Cold email can be an effective way to open B2B conversations — if you respect the rules. Here is a plain-English overview of CAN-SPAM, GDPR and related requirements.
Email remains one of the most effective ways to start B2B conversations. It is also regulated, and the rules differ by country. This guide gives a practical, plain-English overview of the main requirements for businesses reaching prospects in the United States and Europe.
This article is general information, not legal advice. Rules change and vary by jurisdiction — check with a qualified lawyer for your specific situation.
United States: the CAN-SPAM Act
In the US, commercial email — including business-to-business email — is governed by the CAN-SPAM Act. It does not require prior consent, but it does set clear rules for every message:
- Accurate header information. Your "From", "To" and routing information must identify you honestly.
- Honest subject lines. The subject must not mislead recipients about the content.
- Identify the message as commercial where it is an advertisement or promotion.
- Include a valid physical postal address for your business.
- Provide a clear way to opt out, and make it easy to use.
- Honour opt-outs promptly — within 10 business days — and do not sell or transfer the addresses of people who opted out.
- Monitor anyone emailing on your behalf. You remain responsible for compliance even if an agency sends the messages.
Penalties can apply to each individual email that breaks the rules, so these are worth building into your process from day one.
European Union: GDPR and national email rules
In the EU, business contact details such as a named person's work email are personal data under the GDPR. B2B outreach is commonly based on "legitimate interests", which requires you to:
- Have a genuine, relevant reason to contact the person in their professional role.
- Balance your interest against their rights — and keep a short record of that assessment.
- Tell them who you are, how you got their details and how to object.
- Stop immediately if they object, and suppress them from future outreach.
Separately, each EU country has its own electronic marketing rules, and some are stricter than others about unsolicited email to businesses. If you target a specific EU country, check its local rules before launching a campaign.
United Kingdom
The UK GDPR applies alongside the Privacy and Electronic Communications Regulations (PECR). In broad terms, marketing emails to corporate subscribers (such as limited companies) do not require prior consent, but you must identify yourself and offer a simple way to opt out. Sole traders and some partnerships are treated like individual consumers, which means consent is generally required.
Canada
Canada's Anti-Spam Legislation (CASL) is stricter than CAN-SPAM. It generally requires express or implied consent before you send commercial email, along with clear identification and an unsubscribe mechanism. Treat Canadian prospects differently from US ones.
Good practice that works everywhere
- Target carefully. Contact people whose role makes your message genuinely relevant.
- Use verified data from reputable sources, and record where each contact came from.
- Keep a single suppression list shared across every tool and campaign.
- Be transparent. Say who you are and why you're getting in touch.
- Make opting out effortless, and act on it quickly.
- Send at a sensible volume, and warm up new sending domains gradually.
Compliance and effectiveness point in the same direction: relevant, honest, well-targeted emails get better replies and fewer complaints.
How we approach it
At Insight Meridian Group, our InsightLead Partners team builds compliance into every campaign — from how data is sourced and verified, to suppression management and opt-out handling in our Prime Meridian CRM. If you're planning outbound campaigns into the US or Europe, we're happy to talk through a sensible approach.
Want help putting this into practice?
Talk to our team about your goals. The first consultation is free.
Book a Free Consultation