Is B2B cold email legal? GDPR, ePrivacy and CAN-SPAM in plain words
Published

It depends on where your recipients are. In the United States, the CAN-SPAM Act does not require permission before the first email to a business address. It requires honest headers and subject lines, a clear statement that the message is an ad, a physical postal address, and a working opt-out that you honor within 10 business days.
In Europe, the answer changes by country. The GDPR (General Data Protection Regulation) applies as soon as you email a named person, and each country sets its own rules on marketing email. Some, such as Germany, require prior consent even for work addresses. Others, such as France, accept B2B email without consent if it relates to the person's job, they are informed and they can object for free. The UK allows it for companies, with limits.
First, which rules apply to you
Email rules follow your recipients, not only your company. The GDPR can apply to businesses outside the EU that offer goods or services to people in the EU (GDPR, Article 3). Such a business generally has to name a representative in the EU (Article 27), unless its processing is only occasional and low-risk, and give that representative's contact details in its privacy notice. The UK GDPR has a matching rule for the UK.
This article covers B2B email only: messages sent to people at work, about their work. Consumer email has stricter rules in the EU and the UK.
The United States: CAN-SPAM
The main US law is the CAN-SPAM Act, enforced by the Federal Trade Commission (FTC). Its compliance guide for business is clear on a point that surprises founders: "The law makes no exception for business-to-business email."
It is, however, an opt-out law: for ordinary business email addresses, it does not ask for permission before the first message. A cold sales email is a commercial message, not a transactional one like an order confirmation, so the full set of rules applies.
What CAN-SPAM requires
Based on the FTC guide:
- Honest header information. From, To, Reply-To and routing information must be accurate and identify who sent the message.
- A subject line that matches the content. Nothing written to trick people into opening.
- Identification as an ad. You must disclose clearly and conspicuously that the message is an advertisement.
- Your physical postal address. A current street address, or a P.O. box or private mailbox registered as the guide describes.
- A working opt-out. A return email address or another easy online method, not blocked by your spam filter. It must keep working for at least 30 days after you send. Honor requests within 10 business days, without charging a fee or asking for more than an email address.
- Responsibility you cannot outsource. If a freelancer or an agency sends for you, you remain legally responsible.
As of this writing, the FTC guide puts penalties at up to $53,088 for each separate email in violation, an amount the FTC adjusts for inflation.
The European Union: GDPR plus national ePrivacy rules
Two layers of rules apply to cold email in Europe.
Layer one: cold email under the GDPR
A named work address, such as jane.doe@company.example (illustrative), is personal data, so the GDPR applies.
Every use of personal data needs a legal basis. For B2B prospecting, it is usually legitimate interest (Article 6(1)(f)): a genuine business reason that is not outweighed by the person's rights and interests. Recital 47, one of the explanatory notes at the start of the GDPR, says direct marketing "may be regarded as carried out for a legitimate interest." The word "may" matters: you still have to weigh both sides.
Two more articles shape every cold email:
- Article 14, information. When you did not get the address from the person, you must tell them, among other items, who you are, why you use their data and on what legal basis, where it came from, how long you keep it and what rights they have, including the right to complain to a data protection authority. If you use the data to contact them, this must happen at the latest in your first message, and in any case within one month of obtaining the address.
- Article 21, the right to object. People can object to direct marketing at any time, and their data can then no longer be used for it. You must bring this right to their attention explicitly, at the latest in your first message, separately from other information.
Layer two: national email marketing rules
The EU's ePrivacy Directive requires consent for marketing email to individuals. For businesses, its Article 13(5) lets each member state decide how they are protected, so B2B rules differ by country.
Some member states require prior consent even for work addresses. Germany's Act against Unfair Competition, section 7 (in German) requires prior express consent for advertising email, whether the recipient is a person or a business, apart from a narrow exception for existing customers. Other countries accept B2B prospecting on an opt-out basis. Read the regulator's guidance in each country you target.
France, one example of the opt-out model
The French rule sits in article L.34-5 of the Postal and Electronic Communications Code. The data protection authority (the CNIL) explains it on its page about commercial prospecting by email (in French).
