WP Finder

Is Cold Email Legal? GDPR, PECR & CAN-SPAM Explained

By WP Finder · Updated · 7 min read

Is Cold Email Legal? GDPR, PECR & CAN-SPAM Explained

Is cold email legal? In many countries, B2B cold email can be legal, but only if you follow the rules that apply where your recipients are. Those rules differ a lot: the US CAN-SPAM Act is mainly about honesty and opt-outs, the UK combines PECR with UK GDPR, and across the EU each country applies its own version of the ePrivacy rules alongside GDPR. This guide gives a plain-English, high-level overview for web designers, agencies and freelancers who email businesses, plus a practical checklist you can use before every campaign.

Important: this article is general information, not legal advice. Laws change and their application depends on your circumstances. If you’re unsure, check the official guidance from the relevant regulator or speak to a qualified lawyer.

Is cold email legal? The short answer

Cold email isn’t automatically illegal, and it isn’t automatically allowed. Whether a particular message is lawful generally depends on:

  • Where the recipient is, since the recipient’s country usually decides which rules apply.
  • Who the recipient is: a company address, a named employee, a sole trader or a private individual.
  • How you got the address and whether contacting them is relevant to their role or business.
  • What the email contains: honest sender details, an honest subject line and a working way to opt out.

United States: CAN-SPAM

The CAN-SPAM Act covers commercial email, including business-to-business messages. It doesn’t require prior consent before you send, but it sets clear rules for every commercial email. According to the US Federal Trade Commission’s CAN-SPAM compliance guide, the main requirements include:

  • No false or misleading header information. Your “From”, “To”, “Reply-To” and routing information must accurately identify you or your business.
  • No deceptive subject lines. The subject must reflect the content of the message.
  • Identify the message as an advertisement where it’s commercial, in a clear way.
  • Include a valid physical postal address for your business.
  • Tell recipients how to opt out of future emails, clearly and simply.
  • Honour opt-outs promptly (the FTC states within 10 business days), don’t charge for opting out, and don’t sell or transfer the addresses of people who opted out.
  • You’re responsible for anyone sending on your behalf, such as an agency or freelancer.

Penalties can apply per email, so even a small non-compliant campaign can be costly.

United Kingdom: PECR and UK GDPR

In the UK, two sets of rules usually apply to cold email: the Privacy and Electronic Communications Regulations (PECR), which cover electronic marketing, and UK GDPR with the Data Protection Act 2018, which cover personal data. The Information Commissioner’s Office (ICO) publishes guidance on both.

Corporate subscribers vs individuals and sole traders

PECR treats recipients differently depending on who they are:

Recipient type General PECR position for marketing email
Corporate subscribers (for example limited companies, LLPs, government bodies) Consent isn’t generally required under PECR, but you must identify yourself and give a valid way to opt out.
Individual subscribers, including sole traders and some partnerships Generally need prior consent, unless the “soft opt-in” applies (broadly, existing customers who bought or negotiated to buy similar products and were given a chance to opt out).

This matters for small-business outreach. A local plumber or freelance photographer is often a sole trader, so cold marketing emails to them are likely to be treated much like emails to a private individual. When in doubt, be cautious.

Where UK GDPR comes in

Even when PECR allows an email to a company, UK GDPR still applies if you’re processing personal data. A named work email such as jane.smith@example.co.uk identifies a person, so it counts. In practice that usually means:

  • A lawful basis. For B2B outreach this is often legitimate interests, which requires a genuine balancing exercise: your interest in contacting them versus their reasonable expectations and rights. Many organisations document this in a short legitimate interests assessment.
  • Relevance. Contacting someone about something related to their role is easier to justify than generic mass messages.
  • Transparency. People should be told who you are, where you got their details and how to object. A link to a clear privacy notice in your email is a common approach.
  • The right to object. Anyone can object to direct marketing at any time, and you must then stop. Keep a suppression list so they aren’t contacted again.
  • Data minimisation and security. Only collect what you need and keep it safe.

