← Journal
StrategySeptember 23, 2026· Dimitar Petkov· 9 min read

Cold Email Compliance Requirements Every B2B Company Ignores

Most B2B companies sending cold email miss critical compliance requirements under CAN-SPAM, GDPR, and CASL. Each violation carries penalties up to $53,088, yet basic legal obligations remain widely ignored.

Research this article with AI

Follow Well Met on Google

Cold Email Compliance Requirements Every B2B Company Ignores

Cold email remains a standard tool in B2B outreach, yet most companies operate in a legal grey zone they barely understand. The CAN-SPAM Act applies to every commercial message sent in the United States, including business-to-business email. GDPR governs messages to recipients in the European Union. CASL regulates commercial electronic messages sent to or from Canada.

Each law carries different requirements, and each violation can trigger penalties up to $53,088 per message. Despite these stakes, basic compliance failures persist across the industry. Companies send messages with misleading headers, omit required disclosures, ignore opt-out requests, or assume business email falls outside consumer protection laws.

The legal framework is straightforward. The operational discipline to follow it is not. This article walks through the specific requirements under each major jurisdiction, the penalties for non-compliance, and the common mistakes that trigger enforcement action.

What does CAN-SPAM require for cold email in the United States?

The CAN-SPAM Act, enforced by the Federal Trade Commission, sets seven baseline requirements for any commercial email sent in the United States. The law makes no exception for B2B email. A message promoting a product, service, or commercial website must comply, whether it lands in a consumer inbox or a purchasing manager's.

Accurate header information. The 'From', 'To', 'Reply-To', and routing information must identify the person or business that initiated the message. Spoofing or misleading headers violates the law.

Non-deceptive subject lines. The subject line must accurately reflect the message content. Claims that exaggerate, mislead, or disguise the commercial nature of the email breach CAN-SPAM.

Clear identification as an advertisement. The message must disclose clearly and conspicuously that it is an advertisement. The law allows leeway in how this is done, but the disclosure must be obvious.

Physical postal address. The message must include a valid physical postal address. This can be a street address, a registered post office box, or a private mailbox registered with a commercial mail receiving agency.

Functional opt-out mechanism. The message must include a clear, conspicuous explanation of how the recipient can opt out of future messages. The opt-out must remain functional for at least 30 days after the message is sent. Recipients cannot be required to pay, provide personal information beyond an email address, or navigate more than a single page to opt out.

Honor opt-outs within 10 business days. Once a recipient opts out, the sender must stop emailing them within 10 business days. Selling or transferring opted-out addresses is prohibited, except to a service provider helping the sender comply with CAN-SPAM.

Monitor third parties acting on your behalf. If a company hires another firm to send email on its behalf, both parties may be held liable for violations. The company whose product is promoted cannot contract away legal responsibility.

How does GDPR change the rules for cold email to EU recipients?

The General Data Protection Regulation applies to any processing of personal data related to individuals in the European Union, including email addresses. GDPR sets a higher bar than CAN-SPAM: processing is prohibited unless the data subject has consented or another legal basis applies.

Recital 47 of GDPR states that direct marketing may constitute a legitimate interest of the controller, but Article 95 defers to the ePrivacy Directive for electronic communications. Under the ePrivacy Directive, commercial electronic messages require the recipient's prior consent.

This creates a sharp contrast with US law. CAN-SPAM allows cold outreach as long as the sender honors opt-outs. GDPR and the ePrivacy Directive require explicit consent before the first message is sent. The sender must obtain permission, not simply offer an unsubscribe link.

Even if a company argues legitimate interest, the recipient always retains the right to object under Article 21(2) and (3) of GDPR. Once a recipient objects to processing for marketing purposes, the controller must stop immediately. The legitimate interest of the sender cannot outweigh the objection of the data subject.

For B2B companies, this means cold email to EU recipients without prior consent violates the law. Existing customer relationships may provide a legal basis for certain marketing messages, but cold prospecting does not.

What are Canada's anti-spam law requirements?

Canada's Anti-Spam Legislation (CASL), which took effect in 2014, mirrors GDPR's consent-first approach. CASL applies to commercial electronic messages sent to or from Canada. The law defines commercial electronic messages broadly, covering any message that encourages participation in a commercial activity.

CASL requires express or implied consent before sending a commercial electronic message. Express consent means the recipient has clearly agreed to receive messages. Implied consent can arise from an existing business relationship, an inquiry, or a conspicuous publication of the recipient's email address, but these exceptions are narrow.

Abstract visualization of jurisdiction-specific cold email compliance requirements across three geographic regions

Messages sent with consent must include the sender's identity, contact information, and an unsubscribe mechanism. The unsubscribe must be functional, easy to use, and honored within 10 business days.

CASL enforcement has been effective. When the law was introduced in 2014, Canada was home to 7 of the world's top 100 spamming organizations. By 2019, no Canadian organizations remained on that list. The Spam Reporting Centre received more than 167,939 complaints between October 2021 and March 2022, with email sent without consent as the top reason.

For B2B senders, CASL means obtaining consent before the first message or relying on an existing business relationship. Cold outreach to Canadian recipients without one of these bases violates the law.

Can I get sued for cold emailing businesses?

Yes. Both CAN-SPAM and CASL carry significant civil penalties, and GDPR enables supervisory authorities to impose fines. CAN-SPAM violations can result in penalties up to $53,088 per message. Both the company whose product is promoted and the company that sends the message can be held liable.

CAN-SPAM also includes criminal provisions for aggravated violations, such as accessing someone else's computer to send spam without permission, using false information to register email accounts or domain names, or harvesting email addresses through dictionary attacks. Criminal penalties include imprisonment.

