Outbound Strategy

Cold Email Compliance: CAN-SPAM, GDPR and CASL

Three different legal frameworks govern cold email depending on where your recipients are. Here's what each actually requires, in plain terms.

Cold Email Compliance: CAN-SPAM, GDPR and CASL

Cold email's legal status depends heavily on where the recipient is, and the three major frameworks — the US's CAN-SPAM Act, the EU/UK's GDPR, and Canada's CASL — have meaningfully different requirements. Sending internationally without knowing which applies is a real compliance gap, not just a technicality.

Side-by-side comparison

CAN-SPAM (US)GDPR (EU/UK)CASL (Canada)
Consent basisOpt-out — no consent needed to send first"Legitimate interest" for relevant B2B; consent required for B2CExpress or implied consent generally required before sending
Unsubscribe requirementRequired, honored within 10 business daysRequired, honored promptly ("without undue delay")Required, honored within 10 business days
Sender identificationMust not be deceptive; physical address requiredMust clearly identify the senderMust clearly identify the sender and include contact info
Penalty exposurePer-email FTC penalties, historically enforced against high-volume/deceptive sendersUp to 4% of global annual revenue or €20M, whichever is higherUp to CAD $10M per violation for organizations
Strictest forDeceptive headers/subject lines, ignored opt-outsB2C outreach, and B2B without genuine relevanceAny commercial email without consent or an existing business relationship

CAN-SPAM: the most permissive of the three

CAN-SPAM doesn't require consent before the first email — it's an opt-out regime. The actual requirements: don't use deceptive subject lines or sender information, identify the message as an ad if it is one, include a valid physical postal address, and honor opt-out requests within 10 business days. Most legitimate B2B cold email already satisfies this without special effort — the violations that draw enforcement are almost always deceptive headers or ignored unsubscribes, not the act of cold emailing itself.

GDPR: relevance is the real test, not just "B2B vs B2C"

The common shorthand — "B2B cold email is fine under GDPR, B2C isn't" — is directionally right but incomplete. GDPR's legitimate interest basis for B2B outreach requires the outreach to be genuinely relevant to the recipient's professional role, proportionate, and not overriding their reasonable privacy expectations. A relevant, well-targeted B2B email to a decision-maker in their professional capacity is generally defensible; the same volume of generic, poorly-targeted outreach to the same list is a weaker legal position even though it's technically still B2B. Consumer (B2C) cold email requires actual consent in most cases — there's no equivalent legitimate-interest carveout.

CASL: the strictest of the three

Canada's Anti-Spam Legislation generally requires consent — express or implied through an existing business relationship — before sending commercial electronic messages, making it meaningfully stricter than CAN-SPAM's opt-out model. "Implied consent" has specific, narrow definitions (an existing business relationship within a defined lookback period, for example) rather than a broad B2B carveout. Penalties are also significantly higher per violation than CAN-SPAM's, and CASL has been actively enforced against companies treating Canadian recipients under US-style opt-out assumptions.

Practical checklist before sending internationally

  1. Segment lists by recipient jurisdiction before applying a blanket cold email policy — “we comply with CAN-SPAM” doesn't cover Canadian or EU recipients.
  2. For EU/UK B2B recipients: confirm the outreach is genuinely relevant to the person's role, not just their company's industry broadly.
  3. For Canadian recipients: confirm an actual consent basis exists — don't assume the CAN-SPAM opt-out model applies.
  4. Everywhere: make unsubscribe functional and fast, and never use deceptive subject lines or sender names — this is the one requirement that's universal across all three frameworks and the one most enforcement actually targets.
  5. Keep records of consent basis and outreach relevance rationale for EU/Canadian segments — in a complaint or audit, having a documented rationale matters.

Bottom line

None of these frameworks make cold email illegal outright, but they set meaningfully different bars — CAN-SPAM's opt-out model is the most permissive, CASL's consent requirement is the strictest, and GDPR sits in between with a relevance test that's easy to misjudge. Segment by jurisdiction and apply the stricter standard to any list that might include EU or Canadian recipients, rather than assuming one policy covers every region.

Ready for liftoff?

Your next campaign is six minutes away

Connect your business and let Alien AI handle the writing, structuring, and optimizing.

Generate my Business DNA — free