This guide summarises the rules as published by regulators and in the laws themselves. It is not legal advice; for a large programme or a regulated industry, ask a lawyer in the recipient's country.
The short answer
| Where the recipient is | B2B cold email to a work address |
|---|---|
| United States | Allowed without consent if you follow CAN-SPAM |
| United Kingdom, company addresses | Allowed without consent under PECR, with UK GDPR still applying to the person's data |
| United Kingdom, sole traders and some partnerships | Treated like individuals: consent needed |
| European Union | Depends on the country's ePrivacy law; often possible under legitimate interest, but some countries require prior consent |
| Germany | Prior consent required for advertising email, including to businesses |
The rules follow the recipient's location, not yours.
United States: CAN-SPAM
The FTC's guidance is direct: "The law makes no exception for business-to-business email." There is no consent requirement, but every commercial email must:
- Use accurate "From", "To" and routing information.
- Have a subject line that is not deceptive.
- Identify the message as an advertisement where that applies.
- Include a valid physical postal address.
- Explain how to opt out, and honour opt-outs within 10 business days. You cannot charge for opting out or ask for more than an email address.
The FTC lists penalties of up to $53,088 for each email that breaks the law. You stay responsible when someone else sends on your behalf.
European Union: two laws apply together
The ePrivacy Directive decides whether you may send. Article 13 requires prior consent for direct marketing email to individuals. For businesses ("legal persons") it leaves the rule to each member state, which is why countries differ. Each country's national law, not the directive itself, is the one to check.
GDPR decides how you handle the person's data. A work address such as [email protected] is personal data. You need a lawful basis to use it, and for B2B outreach that is usually legitimate interest: Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest". To rely on it, you should be able to show:
- Purpose: you have a real business reason to contact this person.
- Necessity: email to this person is a reasonable way to pursue it.
- Balance: the person would reasonably expect it given their role, and it does not override their interests. Writing to a head of procurement about a procurement tool passes this; writing to a junior employee about an unrelated product does not.
Write this assessment down once and keep it.
GDPR adds two duties that catch cold emailers out:
- Tell people where you got their data. Under Article 14, when you collect data from somewhere other than the person, you must give them the privacy information at the latest in your first message to them. A short line with a link to your privacy policy and the source ("we found your address on your company's website") covers it.
- Stop when asked. Under Article 21, a person can object to direct marketing whenever they choose, and you must then stop using their data for it. There is no balancing test for this objection.
Germany: consent even for businesses
Section 7 of the German Act against Unfair Competition (UWG) treats advertising by email without the recipient's prior express consent as an unacceptable nuisance, and it applies to business recipients as well. In practice, cold email to German companies carries legal risk even when GDPR's legitimate interest would allow it. Many senders exclude Germany from cold email or contact German prospects by other channels first.
United Kingdom: PECR and UK GDPR
The ICO's guidance on the Privacy and Electronic Communications Regulations (PECR) splits recipients into two groups:
- Corporate subscribers (companies, limited liability partnerships, government bodies): you can email them without consent. You must say who you are and give a valid address for opt-outs.
- Individual subscribers, which includes sole traders and some partnerships: the consent rules for individuals apply.
UK GDPR still applies to an employee's personal work address, so the legitimate interest assessment, Article 14 notice and right to object described above apply in the UK too.
A checklist for every campaign
- Contact people in a role that matches what you sell.
- Exclude countries where you have no lawful basis, such as Germany for cold email.
- Keep a written legitimate interest assessment for EU and UK recipients.
- Say who you are, where you found their address and link your privacy policy in the first email.
- Include an opt-out in every email and a postal address for US recipients.
- Honour opt-outs at once, across every campaign, and keep them on a suppression list.
- Keep volume modest: a few personal emails and follow-ups, not a blast.
Doing this in Reach-book.com
Reach-book.com keeps a workspace-wide suppression list, so do-not-contact entries and unsubscribes are honoured across every campaign. Unsubscribes, bounces and replies stop further follow-ups automatically. Templates and signatures let you put your sender details, privacy link and postal address in every email, and the review queue lets you check each message before it goes out.