Cold email compliance means meeting the legal requirements that apply where your recipient is: accurate sender identity, a working opt out, a postal address and honest subject lines under the United States CAN-SPAM Act, plus a lawful basis and an easy objection route under United Kingdom and European data protection law. This is a summary, not legal advice.
What it is
Two regimes with different logic. The United States CAN-SPAM Act permits commercial email without prior consent but sets conditions: no deceptive headers or subject lines, identification of the message as a solicitation, a valid physical postal address, a functioning opt out, and honoring that opt out promptly, within ten business days under the statute. The United Kingdom and the European Union start from data protection: the recipient's business email is personal data, so you need a lawful basis, usually legitimate interest, plus transparency and an unconditional right to object.
How it works
Under United Kingdom PECR rules, marketing email to a corporate subscriber such as a limited company is treated differently from email to an individual, and sole traders and some partnerships are treated as individuals. Under the United Kingdom and European data protection framework you must still be able to show why the contact is relevant to that person's role, say where you got the data if asked, and stop on request. Practically that means recording the source and date of every record, keeping a suppression list that survives tool changes, and honoring an objection everywhere rather than in one platform.
Why it matters for winning clients
The reputational cost usually arrives before the regulatory one. Complaints damage deliverability, and a prospect who has to ask twice to be removed tells other people. For an agency that emails on behalf of clients, the exposure is also contractual: the client's brand is on the message, and a sloppy process makes the agency the risk rather than the solution.
Example in LeadCanvas
An agency sends only to business roles relevant to what it sells, states plainly in the first message who it is and why it is writing, includes a one click removal in every message, and keeps the suppression list in the CRM rather than in the sending tool. Every record carries its source and collection date, so a request to know where the data came from can be answered in minutes instead of guessed at.
Common mistakes
Assuming a business address is exempt from data protection rules because it is at a company domain. Hiding the opt out or making it require a reply. Keeping suppression in a single sending platform, so a tool migration resurrects the people who asked to leave. Scraping personal addresses of individuals rather than role relevant business contacts. And treating a purchased list as evidence of consent, which it is not.
Related terms
Email deliverability is what compliance failures damage first. List building is where provenance has to be recorded. Data hygiene is what keeps the suppression list intact. The links below open those entries.