Is cold email legal? A country-by-country answer (2026)

Where cold email is legal in 2026: the US and UK say yes with conditions, Germany and Czechia say no, Canada sits between. Rules and penalties, compared.

Published August 20, 2026 · 11 min read

There is no single answer to whether cold email is legal — it depends on where the recipient sits, whether they are a business or a consumer, and how you send. As of August 2026, unsolicited B2B email is lawful with conditions in the US, the UK, France, Ireland, and roughly ten other EU states; it is unlawful without prior consent in Germany, Austria, Spain, Italy, Poland, the Czech Republic, and Switzerland; and Canada and Australia sit in between, with narrow exceptions that regulators read strictly. The law follows the recipient, not you: a sender in Prague emailing a prospect in Toronto is inside Canadian law.

This article is general information, not legal advice. Email law is unusually fragmented and changes often — consult a qualified lawyer in each jurisdiction you send into.

Why there is no single answer

Three variables decide the outcome. First, the recipient's jurisdiction: anti-spam statutes apply to messages received in their territory, wherever the sender is. Second, B2B vs B2C: many regimes carve out corporate recipients or published work addresses, but treat consumers as strictly off-limits without consent. Third, how you send: honest headers, sender identification, and working opt-outs are conditions of legality nearly everywhere — the same email can be lawful or unlawful depending on what is in its footer.

One thing legality does not buy you is delivery. A perfectly compliant cold email can still land in spam, and mailbox providers enforce their own rules faster and more harshly than any regulator — that side of the problem is covered in our guide to cold email deliverability.

The CAN-SPAM Act (15 U.S.C. §§ 7701–7713) is an opt-out law. It does not require consent before you send; it requires that the message be honest and that recipients can make you stop. The FTC's compliance guide states that "The law makes no exception for business-to-business email" — a sentence often misread as a restriction, when it actually means B2B email is covered by the rules, not banned by them.

A compliant US cold email needs:

  1. Honest headers — From, Reply-To, and routing information, including the originating domain, must accurately identify the sender.
  2. An honest subject line that reflects the content.
  3. An ad disclosure — clear and conspicuous identification as an advertisement (the FTC allows "a lot of leeway" in how). This is the requirement cold-email senders most often skip.
  4. A valid physical postal address — street address, USPS-registered PO box, or registered commercial mailbox.
  5. A working opt-out, honored within 10 business days, with the mechanism live for at least 30 days after sending. No fees, no login walls, nothing beyond a reply email or a visit to a single web page.

The penalty is up to $53,088 per non-compliant email, and more than one party can be liable — hiring an agency does not transfer your responsibility. That figure is the 2025 inflation adjustment; there was no 2026 increase because the government shutdown left agencies without the CPI data to adjust. Individual recipients cannot sue, but the FTC, state attorneys general, and ISPs can.

European Union: two layers of law, 27 different answers

Two instruments apply at once. The ePrivacy Directive (Art. 13) governs whether you may send unsolicited marketing email at all; the GDPR governs whether you may process the personal data behind it — and a named person's work address is personal data. You must satisfy both.

The catch is that ePrivacy is a directive, transposed 27 different ways. Article 13 requires prior consent for marketing email to natural persons, but Article 13(5) told member states only to protect legal persons "sufficiently" — and left them to decide what that means. Some extended full consent requirements to companies; others created explicit B2B opt-out carve-outs. The proposed ePrivacy Regulation that would have harmonised this was formally withdrawn by the European Commission, with the withdrawal published in the Official Journal on 6 October 2025. The patchwork is permanent; stop waiting for it to be sorted out.

The member-state patchwork

The most reliable cross-border mapping is the Business Information Coalition's B2B compliance guide (February 2025), cross-checked against national regulator guidance. Treat this as a risk map, not a legal opinion — positions move.

Member state Default regime B2B carve-out Practical position
France Opt-in Yes B2B cold email lawful if the offer relates to the recipient's profession, with opt-out. But CNIL now requires consent for open-tracking pixels even in emails that need no consent themselves (enforced from July 2026).
Ireland Opt-in Yes Lawful where the address is used in a commercial context and the message relates solely to that activity.
Finland Opt-in Yes Lawful if the product is substantially related to the person's work duties.
Estonia, Hungary, Latvia, Sweden, Croatia, Luxembourg Opt-in Yes Consent rules apply to natural persons only; every message must offer an opt-out.
Portugal Opt-in Yes Legal-person carve-out — but Portugal runs a national B2B do-not-contact registry you must screen.
Netherlands Opt-in Qualified Only for addresses "intended and provided" for business contact. A scraped personal work address probably does not qualify — do not treat the Netherlands as an easy market.
Germany Double opt-in No Consent for every email advert, even to a CEO at a corporate address. Enforced privately via competitor cease-and-desist (Abmahnung).
Austria Double opt-in No The often-cited under-50-recipients exception is narrower than it looks; other conditions still apply.
Greece Double opt-in No
Czech Republic Opt-in No The regulator ÚOOÚ answers flatly that publicly available addresses found on the internet may not be used for commercial offers ("Nelze"), under Act 480/2004. Fines up to CZK 10M.
Spain Opt-in No LSSI fines run to €600,000 for the most serious tier, separately from GDPR. No prior-relationship exception in the industry mapping.
Poland Opt-in No Also no prior-relationship exception — stricter than the EU baseline.
Italy Opt-in No The Garante enforces actively against B2B lists and purchased addresses.
Belgium, Denmark, and most remaining states Opt-in No Only the own-customer "soft opt-in" for similar products.

