← All postsOUTBOUND · 4 MIN READ · SEP 2026

Is cold email marketing legal? | UK, US and EU rules explained

In most of the world, B2B cold email is legal. The rules differ by country and the one people get wrong is the difference between a limited company and a sole trader.

Yes, in most of the world B2B cold email is legal. It is regulated rather than banned, and the regulations are more workable than people assume.

What follows is how the rules work in the three markets most people ask about. I run outbound for a living, not a law firm, so treat this as a working guide and take advice before you launch anything you're unsure about.

United Kingdom

The relevant law is PECR, and it turns on a distinction most articles miss.

The ICO splits recipients into corporate subscribers and individual subscribers.

RecipientStatusConsent needed?
Limited companyCorporate subscriberNo
Limited liability partnershipCorporate subscriberNo
Scottish partnershipCorporate subscriberNo
Sole traderIndividual subscriberYes
Ordinary partnershipIndividual subscriberYes

In the ICO's own words, the electronic mail marketing rule "doesn't apply to corporate subscribers." So emailing someone at a limited company does not require prior consent.

Sole traders and ordinary partnerships are treated as individuals. Email one without consent and you are likely in breach.

Two things still apply even for corporate subscribers. You must honour an opt-out request, and UK GDPR still governs the personal data itself, since a named person's work address is personal data.

The practical consequence: if your list is built from limited companies, you're on solid ground. If it includes consultants, freelancers and one-person businesses, you have a problem hiding in it. That's an argument for filtering by company size at the list stage rather than hoping.

United States

CAN-SPAM is the governing law, and it's the most permissive of the three.

No prior consent is required, including for B2C. What the law requires instead:

  • Accurate "From", "Reply-To" and routing information
  • A subject line that isn't deceptive
  • Identification that the message is an advertisement
  • A valid physical postal address
  • A working opt-out mechanism
  • Opt-outs honoured within 10 business days

Penalties run into five figures per individual email, so the cost of getting it wrong scales with your send volume rather than being a flat fine.

European Union

GDPR is the relevant regime, and unlike the UK's corporate-subscriber carve-out, it applies to personal data regardless of whether the person is at a company.

You need a lawful basis. For B2B outbound that is normally legitimate interest, which requires you to document that your interest in contacting them doesn't override their rights. In practice that means the contact has to be relevant to their actual job.

You also need to state where you got their data, honour deletion requests, and give an easy opt-out.

Individual member states add their own rules on top, so Germany in particular is stricter than the baseline.

What to do regardless of jurisdiction

Most of compliance is also just good outbound:

Make opting out effortless. One line, no form, no login. Someone who wants out and can't find the exit reports you as spam, which costs you far more than the lost contact.

Suppress immediately. Not within ten days. The same day, across every campaign and every domain.

Use real identity. Your real name, your real company, a real reply address that a human reads. Every regulation above requires this, and so does anyone who might actually buy from you.

Only contact people the message is relevant to. This is the legitimate interest test in the EU, and it's also the difference between a campaign that works and one that doesn't.

Keep records of where your data came from. You may be asked. It's also how you find out which source is producing your bounces.

The short version

In the UK, emailing limited companies needs no consent, sole traders do. In the US, no consent is needed but disclosure and opt-out rules are strict. In the EU, you need a documented lawful basis and genuine relevance.

None of it stops you doing outbound. It mostly stops you doing lazy outbound, which was going to fail on deliverability grounds anyway.