Is cold outreach legal?
Yes, in most jurisdictions, when the correct rules are followed for the channel and the recipient country. US B2B email is legal under CAN-SPAM with honest sender identification and a working unsubscribe. EU B2B email is legal under GDPR legitimate interest when the message is relevant to the recipient role. Phone calls and SMS require more careful consent handling under the TCPA, CASL, and equivalents. Consumer outreach is tightly restricted almost everywhere.
Do I need consent for B2B cold email in the United States?
No. CAN-SPAM does not require prior consent for commercial email in the United States, including B2B outreach. The law requires honest sender identification, a non-deceptive subject line, a valid physical mailing address, and a working opt-out mechanism that is honored within ten business days. Consent is only required in the United States for marketing SMS, autodialed calls, and prerecorded messages under the TCPA.
Can I send cold email to someone in the EU?
Yes, for B2B outreach, under GDPR legitimate interest. The message must be relevant to the recipient professional role, sent to a business address rather than a personal one, identify the sender honestly, and offer a one click opt-out. Consumer addresses in the EU require explicit prior consent and are not safe to cold email. The ePrivacy Directive and country-specific rules can add further restrictions.
What is the difference between CAN-SPAM and GDPR?
CAN-SPAM is a US email-specific law that permits unsolicited commercial email with honest identification and working opt-out. GDPR is a broad EU personal data regulation that governs all processing of personal data, including cold outreach, and requires a lawful basis such as consent or legitimate interest. CAN-SPAM focuses on sender honesty and opt-out mechanics. GDPR focuses on data processing basis, recipient rights, and sender accountability.
What is CASL and who does it apply to?
The Canadian Anti-Spam Legislation applies to any commercial electronic message sent to a recipient in Canada, regardless of where the sender is based. CASL requires express or implied consent before the message is sent. Implied consent includes existing business relationships and conspicuously published business addresses, with limits. CASL carries some of the strictest penalties in the world, with fines running into millions of dollars per violation.
Do I need to check the Do Not Call Registry?
Yes, for US consumer phone outreach. The National Do Not Call Registry must be scrubbed before every outbound call to a residential number, and the scrub has to be recent enough to catch registrations added since the last check. Business lines are not on the DNC Registry, so B2B dialing is more permissive. State-level DNC lists exist in some states and have to be respected on top of the federal registry.
What happens if an outbound program ignores compliance?
The consequences stack. Immediate consequences include higher spam complaint rates, lower deliverability, and sender domain reputation damage. Legal consequences include fines under CAN-SPAM up to around 50 thousand dollars per message, TCPA fines of 500 to 1500 dollars per violation, GDPR fines up to 4 percent of global revenue, and CASL fines up to 10 million CAD per violation. Private class actions under the TCPA are a major additional risk.
How does a CRM help with cold outreach compliance?
A modern CRM runs the suppression list, consent record, DNC check, and audit trail inside the same workflow that sends the outbound messages. Opt-outs land on a tenant-wide suppression list immediately and block every future sequence. Consent timestamps and sources are stored on the contact. DNC checks run at dial time. The audit trail covers every message. Compliance becomes a property of the system, not a reminder in a playbook.