Cold email to businesses is legal in most markets, but only if you have a lawful reason to contact the person, identify yourself honestly, and give an easy way to opt out. That is the whole game in one sentence; the rest is detail.
We run cold email every day, so we care about getting this right, not because a regulator is likely to knock, but because sloppy compliance and sloppy outreach come from the same place: not respecting the person on the other end. This guide walks through the three regimes that matter most for B2B senders (CAN-SPAM in the US, GDPR in the EU and UK, and CCPA in California), then turns them into a short list of guardrails you can apply. One caveat up front: we are practitioners, not lawyers. This is general guidance to help you ask better questions, not legal advice. If you operate at scale or in a regulated industry, get a real lawyer to review your program.
Why compliance and deliverability point the same direction
Here is the useful part most people miss. The behaviors that keep you compliant are almost identical to the behaviors that keep you out of spam folders: honest sender identity, a real physical address, a working unsubscribe, relevant targeting, and low complaint rates. So you rarely have to choose between "compliant" and "effective." A tightly targeted list of people who plausibly have the problem you solve is both more lawful and more likely to reply than a scraped list of ten thousand strangers.
CAN-SPAM: the US baseline
CAN-SPAM is the US federal law that governs commercial email, and it is more permissive than people expect. It does not require prior consent to send a cold email, and it applies to both B2B and B2C. What it does require is a set of honesty and opt-out rules on every commercial message you send:
- Do not use false or misleading headers. Your "From," "To," and routing must accurately identify who sent the message.
- Do not use deceptive subject lines. The subject must reflect the actual content.
- Identify the message as an ad where relevant. For a genuine one-to-one inquiry the line is blurry, but transparency is the safe default.
- Include a valid physical postal address. A real mailing address, which can be a registered PO box.
- Offer a clear opt-out and honor it promptly. Stop within ten business days, and do not charge a fee or make the person do more than reply or click one link.
The penalties are per-email, so at outbound volumes the math gets ugly fast if you ignore the basics. The good news: these are cheap to get right. Most of our US-side compliance work is just keeping the footer and sender identity correct on every template.
GDPR: consent or legitimate interest
GDPR is where most B2B senders get nervous, and where the plain-English version helps most. It does not ban cold email. It requires a lawful basis for processing someone's personal data (a work email tied to a named person counts as personal data), and for B2B outreach the two relevant bases are:
- Consent. The person actively agreed to hear from you. Clean, but rarely available for genuinely cold prospects.
- Legitimate interest. You have a real business reason to contact this specific person, the message is relevant to their professional role, and your interest does not override their rights and reasonable expectations.
Legitimate interest is the basis most compliant B2B cold email relies on. To lean on it defensibly, run a simple balancing test and write down the answer: is this person a plausible fit for what we sell, is the email relevant to their job, and would they reasonably expect outreach like this? Emailing a VP of Sales about a sales problem is a strong case. Emailing a warehouse clerk about enterprise software is not.
A few practical GDPR rules that trip people up:
- Target roles, not humans at random. Relevance is your strongest evidence of legitimate interest.
- Honor objections immediately. Under GDPR the opt-out is stronger than CAN-SPAM: when someone objects, you stop, and you also stop processing their data for that purpose.
- Be ready to explain where you got the data. People have a right to know, and buying a mystery list you cannot source is the fastest way to fail this.
- National rules vary. Some EU countries and the UK apply stricter interpretations to email marketing, and corporate, role-based addresses generally get more latitude than personal ones. Do not assume uniformity across the bloc.
This is why we care so much about how a list is built. Clean, well-sourced targeting through tools like our enrichment product is not just a quality play, it is the paper trail that makes a legitimate-interest argument hold up.
CCPA and the US state patchwork
California's CCPA (as amended by the CPRA) is a privacy law, not an email law, but it touches cold outreach because your business contact data is "personal information" under the statute. For most senders the obligations are lighter than GDPR:
- Disclosure. Your privacy policy should explain what categories of personal information you collect and why.
- Opt-out of sale or sharing. If you sell or share personal data, you must let California residents opt out. Most outbound teams do not "sell" in the CCPA sense, but if you trade lists, look closely.
- Deletion and access requests. California residents can ask what you hold and ask you to delete it, so you need a way to handle that.
More US states are passing similar laws, so the smart move is to build one privacy posture that satisfies the strictest regime you touch. If GDPR-grade hygiene is your baseline, CCPA is largely covered.