Skip to content
From the blog

Is cold email legal? A founder's answer

Yes, in most places, and the part that changes by country is not the part founders worry about. Whether you may send the first message varies a lot. What has to be inside that message barely varies at all: say who you are, truthfully, and carry a working way to stop it. Both are below, with the sources.

By Kshitij Maheshwari, co-founder · Updated August 2026 · 13 min read

The short answer

What has to be in a cold email

Eight things go in the message. The middle column names where each one is a legal requirement rather than a nicety, so you can see which rows apply to the people you are writing to.

What goes in the email Where it is required by law In practice
A truthful sender name, From and Reply-To US, UK, EU, Canada Every regime asks for it. Germany states it again in its own competition law.
A subject line that matches the message US Elsewhere this is a deliverability problem, not a legal one.
Wording that identifies it as an advertisement US Not a banner. The message just cannot pretend to be something else.
A valid physical postal address US A street address, a registered PO box or a commercial mailbox.
A working way to stop it, inside the message US, UK, EU, Canada A reply address counts in the US and Canada. Germany asks the same. In the UK it binds even for company addresses.
Where you got their address EU and UK, on the first email The row every other guide leaves out. One clause covers it.
That they can object, said plainly and on its own EU and UK, on the first email Not folded into a footer with four other links.
Contact details that still work after you send Canada, 60 days. US, an opt-out live 30 days It has to still reach you once the campaign is over.

Sources, all as of August 2026: the FTC's CAN-SPAM compliance guide; the ePrivacy Directive, Article 13(4); the GDPR, Articles 14 and 21; the ICO's business-to-business marketing guidance and PECR regulation 22; Canada's anti-spam law, sections 6 and 11; and Germany's Act Against Unfair Competition, section 7. We are operators, not lawyers, and none of this is legal advice.


The framework

Two questions, not one

"Is it legal" is really two questions wearing one coat. Almost every guide answers the first and stops, which is why founders finish reading with a statute name and no next move.

Definition

Opt-in countries want permission before your first email. Opt-out countries let you send, then require you to stop the moment someone asks.

Question one

May you send it at all?

This is the one that moves. It turns on where the person sits, whether they are a company or a sole trader, and how the address reached you. Four answers cover most of it.

Question two

What has to be in it?

This one barely moves. Four separate laws, written on three continents, land on the same two mechanics: say who you are truthfully, and carry a working way to stop it.

Question one is a research task you do once per market. Question two is a writing task you do once, in a template, and then stop thinking about.

The permission question changes at every border. The contents question does not. Say who you are, truthfully, and give them a way to stop.


The permission question

Where you need permission first, and where you do not

Read the row for where your recipient sits, not the row for where you sit. That is the single most common mistake in this category.

Where the recipient is Permission before the first email? What that turns on
United States No. CAN-SPAM governs how you send, not whether you may start. The FTC's guide is explicit that the law makes no exception for business-to-business email.
United Kingdom Not for companies. Yes for sole traders. PECR regulation 22 covers individual subscribers. The ICO says the electronic mail rule does not reach corporate bodies. UK GDPR still applies to a named person's address.
European Union Each member state decides. ePrivacy Article 13(5) hands business subscribers to national law. Germany requires prior express consent for email, business or not. France allows business prospecting on legitimate interest, with a right to object.
Canada Yes, and it can be implied. Consent is implied where the person published the address, did not refuse unsolicited mail, and your message is relevant to their role. All three limbs, or none of it holds. (CASL section 10(9)(b))

For a file you bought rather than built, the question moves upstream to where the records came from. Our page on buying lead lists carries that country by country.


The deadline

In Europe and the UK, the first email is a deadline

This is the obligation founders miss, and it does not live in a privacy policy somewhere. It lands on the first message you send, and it costs one clause.

Three beats, sourced
1
GDPR, Art 14

The deadline is the first message

If you did not get the address from the person, you owe them an explanation, and the law fixes the moment: at the latest when you first contact them. In the EU and the UK, that is your cold email.

2
What it carries

Who you are, and where you got it

Your name, why you are writing, what you are relying on to do it, and the source the address came from. A sentence like "I found you on your team page" does most of that work on its own.

3
GDPR, Art 21

The right to object, said separately

The same deadline applies to telling them they can object. The text asks for it clearly and separately, which rules out burying it in a footer alongside four other links.

The odd part is how ordinary that sounds once written down. The sentence that discharges a European duty is the same sentence that stops a cold email reading like a scrape.


The basis

What legitimate interest actually gets you

It is the phrase every vendor page reaches for, and it does less work than they suggest.

The wording is careful. Direct marketing may be regarded as a legitimate interest, in a passage that turns twice on whether the person would expect to hear from you. A door, not a pass.

