06 What is allowed, where · 12 pages · 17k words
The law
Cold B2B email is opt-out in the US, broadly tolerated in the UK and France, and effectively consent-only in Germany. The recipient's country decides. This section maps the regimes, goes deep on Europe, and covers what a platform itself is liable for.
| Page | Jurisdiction | Regime | Cold B2B email | Penalty |
|---|---|---|---|---|
| Cold email law: the jurisdiction matrix | Global (20 jurisdictions) | Mixed | Legal on opt-out in the US, Singapore, Brazil and to corporate addresses in the UK, Ireland, Sweden and France; needs consent or narrow implied consent almost everywhere else | From $53,088 per email (US) to C$10M per violation (Canada) and 4% of global turnover (GDPR) |
| GDPR and ePrivacy | European Union / EEA | Mixed | Member-state choice: opt-in in roughly half the bloc, opt-out to legal persons in the rest; GDPR applies to every named contact | GDPR fines up to €20m or 4% of global turnover; national ePrivacy penalties and civil claims vary |
| Platform liability: what the sequencer itself risks | US, Canada, EU | n/a | Platform liability turns on the platform's role, not on the recipient's regime | CAN-SPAM $53,088/email if the platform 'initiates'; CASL s.9 up to C$10M; GDPR up to 4% as controller; DSA up to 6% of turnover |
| Germany | Germany | Opt-in (prior express consent) | Prohibited without prior express consent; a single email to a business address is actionable | Cease-and-desist (Abmahnung, ~€400–500 fees) + injunction at €3,000–3,500 dispute value per first email; contractual penalties; GDPR fines possible |
| Provider rules: Google, Microsoft and the ESPs | Contractual (global) | n/a | Prohibited as 'unsolicited mass email' by every provider's policy; tolerated by Google and Microsoft below their metric thresholds | Throttling, sending blocks, account or tenant suspension; no refund for AUP breaches |
| United States: CAN-SPAM and state email laws | United States | Opt-out | Legal without consent if CAN-SPAM's header, subject, identification, address and opt-out rules are met | Up to $53,088 per email (FTC; 2025 level, not raised for 2026) + $1,000 per email under California law |
| Canada: CASL | Canada | Opt-in (express or implied) | Allowed only with implied consent: published business address, no refusal notice, message relevant to the recipient's role (or an existing relationship) | Up to C$10M per violation for businesses, C$1M for individuals |
| UK: PECR and DUAA 2025 | United Kingdom | Mixed | Allowed without consent to corporate subscribers (opt-out); sole traders and some partnerships need consent or soft opt-in | PECR fines up to £17.5m or 4% of worldwide turnover after the Data (Use and Access) Act 2025; UK GDPR fines on top |
| Australia, New Zealand and APAC | Australia, New Zealand, Singapore, India, Brazil, Japan | Mixed | AU/NZ: allowed via inferred consent for published, role-relevant addresses; SG/BR: opt-out; JP: opt-in with business-publication exception; IN: unregulated until DPDP | Australia: up to 10,000 penalty units per day for repeat corporate offenders; Japan ¥30M; Brazil 2% of local revenue (R$50M cap) |
| France | France | Mixed | Allowed without prior consent if the message relates to the recipient's profession, with information and an easy opt-out | CNIL fines under GDPR (up to 4% of turnover) and the CPCE; recent prospection fines €80k–€900k plus injunctions with €10k/day penalties |
| EU/EEA country matrix | EU-27 + Norway, Iceland, Liechtenstein + Switzerland | Mixed | Consent needed in ~13 countries (incl. DE, AT, IT, ES, PL); opt-out to companies in ~11 (incl. FR, IE, SE, NL-narrow); ~5 unclear | GDPR ceiling (€20m / 4%) everywhere; national ePrivacy penalties and civil claims vary |
| Data sourcing law | EU/EEA (GDPR), with US contract-law cases | n/a | Usable under legitimate interest only with Art. 14 notices, per-record source logging, limited retention and respect for visibility settings | GDPR fines up to 4% of turnover; injunctions with daily penalties (KASPR deleted its ~160M-contact database); platform lawsuits (LinkedIn v Proxycurl) |
Not legal advice. The 31-country table is on the EU country matrix; the 20-jurisdiction overview on the law overview.
The regimes
The jurisdiction matrix, then the US, Canada and Asia-Pacific.
Cold email law: the jurisdiction matrix
Twenty jurisdictions in one table: who allows cold B2B email on an opt-out basis, who demands consent, who regulates it and what it can cost.
United States: CAN-SPAM and state email laws
Cold B2B email is legal in the US with no consent; the real exposure is broken opt-outs, deceptive headers and subject lines, and state laws in California and Washington.
Canada: CASL
Canada requires consent before the first email; cold B2B outreach survives only through the narrow 'conspicuous publication' implied consent, which the regulator reads strictly and the sender must prove message by message.
Australia, New Zealand and APAC
Australia and New Zealand allow cold B2B email only through 'inferred consent' for published, role-relevant addresses; Singapore and Brazil are opt-out; Japan is opt-in with a business-address exception; India has no email law yet but a consent-based privacy act arriving in 2027.
Europe
GDPR and ePrivacy, Germany, the UK, France, every EU country, and data sourcing.
GDPR and ePrivacy
Two laws stack on every EU cold email: the ePrivacy Directive decides whether you may send at all, the GDPR decides how you may hold and use the contact data.
Germany
Germany requires prior express consent for every marketing email, B2B included; one email is enough to be sued, and the enforcers are recipients and competitors, not a regulator.
UK: PECR and DUAA 2025
The UK lets you cold email companies without consent, but sole traders and some partnerships count as individuals, and since 2025–26 PECR fines run to £17.5m or 4% of turnover.
France
France allows B2B cold email without consent if the message relates to the recipient's job, but the CNIL is Europe's most active fining authority on prospection and data brokers, KASPR included.
EU/EEA country matrix
Country-by-country status of B2B cold email across the 27 EU states, Norway, Iceland, Liechtenstein and Switzerland: about 13 require consent, about 11 allow opt-out to companies, and 5 are unclear.
Data sourcing law
Scraped or purchased B2B contact data is not illegal in the EU, but the US data-vendor model of mass scraping, no notices and indefinite retention is what the CNIL fined KASPR for, and KASPR ended up deleting its database.
The platform's own exposure
Liability for what customers send, and the provider terms you cannot ignore.
Platform liability: what the sequencer itself risks
A cold-email platform is shielded as a conduit and GDPR processor until it writes the copy, sells the data, supplies the inboxes or ignores abuse; past that line it becomes a sender, a controller or an aider.
Provider rules: Google, Microsoft and the ESPs
Google and Microsoft ban unsolicited mass email on paper but police it by volume and complaint metrics; SendGrid, Mailgun, SES and Postmark ban cold lists outright and can demand proof of consent, which is why cold email runs on mailboxes, not ESPs.