Cold email vs. spam: the actual distinction
Every cold-email law draws roughly the same line: honest, targeted, professional outreach with a real opt-out is treated differently from deceptive bulk email sent without any way to stop it. None of the four regimes below ban cold outreach outright. They regulate how it's done: who you can email, what the message has to disclose, and how fast you have to stop when someone asks.
Four regimes, four different bars to clear
United States
CAN-SPAM ActOpt-out, not opt-inCAN-SPAM doesn't require consent before you email a business prospect. What it requires: accurate From/Reply-To/subject lines that don't mislead the recipient about the message's content or origin, a valid physical postal address in every email, and a clear, working opt-out mechanism that you honor within 10 business days. There's no cap on cold volume and no requirement to label B2B outreach as an "advertisement."
EU & UK
GDPRLegitimate interest (with limits)GDPR is stricter than CAN-SPAM but doesn't ban B2B cold email outright. "Legitimate interest" can serve as a lawful basis when the outreach is relevant to the recipient's professional role, you can justify why the interest doesn't override their rights, and you provide an easy, immediate way to opt out. It requires more documentation and judgment than the US opt-out model, and it does not extend to buying scraped consumer lists or unrelated targeting.
India
DPDP Act, 2023Notice & consent (still evolving)India's Digital Personal Data Protection Act is newer than CAN-SPAM or GDPR, and the implementing rules and enforcement guidance are still being finalized. Its core principle is notice-and-consent for processing personal data. Professional/business email outreach generally carries a different risk profile than consumer marketing, but because the law is this recent, it's worth confirming specifics with counsel before scaling a campaign targeting India, rather than assuming a US or EU playbook maps directly.
Canada
CASLImplied consent for existing relationshipsCanada's Anti-Spam Legislation is one of the stricter regimes. It allows "implied consent" for a limited window, commonly cited as up to two years, based on an existing business relationship, but cold outreach to a contact with no prior relationship generally needs express consent. Every commercial message needs clear sender identification and a functioning unsubscribe mechanism honored within 10 business days.
A practical compliance checklist
Most compliance failures we see in outbound audits are unforced errors, not deliberate rule-breaking. This covers you across all four regimes above:
- 1
Accurate, non-deceptive From name, Reply-To address, and subject line
- 2
A real physical business address somewhere in the email
- 3
A one-click (or one-reply) way to opt out, honored immediately, not just "within policy"
- 4
Unsubscribe requests processed and suppressed across every future send, not just the current campaign
- 5
Outreach targeted to a professional's business role, not scraped personal/consumer data
- 6
A documented reason the outreach is relevant to the recipient (the "legitimate interest" test, useful even outside the EU)
- 7
No purchased or scraped lists with no verifiable business context
The compliance and deliverability overlap
Compliance and inbox placement aren't separate problems, they reinforce each other. A real unsubscribe link, honest sender identity, and prompt suppression aren't just legal requirements, they're exactly the signals email providers use to decide whether your domain is legitimate. Get the legal basics right and your deliverability tends to improve alongside it. For the technical side of that, see our cold email deliverability guide.
Common questions
Yes, in most jurisdictions B2B cold email is legal when it follows the applicable rules: accurate sender information, no deceptive subject lines, a working opt-out mechanism, and prompt honoring of unsubscribe requests. What's illegal is deceptive or non-consensual bulk spam, not targeted, honest business outreach.
Not always. GDPR allows "legitimate interest" as a lawful basis for B2B outreach in many cases, provided you can justify the interest, keep the message relevant to the recipient's professional role, and offer a clear, immediate opt-out. It's a narrower path than consent-based marketing, and it requires a documented balancing test, not blanket permission to email anyone.
Yes, though the rules are still rolling out. India's DPDP Act, 2023 centers on notice and consent for processing personal data. Professional email addresses used for business outreach carry lower risk than consumer data, but given how recent the law is, get a specific legal check before running large-scale campaigns into India.
Consequences range from spam complaints and blacklisting (a deliverability problem) to regulatory fines under laws like CAN-SPAM or GDPR (a legal problem) in more serious or repeated cases. Most compliance failures we see are unforced errors, missing opt-out links, no physical address, ignored unsubscribe requests, not deliberate violations, and they're straightforward to fix.
Want your outbound checked for compliance and deliverability?
We'll review your sending setup, opt-out handling, and targeting against the rules that apply to your market, and flag anything worth fixing before you scale.
Book a Free GTM AuditHave more questions about Myntmore? Ask your AI