Cold email to a business address is legal in the United States, the United Kingdom, Canada, Australia and most of the EU, provided you identify yourself honestly, do not mislead in the subject line, include a real postal address, and honour opt-outs promptly. The US works on opt-out, so no prior consent is needed. The EU and UK need a lawful basis, which for B2B is normally legitimate interest, and that requires you to have actually assessed and documented it. Germany requires consent for consumers and France tightened toward the same in 2026.
Most founders who have never sent outbound believe cold email is either obviously illegal or obviously fine, and neither belief survives ten minutes of reading. It is legal in most of the world, conditionally, and the conditions are short enough to hold in your head.
This is not legal advice. It is an accurate summary of what the main regimes require, written so you know which questions to take to someone qualified. Rules differ by country and change; the ones below reflect September 2026.
The United States: CAN-SPAM, and it is opt-out
CAN-SPAM is the one people are most afraid of and the most permissive of the lot. You do not need consent before the first email. What you do need:
Accurate routing information. The From, Reply-To and originating address must not be falsified. A subject line that matches the message. Identification as a commercial message, which in a genuine one-to-one sales email is usually satisfied by being obviously what it is. A valid physical postal address. A working opt-out mechanism, honoured within ten business days.
The penalty scale is what makes people pay attention: fines are assessed per email, at figures reported up to $53,088 each. Nobody gets fined for one clumsy message, but the arithmetic on a bad list at volume is not comforting.
Note what is absent. No consent requirement, no volume cap, no restriction on writing to someone who has never heard of you. The American regime is genuinely permissive about the first contact and unforgiving about dishonesty.
The EU and UK: a lawful basis, which for B2B is usually legitimate interest
GDPR does not mention cold email and does not ban it. It says you may not process personal data without a lawful basis, and a work email address that identifies a person is personal data.
For business-to-business, the basis is normally legitimate interest under Article 6(1)(f), which is a balancing test rather than a permission slip. Your commercial interest in contacting someone must not override their rights and freedoms. In practice that means the contact is plausibly relevant to their job, you are writing to a professional address about a professional matter, and leaving is easy.
The part small senders skip is the documentation. A Legitimate Interest Assessment is a written record of why you think the balance falls your way. It is not filed with anyone. It exists so the answer predates the question, and a page of honest notes is enough.
Transparency is the requirement people forget
GDPR expects you to tell people where you got their data when you first contact them, if you did not get it from them directly. One sentence covers it: how you found them and how to object. It also happens to make the message read better, because it answers the question the recipient is already asking.
The UK runs GDPR plus PECR. For corporate subscribers the position is broadly the same as the EU; for sole traders and partnerships the consumer rules bite, which is a distinction worth knowing before you email a one-person consultancy.
Where the answer is closer to no
| Jurisdiction | Regime | What it means in practice |
|---|---|---|
| United States | CAN-SPAM | Opt-out. First email allowed without consent, with honesty and an unsubscribe |
| UK | UK GDPR + PECR | B2B on legitimate interest; sole traders treated closer to consumers |
| EU (general) | GDPR + ePrivacy | B2B on legitimate interest, documented, with a transparency line |
| Germany | UWG | Consumer prospecting needs explicit consent. Strictest common market |
| France | GDPR + 2026 changes | Moved toward the German position for consumers |
| Canada | CASL | Consent-based, stricter than CAN-SPAM, narrow implied-consent window |
| Australia | Spam Act | Consent-based, with inferred consent for published business addresses |
The pattern: the Anglosphere splits between opt-out (US) and consent (Canada, Australia), and Europe sits in between with a documented balancing test. A sending programme designed for American rules will be wrong in Canada and can be wrong in Germany.
The rules that matter most, ranked by risk per unit of effort
Honour opt-outs instantly and everywhere. Under GDPR an objection to direct marketing is absolute: no balancing test survives it. Under CAN-SPAM you have ten business days and no reason to use them. Most small-sender complaints start here, when someone opts out of one campaign and hears from another.
Do not misrepresent who you are. Falsified headers and misleading subject lines are where enforcement actually lands, in every regime, because they are the part that is easy to prove.
Know where your data came from. If you cannot say how you found someone, you cannot defend contacting them, and bought lists are indefensible by construction.
Write to the job, not the person. Professional address, professional subject, plausibly relevant. That is what makes a legitimate interest argument work, and it is also what makes the message get a reply.
Legal is not the same as deliverable
Worth separating, because founders conflate them constantly. Compliance decides whether you can be fined. Deliverability decides whether the message arrives, and mailbox providers apply their own rules that are stricter than any statute.
A perfectly lawful email from a domain with broken authentication gets rejected before anyone reads it. Since 2026 the major providers reject non-compliant bulk mail outright rather than filing it in spam. That is covered in the 2026 bulk sender requirements, and it is the test you will fail first.
What this looks like in practice
For a solo founder writing to businesses: use professional addresses, say who you are and how you found them, include a real postal address and a one-click unsubscribe, keep a note of your sources and your reasoning, stop the moment anyone asks, and treat German and Canadian consumer addresses as a different problem requiring different advice.
That is the whole list. It is shorter than the anxiety around it suggests, and nothing on it requires a lawyer to implement, though the German and Canadian questions are worth one if those markets matter to you.
Operater's Sales agent enforces the mechanical parts because they are the parts that fail through inattention rather than intent: a working one-click unsubscribe on every message, an opt-out that applies permanently across every agent on the account and cannot be reversed, verification before sending, and volume kept inside provider limits. The judgement calls, which markets you sell into and on what basis, stay with you, because they should.
Key takeaways
- CAN-SPAM is opt-out: no consent required before the first email, but sender identity, subject line, postal address and a working unsubscribe are not optional.
- GDPR does not ban B2B cold email. It requires a lawful basis, and legitimate interest is the usual one, which means writing down why your interest does not override theirs.
- The single rule that carries the most legal weight for the least effort is honouring opt-outs immediately and permanently.
- Penalties are large enough to take seriously: CAN-SPAM is assessed per email, and GDPR maxima run to 4% of global turnover.
- Legality and deliverability are different tests. A perfectly legal message still gets blocked if the sending domain fails authentication.