Menu

Is cold email legal? Cold email laws in the US, UK, EU, Canada and Australia

Rather not build this yourself? Pipefire runs your cold email end to end.See how it works →

Cold email is legal in the United States, the UK, the EU, Canada and Australia, but each country attaches different conditions. The US allows it to anyone as long as the message is honest and easy to opt out of. The UK, the EU, Canada and Australia all limit who you can email without consent first.

This page covers what each country's law actually requires, with a link to the regulator behind every claim. It is the detailed version of the legal section in our cold email guide. This is a summary of public regulator guidance, not legal advice: check the current rules with a lawyer before you run a campaign that crosses borders.

Cold email is legal almost everywhere, provided the sender is honest about who they are and offers a working opt-out. No major market bans cold email outright. What differs by country is whether you need the recipient's consent before the first message, or only afterward.

  • United States: Legal to anyone, business or consumer, under the CAN-SPAM Act. No consent needed first.
  • United Kingdom: Legal to companies without consent. Sole traders and some partnerships need consent.
  • European Union: Usually relies on "legitimate interest" under GDPR for B2B, with some countries, Germany in particular, requiring consent first.
  • Canada: Needs consent, express or implied, under CASL. Implied consent is narrow and time-limited.
  • Australia: Needs consent, express or inferred, under the Spam Act 2003.

Is cold email illegal in some cases?

Cold email becomes illegal the moment it misleads the recipient, hides the sender's identity, ignores an opt-out, or is sent to someone the local law requires consent from first. None of these problems come from cold emailing itself: they come from how it is done.

The common mistakes that turn a legal cold email into an illegal one:

  • Faking the "from" name or using a deceptive subject line.
  • Leaving out a working way to opt out, or ignoring opt-out requests.
  • Emailing an individual, sole trader, or EU contact who legally needed consent first, without getting it.
  • Using a list built by harvesting addresses with scraping software, which several of these laws ban outright regardless of what the email says.

What does CAN-SPAM require for cold email in the US?

CAN-SPAM requires every commercial email, including B2B cold email, to use honest sender details, identify itself as an ad, give a real postal address, and offer an opt-out that is honored within 10 business days. The FTC's CAN-SPAM compliance guide sets out the law in full. It makes no exception for business-to-business email.

The core requirements:

  1. No false or misleading header information. The "From" and "To" fields must accurately identify who sent the message.
  2. No deceptive subject lines. The subject must reflect what the message says.
  3. Clear identification as an ad. The message must disclose, clearly and conspicuously, that it is an advertisement.
  4. A valid physical postal address in the email, such as a street address or a registered PO box.
  5. A clear way to opt out, usable for at least 30 days, honored within 10 business days, with no fee and no extra information required beyond an email address.
  6. Accountability for who you hire. Both the business behind the campaign and the company that sends the email can be held responsible.

The FTC can fine violators up to $53,088 per email that breaks the rules, a figure it last adjusted for inflation in January 2024 and confirms on the compliance guide itself.

Cold emailing a company in the UK is legal without prior consent, but emailing an individual, sole trader or some partnerships requires consent first. The rule sits in the Privacy and Electronic Communications Regulations, known as PECR, and the ICO's guide to electronic mail marketing is the regulator's own explanation of it.

The line the ICO draws:

  • Corporate bodies (a limited company, Scottish partnership, LLP or government body) can be emailed without consent, if the sender is identified and a valid opt-out is given.
  • Sole traders and some partnerships are treated like individuals under PECR. They need specific consent, or a narrow "soft opt-in" if they are an existing customer who was offered an opt-out when their details were collected.
  • Emailing named staff at a company also touches UK GDPR, since a named contact's details are personal data. The ICO's guidance on legitimate interests is the practical standard most B2B senders use to justify processing that data without consent.

Our page on what cold email is covers how this differs from email marketing, where UK recipients must opt in regardless of whether they are a company or an individual.

Cold email to EU business contacts is usually legal under GDPR's "legitimate interest" basis, but the rule is not uniform across member states and some countries require consent instead. GDPR Recital 47 states directly that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest," which is the clause B2B senders rely on.

Relying on legitimate interest is not automatic. It requires a documented assessment that the business reason is real, that contacting the person is necessary, and that it does not override their privacy rights. That three-part test is the same one the ICO's practical guidance on legitimate interests walks through, since UK GDPR mirrors the EU text.

Germany is the clearest exception. Its Act Against Unfair Competition treats commercial email sent without prior consent as an unacceptable nuisance, with only a narrow exception for existing customers. The official English translation of Section 7 of the UWG sets this out directly, and it applies to B2B email the same way it applies to consumer email: there is no general business-to-business exemption. Treat any EU-wide cold email plan as needing a country-by-country check, not one GDPR answer.

Cold emailing a Canadian contact requires either express or implied consent under Canada's Anti-Spam Legislation, known as CASL, which is stricter than the US and the UK's company exemption. The CRTC's guidance on implied consent is the regulator's own explanation of when implied consent applies.

