Blog/ Deliverability & authentication

Is Cold Email Legal? CAN-SPAM, GDPR and CASL Compared

Nafiul HasanNafiul Hasan· 10 min read
Diagram comparing whether cold email is legal under CAN-SPAM in the US, GDPR in the EU and CASL in Canada, and how each regime's core rule differs

The short answer

Cold email can be legal in all three, but the logic differs. US CAN-SPAM needs no consent — it regulates how you send: honest headers, a physical address and a working opt-out. EU GDPR and ePrivacy ask whether you may process the data at all. Canada's CASL requires consent, express or implied.

Is cold email legal? Yes, but CAN-SPAM, GDPR and CASL set different rules on consent, sending and data. A jurisdiction-by-jurisdiction map.

On this page
  1. 01Three laws, three different questions
  2. 02First, work out which rules apply to you
  3. 03How to send cold email that stays within the rules
  4. 04CAN-SPAM vs GDPR vs CASL, at a glance
  5. 05Reading the map: which regime is strictest
  6. 06What to do when it feels compliant but still fails
  7. 07Mailbox providers add rules the law does not
  8. 08The other side: what a mail client does with cold email

Is cold email legal? In most cases yes — but the honest answer is that it depends on where your recipient sits, not where you do. Three regimes govern most of the world's business inboxes, and each starts from a different question. The United States asks how you send. The European Union asks whether you may use the data at all. Canada asks whether you have consent.

A message that is fully compliant under one of these can be unlawful under another. So "is cold email legal" is really three separate answers, and the rest of this guide maps CAN-SPAM, GDPR (with ePrivacy) and CASL side by side, with links to each regulator so you can check the current rule yourself.

This is not legal advice

This guide summarises how CAN-SPAM, GDPR, ePrivacy and CASL treat unsolicited outreach, with links to each regulator. Laws change, enforcement varies by country and case, and figures adjust over time. Before you run a campaign, confirm the current rule with the primary source or a qualified lawyer in the relevant jurisdiction.

Three laws, three different questions#

The mistake most compliance checklists make is treating these as one rulebook with regional variations. They are not. Each law answers a different question, and that is why an email can pass one and fail another.

Read the three lines below before anything else. They are the whole shape of the problem, and every detail later hangs off which question applies to your recipient.

  • CAN-SPAM (United States) regulates how you send, not whether. There is no opt-in requirement: you may send a first cold email without prior consent, as long as the message meets the content and opt-out rules. It applies to all commercial email, business-to-business and business-to-consumer alike.
  • GDPR plus the ePrivacy Directive (EU and EEA) regulate the data and the send. GDPR asks whether you have a lawful basis to process someone's personal data; ePrivacy governs whether you may send marketing to them at all. For B2B, senders often rely on legitimate interest — but member states implement the rules differently.
  • CASL (Canada) is consent-first. You generally need consent — express or implied — before you send a commercial electronic message, which makes it the strictest of the three for genuinely cold outreach.

First, work out which rules apply to you#

Before you write a word, figure out which regime governs each contact. As a rule of thumb, the recipient's location drives it: emailing a person in Germany pulls in GDPR and Germany's stricter national rules even if you send from Texas.

Two more distinctions decide how each law treats your list. Get these wrong and a checklist built for one country quietly misfires in another.

  • Is the address personal data? Under GDPR, a named individual's work address ([email protected]) is personal data. A generic role address (info@ or sales@) is a weaker case and often falls outside the strictest rules — but do not assume, because national interpretations vary.
  • Is the message commercial? All three regimes hinge on the message's primary purpose being to promote or sell. A purely transactional or relationship message is treated differently and is largely outside the marketing rules.
  • Where was the data collected, and how? A lawful basis or consent obtained for one purpose does not automatically cover cold sales outreach, and buying or scraping a list rarely gives you either.

How to send cold email that stays within the rules#

These steps are the common core across all three regimes. Where a step differs by country, the difference is called out. Follow the order — the legal groundwork comes before you write the message, not after.

  1. 1

    Segment your list by jurisdiction

    Split contacts into US, EU/EEA and Canada buckets, because the base obligations differ. A single blast under one policy is how a US-style campaign breaks CASL or GDPR.

  2. 2

    Establish your legal footing per region

    US: no prior consent needed, so move to the content rules. EU B2B: document a legitimate-interest assessment where that basis is allowed, or obtain consent where it is required (Germany, for example). Canada: confirm you hold express or implied consent before sending.

  3. 3

    Identify yourself honestly

    Use accurate From and header information, a real sender name, and a subject line that reflects the message. Deceptive headers or subject lines breach CAN-SPAM and undermine your position everywhere.

  4. 4

    Include the disclosures each law requires

    US: a valid physical postal address. Canada: your identity and contact information valid for at least 60 days. EU: on request, and often proactively, tell people where you obtained their details.

  5. 5

    Offer a working opt-out and honor it fast

    Provide a clear unsubscribe path in every message. Both CAN-SPAM and CASL require you to stop sending within 10 business days of a request; under GDPR the right to object to direct marketing is absolute and must be actioned without undue delay.

  6. 6

    Keep records

    Retain your consent evidence, legitimate-interest assessment, data source and suppression list. If a regulator asks why you emailed someone, the burden of showing your basis is on you.