UK rules have been updated in recent years, so check the ICO’s current guidance on direct marketing before you start a campaign.

European Union: GDPR plus national rules

In the EU, GDPR applies to personal data in much the same way as in the UK. Electronic marketing, however, is governed by the ePrivacy Directive, which each member state has implemented in its own national law. The result is that B2B cold email rules vary from country to country:

  • Some countries allow marketing emails to business addresses with an opt-out.
  • Others are much stricter and may effectively require prior consent even for many B2B messages. Germany, for example, is widely regarded as strict.

Before emailing businesses in a specific EU country, check that country’s rules. What’s acceptable in one country may not be elsewhere.

Other countries

Many other countries have their own anti-spam laws. Canada’s CASL, for example, is built around consent and is generally considered stricter than CAN-SPAM. Always check the rules for the countries on your list.

A checklist to keep cold email legal

Use this before every campaign. It covers the basics most rules share, but won’t make every email lawful everywhere:

  1. Know your recipients’ countries and the rules that apply there. Leave out regions you haven’t checked.
  2. Target businesses, not consumers, and keep the message relevant to the recipient’s business or role.
  3. Be careful with sole traders and individuals, especially in the UK and EU, where consent is often required.
  4. Use only publicly available business contact details found on the company’s own website. Don’t buy lists of unknown origin.
  5. Identify yourself honestly: your real name, business name and a genuine reply address.
  6. Write honest subject lines, with no fake “Re:” or “Fwd:”.
  7. Include your business postal address, which CAN-SPAM requires and which is good practice everywhere.
  8. Include a simple opt-out in every email, including follow-ups.
  9. Act on opt-outs quickly and add them to a permanent do-not-email list.
  10. Explain where you got their details and link to a privacy notice.
  11. Record your reasoning, for example a short legitimate interests assessment if you rely on that basis.
  12. Keep volumes modest and personalised.

Our guides to cold email deliverability and building a polite cold email follow-up sequence go hand in hand with this checklist.

How WP Finder supports responsible outreach

WP Finder only collects contact details from the public pages of each website, such as the homepage, contact and about pages, so you can see where every address came from. Its built-in email sender includes unsubscribe links, a do-not-email list, daily limits and delays, which help you put the checklist above into practice. Compliance is still your responsibility: the tool can’t decide for you whether a particular email is lawful in a particular country. For ideas on what to say, see our cold email templates for WordPress services.

Conclusion

So, is cold email legal? Often yes for genuine B2B outreach, but it depends on the country, the type of recipient and how you send. In the US, CAN-SPAM focuses on honesty, a physical address and working opt-outs. In the UK, PECR distinguishes corporate subscribers from sole traders and individuals, and UK GDPR requires a lawful basis such as legitimate interests and respect for objections. In the EU, rules vary by country. Be honest, relevant and respectful, make opting out easy, and check official guidance or get legal advice when you’re unsure. This article is not legal advice.

FAQ

Is cold email legal in the US?

Generally, commercial email to businesses doesn’t require prior consent under CAN-SPAM, but each message must have accurate headers, a non-deceptive subject, identification as an ad where relevant, a physical postal address and a working opt-out that you honour promptly.

Can I cold email UK businesses under GDPR?

Often yes for corporate subscribers such as limited companies, provided you identify yourself, offer an opt-out and have a lawful basis like legitimate interests for any personal data. Sole traders and some partnerships are generally treated like individuals and usually need consent. Check the ICO’s guidance.

Do I need consent to cold email businesses in the EU?

It depends on the country. The EU’s ePrivacy rules are implemented nationally, so some countries allow B2B emails with an opt-out while others are stricter. Check the rules for each country before sending.

Is this article legal advice?

No. It’s a general overview to help you ask the right questions. For decisions about your own campaigns, check the official regulator guidance or consult a qualified lawyer.