ask to hear from you, so complaint rates run higher than permission-based mail, which is why cold sending demands even more discipline — warmed infrastructure, verified lists, tight relevance and a small number of follow-ups rather than an endless sequence. The law and the inbox are pushing in the same direction, which is the theme of this entire guide.

CAN-SPAM (US): the opt-out regime

The United States has the most permissive of the three frameworks, which is why so much cold email originates from US infrastructure. CAN-SPAM does not require prior consent to send commercial email, but “permissive” is not “no rules”: every commercial message must use accurate header and sender information, avoid misleading subject lines, include a physical postal address, and provide a clear opt-out that you honour within 10 business days (Vendisys, 2026). A reply-based opt-out such as “reply STOP to unsubscribe” satisfies the requirement under FTC guidance, and the unsubscribe mechanism must keep working for at least 30 days after you send (Modern Inbound, 2026).

The stakes are real even in the permissive regime: violations carry penalties above $51,000 per email, with no cap on total penalties (Outreach Bloom, 2026). The most common CAN-SPAM failure isn’t the initial send but the follow-up — burying or omitting the opt-out in later sequence steps, or re-adding someone weeks after they asked to be removed, which is a violation regardless of how the first message was worded.

GDPR (EU and UK): B2B under legitimate interest

The most damaging myth in this area is that GDPR forbids cold email; it doesn’t. B2B cold outreach to EU and UK contacts is permitted under the “legitimate interest” lawful basis in Article 6(1)(f), as long as the message is relevant to the recipient’s professional role, you use business rather than personal addresses, you minimise the data you collect, and you offer an easy opt-out (InboxKit, 2026). The requirement people skip is documentation: you should complete and keep a Legitimate Interest Assessment, because when a regulator asks, they’re looking for evidence that you reasoned it through, not for legal perfection (Outreach Bloom, 2026).

Two subtleties matter. Where teams actually fail GDPR is rarely consent — it’s the right to access and the right to erasure, so you need a process to answer “what do you hold on me?” and “delete it” quickly (Modern Inbound, 2026). And national rules vary: Germany effectively requires prior consent, and France’s regulator now mandates explicit opt-in for B2C prospecting, so EU sending is safest when tightly scoped to clearly relevant business roles at business domains. Penalties reach €20 million or 4% of global annual revenue.

CASL (Canada): the strictest, and it flips the default

Canada’s Anti-Spam Legislation is widely regarded as the strictest email law in the world, and it inverts the model the other two use: rather than letting you send until someone opts out, CASL requires express or implied consent before you send the first commercial electronic message (SendCheckIt, 2026). It applies to any message sent to or from Canada regardless of where your business is located, B2B is not exempt, and penalties reach CAD $10 million per violation for organizations (Instantly, 2026).

Consent comes in two forms. Express consent is a documented opt-in — a checked box, a form, a verbal agreement — that doesn’t expire but that you must be able to prove, keeping records for three years after the relationship ends, because the burden of proof falls on you (Prospeo, 2026). Implied consent is where B2B cold outreach lives, and it comes from either an existing business relationship (a prior transaction gives two years, an inquiry gives six months) or “conspicuous publication” — a three-part test where the person’s address is publicly posted, without a statement refusing commercial messages, and your message is relevant to their role (Prospeo, 2026). Every message must still identify you, include your contact information, and carry an unsubscribe that works for at least 60 days.

CAN-SPAM (US)GDPR (EU/UK)CASL (Canada)
Consent modelOpt-out (no prior consent)Lawful basis (B2B: legitimate interest)Opt-in (express or implied)
B2B cold emailPermitted with disclosuresPermitted, documentedPermitted only under implied-consent tests
Opt-out window10 business days24–48 hours (best practice)10 business days
Max penalty~$51,000+ per email€20M or 4% of revenueCAD $10M per violation

Why compliance and deliverability are the same thing

Here’s the convergence that makes all of this less burdensome than it looks. The behaviours regulators penalise — disguising your identity, making opt-out difficult, blasting stale or purchased lists, sending irrelevant mail — are the exact behaviours mailbox providers penalise with spam-folder placement and domain blocklisting (Vendisys, 2026). The thresholds even match the ones from the rest of this library: a bounce rate above 2% or a complaint rate above 0.3% both damages your reputation and signals the poor list practices the law is concerned with (Instantly, 2026).

So a compliant program and a deliverable program are built from the same parts. Cleaning your list, honouring unsubscribes the moment they arrive, using a real sender identity, and only mailing people with a plausible business reason to hear from you all lower your legal risk and raise your inbox placement at once. The single most useful mechanism is a permanent master suppression list, kept forever and synced across every sending tool, so that an opt-out honoured in one place is honoured everywhere — a requirement under both CAN-SPAM’s opt-out rules and GDPR’s right to erasure, and a deliverability safeguard besides.

