Jump past the navigation
Colddraft
Menu

Cold Email Rules: CAN-SPAM, GDPR and PECR, From the Regulators

A sales email to a US company and a sales email to a UK sole trader are governed by different rules with different answers. The difference is quoted here from the FTC and the ICO themselves.

Written Sep 24, 2026

Cold email is lawful in the United States, subject to conditions, and the conditions apply to business-to-business mail exactly as they apply to consumer mail. In the United Kingdom the answer depends on whether the recipient is a limited company or a sole trader, and those two cases have genuinely different rules. That distinction is the single most useful thing on this page.

Everything below is quoted from the regulators' own published guidance, with the date it was read. It is a description of what they have published, not legal advice, and the source pages are worth opening rather than trusting a summary — including this one.

The United States: there is no B2B exception

The Federal Trade Commission's compliance guide for the CAN-SPAM Act says it in one sentence: "The law makes no exception for business-to-business email." A sales email to someone's work address is commercial email and carries the same obligations as a newsletter to a consumer.

The guide's page is dated August 2023 and edited January 2024, and was read on 24 September 2026. It sets out eight main requirements. In its own headings, they are: do not use false or misleading header information; do not use deceptive subject lines; identify the message as an ad; tell recipients where you are located; tell recipients how to opt out of receiving future marketing email; remember that subscribers and members can opt out of marketing emails too; honour opt-out requests promptly; and monitor what others are doing on your behalf.

Four of those have practical teeth for outbound in particular.

  1. A real postal address in every message. The guide allows "your current street address, a post office box you've registered with the U.S. Postal Service, or a private mailbox you've registered with a commercial mail receiving agency". A registered box is acceptable; no address is not.
  2. An opt-out that costs nothing and asks for nothing. In the FTC's words, you "can't charge a fee, require the recipient to give you any personally identifying information beyond an email address, or make the recipient take any step other than sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request". A login wall or a preference survey in front of an unsubscribe is not compliant.
  3. Ten business days. "You must honor a recipient's opt-out request within 10 business days." That is the deadline for the suppression process described in the sending setup guide, and it is why the process has to exist before the first send rather than after the first complaint.
  4. You cannot outsource the liability. "The law makes clear that even if you hire another company to handle your email marketing, you can't contract away your legal responsibility to comply with the law." An agency, a freelancer or a platform sending on your behalf does not move the obligation off you.

On penalties, the FTC's page states that "Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088". The per-email framing is the part worth sitting with, because outbound programmes are measured in thousands of messages.

The United Kingdom: it depends who is receiving it

Two laws apply at once and they ask different questions. PECR asks whether you may send the message. The UK GDPR asks whether you may hold the data you used to send it. It is possible to satisfy one and breach the other.

PECR's rules on marketing email are in regulation 22, and the ICO's guide summarises the position as: "You must not send marketing emails or texts to individuals without specific consent. There is a limited exception for your own previous customers, often called the 'soft opt-in'." And separately: "You can send marketing emails or texts to companies."

The line between the two is not between businesses and consumers. It is between corporate subscribers and individual subscribers, and the ICO defines both.

Who is which, from the ICO's business-to-business marketing guidance, read 24 September 2026.
Type of recipientClassed asMay you send unsolicited marketing email?
A limited companyCorporate subscriberYes — PECR's electronic mail rule does not apply
A limited liability partnershipCorporate subscriberYes
A Scottish partnershipCorporate subscriberYes
Some government bodiesCorporate subscriberYes
A sole traderIndividual subscriberNo — consent or the soft opt-in is required
A non-limited partnershipIndividual subscriberNo — consent or the soft opt-in is required
Any other unincorporated bodyIndividual subscriberNo — consent or the soft opt-in is required

The ICO's wording on the corporate side is direct: "The PECR rule on direct marketing by electronic mail does not apply to corporate subscribers… You do not need their consent under PECR to send such messages. However you must: not disguise or conceal your identity; and give a valid address for business to opt-out or unsubscribe".

And on the awkward middle, where you cannot tell which you are looking at, the guidance gives a rule that also happens to be the safe default for any list bought or built from public sources: "If you are unsure whether the contact details belong to an individual subscriber or a corporate subscriber this puts you at risk of breaching PECR. To mitigate that risk you should treat the details as belonging to an individual subscriber".

