Guide
Cold Email Compliance Guide 2026: CAN-SPAM, GDPR & CASL Explained
September 30, 2026 · 11 min read
What CAN-SPAM, GDPR, and CASL actually require for B2B cold email in 2026: unsubscribe rules, legitimate interest, consent, and penalties explained.
The sending setup
Cold email is legal in the US, EU, and Canada, but each region sets different rules. CAN-SPAM requires a physical address and a working opt-out. GDPR treats a business email tied to a real person as personal data, so most senders lean on "legitimate interest" rather than consent. CASL requires an implied-consent basis and fast unsubscribe handling. Here's what each law actually demands.
Quick Answer
United States (CAN-SPAM): Applies to B2B email too. No opt-in required, but you need a real physical address, an honest subject line, and an opt-out link honored within 10 business days.
European Union (GDPR): A named business email address counts as personal data. Cold outreach usually rests on "legitimate interest," which is a balancing test, not an automatic green light.
Canada (CASL): Default is opt-in. Cold email to a business contact can qualify for implied consent if the address is publicly published and the message is relevant to their role.
Everywhere: Don't scrape personal Gmail or Yahoo addresses, process opt-outs fast, and keep a record of why you emailed each contact.
Is cold email legal in the US, EU, and Canada?
Yes. None of these three laws ban unsolicited business email outright. What they regulate is how you send it: what you have to disclose, how fast you have to honor an opt-out, and in the EU's case, what legal basis lets you process someone's contact details in the first place.
| Region | Governing law | Consent model | Opt-out deadline |
|---|---|---|---|
| United States | CAN-SPAM Act | Opt-out (no prior consent needed) | 10 business days |
| European Union | GDPR, plus national ePrivacy rules | Legitimate interest or consent, varies by member state | Immediate, on objection |
| Canada | CASL | Opt-in (express or implied) | 10 business days |
The consent model is the real fork in the road. CAN-SPAM assumes you can email first and let people leave. CASL assumes the opposite: you need a reason to be in someone's inbox before you send. GDPR sits in between, and it's the one most B2B senders get wrong by treating it like a simple yes/no question.
What does CAN-SPAM actually require for cold email in the US?
CAN-SPAM applies to all commercial email, including B2B outreach, not just consumer marketing. It doesn't require opt-in consent before you send. It requires the email to be honest and easy to escape: real sender information, a real physical address, a subject line that matches the content, and a working opt-out link processed within 10 business days.
- No false or misleading header information. The From, Reply-To, and routing data all have to be accurate.
- Subject lines can't misrepresent what's inside the email.
- The message has to be identifiable as an ad in some clear way, even if that's just plain language in the body.
- A valid physical postal address is required: a street address, a PO box registered with USPS, or a private mailbox registered with a commercial mail receiving agency.
- The opt-out mechanism has to stay functional for at least 30 days after the email goes out.
- Opt-outs must be honored within 10 business days, with no fee, no login, and no request for extra personal information beyond an email address.
If you hire a third party, an agency or a sending tool, to run your outbound, both you and the sender can be held liable for violations. "We didn't send it ourselves" isn't a defense the FTC accepts. Penalties are civil, enforced per violation, and each noncompliant email can be treated as a separate one. The per-email ceiling is adjusted annually and currently sits well into five figures, which is why the math turns ugly fast at real outbound volume.
Does GDPR allow B2B cold email to contacts in the EU?
GDPR doesn't ban B2B cold email, but it does treat a named business address, like a firstname.lastname@company.com tied to an identifiable person, as personal data the moment you process it. Most cold email programs lean on "legitimate interest" as the legal basis instead of consent, but that basis has to survive a three-part test, and it's genuinely debated among privacy lawyers, not a settled green light.
The test has three parts: purpose (is there a legitimate reason to process this data), necessity (is cold outreach actually necessary to achieve that purpose), and balancing (does the individual's right to privacy outweigh your business interest). Relevance does most of the work here. A message tied clearly to the recipient's job function tends to survive the balancing test better than a generic blast that could have gone to anyone at the company.
Two things trip people up. First, several EU member states layer stricter national ePrivacy rules on top of GDPR, and some of them require opt-in consent for unsolicited commercial email even between businesses, which overrides a pure legitimate-interest read. Germany is the most commonly cited example. Second, GDPR's Article 21 gives recipients a right to object to direct marketing specifically, and you're required to tell them about that right and stop processing immediately once they invoke it, no exceptions carved out for that particular objection. There's no EU-wide rule that says "legitimate interest always covers cold email." It depends on the country, the role, and how the message is targeted.
What does CASL require for cold email to Canada?
CASL defaults to opt-in: you need consent, express or implied, before sending a commercial electronic message to a contact in Canada. The path most cold B2B outreach relies on is implied consent under the "conspicuous publication" rule: the recipient's address is publicly listed somewhere like a company website or LinkedIn, there's no notice saying they don't want unsolicited messages, and what you're sending is relevant to their business role.
- The message must identify who sent it, and who it's sent on behalf of if that's a different party.
- Valid contact information (mailing address plus phone, email, or a web form) has to stay reachable for at least 60 days after sending.
- An unsubscribe mechanism is required, has to work without extra steps or cost, and requests must be honored within 10 business days.
- CASL applies based on where the recipient's device is, not where you're sending from. A sender in Mumbai emailing a contact in Toronto is still inside CASL's scope.