CASL recognizes two kinds of consent:

Consent typeWhat qualifiesHow long it lasts
Express consentThe recipient opted in directly, in writing or orallyUntil they withdraw it
Implied consent (existing business relationship)A purchase, inquiry or signed contract with the recipient2 years after a purchase, 6 months after an inquiry
Implied consent (conspicuous publication)The recipient published their own address publicly, with no opt-out notice, and the message relates to their business roleNot time-limited, but narrow in scope

Every commercial electronic message must also identify the sender and include a working unsubscribe mechanism, honored within 10 business days. CASL has no general business-to-business exemption: a narrow version exists only between organizations that already have a relationship, and only for messages about the receiving organization's own activities.

Cold emailing an Australian contact requires consent, express or inferred, under the Spam Act 2003, enforced by the Australian Communications and Media Authority, known as ACMA. Its own guide, Avoid sending spam, lays out what counts as consent and what a compliant message needs.

The Spam Act's three requirements once consent exists:

  1. Identify the sender accurately, with correct contact details that stay valid for at least 30 days.
  2. Include a working unsubscribe option that is honored within 5 working days, which is faster than the 10 business days required in the US and Canada.
  3. Never use a harvested list. Using or supplying address-harvesting software, or a list built with it, is a separate violation regardless of consent.

Inferred consent, where a recipient's conduct makes it reasonable to expect marketing, is treated as weaker evidence than express consent, and the sender always carries the burden of proving it existed.

For the US law in depth, including the current penalty and a checklist, see our CAN-SPAM Act guide for cold email.

Cold email law by country

CountryLawDefault rule for B2B cold emailOpt-out deadlineRegulator
United StatesCAN-SPAM ActLegal to anyone, no consent required10 business daysFTC
United KingdomPECR + UK GDPRLegal to companies, consent needed for sole tradersHonored "promptly"ICO
European UnionGDPRUsually legal via legitimate interest; Germany requires consentImmediate on requestNational data protection authorities
CanadaCASLConsent required, express or implied10 business daysCRTC
AustraliaSpam Act 2003Consent required, express or inferred5 working daysACMA

Cold email compliance checklist

A cold email campaign that follows these steps clears the main requirements in every country above, though a lawyer should confirm anything targeting a specific jurisdiction.

  1. Identify yourself honestly. Real sender name, real company, no misleading subject line.
  2. Add a physical postal address to every email, as US law requires it directly in the message.
  3. Give a working opt-out in every email, and route replies like "stop" or "unsubscribe" to a suppression list that blocks every future send.
  4. Honor opt-outs fast. Build to the strictest deadline in play, Australia's 5 working days, rather than the US and Canada's 10.
  5. Check who you are emailing. A company address in the UK needs no consent; a sole trader, an EU contact outside a clear legitimate-interest case, a Canadian contact, or an Australian contact likely does.
  6. Never buy or scrape a harvested list. Canada and Australia both treat harvested lists as a separate violation.
  7. Keep records. Consent source, the date, and every opt-out request, in case a regulator or a recipient disputes it later.
  8. Get local legal advice before emailing outside your home country, since consent rules vary by country and some, like Germany, differ sharply from their regional norm.

Pipefire builds the mechanical parts of this checklist into every send rather than leaving them to a template. Every campaign email carries a plain opt-out line and the sender's postal address in the body, plus a one-click List-Unsubscribe header that Gmail and Yahoo read directly.

A reply containing an opt-out phrase is detected automatically. The prospect is then marked unsubscribed for good, across every domain and mailbox.

None of this replaces legal judgment about who you can email in a given country. It only makes sure the parts a platform can enforce are never missed.

For the mechanics of running a compliant send at volume, our cold email deliverability guide covers authentication and the opt-out and bounce thresholds that keep a domain in good standing. See how Pipefire works for how these checks run on every email without manual setup.

Cold email is legal in every country covered here, but several of them require the recipient's consent before the first message. The email itself is not illegal; sending it to the wrong person without the right basis is what creates the risk.

Is cold email illegal under GDPR?

No, cold email is not illegal under GDPR on its own. Most B2B senders rely on "legitimate interest" as their legal basis, though some countries, Germany in particular, require consent first regardless of GDPR's general allowance.

Do I need a physical address in a cold email?

Yes, if you are emailing US recipients. CAN-SPAM requires a valid physical postal address in the body of every commercial email, a requirement the UK, EU, Canadian and Australian rules do not list as explicitly but that is good practice everywhere.

Can I buy an email list for cold outreach?

You can, but Canada and Australia explicitly ban lists built with address-harvesting software, and an unverified bought list raises bounce rates regardless of legality. Our guide to building a cold email list covers how to verify one before sending.

Is cold emailing a business the same as spamming it?

No. A relevant, honest, one-to-one email with a working opt-out is cold email; a bulk, irrelevant or deceptive message, or one sent after an opt-out, is spam under every law on this page. Our page on what cold email is breaks down that difference in full.