The soft opt-in does not rescue a cold list. The ICO is explicit that it "does not apply to prospective customers or new contacts (eg from bought-in lists)".

The UK GDPR question, which is about the data rather than the message

Send to [email protected] and, in the ICO's own example, you are probably not processing personal data at all: "If you do not know the name of the person you are sending direct marketing to at a business, then you are not processing personal data and the UK GDPR does not apply to your marketing."

Send to a named person at that company and you are. The ICO says an address of the form initials and surname at a company domain identifies an individual, and that the UK GDPR applies "even if they are acting in their business capacity". Every personalised outbound campaign is therefore processing personal data, and needs a lawful basis — in practice, legitimate interests.

Two consequences follow, and both are the kind of thing that gets discovered late.

  • A transparency deadline. Where the data came from somewhere other than the person themselves — a database, an enrichment provider, a finder — the ICO says privacy information must be provided "within a reasonable period of obtaining the data and no later than one month from the date of collection". That clock starts when you obtain the record, not when you write to them. What that means for enrichment tools is a page of its own.
  • An objection you cannot refuse. On the right to object to direct marketing, the ICO's guidance is blunt: "This right is absolute and there are no grounds for you to refuse."

The ICO also addresses the assumption that underpins a great deal of outbound: "you cannot assume that simply because an individual's personal data is in the public domain they are agreeing to it being used for direct marketing purposes." A published address is not a consent, and PECR still applies to details taken from public sources.

One caveat with a date on it

The ICO's PECR guidance currently carries its own notice: "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change." That notice was on the page when it was read on 24 September 2026. Anything on this page sourced from the ICO should be re-checked against the live guidance before it is relied on.

What this means in practice

  1. Segment the list by jurisdiction and by legal form before segmenting it by anything commercial. A US company, a UK limited company and a UK sole trader are three different cases.
  2. Put a real postal address and a working one-click opt-out in every message, everywhere. It is required in the US and it is required by PECR's identity rule in the UK, and it costs nothing.
  3. Keep a suppression list and screen new lists against it. The ICO calls this good practice for corporate subscribers; US law makes it a ten-business-day obligation.
  4. Write to a person under your own name, from a domain that plainly belongs to you. Both regulators forbid disguising the sender, which is also why this site describes no technique for doing so.
  5. Know where every record came from, and when. The one-month transparency clock cannot be met by a list whose origin nobody recorded.

None of this is a reason not to do outbound. It is the reason the sequence has to start with the list rather than with the tool — and once it does, the platform comparison is a straightforward question of which meter fits.

Questions about the rules

Is cold email legal in the United States?

Yes, subject to CAN-SPAM. The FTC's compliance guide states that "The law makes no exception for business-to-business email", so a sales email carries the same obligations as any other commercial message: honest headers and subject lines, identification as an ad, a valid postal address, a free and simple opt-out, and that opt-out honoured within 10 business days.

Can I cold email a UK company without consent?

Under PECR, yes if the recipient is a corporate subscriber — a limited company, an LLP, a Scottish partnership or some government bodies. The ICO says the electronic mail rule "does not apply to corporate subscribers". You must still not conceal your identity and must give a valid opt-out address, and if you know the recipient's name the UK GDPR applies to the data separately.

Can I cold email a sole trader in the UK?

Not without consent or the soft opt-in. The ICO classes sole traders and non-limited partnerships as individual subscribers, treated the same as private individuals. Where you cannot tell which you are dealing with, the ICO's own advice is to treat the record as an individual subscriber.

How long do I have to honour an unsubscribe?

In the US, 10 business days, per the FTC's guide. Under the UK GDPR, the right to object to direct marketing is described by the ICO as absolute with no grounds to refuse, so the practical answer is immediately.

Do I have to tell people I bought their data?

In the UK, yes. Where personal data was obtained from a source other than the person, the ICO requires privacy information "within a reasonable period of obtaining the data and no later than one month from the date of collection". That deadline runs from when you got the record, not from when you write.

Does an email finder tool make my list compliant?

No tool can. A finder returns an address; a regulator decides whether you may write to it. Some vendors advertise compliance certifications, and those describe the vendor's own software and hosting rather than your list.