GDPR still applies even where sending is allowed

A B2B carve-out removes the consent-to-send barrier; it does not remove GDPR. To email firstname.lastname@company.com lawfully you still need a legitimate-interests basis under Art. 6(1)(f) — Recital 47 accepts direct marketing as a possible legitimate interest, but the EDPB's Guidelines 1/2024 make clear it is not automatic, and the balancing test must be written down. Two obligations are routinely missed: Art. 14 requires you to disclose the source of the address ("we found your address on your company site") at the latest in the first message, and Art. 21(2) gives the recipient an absolute, no-balancing right to object to marketing. GDPR fines reach €20M or 4% of global turnover, and national spam fines stack on top.

United Kingdom: the corporate subscriber exemption

The UK has the clearest statutory basis for B2B cold email of any major market. PECR regulation 22 requires consent only for individual subscribers — and the ICO's guidance confirms you may email any corporate body (company, LLP, Scottish partnership, government body) without prior consent, though it recommends keeping a do-not-email list of objectors.

Two qualifications most summaries omit. Sole traders and unincorporated partnerships count as individuals — emailing a one-person plumbing business requires consent, exactly as for a consumer. And UK GDPR still applies to named individuals at corporate addresses: you need the same legitimate-interests basis, source disclosure, and objection handling as in the EU.

The stakes changed materially in 2026. The Data (Use and Access) Act 2025 raised the maximum PECR fine from £500,000 to £17.5 million or 4% of global turnover — a 35× increase — in force since 5 February 2026. The corporate subscriber exemption survived intact, but the ICO's guidance is flagged as under review, so recheck it before relying on the details.

Canada: the strict one

CASL flips the burden: no commercial electronic message without consent, express or implied, and the sender must prove it. Implied consent exists only in defined windows — two years from a purchase or contract, six months from an inquiry — or under the B2B lever in s. 10(9)(b): the recipient conspicuously published their address, without a no-solicitation notice, and your message is relevant to their business role.

The CRTC reads that lever narrowly. In Blackstone Learning (2016) it held that conspicuous publication sets a higher standard than an address merely being publicly available — scraping an address off a website is not automatically enough, per the CRTC's implied-consent guidance. Every message must identify the sender, provide contact details valid for 60 days, and carry an unsubscribe honored within 10 business days with no further action required from the recipient — confirmation pages and login walls are non-compliant by construction.

Penalties reach CAD 10 million per violation for companies and CAD 1 million for individuals, with personal liability for directors. The private right of action was suspended indefinitely in 2017 and remains suspended as of August 2026 — but it could be switched on by Order in Council with little notice. CASL applies to any message received on a computer system in Canada, wherever you send from.

Australia and the rest of the world

Australia's Spam Act 2003 is opt-in, but consent may be inferred from an existing business relationship or a conspicuously published work address where the message is relevant to the role — similar to CASL. The distinctive trap is the unsubscribe deadline: 5 business days, the shortest of any major regime. The regulator ACMA enforces aggressively, with penalties reaching roughly AUD 3.1M per day for repeat corporate offenders and individual penalties above AUD 2.5M already on the books.

Elsewhere, briefly: Singapore is effectively opt-out for email (label unsolicited commercial mail, identify yourself, honor unsubscribes within 10 business days), which is why it is a common first APAC market. Japan is opt-in with a narrow business-card exception. Brazil's LGPD permits marketing on legitimate interests with an opt-out, GDPR-style. Switzerland requires prior consent and enforces criminally, with fines up to CHF 250,000 imposed on the responsible individual, not the company. South Africa's POPIA allows exactly one approach to request consent — if refused, that address is closed forever. China is strict opt-in with penalties to RMB 50M or 5% of turnover; small senders generally treat it as out of scope.

