Cold Email Compliance: CAN-SPAM, GDPR & What's Actually Illegal

A practical breakdown of CAN-SPAM, GDPR, and CASL cold email rules — what's actually required, where jurisdictions conflict, and how AI-driven outreach volume raises compliance stakes.

On this page

"Is cold email even legal?" comes up in almost every outbound kickoff call, and the honest answer is: yes, in every major market, but the rules differ enough by jurisdiction that a compliant campaign to US prospects can be a violation the moment it crosses into Canada or the EU. CAN-SPAM fines start at roughly $517 per non-compliant email, and they stack per recipient — a single sloppy 1,000-email send with a missing physical address and a misleading subject line can generate two violations per email and six figures of exposure. This is a practical breakdown of what CAN-SPAM, GDPR, and CASL actually require, where they overlap, and where a campaign compliant in one jurisdiction can be flatly illegal in another. (This is general information, not legal advice — talk to counsel before launching a cross-border campaign at scale.)

The Core Distinction: Cold Email, Unsolicited Email, and Spam

These three terms get used interchangeably, but the legal frameworks treat them very differently. A cold email is a message sent to a prospect with a legitimate business reason for contact, without prior interaction. An unsolicited email lacks prior consent but may still be lawful if it meets the applicable compliance requirements. Spam, legally speaking, refers specifically to bulk, deceptive, or misleading messages that violate anti-spam law and lack a working opt-out — and it's spam, not cold email itself, that regulators are actually built to punish.

Cold email is legal in every major market covered here. What's illegal is misleading subject lines, missing sender identification, no working unsubscribe link, and ignoring opt-out requests. The message type isn't the violation — the missing disclosures are.

CAN-SPAM (United States): The Most Permissive Framework

CAN-SPAM is opt-out based, which makes it the least restrictive of the three major regimes covered in this guide. Under CAN-SPAM, you can send commercial cold email without obtaining consent first, as long as the message isn't deceptive, includes accurate sender information, and gives the recipient a clear way to opt out. Requirements that apply to every commercial email sent to a US address:

  • Accurate "From," "To," and routing information — no disguised sender identity
  • A subject line that isn't misleading about the email's content
  • Clear identification that the message is an advertisement, where applicable
  • A valid physical postal address for the sender
  • A visible, functioning opt-out mechanism, processed within 10 business days
  • No sending to a recipient after they've opted out, even from a different list

The penalty structure is where CAN-SPAM gets teeth despite being permissive on consent. The FTC's maximum CAN-SPAM penalty runs up to $51,744 per non-compliant email, and because each email is treated as a separate violation, financial exposure scales directly with send volume — a distinction that matters enormously for high-volume outbound motions.

GDPR (EU/UK): Legitimate Interest, Not Consent, for B2B

The most persistent myth in cold email compliance is that GDPR bans cold outreach outright. It doesn't. GDPR's Article 6(1)(f) permits B2B cold outreach under a "legitimate interest" basis, provided the sender passes a three-part test: a genuine purpose for the contact, necessity of the outreach to achieve it, and a balancing test weighing the sender's interest against the recipient's rights. In practice, this means the outreach needs to be relevant to the recipient's professional role and something they could reasonably expect given their public position — a VP of Sales getting outreach about a sales tool clears this bar; a personal, unrelated pitch does not.

Legal Basis
Legitimate Interest
Article 6(1)(f) — not consent — is the basis most B2B cold email relies on.
Opt-Out Window
24–48 hrs
Best-practice processing time, stricter than CAN-SPAM's 30-day allowance.
Max Penalty
4% of revenue
Or €20 million, whichever is higher — calculated on global annual revenue.

A Legitimate Interest Assessment (LIA) isn't strictly mandated by statute, but skipping it is a real risk: without a documented LIA on file, you lose the legitimate-interest argument by default in any ICO investigation. Enforcement also isn't uniform across the EU — the UK's ICO and France's CNIL tend to be more permissive toward B2B outreach, Germany's DSK enforces more strictly, and Poland's regulator typically expects consent even in B2B contexts. A campaign that's comfortably compliant when targeting London can be a liability when targeting Warsaw with identical messaging.

Every GDPR-compliant cold email needs, at minimum: a working opt-out mechanism, the sender's physical address, clear sender identity, and — unlike CAN-SPAM — a link to a privacy policy explaining how the recipient's data was sourced and will be used.

