By region
The regional split below is the practical version, not the full statutory text. Where a jurisdiction says "yes," it means unsolicited B2B email is permitted under stated conditions, not that anything goes.
| Region | Cold B2B email allowed? | Conditions |
|---|---|---|
| USA (CAN-SPAM) | Yes | Working unsubscribe, accurate "from", no deceptive subject line, valid physical postal address |
| EU (GDPR) | Yes | Legitimate interest documented, opt-out in message, honor erasure requests |
| France (RGPD-DPCP) | Yes (B2B) | Business email to a professional role, on a professional topic, is explicitly allowed; B2C requires opt-in |
| UK (UK GDPR) | Yes | Same as EU GDPR |
| Germany (UWG) | Restrictive | Prior consent is the default expectation; a narrow existing-customer exception applies |
| Canada (CASL) | Restrictive | Express or implied consent required. Implied consent can cover a conspicuously published business address, but only for messages relevant to that person's role |
| Australia (Spam Act) | Yes | With unsubscribe and accurate sender identification |
Universal rules
Ignore the regional differences for a moment and five rules cover nearly every jurisdiction a B2B team is likely to sell into:
- Always include a working opt-out / unsubscribe link, and make sure it actually removes the person, not just marks a flag nobody checks
- Use accurate sender info: your real name, your real domain, a real reply-to address
- No deceptive subject lines. "Re: our call" when there was no call is the textbook violation
- Honor opt-outs within 10 business days (US) or without undue delay, generally within 30 days (EU)
- Never email a list you bought or scraped from a data broker with no visibility into how it was collected
Subject lines and deceptive practices
CAN-SPAM's deception rules get less attention than the unsubscribe requirement, but they carry the same enforcement weight. A subject line has to reflect the actual content, "quick question" is fine if there's genuinely a question in the email, "Re:" or "Fwd:" on a message that isn't actually a reply or forward is not. The same logic covers spoofed sender names (using a real person's name you don't have authorization to send as) and misleading routing information in the header, both of which are independently actionable under the statute regardless of whether the recipient ever complains. The FTC's compliance guidance treats the header and the subject line as two separate checks, not one, which is worth knowing since a lot of outreach tooling only validates the unsubscribe link and assumes the rest is fine by default.
What gets you fined
- No unsubscribe link, or one that doesn't actually work
- Continuing to email a contact after they've opted out
- Buying lists from data brokers with no chain of custody and emailing them cold
- Hiding or spoofing sender identity
- Deceptive subject lines that misrepresent the email's content or origin
Frequently asked questions
Is cold B2B email legal in the United States?
Yes. CAN-SPAM permits unsolicited commercial email, B2B included, as long as the sender uses accurate header and from information, avoids deceptive subject lines, includes a valid physical postal address, and honors opt-outs within 10 business days.
Can I cold email prospects in the EU under GDPR?
Yes, under the legitimate interest legal basis, provided the outreach is genuinely relevant to the recipient's professional role, you can document why your interest isn't overridden by theirs, and you give a clear, working opt-out in the message itself. This is a lower bar than consent, but it still requires a real assessment, not just a company policy stating you rely on it.
Does France really allow B2B cold email without opt-in?
Yes, this is one of the more B2B-friendly interpretations in the EU. French law explicitly permits unsolicited commercial email to a professional email address when the content is relevant to that person's professional activity, without requiring prior opt-in, unlike the default B2C rule.
What's the single biggest email compliance mistake B2B teams make?
Buying or scraping a list from a data broker and emailing it cold with no working unsubscribe link. It combines the two things regulators actually act on: an unverifiable data source and a broken opt-out, which is the exact pattern behind most of the CAN-SPAM and GDPR enforcement actions that reach a public settlement.
Sources: FTC, CAN-SPAM Act compliance guide. General information only, not legal advice; confirm current requirements with counsel for your specific jurisdictions.
Compliant outreach starts with compliant sourcing.
Leadsforlinked extracts public LinkedIn data. Always include an opt-out in your messages.
Start free