CAN-SPAM vs GDPR vs CASL, at a glance#

The table below is the fast reference. Treat the penalty figures as current at the date shown and confirm them at the linked regulator, because they change: US caps rise with inflation, and EU and Canadian maximums are set in statute but applied case by case.

DimensionCAN-SPAM (US)GDPR + ePrivacy (EU/EEA)CASL (Canada)
Core questionHow you send the messageWhether you may process the data at allWhether you have consent
Consent before sendingNot required — opt-out modelOften legitimate interest for B2B; consent where a member state requires itRequired — express or implied
Applies to B2B?Yes — same rules as B2C, no exemptionYes — a named work address is personal dataYes — with a narrow conspicuously-published route
Identify the senderYes — accurate headers and FromYes — transparency about who you areYes — plus contact info valid 60+ days
Physical addressRequired — valid postal addressNot set by GDPR; identity and data source requiredContact information required
Unsubscribe / objectionRequired; honor within 10 business daysRight to object is absolute; must be easy and freeRequired; honor within 10 business days
Max penalty (as of Aug 2026)Up to $53,088 per emailUp to €20M or 4% of global annual turnoverUp to CAD $10M (org) / $1M (individual) per violation

Reading the map: which regime is strictest#

CAN-SPAM is the most permissive. It lets you send a first message to a stranger with no consent, provided your headers are honest, you name a physical address and you give a working opt-out. The penalty is steep — up to $53,088 per individual email under the FTC's inflation adjustment that took effect on 17 January 2025 and remains the operative maximum in 2026 — but the bar to send lawfully is the content of the message, not permission to send it.

GDPR and ePrivacy sit in the middle and are the hardest to summarise, because ePrivacy is a directive that each member state transposes into its own national law. For B2B, many countries let you rely on legitimate interest under Article 6(1)(f), which Recital 47 explicitly links to direct marketing — but you must pass a balancing test and be ready to justify it. Others, such as Germany under its UWG, require prior consent even for business recipients.

CASL is the strictest for genuinely cold contact, because implied consent is narrow. It typically rests on an existing business relationship — for instance a purchase or inquiry within defined windows — or a business email address the person has conspicuously published without a note refusing such messages, where your email relates to their role.

A single cold email routed down three separate paths by the recipient's location: to CAN-SPAM's send-rules gate in the US, to GDPR and ePrivacy's data-and-consent gate in the EU, and to CASL's consent gate in Canada.
The recipient's location, not the sender's, usually decides which rulebook a cold email must clear.

What to do when it feels compliant but still fails#

Most trouble traces back to a small number of patterns. If your outreach keeps drawing complaints, bounces or takedown demands, check these before you blame the copy.

The recurring one is the source of the list. A purchased or scraped list gives you no lawful basis under GDPR and no existing relationship under CASL, so no amount of tidy formatting makes it compliant. A generic legitimate-interest claim that ignores the balancing test fails for the same reason: the basis has to be genuine and documented, not asserted.

  • Bought or scraped lists: no consent, no existing business relationship, no defensible legitimate interest. This is the fastest way to break both GDPR and CASL at once.
  • Stale data and no suppression: emailing people who already opted out, or whose details are years old, breaches the opt-out rules and erodes any legitimate-interest case.
  • One policy for the whole world: a US-shaped campaign sent to EU and Canadian addresses inherits none of the consent or data-source obligations those regions add.
  • Treating an unsubscribe link as a licence: the link satisfies part of CAN-SPAM and CASL, but it does not create a lawful basis under GDPR or consent under CASL.

The list is where compliance usually breaks

A bought or scraped list has no lawful basis under GDPR and no existing business relationship under CASL. Building your own list, with a recorded source and consent where required, is the only version that holds up. There is no formatting trick that makes a purchased list lawful.

Mailbox providers add rules the law does not#

Even a legally perfect email can be blocked before a human sees it. Gmail, Yahoo, Apple and Outlook.com run their own sender requirements on top of the law, and these are policy, not legislation — but they decide whether your mail is delivered at all.

Legal is not the same as deliverable

Bulk senders to the major inbox providers must authenticate with SPF, DKIM and DMARC, keep spam complaints low, and — for marketing mail to Gmail, Yahoo and Apple — support one-click unsubscribe (RFC 8058). Meeting CAN-SPAM, GDPR or CASL does not exempt you from these provider rules; failing them means non-delivery regardless of legality.

The other side: what a mail client does with cold email#

Everything above is the sender's job. AI Emaily is a mail client, not a sending platform or ESP — it will not run your campaigns or check them against CAN-SPAM, GDPR or CASL. If you need that, a dedicated cold-email tool or an ESP with suppression lists and unsubscribe handling is the right category, and you still have to do the legal groundwork in the steps above.

Where a client like AI Emaily is the adjacent job is the receiving end. Its cold email filter keeps unsolicited outreach out of your primary inbox by matching on sender behaviour and domain rather than a single address, so a compliant-but-unwanted pitch lands where you can triage it on your terms rather than in the middle of real work. Its privacy model means the personal data in your mail is not used to train models. If you are the recipient of cold email rather than the sender, that is the part we do. We build AI Emaily.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Cold email you didn't ask for, handled

AI Emaily's cold email filter keeps unsolicited outreach out of your primary inbox, so you decide what deserves a reply. Start a 7-day free trial.

  • 7-day free trial
  • Cancel anytime
  • Every provider