Sign inCreate an account

Data glossary

Cold email compliance

The rules that govern B2B cold email in the United States and the United Kingdom, and the practices that keep you inside them.

Quick answer

Cold email compliance means meeting the legal requirements that apply where your recipient is: accurate sender identity, a working opt out, a postal address and honest subject lines under the United States CAN-SPAM Act, plus a lawful basis and an easy objection route under United Kingdom and European data protection law. This is a summary, not legal advice.

What it is

Two regimes with different logic. The United States CAN-SPAM Act permits commercial email without prior consent but sets conditions: no deceptive headers or subject lines, identification of the message as a solicitation, a valid physical postal address, a functioning opt out, and honoring that opt out promptly, within ten business days under the statute. The United Kingdom and the European Union start from data protection: the recipient's business email is personal data, so you need a lawful basis, usually legitimate interest, plus transparency and an unconditional right to object.

How it works

Under United Kingdom PECR rules, marketing email to a corporate subscriber such as a limited company is treated differently from email to an individual, and sole traders and some partnerships are treated as individuals. Under the United Kingdom and European data protection framework you must still be able to show why the contact is relevant to that person's role, say where you got the data if asked, and stop on request. Practically that means recording the source and date of every record, keeping a suppression list that survives tool changes, and honoring an objection everywhere rather than in one platform.

Why it matters for winning clients

The reputational cost usually arrives before the regulatory one. Complaints damage deliverability, and a prospect who has to ask twice to be removed tells other people. For an agency that emails on behalf of clients, the exposure is also contractual: the client's brand is on the message, and a sloppy process makes the agency the risk rather than the solution.

Example in LeadCanvas

An agency sends only to business roles relevant to what it sells, states plainly in the first message who it is and why it is writing, includes a one click removal in every message, and keeps the suppression list in the CRM rather than in the sending tool. Every record carries its source and collection date, so a request to know where the data came from can be answered in minutes instead of guessed at.

Common mistakes

Assuming a business address is exempt from data protection rules because it is at a company domain. Hiding the opt out or making it require a reply. Keeping suppression in a single sending platform, so a tool migration resurrects the people who asked to leave. Scraping personal addresses of individuals rather than role relevant business contacts. And treating a purchased list as evidence of consent, which it is not.

Email deliverability is what compliance failures damage first. List building is where provenance has to be recorded. Data hygiene is what keeps the suppression list intact. The links below open those entries.

Frequently asked questions

A concise answer before the next action.

Is cold email legal in the United States?

Commercial email is permitted under CAN-SPAM without prior consent, provided the message identifies itself honestly, includes a valid physical postal address and a working opt out, and that opt out is honored promptly. State laws and sector rules can add obligations, so treat this as an orientation rather than a clearance.

Is cold email legal in the United Kingdom?

It can be, and the analysis is stricter. Email to a corporate subscriber is treated differently from email to an individual under PECR, while data protection law still requires a lawful basis, transparency and an unconditional right to object. Sole traders and some partnerships are treated as individuals, which is where many campaigns go wrong.

Do I need consent to email a business address?

Not necessarily in either regime, but the absence of a consent requirement is not the absence of obligations. You still need honest identification, a working opt out, a defensible reason the contact is relevant to that role, and a record of where the data came from and when.

How fast must an opt-out be honored?

CAN-SPAM allows up to ten business days; under data protection law an objection should be actioned without undue delay. In practice, immediately and everywhere. A suppression that lives in one tool while the record stays active in the CRM is the same as no suppression at all.

Does using a purchased list break the rules?

Not automatically, and it makes every obligation harder to meet. You inherit records with unknown provenance and no collection date, which is exactly what you must be able to explain if someone asks. If the seller cannot document the source, you are carrying the risk on their behalf.

Apply the guide

Turn the criteria into a company search.

Open this search

LeadCanvas is listed and reviewed on