For professionals, prior consent is not required. Prospecting can rest on the sender's legitimate interest when the message relates to the profession of the person contacted. The CNIL's example, given on that email page, is a call presenting software to a company's IT director. In practice:
- Write to the person's professional address.
- Make the offer relevant to their role. Accounting software for a finance lead fits. Car insurance for the same person does not.
- In every message, identify yourself and give a simple, free way to refuse further email.
The CNIL also says generic addresses such as contact@ or info@, which belong to the company rather than to a person, are not subject to these principles.
The United Kingdom: PECR
UK marketing email falls under the Privacy and Electronic Communications Regulations (PECR), alongside the UK GDPR, the UK's own version of the GDPR. The UK Information Commissioner's Office (ICO) says in its guidance on electronic mail marketing that you can email any corporate body without consent: a company, a Scottish partnership, a limited liability partnership or a government body. The ICO also notes that this guidance is under review after the Data (Use and Access) Act 2025, so check the current page before you rely on it.
Sole traders (sole proprietors in US terms) and some partnerships are treated as individuals. You can only email them if they consented, or if they bought a similar product from you and did not opt out. In every case, show who you are and give a valid address for opting out. The ICO adds that named employees' corporate addresses also raise data protection questions.
What to put in every cold email
Across these rules, the same elements recur:
- Your real name and company, in the From line and the signature.
- A subject line that honestly describes the message.
- A reason for writing that ties to the recipient's role. This is easier with a clear target profile; see how to choose an ideal customer profile.
- For EU and UK recipients, a short notice: who you are, why you are writing, where you got their address and their rights, plus a link or a written-out address to your full privacy notice, so the rest of the required information is one step away.
- A clear, free way to stop receiving email. For EU and UK recipients, name the right to object explicitly and keep it apart from other information.
- For US recipients, your physical postal address and a clear disclosure that the message is an advertisement.
An illustrative footer, to adapt and have reviewed:
Jane Doe, Founder, Example Analytics Ltd, [street address, city, postal code, country]. This is a commercial message. I found your work address on [source]. How we handle your data: [link to privacy notice].
You have the right to object to this use of your data. Reply "no thanks" and I will remove you from my list.
Asking for a reply instead of adding a link is common practice; the FTC guide accepts a return email address as an opt-out method. Unsubscribe options also affect deliverability; see cold email deliverability basics.
Follow-ups are separate messages. They must repeat your identity and the opt-out, plus the postal address and ad disclosure for US recipients. The full Article 14 information is due by the first message and need not be repeated. See how to write a short B2B cold email sequence.
Keep an opt-out list, and use it everywhere
A suppression list, meaning a list of addresses you must never email again, makes opt-outs reliable:
- Keep one list shared by every mailbox, sending domain, campaign and tool you use.
- Add people as soon as they object, whether by link, by reply or in any other way. Act right away rather than waiting for the 10-day CAN-SPAM deadline.
- Check every new list against it before you import.
- Keep only what you need to honor the request, such as the address and the date.
- Record where each prospect's address came from, so you can answer the Article 14 source question.
- Never sell the list or give it to third parties, except service providers that help you honor opt-outs.
The ICO also suggests such a list for UK corporate bodies that object, even though consent is not required.
When to talk to a lawyer
A short consultation with a data protection lawyer is worth it if you email several countries at once, target a regulated profession, buy contact data or send at high volume.
This article is general information, not legal advice. Laws and guidance change.
Key takeaways
- CAN-SPAM covers US B2B email on an opt-out basis: honest headers and subject, an ad disclosure, a postal address, and opt-outs honored within 10 business days.
- The GDPR applies to named work addresses in the EU. Legitimate interest is the usual basis for B2B prospecting.
- National rules decide the rest. Some EU countries, such as Germany, require prior consent even for work addresses.
- France is only one example of the opt-out model: no prior consent is needed when the email relates to the person's job, they are informed and they can object for free.
- PECR lets you email UK corporate bodies without consent, but not sole traders and some partnerships.
- Keep one suppression list across all your tools and honor every objection.
- This is general information, not legal advice. Check with a qualified lawyer before relying on it.