Penalties are steep on paper: administrative monetary penalties up to CAD $1 million for an individual and CAD $10 million for an organization, enforced by the CRTC. CASL's private right of action, which would have let individuals sue directly, was suspended before it ever took effect, so enforcement runs through the regulator, not the courts.
What happens if you don't include a working unsubscribe link?
Legally, you're exposed on three fronts at once: an FTC penalty under CAN-SPAM, a CRTC penalty under CASL, and a data protection authority complaint under GDPR's right to object. But in practice, the faster and more common damage is deliverability, not a regulator's letter. Inbox providers track spam complaint rates in real time, and a broken or missing unsubscribe link is one of the fastest ways to push a recipient toward hitting "report spam" instead of just leaving quietly.
That complaint rate feeds directly into whether your next campaign lands in the inbox or the spam folder, for every domain you're sending from, not just the one flagged. Sending platforms like ReachInbox, Smartlead, and Instantly automate opt-out suppression lists, but the legal responsibility to actually honor the request on time is still yours, not the tool's. If your infrastructure is already fragile, an unsubscribe complaint can be the thing that tips a domain into the spam folder. See our guide on fixing cold email spam placement for how complaint rate interacts with domain reputation.
Can you cold email personal Gmail or Yahoo addresses?
You can, but it's a bad practice on both the legal and deliverability side. Personal webmail addresses sit further outside the "business relevance" logic that makes GDPR's legitimate interest and CASL's implied consent defensible in the first place. A message to someone's work address about a work problem has a clear justification. The same message to their personal Gmail account doesn't carry that justification nearly as well.
On top of the legal exposure, consumer inbox providers filter far more aggressively than corporate mail servers. Gmail and Yahoo's spam models are tuned around consumer complaint patterns, and B2B cold email sent to personal addresses gets flagged at a noticeably higher rate than the same message sent to a work domain. Scope your sourcing to work email addresses tied to an actual business role, and skip personal domains entirely when building a list.
What's the practical difference between B2B and B2C cold email compliance?
None of these three laws carve out a blanket B2B exemption, but all three treat B2B messages more leniently in specific, narrow ways. CAN-SPAM applies equally to both, but B2B recipients are generally assumed to expect some amount of vendor outreach as part of their job. GDPR's legitimate-interest balancing test tips more favorably when a message is relevant to someone's professional function rather than their personal life. CASL's implied-consent path through conspicuous publication is essentially built for B2B scenarios: a person's title and public business contact details doing the work that explicit consent does elsewhere.
The thread connecting all three: relevance to the recipient's actual job is what buys you room under every framework here. A tightly defined ICP, sent to the right title at the right kind of company, holds up a lot better than a broad list sprayed across unrelated industries and functions. Loose targeting doesn't just waste send volume, it thins out your legal footing too. Our ICP targeting guide covers how to keep that targeting tight enough to matter.
This is general information based on our own reading of these laws as of 2026. It isn't legal advice, and requirements shift by jurisdiction, sender volume, and the specific facts of your outreach. If you're sending meaningful volume into the EU, UK, or Canada, get a lawyer who handles data protection or anti-spam law to review your actual setup before you scale it.
We've built our own outbound workflows around these requirements after running enough campaigns to know where the legal risk and the deliverability risk overlap, which is most of the time. 6,000+ warm leads delivered came from lists and sequences built with this in mind, not around it. If you'd rather not build this compliance layer yourself, see how Modern Inbound's setup service handles it, or get in touch to talk through your specific market.
By Rishabh Ambasta, Founder, Modern Inbound.
Do I need consent to send a cold email in the US?
No. CAN-SPAM doesn't require opt-in consent before you send a commercial email, including B2B outreach. What it requires is honesty and an easy way out: accurate sender information, a real physical address, a subject line that matches the content, and a working opt-out link you honor within 10 business days.
Is scraping business emails from LinkedIn a GDPR violation?
Not automatically. Collecting a publicly visible business email doesn't sidestep GDPR, because a named email address is still personal data once it's tied to an identifiable person. You need a legal basis, usually legitimate interest, that survives a purpose, necessity, and balancing test, plus a way for the person to object that you honor immediately.
How fast do I have to process an unsubscribe request?
CAN-SPAM and CASL both set 10 business days as the outer legal limit, but neither is a target worth aiming for. GDPR's right to object under Article 21 doesn't specify a grace period at all, so the safer practice across all three laws is same-day suppression, not the maximum allowed window.
Does CASL apply if I'm emailing a Canadian company from outside Canada?
Yes. CASL applies to any commercial electronic message sent to a device located in Canada, regardless of where the sender is based. The relevant question isn't your location, it's whether the recipient's inbox is in Canada and whether you have express or implied consent to email them.
Can a small agency cold email EU contacts without hiring a data protection officer?
Most small and mid-size senders don't meet the thresholds that trigger a mandatory DPO under GDPR. But not needing a DPO doesn't remove the obligation to pick a defensible legal basis, keep records of why each contact was emailed, and honor objections immediately. That responsibility sits with the business regardless of headcount.
Outreach built for your business. Yours to keep.
We build and run outreach inside your business for 90 days, then it stays yours. Tell us your offer and your market and we tell you if it fits.
Rishabh AmbastaFounder, Modern Inbound
Runs a research-led cold email agency measured in delivered replies. Before that, outbound for SaaS teams from $1M to $50M ARR. LinkedIn
Keep reading
Work with us