Skip to content
CM
Compliance & Reference··10 min read

Cold Email Compliance Guide

Complete guide to cold email compliance — CAN-SPAM, GDPR, CCPA, and other regulations. What you must do to send cold email legally.

Quick Answer

Cold email is legal in most jurisdictions when done correctly. The core requirements everywhere are: include your physical address, provide an opt-out mechanism, honor unsubscribes promptly, and use accurate sender information.

Introduction

Cold email is legal in most countries, but it comes with specific rules. Failing to comply with anti-spam regulations can result in fines, domain blacklisting, and damage to your brand reputation.

This guide covers the major regulations that apply to cold email — CAN-SPAM, GDPR, CASL, and CCPA — and explains exactly what you need to do to stay compliant.

Who This Guide Is For

  • Anyone sending cold email who wants to understand the legal requirements
  • Sales teams operating across multiple regions
  • Founders and marketers who are unsure whether cold email is legal

Key Takeaways

  • 1. Cold email is legal in the US (CAN-SPAM) and most countries with proper compliance
  • 2. GDPR (EU) requires a legitimate interest basis for cold email to individuals
  • 3. Every cold email must include a physical address and opt-out mechanism
  • 4. Unsubscribe requests must be honored within 10 business days (CAN-SPAM)
  • 5. Penalties for non-compliance can reach $46,517 per email under CAN-SPAM

CAN-SPAM Act (United States)

CAN-SPAM is the primary US anti-spam law. It applies to all commercial email messages, including cold email. Violations can result in fines of up to $46,517 per email.

CAN-SPAM Requirements

  • Do not use deceptive subject lines — they must accurately represent the email content
  • Identify the message as an advertisement (if applicable)
  • Include your valid physical postal address
  • Tell recipients how to opt out of future emails
  • Honor opt-out requests within 10 business days
  • Do not send email after someone has opted out
  • Monitor what third parties are doing on your behalf (your email vendor)

⚠️ Warning

CAN-SPAM does not require prior consent. You CAN send cold email under CAN-SPAM. But you MUST include all required elements. Missing any one of them is a violation.

GDPR (European Union)

GDPR is stricter than CAN-SPAM and applies to any email sent to individuals in the EU, regardless of where you are located. Cold email under GDPR requires a lawful basis.

Lawful Bases for Cold Email

BasisWhat It MeansPractical Use
Legitimate InterestYou have a genuine business reason to contact themMost B2B cold email relies on this basis
ConsentThey explicitly agreed to receive email from youNot applicable for truly cold outreach

GDPR Requirements for Cold Email

  • You must have a legitimate interest basis for contacting the individual
  • The email must be relevant to their professional role
  • You must identify yourself clearly (who you are and why you are contacting them)
  • You must provide a clear way to opt out
  • You must honor opt-out requests immediately
  • You must be able to demonstrate your legitimate interest if challenged

GDPR also gives individuals the right to access, rectify, and erase their personal data. If someone asks what data you hold about them, you must respond.

CASL (Canada)

CASL (Canada's Anti-Spam Legislation) is one of the strictest anti-spam laws in the world. It requires express consent for commercial email, with limited exceptions for B2B outreach.

  • Express consent is generally required for commercial email to individuals
  • Implied consent exists for existing business relationships (within 2 years of last transaction)
  • Implied consent exists for conspicuous publication of email (with conditions)
  • All emails must include sender identification, contact info, and an unsubscribe mechanism
  • Penalties can reach $10 million per violation for organizations

⚠️ Warning

CASL's B2B exception is narrower than many people think. Consult legal advice before sending cold email to Canadian recipients.

CCPA (California)

CCPA (California Consumer Privacy Act) applies to businesses that collect personal information from California residents. While it primarily focuses on data collection and privacy rights, it affects cold email in how you obtain and manage prospect data.

  • You must disclose what personal data you collect and how you use it
  • California residents can request deletion of their personal data
  • You must honor opt-out requests (Do Not Sell My Personal Information)
  • Privacy policy must be accessible and transparent

Practical Compliance Checklist

Regardless of which regulations apply to you, here is the practical checklist that covers the core requirements everywhere:

  • Include your company name and physical mailing address in every email
  • Use accurate From, To, and Reply-To header information
  • Provide a clear opt-out mechanism (reply with 'unsubscribe' or an unsubscribe link)
  • Honor opt-out requests within 10 business days
  • Never email someone who has opted out
  • Maintain a suppression list of opted-out addresses
  • Do not use deceptive subject lines
  • Keep records of your legitimate interest basis (for GDPR)
  • Review your compliance quarterly

Best Practices

  • Include a physical address in every cold email
  • Provide a clear opt-out mechanism
  • Maintain and honor a suppression list
  • Use accurate sender information
  • Document your legitimate interest basis for GDPR compliance
  • Review compliance requirements for each region you send to
  • Consult legal counsel for complex multi-region campaigns

Mistakes to Avoid

  • Not including a physical address in cold emails
  • Not providing an opt-out mechanism
  • Continuing to email after someone has opted out
  • Using deceptive subject lines
  • Not maintaining a suppression list
  • Ignoring GDPR requirements for EU contacts
  • Assuming cold email is illegal instead of learning the rules

Expert Tips

  • Compliance is not optional — the fines are real and enforceable
  • A simple opt-out mechanism (reply 'unsubscribe') is often more effective than a link
  • Maintaining a suppression list protects you legally and improves deliverability
  • When in doubt, more transparency is always better than less

Compliance Checklist for Every Campaign

  • Physical mailing address is included in the email footer
  • Sender name and email are accurate
  • Opt-out mechanism is clear and functional
  • Suppression list is maintained and checked before each send
  • Subject line accurately represents the email content
  • Legitimate interest documentation is on file (for GDPR)
  • Opt-out requests are processed within 10 business days

Summary

Cold email is legal in most countries when done correctly. The core requirements are consistent: honest sender information, accurate subject lines, a physical address, and an opt-out mechanism.

CAN-SPAM (US) does not require consent but mandates specific email elements. GDPR (EU) requires a legitimate interest basis. CASL (Canada) is stricter and generally requires express consent. CCPA (California) adds data privacy requirements.

Compliance is not complicated — it requires transparency, honesty, and respect for the recipient's right to opt out. Build compliance into every campaign from the start.

Frequently Asked Questions

Is cold email legal?
Yes, in most countries when you follow the applicable regulations. In the US, CAN-SPAM allows cold email with specific requirements. In the EU, GDPR requires a legitimate interest basis. The key is compliance, not prohibition.
Do I need consent to send cold email?
It depends on the jurisdiction. In the US (CAN-SPAM), consent is not required but specific elements are. In the EU (GDPR), you need a legitimate interest basis. In Canada (CASL), express consent is generally required with limited exceptions.
What happens if I violate anti-spam laws?
Penalties vary by regulation. CAN-SPAM fines reach $46,517 per email. GDPR fines can reach €20 million or 4% of global revenue. CASL penalties reach $10 million per violation for organizations.
Do I need an unsubscribe link or just a way to opt out?
The method varies by regulation, but a clear opt-out mechanism is required everywhere. An unsubscribe link is the most common approach. Some senders use a simpler 'reply unsubscribe' approach.

Next Steps

  • Review your cold email templates for compliance elements
  • Set up a suppression list management process
  • Understand deliverability requirements in our Deliverability guide
  • Audit your current campaigns with our Mistakes to Avoid guide

Plan compliant campaigns

Use ColdMailCalculator to forecast your cold email results before you send.

Related Resources