How it worksCase studiesFree toolsBlogCold email agencyAppointment settingOutsourced SDRAboutBook a Call →Client login
Compliance·10 min read

Is B2B Cold Email Legal in 2026? US, UK, EU, and Canada

The answer depends on the country, recipient type, data source, and message. Use this regulator-sourced comparison before launching B2B email.

Is B2B Cold Email Legal in 2026? US, UK, EU, and Canada
TL;DR

There is no universal yes or no. US federal law does not require prior consent for commercial email, while UK, EU/EEA, and Canadian rules depend more heavily on recipient type, national implementation, consent, and the source of the address. Classify the jurisdiction and recipient before sending.

This is an operating guide, not legal advice. It covers person-to-person commercial email, not calling, SMS, automated messages, regulated-sector rules, employment outreach, or every state and country overlay. For a new market, large program, or unusual data source, have qualified counsel review the exact facts.

The fast jurisdiction decision table

MarketOperational starting pointReview before launch
United StatesCAN-SPAM applies to commercial email, including B2B. Federal law does not create a prior-consent requirement, but sender identity, subject line, ad identification, postal address, opt-out, and suppression rules apply.State privacy rules, sector rules, address sourcing, and any channel beyond email.
United KingdomPECR's consent rule for electronic mail does not apply to corporate subscribers. Sole traders and some partnerships are treated as individual subscribers. UK GDPR still applies when personal data is processed.Recipient classification, lawful basis, transparency, objections, and current ICO guidance.
EU/EEAThe ePrivacy Directive protects natural-person subscribers and is implemented through national laws. Rules for legal persons vary by member state. GDPR lawful basis does not replace the separate ePrivacy check.Each target country's implementation, recipient type, lawful basis, notice, and right to object.
CanadaCASL generally requires consent, identification, and an unsubscribe mechanism. Implied consent is limited and must be proved.The exact consent category, how the address was published or obtained, message relevance, and evidence retention.

Do not use this table as a global send/no-send answer. Use it to identify which legal test must be documented for each segment.

United States: CAN-SPAM

CAN-SPAM governs commercial email in the US and makes no B2B exception. It does not impose a federal prior-consent requirement, but a commercial message must satisfy the Act. The FTC's business compliance guide lists these core requirements:

  • No false or misleading headers. Your from name, reply-to, and routing information must accurately identify who sent the message.
  • No deceptive subject lines. The subject has to reflect what the email is actually about.
  • Include a physical postal address. A real street address or registered mailbox for your business, in the message.
  • Identify the message as an advertisement. The FTC gives senders flexibility in how they disclose this, but the disclosure must be clear and conspicuous.
  • Give a clear way to opt out. The mechanism must work for at least 30 days after sending, and a request must be honored within 10 business days.
  • Never email someone who opted out. Suppression lists are not optional.
  • Monitor vendors. A company cannot contract away its CAN-SPAM responsibility when an agency or platform sends on its behalf.

United Kingdom: PECR and UK GDPR

The UK's rules depend on who subscribes to the address. According to the ICO's B2B marketing guidance, PECR's consent rule for electronic mail does not apply to corporate subscribers such as companies and limited liability partnerships. The sender must not conceal its identity and must provide a valid opt-out address. Sole traders and some partnerships are individual subscribers, so consent or the limited soft opt-in may be required.

Named work addresses are still personal data. The UK GDPR requires a lawful basis, transparency, and respect for objections when personal data is used for direct marketing. The ICO says its guidance is under review following the Data (Use and Access) Act, which is another reason to check the current source before launch.

European Union and EEA: GDPR plus national ePrivacy law

A named business email address is personal data, but GDPR is only one layer. The ePrivacy Directive's Article 13 regulates unsolicited electronic-mail marketing and is implemented through national law. It requires prior consent for protected natural-person subscribers, provides a limited existing-customer exception, and lets member states choose protections for legal-person subscribers. That makes country and recipient type decisive.

  • Run both tests. A GDPR lawful basis does not override a national ePrivacy consent rule. The European Commission's lawful-basis guidance says legitimate interest requires necessity and a balance against the individual's rights.
  • Minimize the data you hold. Collect what you need for outreach, nothing more.
  • Make opting out effortless, and honor it immediately.
  • Be transparent. Identify who is processing the data, the purpose and lawful basis, the source when required, retention, rights, and a contact route.
  • Check country-level rules. Do not treat “the EU” as one cold-email rulebook.
Need an enterprise launch review?We can map the target markets, recipient types, exclusions, and operating boundaries before outreach starts. Legal conclusions stay with your counsel.
Book a 20-min diagnostic

Canada: CASL

CASL generally requires consent, identification information, and an unsubscribe mechanism. The CRTC's current FAQ explains that conspicuous publication can support implied consent only when the recipient or account holder published the address, no statement rejects unsolicited commercial messages, and the message relates to the person's business role. A third-party list reproducing a public address does not create implied consent on its own. The sender must be able to prove the basis it relies on and stop messages within 10 business days after an unsubscribe request.

The practical compliance checklist

  • Accurate sender identity on every send, no spoofed names.
  • Subject lines that match the body. This also helps deliverability, which we cover in the deliverability guide.
  • Physical address in the footer of every message.
  • A one-step opt-out, honored fast, with a maintained suppression list.
  • Targeting that is genuinely role-relevant, which doubles as good marketing. Relevance is the core of real personalization.
  • Region-aware list building: know which countries are in your list before you send. That starts with how you build the list.
  • Recipient-type classification for UK and EU/EEA segments, not only a country field.
  • A source record for every address when the legal test depends on where and how it was published.
  • A written approval gate for counsel, compliance, and account-level exclusions before an enterprise launch.

Legal is the floor, not the strategy

Compliance is a launch constraint, not a claim that outreach will perform. For established software teams, make jurisdiction, recipient type, address source, suppression, and counsel approval explicit parts of the operating brief. The enterprise readiness checklist covers the surrounding controls, and the enterprise outbound scope shows what Snipe can operate after those boundaries are approved. Review Snipe's anti-spam policy, or book a 20-minute diagnostic to assess fit.

Frequently asked questions

Is B2B cold email legal in the US?

CAN-SPAM does not impose a federal prior-consent requirement, and it applies to B2B commercial email. Accurate headers and subject lines, ad identification, a valid postal address, a clear opt-out, suppression, and vendor oversight still apply.

Can I cold email a UK company without consent?

PECR's electronic-mail consent rule does not apply to corporate subscribers, but sole traders and some partnerships are treated as individual subscribers. UK GDPR duties can still apply to named work addresses. Classify the recipient before sending.

Does GDPR legitimate interest make EU cold email legal?

Not by itself. GDPR governs personal-data processing, while the ePrivacy Directive is implemented through national marketing laws. A legitimate-interest assessment cannot override a consent rule that applies in the target country.

Can I cold email Canada?

CASL generally requires consent. Implied consent based on a published address is narrow: the recipient or account holder must have published it without a no-message statement, the message must relate to the recipient's role, and the sender must be able to prove the basis.

Set the operating boundaries before launch.

We review targeting, source evidence, exclusions, qualification, and the email-led work Snipe can own. Counsel remains responsible for legal conclusions.

Book your diagnostic call
Qualified demos through a done-for-you cold-email system.Book a call