Build to the highest standard, once

The practical strategy that falls out of all this is to build a single program to the strictest bar, which almost always satisfies the looser regimes automatically (Vendisys, 2026). That means, as a baseline across every jurisdiction: mail only business addresses at business domains, targeted to roles with genuine relevance to your offer; never disguise your identity, using a real sender, company and reply path; put a physical postal address and clear company identification in every footer; include a visible one-click unsubscribe and suppress opt-outs the moment they arrive; keep that suppression list forever and check every send against it; document your data source and, for EU sending, your legitimate-interest reasoning; and validate your list continuously so you’re never mailing dead, personal or role-mismatched addresses.

As a Canadian studio, we build to CASL by default — the strictest standard — which is a happy accident of geography, because it means the outreach practices we consider normal already clear the bar almost everywhere else. It’s worth adding one honest caution about sources: nearly every guide on this topic is published by a company selling verified lists, pre-warmed inboxes or sending software, so weigh the underlying principles above any specific product. And the most important caveat bears repeating: everything here is an operational overview written for people running outreach, not formal legal advice, and your specific circumstances deserve a conversation with a qualified professional.

Same discipline, two payoffs

Cold email compliance turns out to embody the pattern that runs through this whole library: doing the unglamorous thing properly removes a trade-off other people treat as unavoidable. You don’t choose between staying legal and reaching the inbox, any more than you choose between owning your site and hosting it well, or building it fast and building it rich — the disciplined version delivers both. A clean list, a real identity, instant opt-outs and genuine relevance are simultaneously your legal defence and your deliverability engine.

The through-line to the rest of the email foundation is direct. Compliance leans on the same list hygiene that protects your reputation, the same authentication that proves your identity, and — for cold sending specifically — the same warming discipline that keeps a new domain out of the spam folder. Get those right, keep your outreach relevant and honest, respect the strictest regime that touches your recipients, and the law and the inbox reward you with the same thing: mail that actually arrives, to people who have a real reason to read it.

Frequently asked

Is cold email legal?
Yes, in the United States, the European Union, the UK and Canada, provided you follow each jurisdiction's rules — the widespread belief that GDPR bans cold email is a myth. What differs is the consent model. In the US, CAN-SPAM permits commercial cold email without prior consent as long as you identify yourself, include a postal address, and honour opt-outs. In the EU and UK, B2B cold email is permitted under a documented 'legitimate interest' basis. In Canada, CASL requires express or implied consent before the first message. Cold email is legal; spam is not, and the difference is compliance and relevance.
What's the difference between CAN-SPAM, GDPR and CASL?
They use fundamentally different consent models. CAN-SPAM (US) is opt-out: you can send without prior permission but must honour unsubscribes within 10 business days. GDPR (EU/UK) requires a lawful basis before sending — for B2B that's usually 'legitimate interest', which you must document and which requires relevance to the recipient's professional role. CASL (Canada) is opt-in and the strictest of the three: it requires express or implied consent before you send the first commercial message, and it applies to any message sent to or from Canada regardless of where your business is. Penalties also differ sharply, with CASL reaching CAD $10 million per violation.
Can I send cold email to Canada under CASL?
Yes, but only under specific conditions, because CASL flips the default to consent-first. For B2B, the usual path is implied consent through 'conspicuous publication': the person's email is publicly posted — on a company website, directory or professional profile — without any statement refusing commercial messages, and your message is relevant to their business role. Express consent (a documented opt-in) is stronger and is required for consumer contacts and anyone whose address isn't publicly published. Either way you must identify yourself, include a working unsubscribe, and honour opt-outs within 10 business days. This is a general overview, not legal advice — confirm your situation with a qualified professional.
Does GDPR allow cold email?
Yes — the idea that GDPR bans cold email is a common misconception. B2B cold outreach to EU and UK contacts is permitted under the 'legitimate interest' lawful basis in Article 6(1)(f), provided the email is relevant to the recipient's professional role, you use business rather than personal addresses, you minimise the data you hold, and you provide an easy opt-out. The key requirement teams overlook is documentation: you should complete and keep a Legitimate Interest Assessment, because regulators look for evidence that you thought it through. B2C cold email generally does require consent, and some countries such as Germany apply stricter national rules.
Does complying with email law also help deliverability?
Yes, and this is the useful part: compliance and deliverability are built from the same parts. The behaviours regulators penalise — hiding your identity, making opt-out difficult, blasting stale or purchased lists, sending irrelevant mail — are the exact behaviours mailbox providers penalise with spam-folder placement and blocklisting. Honouring unsubscribes instantly, keeping a clean verified list, using a real sender identity, and only mailing people with a genuine reason to hear from you simultaneously lowers your legal risk and raises your inbox placement. A compliant program and a deliverable program are the same program.