Is cold email legal? CAN-SPAM, GDPR & PECR explained
Yes — in most places, cold email to a business is legal, as long as you follow a short list of rules. The rules differ by where your recipient sits, and “legal” is not the same as “lands in the inbox.” Here's the practical version for the US, EU, and UK.
Not legal advice. This is a plain-English overview to help you ask the right questions, not a substitute for a lawyer. Regulations change and enforcement varies — confirm your specifics with qualified counsel before you rely on any of this.
United States: CAN-SPAM
The US takes an opt-out approach. You generally don't need prior consent to send a commercial email, but you must follow CAN-SPAM's core requirements on every message:
- No deceptive headers. Your “From,” “Reply-To,” and routing info must be accurate and identify you.
- No misleading subject lines. The subject must reflect the actual content.
- A clear way to opt out, honored promptly — within 10 business days, and you can't charge or make them jump through hoops.
- A valid physical postal address for your business in the email.
- Identify the message as an ad where applicable.
Penalties are per-email and add up fast, so treat these as non-negotiable. Notably, CAN-SPAM does not require opt-in consent — which is why US-targeted cold outreach is common and lawful when done cleanly.
EU: GDPR
The EU is stricter because email addresses that identify a person are personal data. You need a lawful basis to process them. For B2B cold outreach, that's usually legitimate interest — but relying on it comes with obligations:
- Do a balancing test. Your interest in reaching the person has to outweigh their privacy interest. Relevance to their professional role is what makes this defensible.
- Be transparent. Say who you are, why you're emailing, and how you got their details; link a privacy notice.
- Honor objections and erasure. An easy opt-out and prompt deletion on request are mandatory.
- Target roles, not inboxes. Emailing
role@company.comor a clearly professional contact about a genuinely relevant business matter is far safer than personal addresses.
UK: PECR (plus UK GDPR)
The UK layers PECR on top of UK GDPR. The helpful nuance for outbound: PECR's consent rule for unsolicited email applies most strictly to individuals and sole traders. Emailing corporate bodies (limited companies, LLPs) is generally permitted without prior consent — provided you still identify yourself and offer an opt-out every time. As always, relevance to the recipient's role is what keeps you on the right side of it.
The rules that apply almost everywhere
Regardless of jurisdiction, these keep you both compliant and welcome:
- Tell the truth in headers and subject lines.
- Identify yourself and your business clearly.
- Make opting out effortless, and honor it immediately.
- Only contact people for whom your message is genuinely relevant.
- Keep a suppression list and never re-contact an opt-out.
Legal isn't the same as deliverable
You can follow every rule and still land in spam. Compliance is the floor; deliverability and relevance are what actually get you read. The good news is they pull in the same direction: honest, targeted, easy-to-leave email is what regulators want and what mailbox providers reward. An approval-first workflow — where a human signs off on each send from a real inbox — makes both easier to hold to.
The short version
- US (CAN-SPAM): opt-out model — no consent needed, but honest headers, easy unsubscribe, and a physical address are required.
- EU (GDPR): lean on legitimate interest, stay transparent, target professional roles, honor objections.
- UK (PECR): corporate contacts generally OK without prior consent; always identify yourself and offer opt-out.
- Everywhere: be truthful, relevant, and easy to leave — and talk to a lawyer about your specifics.
Keep reading: Cold email deliverability in 2026 and AI SDR vs. approval-first outreach.