Under GDPR, data protection authorities can impose administrative fines. The specific amounts depend on the nature and severity of the violation, but fines can reach significant levels for organizations that process personal data unlawfully.

CASL similarly imposes penalties for non-compliance. While the law does not specify a per-message fine in the same way CAN-SPAM does, enforcement actions have resulted in substantial settlements.

Beyond regulatory penalties, violating these laws damages sender reputation, deliverability, and brand trust. Email providers monitor sender behavior, and consistent violations result in emails landing in spam folders or being blocked entirely.

What compliance mistakes do B2B companies make most often?

Assuming B2B email is exempt. CAN-SPAM explicitly covers business-to-business email. The law applies to any commercial message, regardless of the recipient's role or industry. Companies that treat B2B outreach as a separate category operate outside compliance.

Ignoring jurisdiction-specific rules. A company based in the United States that sends email to recipients in the EU or Canada must comply with GDPR or CASL, not just CAN-SPAM. Many B2B senders fail to segment their lists by jurisdiction or apply a single compliance standard globally.

Delaying or ignoring opt-out requests. CAN-SPAM and CASL both require opt-outs to be honored within 10 business days. Companies that manually process unsubscribe requests or batch them monthly violate this requirement. Automated, immediate processing is the only safe approach.

Omitting required disclosures. Messages that lack a physical address, fail to identify themselves as advertisements, or bury the unsubscribe link in fine print violate CAN-SPAM. Many senders treat these as optional formatting choices rather than legal requirements.

Using misleading headers or subject lines. Subject lines that exaggerate results, imply a prior relationship, or obscure the commercial intent of the message violate CAN-SPAM. Headers that spoof sender identity or route through misleading domains compound the violation.

Buying or renting email lists without consent verification. Lists purchased from third parties often lack the consent required under GDPR and CASL. Even if the list vendor claims compliance, the sender remains liable for violations. Consent is specific to the sender and the relationship, not transferable through a list sale.

Failing to monitor third-party senders. Companies that outsource email marketing or lead generation remain legally responsible for compliance. If the vendor violates CAN-SPAM, GDPR, or CASL, the company whose product is promoted faces penalties.

What is the safest legal approach to cold B2B outreach?

The safest legal approach depends on the jurisdiction of the recipient. For recipients in the United States, CAN-SPAM allows cold email as long as the sender complies with disclosure, opt-out, and identification requirements. For recipients in the EU or Canada, consent-first rules under GDPR and CASL make cold email legally risky without prior permission.

For US recipients: send messages that clearly identify the sender, include a physical address, disclose the message as an advertisement, provide a functional one-click unsubscribe, and honor opt-outs within 10 business days. Avoid misleading subject lines and spoofed headers.

For EU and Canadian recipients: obtain explicit consent before sending the first message, or rely on an existing business relationship if one exists. Document the consent or relationship. Include sender identity, contact information, and a working unsubscribe in every message.

Consider alternative outreach methods. Cold email compliance is legally complex and reputationally fragile. Familiarity-first strategies, such as commenting on a prospect's LinkedIn content before connecting, build trust without triggering spam laws. These methods avoid inbox friction, improve response rates, and eliminate the legal risk of unsolicited commercial messages.

Jurisdiction-specific cold email compliance requirements
JurisdictionConsent requiredOpt-out windowMaximum penalty per message
United States (CAN-SPAM)No (opt-out required)10 business days$53,088 USD
European Union (GDPR/ePrivacy)Yes (prior consent)Immediate upon objectionAdministrative fines (varies)
Canada (CASL)Yes (express or implied)10 business daysSignificant settlements (varies)

CAN-SPAM Act penalties up to $53,088 per violation and applies to all commercial email including B2B

Federal Trade Commission (accessed), 2026-09-23

CASL led to reduction in Canadian spam organizations from 7 of top 100 in 2014 to zero by 2019, with 167,939 complaints between October 2021 and March 2022

Innovation, Science and Economic Development Canada, 2024-07-15

GDPR requires consent for marketing email under ePrivacy Directive Article 13(1) of Directive 2002/58/EC

GDPR.eu (accessed), 2026-09-23

PECR sit alongside UK GDPR with specific rules on marketing calls, emails, texts and faxes requiring consent

UK Information Commissioner's Office (accessed), 2026-09-23

Frequently asked questions

  • Does CAN-SPAM apply to business-to-business email?

    Yes. The CAN-SPAM Act covers all commercial email, including messages sent to business email addresses. The law makes no exception for B2B outreach. Every commercial message must comply with CAN-SPAM requirements, including accurate headers, clear identification as an advertisement, a physical address, and a functional opt-out mechanism.

  • Can I send cold email to EU recipients if I include an unsubscribe link?

    No. GDPR and the ePrivacy Directive require explicit consent before sending commercial electronic messages to recipients in the European Union. An unsubscribe link does not satisfy this requirement. Cold email to EU recipients without prior consent violates the law.

  • What happens if I ignore an opt-out request?

    Ignoring an opt-out request violates CAN-SPAM and CASL. Both laws require opt-outs to be honored within 10 business days. Each message sent after the opt-out period expires is a separate violation, subject to penalties up to $53,088 per message under CAN-SPAM.

  • Am I liable if I hire a vendor to send cold email on my behalf?

    Yes. CAN-SPAM and CASL hold both the sender and the company whose product is promoted liable for violations. You cannot contract away legal responsibility by outsourcing email to a third party. If the vendor violates compliance requirements, you face penalties.

  • Is buying an email list legal?

    Buying an email list is legal in the United States, but using it to send cold email can violate GDPR or CASL if the recipients are in the EU or Canada and have not consented to receive messages from your company. Consent under GDPR and CASL is specific to the sender and the relationship, not transferable through a list sale.

Want warm pipeline without the hours?

Book a call