France's regulator, the CNIL, attaches a test in June 2026 guidance that reads like copy advice: business prospecting can rest on legitimate interest where the subject relates to the person's job, its own example being software pitched to an IT director. So an off-target email is a worse email and a thinner basis at once.

The distinction

A lawful basis says you may hold and use the address. Whether you may send the first email is a separate rulebook, written member state by member state. The test itself is set at sourcing time, and our guide to building a lead list runs it.

Operator note
Relevance is the basis

I used to treat targeting as a performance question and compliance as a checklist somewhere else. They are the same question. The off-target email is both the one that reads as spam and the one whose basis I would struggle to defend.

KM
Kshitij Maheshwari
Co-founder, Real Good GTM

The opt-out

The opt-out, and the clock to use

When somebody asks to be left alone, stop that day. By hand if that is what it takes. It is correct in every country on this page, and the reputational cost never waited for a statute anyway.

You are two people and one file. Doing it the moment you read the reply costs a minute and removes the whole question, which is why the rule below is a floor rather than a target.

The compliance line

In the US the Federal Trade Commission gives you ten business days to honor an opt-out, and asks the mechanism to keep working for thirty days after you send.

In Canada the law asks for effect to be given without delay, with ten business days named only as the outer limit. In the EU and the UK, the right to object to direct marketing carries no grace period in the text at all.

The catch is that none of it arrives as a click. It arrives as a sentence in a reply, so nothing logs it and nothing suppresses anybody on its own.

One list, at domain level, updated the same day, owned by a named person. Our guide to reply management runs that as an operation.

Watch-outs: what a stop has to cover
  • !The person, not only the sequence they replied to
  • !The domain, when the reply speaks for the company
  • !An EU or UK objection, which has no expiry to wait out
  • !The next list refresh, which will add them back

Want outbound that reads as one-to-one and still clears the rules?

Book a Fit Check

Public data

Public is not the same as permitted, except where it is

Finding an address on a company website answers where it came from. It does not answer whether you may use it, and two regulators give opposite answers.

The assumption

"It is on their website, so it is fair game."

  • Reads publication as agreement to be marketed to
  • Assumes the person chose to publish it themselves
  • Leaves the responsibility with whoever posted it
What the UK regulator says

"You cannot assume that simply because an individual's personal data is in the public domain they are agreeing to it being used for direct marketing purposes."

  • Use it for your own purposes and you become the controller
  • You still need a basis and you still say where you got it
  • Workable in a business context, and never automatic

India answers the same question the other way. Its 2023 data protection act does not apply to personal data the person made public themselves, and it carries a worked illustration about someone publishing their own details on social media.

Timing matters there. The rules that operationalize it were notified in November 2025 with an eighteen-month phased compliance period, so the deadline lands in 2027 rather than today.


The real risk

The realistic risk is the mailbox, not the regulator

One number gets quoted at founders here. The tens-of-millions figures beside it come from Europe's top fine band for the gravest breaches, not from a cold email.

In the US, the Federal Trade Commission's guide sets penalties of up to $53,088 for each email in violation, current as of August 2026 and re-adjusted for inflation most Januarys. "Up to" is a ceiling, and the FTC describes the provision behind it as covering knowing violations.

What actually costs a small sender is quieter. Complaints accumulate, the mailbox providers notice, and mail from your domain stops arriving. Google and Yahoo publish those thresholds, and our page on the sender requirements carries them.

The through-line

Compliance does not scale with volume. Every rule on this page binds at forty emails a day exactly as it binds at forty thousand. What scales is the chance somebody minds, and that gets settled in the inbox rather than by a regulator.


The copy

Write the compliant version, not the cautious one

The lines the law wants at the end of a cold email are the same lines that stop it reading like a blast. Founders reach for a footer instead, and the footer does neither job.

Don't

Bolt on a mailing-list footer

You are receiving this because you opted in to communications from Acme. Unsubscribe | Manage preferences | Privacy | Acme Ltd, Reg. 09283746

  • Claims an opt-in that never happened
  • Looks like every newsletter in the inbox
  • Buries the stop line among three other links
Do

Say it in your own voice

I found you on Acme's engineering page. If this is not for you, reply "no thanks" and I will not write again. Kshitij, Real Good GTM, 6 Rue Anatole, 92400 Courbevoie

  • Names where the address came from
  • Offers a stop that takes one word to use
  • Carries the postal address without a footer

Two plain sentences do both jobs better than a footer does either. Writing into the US, the message also has to read as what it is, which an honest opening line already handles.


The ops

Running this as a two-person team

None of this needs a compliance function. It needs four things written down once, and one person who owns them.

Before the next send

4 checks

  • The stop line is in every template

    In the last two sentences, in the sender's own words, not in a footer.

  • One suppression list, at domain level

    One file, one owner, updated the same day a reply lands.

