Cold B2B email is not one legal question. Three regimes cover the 20 markets a sequencer sells into. The opt-out world (US, Singapore, Brazil, and corporate addresses in the UK, Ireland, Sweden and France) lets you send first and stop when asked. The inferred-consent world (Canada, Australia, New Zealand, Japan) lets you email an address that was published for business if the pitch fits the recipient's role. The prior-consent world (Germany, Austria, Switzerland, Denmark, Spain, Italy, Poland, the Netherlands) treats a cold pitch to a named business contact as unlawful without consent. Some of these countries tolerate it in practice. Their courts and regulators do not.
The law follows the recipient. A US agency using Instantly to email a Munich CFO is under German law (UWG) and, because it is targeting people in the EU, under GDPR (Art. 3(2)). Every incumbent pushes this problem onto the user. Instantly's terms make the subscriber "the sole 'sender' and 'initiator'" of every message, including AI-written ones (ToS updated 22 September 2026).
For a product, what matters is that the regimes are predictable by recipient country, and a sequencer could enforce them. No incumbent we checked gates sending by recipient jurisdiction or records where an address came from. In Canada, Australia and Japan, that record decides whether a send was legal at all.
The matrix
Penalties are statutory maxima, not typical outcomes. The Europe rows are summaries; EU/EEA country matrix and the country pages are canonical and override this table where they differ.
| Jurisdiction | Regime | Cold B2B email | Regulator | Max penalty |
|---|---|---|---|---|
| United States | Opt-out | Legal if CAN-SPAM compliant; state laws punish deceptive subject lines | FTC, state AGs, private suits (CA, WA) | $53,088 per email; no 2026 increase |
| Canada | Opt-in (express or implied) | Only with implied consent (conspicuous publication + role relevance) or an existing relationship | CRTC | C$10M per violation (business) |
| United Kingdom | Soft opt-in; B2B opt-out | Corporate subscribers: allowed with identification + opt-out. Sole traders/partnerships: consent | ICO | UK GDPR-level fines under DUAA 2025 (see UK: PECR and DUAA 2025) |
| Germany | Opt-in | Effectively prohibited without express prior consent, B2B included (presumed consent covers phone only) | Courts (UWG, Abmahnung), DPAs | Cease-and-desist + GDPR up to 4% |
| France | Mixed | B2B allowed to professional addresses if offer fits the role, with opt-out; B2C opt-in | CNIL | GDPR up to 4% |
| Netherlands | Opt-in | Consent required, including for legal persons in principle | ACM, AP | National ePrivacy fines + GDPR |
| Spain | Opt-in | Consent required, B2B included (LSSI art. 21) | AEPD | LSSI fines + GDPR |
| Italy | Opt-in | Consent required (Privacy Code art. 130) | Garante | GDPR up to 4% |
| Austria | Opt-in | Consent required, businesses included (TKG 2021) | Telecom offices, DSB | Administrative fines + GDPR |
| Poland | Opt-in | Consent required, B2B included (Electronic Communications Law 2024) | UKE, UOKiK, UODO | National fines + GDPR |
| Sweden | Mixed | Opt-out to legal persons; consent for individuals | Konsumentverket, IMY | Market disruption fee + GDPR |
| Denmark | Opt-in | Consent required, businesses included (Marketing Practices Act) | Consumer Ombudsman, Datatilsynet | Fines + GDPR |
| Ireland | Mixed | Opt-out to non-natural-person subscribers; consent for individuals | DPC | Per-message criminal fines + GDPR |
| Switzerland | Opt-in | Consent required, B2B included (UWG art. 3(1)(o)) | SECO, courts, FDPIC | Criminal fines + revFADP |
| Australia | Opt-in (express or inferred) | Allowed via inferred consent: published business address + relevance + no "no spam" notice | ACMA | 10,000 penalty units/day for repeat corporate offenders |
| New Zealand | Opt-in (express, inferred, deemed) | Deemed consent via conspicuous publication, similar to Australia | DIA | NZ$500k (organisations), unverified |
| Singapore | Opt-out | Allowed; bulk senders need unsubscribe facility and labelling | IMDA / courts; PDPC for data | Civil damages per message, unverified |
| India | No email statute; DPDP Act phasing in | Unregulated today; consent-centred DPDP fully in force 13 May 2027 | Data Protection Board | ₹250 crore, unverified |
| Brazil | Opt-out in practice | Allowed on LGPD legitimate interest with opt-out | ANPD | 2% of Brazil revenue, capped R$50M per infraction |
| Japan | Opt-in | Exception for addresses publicly disclosed for business | MIC, Consumer Affairs Agency | ¥30M for corporations |
Rows marked unverified (New Zealand, Singapore damages, India's ₹250 crore cap) and the national-law cites in the Europe rows come from prior knowledge. This pass could not re-fetch them because primary sources blocked automated access or the search budget ran out. The Europe rows are a pointer; EU/EEA country matrix carries the sourced detail.
