Is Cold Email Legal? GDPR and CAN-SPAM for B2B

Yes, cold email is legal for B2B in most jurisdictions, provided you follow the rules. The rules differ between the US and Europe, and getting them right is both a legal matter and a deliverability one, because compliant senders get flagged less.

Here is the practical version.

CAN-SPAM (United States)

CAN-SPAM governs commercial email in the US. It does not require prior consent, which makes cold B2B email straightforward there. It does require that you:

  • Use accurate From, To, and routing information. No spoofing.
  • Write a subject line that reflects the actual content. No deception.
  • Identify the message as a solicitation if it is one.
  • Include a valid physical postal address.
  • Offer a clear way to opt out, and honor it within 10 business days.

Break these and penalties run into the thousands of dollars per email, so treat them as hard requirements.

GDPR (European Union and UK)

GDPR is stricter because it protects personal data, and a work email that identifies a named person (jane.doe@company.com) counts as personal data. But GDPR does not ban cold email. It gives you a lawful basis called legitimate interest.

To rely on legitimate interest for B2B outreach:

  1. Relevance: the person’s role must plausibly relate to what you are offering. Emailing a head of sales about a sales tool is defensible. Emailing them about pet insurance is not.
  2. Proportionality: use minimal data, and do not scrape or store more than you need.
  3. Balancing test: document why your interest in reaching them does not override their rights. A short written note is enough, but you must have one.
  4. Easy opt-out: every message must let them object, and you must stop immediately and permanently.
  5. Transparency: on request, tell people what data you hold and where you got it.

Note that ePrivacy rules in some EU countries are stricter still, especially for sole traders and certain personal-email formats. When in doubt, target genuine business roles at genuine businesses.

What to include in every cold email

  • Your real identity and company.
  • A truthful subject line.
  • A clear, working way to opt out or reply “stop.”
  • A physical address (required by CAN-SPAM, good practice everywhere).
  • Relevance to the recipient’s actual job.

What to avoid

  • Buying or scraping large lists with no role relevance.
  • Hiding or faking who you are.
  • Ignoring opt-outs, or making people opt out more than once.
  • Continuing to email someone after they object.

Respecting opt-outs is not just legal hygiene, it protects your sender reputation too. See why cold emails go to spam for how ignored opt-outs damage deliverability.

How PitchButler stays on the right side

Compliance is easier when the tool enforces it. PitchButler sends genuine one-to-one emails to relevant business roles, honors opt-outs permanently (once someone is out, they stay out, no undo), and supports GDPR data export and erasure on request. It is built in Sweden and GDPR-first, so the defaults lean toward the stricter regime. Details are on our security page and about page.

A short, honest note

This is a practical overview, not legal advice. Rules vary by country, industry, and how you source your data, and they change. For anything high-stakes, confirm with a qualified lawyer in your market. If you want more on doing outreach the right way, start with our cold email best practices.

Found this useful? Join the PitchButler waitlist or read how it works.

Put your outreach in good hands.

We open 30 new mailboxes a week, no more. Join the waitlist and we take you in turn.

Join the waitlist