Outbound Atlas

Atlas/The law/The regimes

Cold email law: the jurisdiction matrix

Twenty jurisdictions in one table: who allows cold B2B email on an opt-out basis, who demands consent, who regulates it and what it can cost.

Lawmedium confidence9 minupdated 2026-10-0516 sources
Jurisdiction
Global (20 jurisdictions)
Regime
Mixed
Cold B2B email
Legal on opt-out in the US, Singapore, Brazil and to corporate addresses in the UK, Ireland, Sweden and France; needs consent or narrow implied consent almost everywhere else
Penalty
From $53,088 per email (US) to C$10M per violation (Canada) and 4% of global turnover (GDPR)
Enforced by
FTC, CRTC, ACMA, ICO, EU data protection and consumer authorities, courts

Cold B2B email is not one legal question. Three regimes cover the 20 markets a sequencer sells into. The opt-out world (US, Singapore, Brazil, and corporate addresses in the UK, Ireland, Sweden and France) lets you send first and stop when asked. The inferred-consent world (Canada, Australia, New Zealand, Japan) lets you email an address that was published for business if the pitch fits the recipient's role. The prior-consent world (Germany, Austria, Switzerland, Denmark, Spain, Italy, Poland, the Netherlands) treats a cold pitch to a named business contact as unlawful without consent. Some of these countries tolerate it in practice. Their courts and regulators do not.

The law follows the recipient. A US agency using Instantly to email a Munich CFO is under German law (UWG) and, because it is targeting people in the EU, under GDPR (Art. 3(2)). Every incumbent pushes this problem onto the user. Instantly's terms make the subscriber "the sole 'sender' and 'initiator'" of every message, including AI-written ones (ToS updated 22 September 2026).

So what

For a product, what matters is that the regimes are predictable by recipient country, and a sequencer could enforce them. No incumbent we checked gates sending by recipient jurisdiction or records where an address came from. In Canada, Australia and Japan, that record decides whether a send was legal at all.

The matrix

Penalties are statutory maxima, not typical outcomes. The Europe rows are summaries; EU/EEA country matrix and the country pages are canonical and override this table where they differ.

JurisdictionRegimeCold B2B emailRegulatorMax penalty
United StatesOpt-outLegal if CAN-SPAM compliant; state laws punish deceptive subject linesFTC, state AGs, private suits (CA, WA)$53,088 per email; no 2026 increase
CanadaOpt-in (express or implied)Only with implied consent (conspicuous publication + role relevance) or an existing relationshipCRTCC$10M per violation (business)
United KingdomSoft opt-in; B2B opt-outCorporate subscribers: allowed with identification + opt-out. Sole traders/partnerships: consentICOUK GDPR-level fines under DUAA 2025 (see UK: PECR and DUAA 2025)
GermanyOpt-inEffectively prohibited without express prior consent, B2B included (presumed consent covers phone only)Courts (UWG, Abmahnung), DPAsCease-and-desist + GDPR up to 4%
FranceMixedB2B allowed to professional addresses if offer fits the role, with opt-out; B2C opt-inCNILGDPR up to 4%
NetherlandsOpt-inConsent required, including for legal persons in principleACM, APNational ePrivacy fines + GDPR
SpainOpt-inConsent required, B2B included (LSSI art. 21)AEPDLSSI fines + GDPR
ItalyOpt-inConsent required (Privacy Code art. 130)GaranteGDPR up to 4%
AustriaOpt-inConsent required, businesses included (TKG 2021)Telecom offices, DSBAdministrative fines + GDPR
PolandOpt-inConsent required, B2B included (Electronic Communications Law 2024)UKE, UOKiK, UODONational fines + GDPR
SwedenMixedOpt-out to legal persons; consent for individualsKonsumentverket, IMYMarket disruption fee + GDPR
DenmarkOpt-inConsent required, businesses included (Marketing Practices Act)Consumer Ombudsman, DatatilsynetFines + GDPR
IrelandMixedOpt-out to non-natural-person subscribers; consent for individualsDPCPer-message criminal fines + GDPR
SwitzerlandOpt-inConsent required, B2B included (UWG art. 3(1)(o))SECO, courts, FDPICCriminal fines + revFADP
AustraliaOpt-in (express or inferred)Allowed via inferred consent: published business address + relevance + no "no spam" noticeACMA10,000 penalty units/day for repeat corporate offenders
New ZealandOpt-in (express, inferred, deemed)Deemed consent via conspicuous publication, similar to AustraliaDIANZ$500k (organisations), unverified
SingaporeOpt-outAllowed; bulk senders need unsubscribe facility and labellingIMDA / courts; PDPC for dataCivil damages per message, unverified
IndiaNo email statute; DPDP Act phasing inUnregulated today; consent-centred DPDP fully in force 13 May 2027Data Protection Board₹250 crore, unverified
BrazilOpt-out in practiceAllowed on LGPD legitimate interest with opt-outANPD2% of Brazil revenue, capped R$50M per infraction
JapanOpt-inException for addresses publicly disclosed for businessMIC, Consumer Affairs Agency¥30M for corporations
Not verified

Rows marked unverified (New Zealand, Singapore damages, India's ₹250 crore cap) and the national-law cites in the Europe rows come from prior knowledge. This pass could not re-fetch them because primary sources blocked automated access or the search budget ran out. The Europe rows are a pointer; EU/EEA country matrix carries the sourced detail.

