Skip to content
legal

Is cold email legal? GDPR, CAN-SPAM and what actually gets you fined

The rules are less restrictive than most people assume — and the thing that actually gets enforced is not what most people worry about.

updated · 2026-09-20

Is it legal to send cold emails to businesses?

Cold email to business addresses is legal in both the EU and the US, under different conditions. Under GDPR you need a lawful basis, and legitimate interest generally covers B2B outreach if you document the assessment, say where you got the data and honour objections. Under CAN-SPAM no prior consent is required at all, but you must identify yourself, give a real postal address and process opt-outs within ten business days.

In short

  • GDPR permits B2B cold email under legitimate interest, provided the assessment is documented.
  • CAN-SPAM requires no prior consent at all — it regulates how you send, not whether you may.
  • Both regimes require a working opt-out, and failing to process one is what actually gets enforced.
  • Buying a list you cannot trace to a source leaves you unable to answer the only question a regulator asks.

The two regimes you are likely under

If your recipient is in the EU or the UK, GDPR and the local ePrivacy rules apply. If your recipient is in the US, CAN-SPAM applies. They differ in a way that surprises people: the American rule is the permissive one.

CAN-SPAM requires no consent before sending. It regulates conduct: identify yourself honestly, do not fake the header or subject, include a valid physical postal address, and honour opt-outs within ten business days.

What GDPR actually requires for B2B

GDPR does not ban cold email. It requires a lawful basis for processing the contact data, and for business-to-business outreach legitimate interest is the ordinary basis. What it demands is that you can show your work.

In practice that means three things you should be able to produce: a legitimate interest assessment, a record of where the data came from, and evidence you act on objections.

  • Write down the legitimate interest assessment before you start, not after a complaint.
  • Record the source of every address, per record.
  • Tell the recipient in the first email where you got their details.
  • Give a working opt-out and process it immediately, not in thirty days.
  • Delete on request and keep proof you deleted.

Where national rules are stricter

Some member states apply the ePrivacy rules more tightly than others. Germany is the clearest example: advertising email generally requires prior consent, and enforcement there comes through competitor warning letters rather than the regulator.

If you are writing into those markets, keeping the message informational rather than promotional is both safer and more effective. The two goals point the same way.

Pocufy

Three agents run the part of these steps that repeats every week: defining the audience, building the list, writing each email for the person, and following up on the reply.

What actually gets enforced

Almost nobody is penalised for the first email. Complaints come from people who tried to get off a list and could not. That is the failure mode that turns a routine campaign into an enforcement problem.

The practical consequence: your opt-out plumbing matters more than your legal wording. An unsubscribe that works within minutes prevents most of the risk.

Bought lists

A purchased list creates a problem that is legal before it is commercial: you cannot say where the data came from, and that is the first question anyone will ask.

It is also the commercial problem. Bought lists carry dead addresses, dead addresses bounce, and bounces degrade the deliverability of every later send from your domain.

What a compliant send looks like

Written to a business address, addressed to a named person, stating who you are, saying where you found them, asking one question and offering a way out. That message satisfies both regimes and also happens to be the version that gets replies.

Pocufy builds that frame into the flow: business addresses only, an opt-out on every message, automatic removal on opt-out and a record of what was sent to whom. You approve the copy before it goes.

Common questions

  • In the US, yes — CAN-SPAM requires no prior consent. In the EU, yes under legitimate interest for B2B, provided you document the assessment, disclose the data source and honour objections. Some member states, notably Germany, are stricter.

  • GDPR penalties are tiered and scale with turnover. CAN-SPAM is assessed per violating email, which compounds fast in bulk sending. In practice the more common cost is a blocked domain rather than a fine.

  • CAN-SPAM requires an opt-out mechanism in commercial email. A plain sentence offering to stop writing satisfies it and reads better than a marketing footer in a personal message.

  • Not inherently, but it puts you in a position where you cannot evidence the source, which is the first thing asked. It also damages deliverability through bounces, so it usually fails commercially before it fails legally.

Pocufy

Rather than doing all of this by hand, try it: paste your website link and get your first customer list in ten minutes.