CASL (Canada): The Strictest of the Three

If GDPR requires justification, CASL requires permission first. Canada's Anti-Spam Legislation is consent-based rather than opt-out based, and it applies based on the recipient's location, not the sender's — a Texas-based SDR emailing a procurement lead in Toronto is subject to CASL regardless of where the sending company is incorporated.

Framework Consent Model Max Penalty
CAN-SPAM (US) Opt-out — no prior consent required $51,744 per email
GDPR (EU/UK) Legitimate interest (B2B) — documented justification 4% of global revenue or €20M
CASL (Canada) Implied or express consent required before sending $10M CAD per violation (organizations)

CASL does allow B2B cold outreach under a narrow implied-consent exception when a prospect's contact information is "conspicuously published" — listed on a company website, LinkedIn profile, or professional directory — and the email content is relevant to their business role, per Tomba's 2026 CASL compliance guide. That exception has real limits: it doesn't cover off-topic pitches (a marketing director's published contact info doesn't license an engineering-related pitch), and it requires the sender to have verified the publication themselves rather than assuming a purchased list meets the bar.

Reporting from early 2026 also flags a tightening trend worth watching: some coverage of CASL's 2026 changes describes an expanded expectation of express consent for commercial electronic messages, even as the traditional implied-consent B2B exemption remains in guidance. Given the $10 million CAD per-violation exposure and the CRTC's active enforcement — its Spam Reporting Centre logged over 150,000 complaints in just six months of 2025, per Prospeo's CASL compliance guide — teams running meaningful volume into Canada should treat this as an area to confirm with counsel rather than assume last year's playbook still applies unchanged.

Every CASL-covered message needs sender identification, a mailing address, and an unsubscribe mechanism that's processed within 10 business days — a hard legal deadline, not a best practice.

Where AI-Generated Outreach Adds New Exposure

Compliance risk in 2026 isn't only about the classic disclosure checklist — it's also about volume and pattern. Regulatory coverage of 2026 enforcement trends points specifically to the rise of AI-generated outreach as an accelerant: sales teams using AI writing tools and cold outreach platforms to flood inboxes at a scale that wasn't previously feasible manually, which is exactly the behavior these laws were built to catch. The compliance rules themselves haven't fundamentally changed for AI-assisted email — the same CAN-SPAM, GDPR, and CASL requirements apply regardless of whether a human or a model drafted the message — but AI materially lowers the cost of generating high volume, which raises the odds that a compliance gap (a missing address field, an unprocessed opt-out) gets multiplied across thousands of sends before anyone notices.

AI doesn't change what's legal — it changes how fast a small compliance gap can turn into thousands of violations. A missed opt-out field in a manually-built campaign might affect 200 emails; the same gap in an automated AI-driven send can affect 50,000 before anyone catches it.

This is one of the strongest practical arguments for building compliance checks into the sending platform itself rather than relying on a manual review step — automated unsubscribe processing, automated suppression list management, and automated sender-identity fields close the exact gaps that scale fastest when AI tools increase send volume.

A Practical Pre-Send Compliance Checklist

Regardless of which jurisdiction a list falls under, these checks apply across all three frameworks and are worth running before any new sequence goes live:

1
Verify Sender ID
Accurate "From" name, reply-to address, and a real physical mailing address on every email.
2
Confirm the Legal Basis
Legitimate interest documentation for EU contacts; conspicuous-publication check for Canadian contacts.
3
Test the Opt-Out
Send a real test unsubscribe through the sequencer and confirm it's suppressed platform-wide, not just per-campaign.
4
Check Content Relevance
Confirm the pitch matches the recipient's professional role — required under both GDPR and CASL's B2B exceptions.
5
Audit List Sourcing
Confirm lead enrichment and scraping vendors document where contact data originated.

That last step matters more than most teams assume. Third-party data vendors vary widely in how they source and document contact information, and under GDPR in particular, the burden of demonstrating a lawful basis for processing sits with the sender — not the vendor that sold the list. Ask any enrichment or data provider whether they retain origin documentation before assuming a purchased list is compliance-ready.

Common Compliance Myths, Corrected

A few misconceptions come up often enough to be worth addressing directly. "Cold email is illegal under GDPR" is false — B2B cold email under legitimate interest is permitted; it's personal, B2C-style outreach that requires consent. "I need consent for every cold email" is false under CAN-SPAM and true under CASL — it genuinely depends on the jurisdiction, which is exactly why a single global compliance policy rarely works. "Unsubscribe links hurt deliverability" is also false: they're a legal requirement in every framework here, and honoring them actually improves deliverability by reducing spam complaints, which sending providers weigh heavily in inbox placement decisions.