The three groups, and what each means for the send button
Opt-out (send, then honour the stop). The US is the anchor market and the most permissive. CAN-SPAM makes "no exception for business-to-business email" but needs no consent. You need accurate headers, a non-deceptive subject, a postal address, an opt-out and processing within 10 business days. The live US risk sits in state deception law, not federal consent rules: California allows $1,000 per email, and Washington saw nearly 200 class actions after Brown v. Old Navy. See United States: CAN-SPAM and state email laws. The UK, Ireland, Sweden and France sit here only for corporate recipients. Their consent rules return for sole traders and individuals, and GDPR still applies to the personal data in a named work address (GDPR and ePrivacy, UK: PECR and DUAA 2025, France).
Inferred consent (published + relevant). Canada, Australia, New Zealand and Japan permit cold B2B email in a narrow lane. The address must have been published, without a "no unsolicited messages" notice, and the message must fit the recipient's job. Australia's Spam Act spells this out in Schedule 2. The CRTC warns that "merely finding an address online doesn't establish consent". An email guessed by pattern-matching (first.last@) and verified by an SMTP ping was never published. Most of the market's lead data looks like that, so it fails this test. See Canada: CASL and Australia, New Zealand and APAC.
Prior consent (don't, or only with consent). Germany is the strictest major market. UWG §7 treats unsolicited email advertising as an unreasonable nuisance for businesses too, and competitors and associations enforce it through Abmahnungen faster than regulators do. Austria, Switzerland, Denmark, Spain, Italy and Poland are similar on paper. See Germany, EU/EEA country matrix, and Data sourcing law for the separate GDPR question of whether you may hold the contact data at all.
Two laws apply to every EU send: the ePrivacy rule on sending (national, varies by country) and GDPR on processing the contact data (uniform, needs a lawful basis and an Art. 14 notice). A message can pass the first and fail the second. Most "cold email is legal in the UK/France" advice covers only the first.
Where enforcement actually lands
Enforcement against cold B2B senders is rare but not zero, and it hits volume and sloppiness, not the concept:
| Case | Where | What | Amount |
|---|---|---|---|
| Verkada (B2B SaaS) | US, FTC/DOJ, Aug 2024 | 30M+ emails, ignored unsubscribes, no postal address | $2.95M |
| Compu-Finder (B2B training) | Canada, CRTC | Scraped business addresses, no consent | C$1.1M, cut to C$200k |
| Tabcorp | Australia, ACMA, Apr 2026 | Email/SMS after consent withdrawn | A$1.254M |
| Washington retailers | US state courts, 2025–26 | Misleading subject lines (B2C) | ~200 class actions; damages cut to $100/email from 11 Jun 2026 |
The failure mode across all four is broken opt-out plumbing or unprovable consent, not the act of cold emailing. Both can be fixed in software.
We found no 2024–2026 enforcement action by the FTC, CRTC or ACMA against a cold-email SaaS platform itself, as opposed to its senders. The search budget ran out before we could confirm that none exists. See Platform liability: what the sequencer itself risks.
Notable 2026 developments
- FTC froze penalties. The FTC announced in September 2026 that "no civil penalty adjustments will be made in 2026", so the CAN-SPAM maximum stays at the 2025 figure of $53,088 per email.
- Washington narrowed CEMA. HB 2274, in force 11 June 2026, adds a knowledge requirement and cuts damages from $500 to $100 per email.
- India's DPDP clock is running. Parts commenced 13 November 2025, more on 13 November 2026, and the rest on 13 May 2027.
- ACMA keeps fining. ACMA said businesses paid over A$16M in spam penalties in 18 months to March 2025, and Tabcorp added A$1.25M in 2026.
What this means for an entrant
- Make jurisdiction a first-class field. Classify each lead by recipient country (from domain ccTLD, company HQ and enrichment data) and apply rules per country: block, warn, or require a recorded legal basis. Incumbents leave this to the user. A German founder who sells "send to the US and UK freely, Germany only with consent proof" can sell that as risk reduction to EU buyers.
- Record provenance at import. For Canada, Australia, New Zealand and Japan, legality depends on where the address was published and whether the pitch fits the role. A lead record that stores source URL, capture date and a role-relevance check turns a legal theory into evidence. See Contact data and enrichment.
- Ship a compliance floor by default. Postal address, a working one-click unsubscribe honoured across all workspaces and inboxes within hours (the US and Canada allow 10 business days, Australia 5 working days), and a subject-line linter for fake "Re:" threads. Verkada, Compu-Finder and Tabcorp all failed on this floor.
- Do not claim to make cold email "legal in the EU". You can't. The honest pitch is that you shrink the risk in opt-out markets and stop accidental sends into prior-consent markets. For the EU detail, read GDPR and ePrivacy and Germany before writing marketing copy.
- Expect the law to tighten slowly while the providers tighten fast. Statutes moved little in 2025–26 and Washington even loosened. Google and Microsoft rules moved much faster (Provider rules: Google, Microsoft and the ESPs, Google and Yahoo sender rules). Provider policy is the bigger short-term risk; law is the long-term moat.