Summary: where cold email stands in 2026

Jurisdiction B2B rule B2C rule Maximum penalty
United States Legal — opt-out regime with five conditions Same opt-out regime USD 53,088 per email
United Kingdom Legal to corporate bodies; sole traders excluded Consent required £17.5M or 4% of turnover
France Legal if the offer relates to the profession Consent required GDPR: €20M or 4%
Ireland Legal — commercial-context carve-out Consent required €250,000 per message + GDPR
~8 more EU states (FI, EE, HU, LV, PT, SE, HR, LU) Legal with opt-out, conditions vary Consent required GDPR + national fines
Germany, Austria, Greece Consent required (double opt-in expected) Consent required Injunctions, Abmahnung costs, GDPR
Czechia, Spain, Italy, Poland + ~9 more Consent required Consent required CZK 10M (CZ); €600k LSSI (ES); GDPR
Switzerland Consent required Consent required Criminal; CHF 250k, personal
Canada Narrow implied-consent exceptions only Express consent CAD 10M per violation
Australia Inferred consent, narrowly read Consent required ~AUD 3.1M per day, repeat offenders
Singapore Legal — opt-out with labelling Opt-out SGD 200k–1M
Brazil Legal on legitimate interests + opt-out Similar 2% of Brazil revenue, cap BRL 50M

A compliance checklist that works everywhere

Building to the strictest rule in each category puts you inside every regime at once:

  • Identify yourself honestly. Real From and Reply-To, accurate routing, authenticated with SPF, DKIM, and DMARC. A subject line that matches the content. Sender name and a physical postal address in the footer.
  • Honor opt-outs within 48 hours. Statutes give you 5–10 business days, but Gmail and Yahoo's bulk-sender rules require unsubscribes processed within 2 days — the provider deadline, not the statute, is the real one. Support one-click unsubscribe per RFC 8058 on marketing mail, and track how these provider requirements keep tightening on our email deliverability changes timeline.
  • Keep a global, permanent suppression list, screened before every send. An opt-out in one campaign is an opt-out everywhere, forever.
  • Document your data sources. Record where every address came from and when. In the EU/UK, disclose the source in the first message (GDPR Art. 14), write a Legitimate Interests Assessment before the campaign, and present the right to object explicitly.
  • Check the recipient's country before sending. If it is an opt-in jurisdiction with no B2B carve-out — Germany, Czechia, Spain, Italy, Poland, Switzerland among them — do not send cold. No footer fixes that.
  • Don't open-track EU recipients for analytics without consent. France's CNIL (enforcing since July 2026) treats tracking pixels as requiring consent independently of the email itself; Italy's regulator has taken the same position. Deliverability-only tracking, minimised to a last-open date, survives.

What about warm-up emails?

Warm-up mail is the one category this whole framework mostly does not touch. A warm-up email — sent from your own domain, to inboxes you control, to build sending reputation — advertises nothing and goes to yourself. It fails CAN-SPAM's "primary purpose" test for a commercial message, is not a commercial electronic message under CASL (which also excludes intra-organisation mail), and is not "unsolicited communication for direct marketing" under ePrivacy Art. 13. The duties above — ad disclosure, postal address, unsubscribe links — almost certainly do not apply, and adding them would actively make warm-up mail look like the bulk marketing it isn't. The one rule that still binds is the universal one: no false or misleading headers. This is the model WarmEnvelopes uses — your domain, your Resend account, your own inboxes — which also avoids the unresolved data-protection questions raised by warmup networks that pool strangers' mailboxes.

Two honest caveats. No regulator anywhere has published guidance on email warm-up, so this is reasoning from general principles, not a ruling. And the boundary is sharp: the moment a "warm-up" message carries promotional content or reaches an address you don't control, it becomes a commercial message and every duty in this article attaches. Warming a domain improves delivery; it does nothing for legality. If your cold email is unlawful in Berlin, it is unlawful from a warmed domain too.

Frequently asked questions

Is cold email illegal in the United States?

No. CAN-SPAM is an opt-out law: you may email someone you have no relationship with, provided the headers and subject are honest, the message identifies itself as an ad, includes a physical postal address, and offers an opt-out you honor within 10 business days. Each non-compliant email carries a penalty of up to $53,088.

Is cold email legal under GDPR?

GDPR alone does not answer the question — the ePrivacy Directive's 27 national implementations decide whether you may send at all, and they disagree. Roughly ten member states plus the UK allow B2B cold email on an opt-out basis; Germany, Austria, Czechia, Spain, Italy, and Poland require prior consent. Even where sending is allowed, GDPR requires a documented legitimate-interests basis, disclosure of where you got the address, and an absolute right to object.

Is cold email legal in Germany?

Not without prior consent. UWG § 7(2) requires consent for every email advertisement, including to a corporate address, and double opt-in is the expected standard. Enforcement is largely private: competitors send cease-and-desist letters (Abmahnung) with costs typically quoted at €1,000–5,000 per violation, on top of separate GDPR exposure.

What are the penalties for violating CAN-SPAM?

Up to $53,088 per non-compliant email as of August 2026, enforced by the FTC, state attorneys general, and ISPs — individual recipients cannot sue. Aggravated conduct like address harvesting can multiply exposure, and some violations are criminal under 18 U.S.C. § 1037 with up to five years' imprisonment.

Do warm-up emails need an unsubscribe link or a postal address?

Almost certainly not. Warm-up mail sent from your own domain to inboxes you control advertises nothing and goes to yourself, so it does not meet the definition of a commercial message under CAN-SPAM, CASL, or the ePrivacy Directive. No regulator has published guidance on warm-up specifically, though, so this is reasoning from general principles rather than a ruling.

Related reading