  • Every row says where it came from

    A source column, so the first-email clause writes itself.

  • The recipient's country is on the row

    It decides which rules you are under, and it is not where you sit.

Key takeaways
4 points
  • 1 The contents rules barely move. Learn those once.
  • 2 Permission changes at the border. Check the recipient's country.
  • 3 A role address like info@ is a simpler object than a named one.
  • 4 Stop the day they ask. Nowhere asks for less.
Operator note
One file, one owner

The teams that get this wrong are never the careless ones. They are the ones with three tools, two inboxes and a suppression list that lives in whoever happened to read the reply that morning.

RB
Rahul Bageria
Co-founder, Real Good GTM

If the suppression file is the part that keeps slipping, that is the job our reply automation add-on does.


Failure modes

Five ways founders get this wrong

Four of these cost you a little. The fifth is the one worth writing on a wall.

Reading the GDPR as the cold-email rulebook

It governs the personal data. Whether you may send an unsolicited message sits in a separate European directive that each member state implemented itself.

Trusting a country list that just says "legal"

The US asks for no permission and Canada does. A list that puts them in the same column has told you nothing you can act on.

Answering the opt-out on somebody else's clock

Ten business days was written for a company processing thousands through a system. You saw the reply. The person who asked is counting in hours.

Treating a badge on a bought file as your basis

Use the data for your own purposes and the responsibility is yours. A supplier's assurance does not travel with the file.

!
Caution

"We are GDPR compliant" does not cover Europe

Germany treats advertising by email without prior express consent as an unacceptable nuisance, and its email rule draws no line between a consumer and another business. Same continent, opposite answer, because Europe handed this question to each member state.

Do this instead
Segment the list by the recipient's country before the send, not the sender's.

FAQ

Questions founders ask

Is cold email legal?
Yes in most places, and the rules differ by where the recipient is. The US allows it without prior permission as long as the message is honest and carries a real opt-out. The UK lets you email companies but not sole traders. Germany asks for prior consent even between businesses, and Canada asks for consent that can be implied from a published address.
Does the GDPR ban cold email?
No. It names direct marketing as something that may rest on legitimate interest. What it does require is that you have a basis, that you tell the person where you got their details, and that you stop the moment they object. Whether you may send at all is a separate European rulebook, and each member state implemented that one itself.
Does CAN-SPAM apply to B2B email?
Yes. The FTC's own compliance guide says the law covers all commercial messages and makes no exception for business-to-business email. It does not ask for permission before the first message, but it does ask for accurate headers, an honest subject line, identification as an ad, a valid postal address and a working opt-out. It is a US law, and it binds you when you write into the US.
Do I need consent to cold email someone in the EU?
It depends which country, which is the part most guides skip. The European rule on unsolicited email leaves the treatment of business subscribers to each member state. Germany requires prior express consent even for business email, while France allows business prospecting on legitimate interest with a right to object. Check the recipient's country rather than "the EU".
Can I email a company in the UK without permission?
Yes, if it is a corporate body. The ICO says the electronic mail rule in PECR does not apply to corporate subscribers, so companies, limited liability partnerships, Scottish partnerships and government bodies can be emailed. Sole traders and some partnerships are treated as individuals and need consent. UK data protection law still applies to a named person's address either way.
How fast do I have to honor an unsubscribe?
Faster than any of the rules require, which means the same day you see it. In the US the FTC gives ten business days and asks the mechanism to work for thirty. Canada says without delay, with ten business days as the outer limit. In the EU and the UK the right to object carries no grace period in the text at all.
What is the fine for cold email?
In the US the FTC's guide states penalties of up to $53,088 for each email in violation, current as of August 2026. That is a ceiling attached to knowing violations rather than a price list. Figures in the tens of millions circulating online come from Europe's top fine band for the gravest data breaches and have nothing to do with a cold email. For a small sender the realistic consequence is the spam folder.
Kshitij Maheshwari, co-founder of Real Good GTM
About the author
Kshitij Maheshwari

Co-founder of Real Good GTM. He has been the first business hire and Chief of Staff at seed-stage B2B startups, building outbound pipeline before any playbook existed. This post comes from reading the statutes and the regulators' own guidance instead of the vendor blogs about them, and from writing the last two lines of a cold email often enough to know they do two jobs.

Connect on LinkedIn

Keep going

The three pages this one hands off to

The judgment call the rules do not make for you, the inbox routine behind the opt-out, and the mailbox machinery this page calls the real risk.

Want outbound that clears the rules and still gets replies?

Book a fit check. We'll look at where your buyers actually sit, what the first email has to carry for them, and tell you straight if outbound is not the right motion for you yet.

Book a Fit Check

No hard sell. No fake numbers. Real good work speaks for itself.