Outbound Atlas

06 What is allowed, where · 12 pages · 17k words

The law

Cold B2B email is opt-out in the US, broadly tolerated in the UK and France, and effectively consent-only in Germany. The recipient's country decides. This section maps the regimes, goes deep on Europe, and covers what a platform itself is liable for.

PageJurisdictionRegimeCold B2B emailPenalty
Cold email law: the jurisdiction matrixGlobal (20 jurisdictions)MixedLegal on opt-out in the US, Singapore, Brazil and to corporate addresses in the UK, Ireland, Sweden and France; needs consent or narrow implied consent almost everywhere elseFrom $53,088 per email (US) to C$10M per violation (Canada) and 4% of global turnover (GDPR)
GDPR and ePrivacyEuropean Union / EEAMixedMember-state choice: opt-in in roughly half the bloc, opt-out to legal persons in the rest; GDPR applies to every named contactGDPR fines up to €20m or 4% of global turnover; national ePrivacy penalties and civil claims vary
Platform liability: what the sequencer itself risksUS, Canada, EUn/aPlatform liability turns on the platform's role, not on the recipient's regimeCAN-SPAM $53,088/email if the platform 'initiates'; CASL s.9 up to C$10M; GDPR up to 4% as controller; DSA up to 6% of turnover
GermanyGermanyOpt-in (prior express consent)Prohibited without prior express consent; a single email to a business address is actionableCease-and-desist (Abmahnung, ~€400–500 fees) + injunction at €3,000–3,500 dispute value per first email; contractual penalties; GDPR fines possible
Provider rules: Google, Microsoft and the ESPsContractual (global)n/aProhibited as 'unsolicited mass email' by every provider's policy; tolerated by Google and Microsoft below their metric thresholdsThrottling, sending blocks, account or tenant suspension; no refund for AUP breaches
United States: CAN-SPAM and state email lawsUnited StatesOpt-outLegal without consent if CAN-SPAM's header, subject, identification, address and opt-out rules are metUp to $53,088 per email (FTC; 2025 level, not raised for 2026) + $1,000 per email under California law
Canada: CASLCanadaOpt-in (express or implied)Allowed only with implied consent: published business address, no refusal notice, message relevant to the recipient's role (or an existing relationship)Up to C$10M per violation for businesses, C$1M for individuals
UK: PECR and DUAA 2025United KingdomMixedAllowed without consent to corporate subscribers (opt-out); sole traders and some partnerships need consent or soft opt-inPECR fines up to £17.5m or 4% of worldwide turnover after the Data (Use and Access) Act 2025; UK GDPR fines on top
Australia, New Zealand and APACAustralia, New Zealand, Singapore, India, Brazil, JapanMixedAU/NZ: allowed via inferred consent for published, role-relevant addresses; SG/BR: opt-out; JP: opt-in with business-publication exception; IN: unregulated until DPDPAustralia: up to 10,000 penalty units per day for repeat corporate offenders; Japan ¥30M; Brazil 2% of local revenue (R$50M cap)
FranceFranceMixedAllowed without prior consent if the message relates to the recipient's profession, with information and an easy opt-outCNIL fines under GDPR (up to 4% of turnover) and the CPCE; recent prospection fines €80k–€900k plus injunctions with €10k/day penalties
EU/EEA country matrixEU-27 + Norway, Iceland, Liechtenstein + SwitzerlandMixedConsent needed in ~13 countries (incl. DE, AT, IT, ES, PL); opt-out to companies in ~11 (incl. FR, IE, SE, NL-narrow); ~5 unclearGDPR ceiling (€20m / 4%) everywhere; national ePrivacy penalties and civil claims vary
Data sourcing lawEU/EEA (GDPR), with US contract-law casesn/aUsable under legitimate interest only with Art. 14 notices, per-record source logging, limited retention and respect for visibility settingsGDPR fines up to 4% of turnover; injunctions with daily penalties (KASPR deleted its ~160M-contact database); platform lawsuits (LinkedIn v Proxycurl)

Not legal advice. The 31-country table is on the EU country matrix; the 20-jurisdiction overview on the law overview.

01

The regimes

The jurisdiction matrix, then the US, Canada and Asia-Pacific.

02

Europe

GDPR and ePrivacy, Germany, the UK, France, every EU country, and data sourcing.

03

The platform's own exposure

Liability for what customers send, and the provider terms you cannot ignore.