One more that trips up automated sequences specifically: "if they don't reply, I can keep emailing indefinitely." Under CAN-SPAM, that's technically legal until the recipient opts out — but it's a deliverability liability regardless of legality, since repeated unanswered outreach is a leading driver of spam complaints. Compliance guidance from InboxKit recommends capping follow-ups at three to four touches per contact for exactly this reason.

Building Compliance Into the Sequence, Not Around It

The teams that stay compliant without slowing down outbound treat these checks as configuration, not a manual gate before each send. That means: suppression lists that sync across every campaign a contact could land in, automated processing of unsubscribe requests at the platform level rather than the campaign level, and list-building rules that flag contacts outside a documented legitimate-interest or conspicuous-publication basis before they ever enter a sequence. Getting this right once at the platform level is far less expensive than auditing every individual campaign after the fact — and it's the difference between compliance being a bottleneck on outbound velocity or simply a property the system already has.

Documentation: The Part Most Teams Skip

Every framework in this guide rewards the same underlying habit: keeping a paper trail. It's tempting to treat compliance as a set of technical settings — an unsubscribe link here, a physical address in the footer there — and skip the documentation layer entirely. That's a mistake, because in an actual investigation or audit, the question regulators ask isn't just "did you have an opt-out link," it's "can you show us why you believed this contact and this content were compliant at the time you sent it."

For GDPR, that means keeping the Legitimate Interest Assessment on file per list segment, not just performing the mental exercise once and moving on. For CASL, it means retaining evidence that a contact's information was genuinely conspicuously published — a screenshot or archived link to the source, not just a note that "it was on LinkedIn." For CAN-SPAM, it's less about justification and more about proof of timely opt-out processing: logs showing when an unsubscribe request came in and when it was honored, since the 10-day (CAN-SPAM) or 10-business-day (CASL) clock is measured from the request, not from whenever someone happens to check the suppression list.

This documentation habit also protects against a specific and underrated risk: third-party vendor liability. If a sales team hires an outsourced SDR agency or buys a list from a data provider, compliance guidance is explicit that both parties remain legally responsible for the campaign's compliance — hiring someone else to send on your behalf doesn't transfer the legal exposure away from your company. Any outsourcing arrangement should include a contractual requirement that the vendor follows the same documentation standards, plus a right to audit their list-sourcing practices.

Why Penalty Structures Change How Teams Should Think About Volume

It's worth sitting with how differently these three frameworks scale penalties, because it changes the calculus for how aggressively a team should scale send volume before compliance processes are solid. CAN-SPAM and CASL penalties are both structured per violation, which means a single flawed campaign template — one missing address field, one broken unsubscribe link — doesn't produce one fine. It produces one fine multiplied by every email sent using that template. A 50,000-email send with a single systemic defect isn't a $517 problem; under CAN-SPAM's stacking logic it's a problem that scales directly with list size.

GDPR's penalty structure works differently — it's a percentage of global revenue rather than a per-message multiplier — which in practice means GDPR exposure is less about how many emails went out and more about the severity and pattern of the violation as evidence of a systemic compliance failure. Both structures point to the same practical conclusion: fix compliance gaps in the template and the platform configuration before scaling volume, not after. A defect caught at 500 sends is an inconvenience; the same defect caught at 50,000 sends is a very different conversation with legal counsel.

Frequently Asked Questions

Is cold email legal in the US, EU, and Canada?
Yes, in all three, but the legal basis differs: CAN-SPAM is opt-out based, GDPR requires a documented legitimate-interest justification for B2B outreach, and CASL requires implied or express consent before the first message.

What's the biggest compliance risk with AI-generated cold email?
The disclosure rules don't change for AI-written messages, but AI increases send volume, which means a small compliance gap — like an unprocessed opt-out — can multiply across thousands of emails before it's caught.

Do I need a lawyer to run compliant cold email campaigns?
For single-jurisdiction, low-volume outreach, a documented checklist covering sender ID, opt-out processing, and content relevance usually suffices. For multi-jurisdiction, high-volume motions, legal review is worth the cost given how fast per-email penalties can stack.

Call to Action

Precision Prospecting Predictable Growth

tario isn’t just software—it’s a proactive, always-ready teammate built to help you scale sales effortlessly.