Is cold email legal? GDPR, CAN-SPAM and what actually gets you fined
The rules are less restrictive than most people assume — and the thing that actually gets enforced is not what most people worry about.
updated · 2026-09-20
Is it legal to send cold emails to businesses?
Cold email to business addresses is legal in both the EU and the US, under different conditions. Under GDPR you need a lawful basis, and legitimate interest generally covers B2B outreach if you document the assessment, say where you got the data and honour objections. Under CAN-SPAM no prior consent is required at all, but you must identify yourself, give a real postal address and process opt-outs within ten business days.
In short
- GDPR permits B2B cold email under legitimate interest, provided the assessment is documented.
- CAN-SPAM requires no prior consent at all — it regulates how you send, not whether you may.
- Both regimes require a working opt-out, and failing to process one is what actually gets enforced.
- Buying a list you cannot trace to a source leaves you unable to answer the only question a regulator asks.
The two regimes you are likely under
If your recipient is in the EU or the UK, GDPR and the local ePrivacy rules apply. If your recipient is in the US, CAN-SPAM applies. They differ in a way that surprises people: the American rule is the permissive one.
CAN-SPAM requires no consent before sending. It regulates conduct: identify yourself honestly, do not fake the header or subject, include a valid physical postal address, and honour opt-outs within ten business days.
What GDPR actually requires for B2B
GDPR does not ban cold email. It requires a lawful basis for processing the contact data, and for business-to-business outreach legitimate interest is the ordinary basis. What it demands is that you can show your work.
In practice that means three things you should be able to produce: a legitimate interest assessment, a record of where the data came from, and evidence you act on objections.
- Write down the legitimate interest assessment before you start, not after a complaint.
- Record the source of every address, per record.
- Tell the recipient in the first email where you got their details.
- Give a working opt-out and process it immediately, not in thirty days.
- Delete on request and keep proof you deleted.
Where national rules are stricter
Some member states apply the ePrivacy rules more tightly than others. Germany is the clearest example: advertising email generally requires prior consent, and enforcement there comes through competitor warning letters rather than the regulator.
If you are writing into those markets, keeping the message informational rather than promotional is both safer and more effective. The two goals point the same way.
Pocufy
Three agents run the part of these steps that repeats every week: defining the audience, building the list, writing each email for the person, and following up on the reply.
What actually gets enforced
Almost nobody is penalised for the first email. Complaints come from people who tried to get off a list and could not. That is the failure mode that turns a routine campaign into an enforcement problem.
The practical consequence: your opt-out plumbing matters more than your legal wording. An unsubscribe that works within minutes prevents most of the risk.
Bought lists
A purchased list creates a problem that is legal before it is commercial: you cannot say where the data came from, and that is the first question anyone will ask.
It is also the commercial problem. Bought lists carry dead addresses, dead addresses bounce, and bounces degrade the deliverability of every later send from your domain.
What a compliant send looks like
Written to a business address, addressed to a named person, stating who you are, saying where you found them, asking one question and offering a way out. That message satisfies both regimes and also happens to be the version that gets replies.
Pocufy builds that frame into the flow: business addresses only, an opt-out on every message, automatic removal on opt-out and a record of what was sent to whom. You approve the copy before it goes.
Common questions
In the US, yes — CAN-SPAM requires no prior consent. In the EU, yes under legitimate interest for B2B, provided you document the assessment, disclose the data source and honour objections. Some member states, notably Germany, are stricter.
GDPR penalties are tiered and scale with turnover. CAN-SPAM is assessed per violating email, which compounds fast in bulk sending. In practice the more common cost is a blocked domain rather than a fine.
CAN-SPAM requires an opt-out mechanism in commercial email. A plain sentence offering to stop writing satisfies it and reads better than a marketing footer in a personal message.
Not inherently, but it puts you in a position where you cannot evidence the source, which is the first thing asked. It also damages deliverability through bounces, so it usually fails commercially before it fails legally.
Pocufy
Rather than doing all of this by hand, try it: paste your website link and get your first customer list in ten minutes.
this page answers these searches
- is cold email legal
- cold email gdpr
- can spam compliance
- gdpr b2b email
- cold email rules
- email marketing law
related pages
- Why emails do not arriveWhether your email gets read depends on three DNS records set up before it is ever sent. This page covers those three records and Pocufy's sending rules.
- Why do my emails go to spam?Why do the emails I send land in spam?
- Buying a contact list vs PocufyIs buying a company contact list worth it?
other guides
- Why am I not getting sales? Six causes, in diagnostic orderWhen sales stall, everyone rewrites the pitch. The pitch is usually not the problem. Here is where to look, in order.
- How B2B sales worksSelling to a company is not selling to a person. Who decides, why it takes so long, and how to shorten it.
- How to find buyers abroadYou cannot look for buyers before you have picked a country. The order that gets to a first order.