The three groups, and what each means for the send button

Opt-out (send, then honour the stop). The US is the anchor market and the most permissive. CAN-SPAM makes "no exception for business-to-business email" but needs no consent. You need accurate headers, a non-deceptive subject, a postal address, an opt-out and processing within 10 business days. The live US risk sits in state deception law, not federal consent rules: California allows $1,000 per email, and Washington saw nearly 200 class actions after Brown v. Old Navy. See United States: CAN-SPAM and state email laws. The UK, Ireland, Sweden and France sit here only for corporate recipients. Their consent rules return for sole traders and individuals, and GDPR still applies to the personal data in a named work address (GDPR and ePrivacy, UK: PECR and DUAA 2025, France).

Inferred consent (published + relevant). Canada, Australia, New Zealand and Japan permit cold B2B email in a narrow lane. The address must have been published, without a "no unsolicited messages" notice, and the message must fit the recipient's job. Australia's Spam Act spells this out in Schedule 2. The CRTC warns that "merely finding an address online doesn't establish consent". An email guessed by pattern-matching (first.last@) and verified by an SMTP ping was never published. Most of the market's lead data looks like that, so it fails this test. See Canada: CASL and Australia, New Zealand and APAC.

Prior consent (don't, or only with consent). Germany is the strictest major market. UWG §7 treats unsolicited email advertising as an unreasonable nuisance for businesses too, and competitors and associations enforce it through Abmahnungen faster than regulators do. Austria, Switzerland, Denmark, Spain, Italy and Poland are similar on paper. See Germany, EU/EEA country matrix, and Data sourcing law for the separate GDPR question of whether you may hold the contact data at all.

Caution

Two laws apply to every EU send: the ePrivacy rule on sending (national, varies by country) and GDPR on processing the contact data (uniform, needs a lawful basis and an Art. 14 notice). A message can pass the first and fail the second. Most "cold email is legal in the UK/France" advice covers only the first.

Where enforcement actually lands

Enforcement against cold B2B senders is rare but not zero, and it hits volume and sloppiness, not the concept:

CaseWhereWhatAmount
Verkada (B2B SaaS)US, FTC/DOJ, Aug 202430M+ emails, ignored unsubscribes, no postal address$2.95M
Compu-Finder (B2B training)Canada, CRTCScraped business addresses, no consentC$1.1M, cut to C$200k
TabcorpAustralia, ACMA, Apr 2026Email/SMS after consent withdrawnA$1.254M
Washington retailersUS state courts, 2025–26Misleading subject lines (B2C)~200 class actions; damages cut to $100/email from 11 Jun 2026

The failure mode across all four is broken opt-out plumbing or unprovable consent, not the act of cold emailing. Both can be fixed in software.

Gap in the record

We found no 2024–2026 enforcement action by the FTC, CRTC or ACMA against a cold-email SaaS platform itself, as opposed to its senders. The search budget ran out before we could confirm that none exists. See Platform liability: what the sequencer itself risks.

Notable 2026 developments

  • FTC froze penalties. The FTC announced in September 2026 that "no civil penalty adjustments will be made in 2026", so the CAN-SPAM maximum stays at the 2025 figure of $53,088 per email.
  • Washington narrowed CEMA. HB 2274, in force 11 June 2026, adds a knowledge requirement and cuts damages from $500 to $100 per email.
  • India's DPDP clock is running. Parts commenced 13 November 2025, more on 13 November 2026, and the rest on 13 May 2027.
  • ACMA keeps fining. ACMA said businesses paid over A$16M in spam penalties in 18 months to March 2025, and Tabcorp added A$1.25M in 2026.

What this means for an entrant

  • Make jurisdiction a first-class field. Classify each lead by recipient country (from domain ccTLD, company HQ and enrichment data) and apply rules per country: block, warn, or require a recorded legal basis. Incumbents leave this to the user. A German founder who sells "send to the US and UK freely, Germany only with consent proof" can sell that as risk reduction to EU buyers.
  • Record provenance at import. For Canada, Australia, New Zealand and Japan, legality depends on where the address was published and whether the pitch fits the role. A lead record that stores source URL, capture date and a role-relevance check turns a legal theory into evidence. See Contact data and enrichment.
  • Ship a compliance floor by default. Postal address, a working one-click unsubscribe honoured across all workspaces and inboxes within hours (the US and Canada allow 10 business days, Australia 5 working days), and a subject-line linter for fake "Re:" threads. Verkada, Compu-Finder and Tabcorp all failed on this floor.
  • Do not claim to make cold email "legal in the EU". You can't. The honest pitch is that you shrink the risk in opt-out markets and stop accidental sends into prior-consent markets. For the EU detail, read GDPR and ePrivacy and Germany before writing marketing copy.
  • Expect the law to tighten slowly while the providers tighten fast. Statutes moved little in 2025–26 and Washington even loosened. Google and Microsoft rules moved much faster (Provider rules: Google, Microsoft and the ESPs, Google and Yahoo sender rules). Provider policy is the bigger short-term risk; law is the long-term moat.
16 sources cited on this page · 13 domains
  1. Art. 3(2) eur-lex.europa.eu
  2. including AI-written ones instantly.ai
  3. $53,088 per email ftc.gov
  4. C$10M per violation crtc.gc.ca
  5. 10,000 penalty units/day legislation.gov.au
  6. 13 May 2027 en.wikipedia.org
  7. 2% of Brazil revenue, capped R$50M per infraction en.wikipedia.org
  8. ¥30M for corporations laws.e-gov.go.jp
  9. $1,000 per email law.justia.com
  10. nearly 200 class actions morganlewis.com
  11. $2.95M ftc.gov
  12. C$1.1M, cut to C$200k slaw.ca
  13. A$1.254M acma.gov.au
  14. announced in September 2026 public-inspection.federalregister.gov
  15. HB 2274 lawfilesext.leg.wa.gov
  16. over A$16M in spam penalties in 18 months acma.gov.au