Content

Cold Email Compliance: A Plain-English Guide to GDPR, CAN-SPAM, and CCPA for B2B

2026-07-22· 7 min read

Cold email to businesses is legal in most markets, but only if you have a lawful reason to contact the person, identify yourself honestly, and give an easy way to opt out. That is the whole game in one sentence; the rest is detail.

We run cold email every day, so we care about getting this right, not because a regulator is likely to knock, but because sloppy compliance and sloppy outreach come from the same place: not respecting the person on the other end. This guide walks through the three regimes that matter most for B2B senders (CAN-SPAM in the US, GDPR in the EU and UK, and CCPA in California), then turns them into a short list of guardrails you can apply. One caveat up front: we are practitioners, not lawyers. This is general guidance to help you ask better questions, not legal advice. If you operate at scale or in a regulated industry, get a real lawyer to review your program.

Why compliance and deliverability point the same direction

Here is the useful part most people miss. The behaviors that keep you compliant are almost identical to the behaviors that keep you out of spam folders: honest sender identity, a real physical address, a working unsubscribe, relevant targeting, and low complaint rates. So you rarely have to choose between "compliant" and "effective." A tightly targeted list of people who plausibly have the problem you solve is both more lawful and more likely to reply than a scraped list of ten thousand strangers.

CAN-SPAM: the US baseline

CAN-SPAM is the US federal law that governs commercial email, and it is more permissive than people expect. It does not require prior consent to send a cold email, and it applies to both B2B and B2C. What it does require is a set of honesty and opt-out rules on every commercial message you send:

  • Do not use false or misleading headers. Your "From," "To," and routing must accurately identify who sent the message.
  • Do not use deceptive subject lines. The subject must reflect the actual content.
  • Identify the message as an ad where relevant. For a genuine one-to-one inquiry the line is blurry, but transparency is the safe default.
  • Include a valid physical postal address. A real mailing address, which can be a registered PO box.
  • Offer a clear opt-out and honor it promptly. Stop within ten business days, and do not charge a fee or make the person do more than reply or click one link.

The penalties are per-email, so at outbound volumes the math gets ugly fast if you ignore the basics. The good news: these are cheap to get right. Most of our US-side compliance work is just keeping the footer and sender identity correct on every template.

GDPR is where most B2B senders get nervous, and where the plain-English version helps most. It does not ban cold email. It requires a lawful basis for processing someone's personal data (a work email tied to a named person counts as personal data), and for B2B outreach the two relevant bases are:

  • Consent. The person actively agreed to hear from you. Clean, but rarely available for genuinely cold prospects.
  • Legitimate interest. You have a real business reason to contact this specific person, the message is relevant to their professional role, and your interest does not override their rights and reasonable expectations.

Legitimate interest is the basis most compliant B2B cold email relies on. To lean on it defensibly, run a simple balancing test and write down the answer: is this person a plausible fit for what we sell, is the email relevant to their job, and would they reasonably expect outreach like this? Emailing a VP of Sales about a sales problem is a strong case. Emailing a warehouse clerk about enterprise software is not.

A few practical GDPR rules that trip people up:

  • Target roles, not humans at random. Relevance is your strongest evidence of legitimate interest.
  • Honor objections immediately. Under GDPR the opt-out is stronger than CAN-SPAM: when someone objects, you stop, and you also stop processing their data for that purpose.
  • Be ready to explain where you got the data. People have a right to know, and buying a mystery list you cannot source is the fastest way to fail this.
  • National rules vary. Some EU countries and the UK apply stricter interpretations to email marketing, and corporate, role-based addresses generally get more latitude than personal ones. Do not assume uniformity across the bloc.

This is why we care so much about how a list is built. Clean, well-sourced targeting through tools like our enrichment product is not just a quality play, it is the paper trail that makes a legitimate-interest argument hold up.

CCPA and the US state patchwork

California's CCPA (as amended by the CPRA) is a privacy law, not an email law, but it touches cold outreach because your business contact data is "personal information" under the statute. For most senders the obligations are lighter than GDPR:

  • Disclosure. Your privacy policy should explain what categories of personal information you collect and why.
  • Opt-out of sale or sharing. If you sell or share personal data, you must let California residents opt out. Most outbound teams do not "sell" in the CCPA sense, but if you trade lists, look closely.
  • Deletion and access requests. California residents can ask what you hold and ask you to delete it, so you need a way to handle that.

More US states are passing similar laws, so the smart move is to build one privacy posture that satisfies the strictest regime you touch. If GDPR-grade hygiene is your baseline, CCPA is largely covered.

The five guardrails we actually run

Strip away the acronyms and compliant B2B cold email comes down to five habits. We build these into every campaign our email agent sends, and into our cold leads solution.

  1. Lawful basis first. Before a list goes live, we can name why each contact is a fair target: honesty plus opt-out for US sends, a written legitimate-interest rationale tied to role relevance for the EU.
  2. Identify yourself honestly. Real name, real company, real sending domain, accurate subject lines. No spoofing, no bait-and-switch.
  3. Working opt-out on every message. One click or one reply, honored fast. We treat an opt-out as permanent across channels, not just that inbox.
  4. A physical address and clear footer. Non-negotiable on commercial sends, and it doubles as a trust signal.
  5. Record-keeping. Where the data came from, when you contacted someone, and when they opted out. If you ever have to answer a question, the record is what saves you.

Record-keeping is the one people skip and the one that matters most under scrutiny. A regulator or an annoyed prospect rarely cares that you meant well; they care whether you can show your work. Automated systems make this easier because the log is a byproduct of the send. It is also why we favor multi-channel sequences that respect a single opt-out across email, LinkedIn, and WhatsApp rather than treating each channel as a fresh start.

One more honest note: compliance does not make bad outreach acceptable. A perfectly footered email that is irrelevant is still spam in spirit, and it will still hurt your domain. Our breakdown of common AI outbound mistakes and our AI SDR overview both show how good targeting keeps relevance high. Compliance is the floor. Relevance is how you win.

If you would rather see compliant outreach run end to end than assemble the rules yourself, explore the full agent lineup on our homepage, then watch the live demo or book a meeting and we will walk you through how we handle basis, opt-out, and record-keeping on real campaigns.

FAQ

Yes, in most major markets cold email to business contacts is legal when done correctly. In the US, CAN-SPAM permits it without prior consent as long as you are honest and offer an opt-out. In the EU and UK you generally rely on a legitimate-interest basis, which means targeting relevant roles and honoring objections.

Not necessarily. GDPR allows two main lawful bases for B2B cold email: explicit consent or legitimate interest. Most cold outreach relies on legitimate interest, which requires that the person is a genuine fit, the message is relevant to their job, and your interest does not override their rights. Document that reasoning before you send.

What has to be included in a compliant cold email?

At minimum, an accurate sender identity, a truthful subject line, a valid physical postal address, and a clear working way to opt out. Under CAN-SPAM these are required on every commercial message. Under GDPR you should also be prepared to explain where the contact data came from if asked.

How fast do I have to honor an opt-out?

Honor it as quickly as you can. CAN-SPAM sets a maximum of ten business days in the US, but the practical standard is to suppress the contact immediately across all channels. Under GDPR an objection should stop processing without undue delay. Treating opt-outs as instant and permanent is safer and better for deliverability.

No. This is general, practical guidance from a team that runs outbound, not legal advice. Laws vary by jurisdiction and change over time, and your situation may carry obligations this article does not cover. If you operate at scale or in a regulated industry, have a qualified attorney review your program.

Put this into practice

Leaderra's four AI agents qualify, chase, and book meetings on your leads — verified, scored, and briefed.

Related reading