Skip to content
Reach-book.com

Is cold email legal? GDPR, UK PECR and CAN-SPAM for B2B senders

B2B cold email is lawful in the US and UK when you follow a few clear rules, and possible in much of the EU under legitimate interest. Some countries, Germany among them, require prior consent even for business recipients. This guide sets out the rules from the laws and regulators themselves.

Updated · 4 min read · Written by the Reach-book.com team

This guide summarises the rules as published by regulators and in the laws themselves. It is not legal advice; for a large programme or a regulated industry, ask a lawyer in the recipient's country.

The short answer

Where the recipient is B2B cold email to a work address
United States Allowed without consent if you follow CAN-SPAM
United Kingdom, company addresses Allowed without consent under PECR, with UK GDPR still applying to the person's data
United Kingdom, sole traders and some partnerships Treated like individuals: consent needed
European Union Depends on the country's ePrivacy law; often possible under legitimate interest, but some countries require prior consent
Germany Prior consent required for advertising email, including to businesses

The rules follow the recipient's location, not yours.

United States: CAN-SPAM

The FTC's guidance is direct: "The law makes no exception for business-to-business email." There is no consent requirement, but every commercial email must:

  • Use accurate "From", "To" and routing information.
  • Have a subject line that is not deceptive.
  • Identify the message as an advertisement where that applies.
  • Include a valid physical postal address.
  • Explain how to opt out, and honour opt-outs within 10 business days. You cannot charge for opting out or ask for more than an email address.

The FTC lists penalties of up to $53,088 for each email that breaks the law. You stay responsible when someone else sends on your behalf.

European Union: two laws apply together

The ePrivacy Directive decides whether you may send. Article 13 requires prior consent for direct marketing email to individuals. For businesses ("legal persons") it leaves the rule to each member state, which is why countries differ. Each country's national law, not the directive itself, is the one to check.

GDPR decides how you handle the person's data. A work address such as [email protected] is personal data. You need a lawful basis to use it, and for B2B outreach that is usually legitimate interest: Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest". To rely on it, you should be able to show:

  1. Purpose: you have a real business reason to contact this person.
  2. Necessity: email to this person is a reasonable way to pursue it.
  3. Balance: the person would reasonably expect it given their role, and it does not override their interests. Writing to a head of procurement about a procurement tool passes this; writing to a junior employee about an unrelated product does not.

Write this assessment down once and keep it.

GDPR adds two duties that catch cold emailers out:

  • Tell people where you got their data. Under Article 14, when you collect data from somewhere other than the person, you must give them the privacy information at the latest in your first message to them. A short line with a link to your privacy policy and the source ("we found your address on your company's website") covers it.
  • Stop when asked. Under Article 21, a person can object to direct marketing whenever they choose, and you must then stop using their data for it. There is no balancing test for this objection.

Germany: consent even for businesses

Section 7 of the German Act against Unfair Competition (UWG) treats advertising by email without the recipient's prior express consent as an unacceptable nuisance, and it applies to business recipients as well. In practice, cold email to German companies carries legal risk even when GDPR's legitimate interest would allow it. Many senders exclude Germany from cold email or contact German prospects by other channels first.

United Kingdom: PECR and UK GDPR

The ICO's guidance on the Privacy and Electronic Communications Regulations (PECR) splits recipients into two groups:

  • Corporate subscribers (companies, limited liability partnerships, government bodies): you can email them without consent. You must say who you are and give a valid address for opt-outs.
  • Individual subscribers, which includes sole traders and some partnerships: the consent rules for individuals apply.

UK GDPR still applies to an employee's personal work address, so the legitimate interest assessment, Article 14 notice and right to object described above apply in the UK too.

A checklist for every campaign

  • Contact people in a role that matches what you sell.
  • Exclude countries where you have no lawful basis, such as Germany for cold email.
  • Keep a written legitimate interest assessment for EU and UK recipients.
  • Say who you are, where you found their address and link your privacy policy in the first email.
  • Include an opt-out in every email and a postal address for US recipients.
  • Honour opt-outs at once, across every campaign, and keep them on a suppression list.
  • Keep volume modest: a few personal emails and follow-ups, not a blast.

Doing this in Reach-book.com

Reach-book.com keeps a workspace-wide suppression list, so do-not-contact entries and unsubscribes are honoured across every campaign. Unsubscribes, bounces and replies stop further follow-ups automatically. Templates and signatures let you put your sender details, privacy link and postal address in every email, and the review queue lets you check each message before it goes out.

Try Reach-book.com on your own pipeline

Find decision makers, verify their emails and send personal sequences from your own Gmail or Microsoft 365 mailbox. The 7-day trial needs a card and is once per new workspace owner.

Sources

Checked on 4 October 2026. Vendors change plans often, so confirm on their own pages before you buy.

  1. FTC: CAN-SPAM Act compliance guide for business
  2. GDPR Recital 47: legitimate interests
  3. GDPR Article 14: information where data was not obtained from the data subject
  4. GDPR Article 21: right to object
  5. Directive 2002/58/EC (ePrivacy Directive), Article 13
  6. German Act against Unfair Competition (UWG), section 7
  7. ICO: electronic mail marketing under PECR