MCP

Staying legal in a nutshell

Last verified: 2026-08-05

TL;DR

  • There is no single global rule. The US runs an opt-out regime, Canada a consent regime, the EU splits country by country, and the UK carves out corporate addresses — the recipient's country decides, not yours.
  • Four duties hold nearly everywhere: say truthfully who you are, give a real postal address, make opting out easy, and honor it permanently.
  • This page is an educational summary, not legal advice. Laws change and vary by country; the regulator pages linked below are the canonical text, and a lawyer is the right call for anything load-bearing.

The four regimes worth knowing

United States — opt-out. CAN-SPAM permits commercial email without prior consent and regulates conduct instead: no deceptive headers or subjects, the message identifiable as an ad, a valid physical postal address, and a working opt-out honored within 10 business days, with the mechanism live for at least 30 days after the send. Each non-compliant email is separately liable, at up to $53,088 per message under the FTC's current figure [1]. This is the regime most cold-email advice silently assumes.

Canada — consent. CASL is the strictest major regime: a commercial electronic message needs consent, express or implied. The route that matters for B2B outreach is implied consent through a conspicuously published business address — permitted only when that address carries no statement refusing such messages and your message is relevant to the person's business role. Identification and an unsubscribe mechanism are required in every message, and requests must be given effect within 10 business days [2, 3].

United Kingdom — the corporate carve-out. PECR's marketing rules apply to "individual subscribers", which leaves email to corporate subscribers — a named person at a limited company — lawful without prior consent. Sole traders and most partnerships count as individuals, so the carve-out does not cover them. Separately, UK GDPR still applies to the personal data in your list: you need a lawful basis, in practice legitimate interests, and a documented balancing assessment [4].

European Union — no single answer. The ePrivacy Directive left B2B electronic marketing to member states, and they genuinely diverged. Germany is at the strict end, requiring consent even for business recipients; France permits messages relevant to the recipient's professional role. Practitioner summaries treat "the EU rule" as one thing; there isn't one, and a campaign spanning several member states is really several compliance questions [5, 6]. Country-by-country tables maintained by outreach vendors are a useful orientation layer, but they are marketing material summarizing law — treat them as a map to the regulator pages rather than as the answer [11, 12].

Australia rounds out the set: the Spam Act 2003 requires consent, accurate sender identification (s 17) and a functional unsubscribe facility (s 18), enforced by ACMA [7, 8].

The duties that travel

Whatever the jurisdiction, four things are safe to treat as universal, because every regime above demands them and the mailbox providers enforce their own versions regardless:

  1. Identify yourself honestly. A real sender name, a real company, a real reply path. Fake "Re:" and "Fwd:" prefixes are deceptive subject lines in the CAN-SPAM sense and pattern-matched by providers — see Subject lines.
  2. Give a physical address. Required outright in the US, expected everywhere.
  3. Make opting out trivial, and never charge, gate, or interrogate someone for doing it.
  4. Suppress permanently. Legally required, and cheaper than the complaint you get for the second unwanted message — the mechanics are in Stopping rules and suppression.

Provider rules act like law

The mailbox providers' sender requirements are not legislation, but they bind you more immediately than any statute: Google's and Yahoo's bulk-sender rules (in force since February 2024) and Microsoft's high-volume requirements (May 2025) reject or filter non-compliant mail automatically, with no complaint, notice or appeal [9, 10]. A campaign can be perfectly lawful and still fail entirely on these. The technical side is Deliverability in a nutshell.

References

  1. FTC — CAN-SPAM Act: A compliance guide for business (official guide, current)
  2. CRTC — Canada's Anti-Spam Legislation: compliance guide (official guide, current)
  3. ISED — Canada's Anti-Spam Legislation (official portal, current)
  4. ICO — Business to business marketing (regulator guidance, current)
  5. Harper James — B2B marketing and GDPR: the basics (law-firm guide, current)
  6. Hybrid Legal — Using business emails for B2B cold outreach in the UK (law-firm guide, current)
  7. ACMA — Avoid sending spam (regulator guidance, current)
  8. Federal Register of Legislation — Spam Act 2003 (statute, current compilation)
  9. Google — Email sender guidelines (support page, requirements in force since Feb 2024)
  10. Microsoft — Strengthening the email ecosystem: Outlook's new requirements for high-volume senders (official blog, 2025)
  11. Woodpecker — Is cold email illegal? (practitioner country tables, updated 2025–26)
  12. lemlist — GDPR and cold emailing (practitioner guide, updated 2025–26)