A sequencer's legal safety rests on one claim: the user sends, the platform only carries. In the US that is the CAN-SPAM "routine conveyance" carve-out. In the EU it is GDPR's processor role. In Canada it is staying outside CASL's "aiding" provision. Every incumbent writes this into its terms. Instantly's terms (updated 22 September 2026) make subscribers "the sole 'sender' and 'initiator'" of all messages, "whether created by humans or AI". lemlist's T&Cs state that "lemlist processes personal data on your behalf as a processor".
The claim holds less well as platforms do more. The current product race to AI-written copy, bundled lead databases, done-for-you inboxes and shared warmup networks (The AI shift, AI SDR layer) moves the platform from conduit towards co-sender, from processor towards controller, and from tool towards aider. This page maps where each line sits.
Each feature that makes a sequencer more valuable (it picks the leads, writes the email, owns the inboxes, learns from every customer's data) also weakens the legal shield. An entrant should decide which features it will build as a controller or sender and design for that role, rather than keep the "we're just a tool" claim and hope.
United States: initiator or conveyor
Under 15 U.S.C. §7702, liability attaches to whoever initiates a message ("to originate or transmit such message or to procure the origination or transmission"). Procure means "intentionally to pay or provide other consideration to, or induce, another person to initiate such a message on one's behalf". Routine conveyance, meaning "transmission, routing, relaying, handling, or storing, through an automatic technical process", is excluded from initiating. The FTC adds that "both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible".
| Platform activity | Likely CAN-SPAM role | Why |
|---|---|---|
| Relays user-written emails from user-connected inboxes | Conveyor | Automatic technical process |
| Suggests copy the user edits and approves | Probably conveyor | User still originates |
| Autonomous AI SDR picks recipients, writes and sends | Arguably initiator / co-originator | Platform originates the content and the decision to send |
| Done-for-you service: platform runs campaigns for a fee | Initiator | Platform "transmits" on the advertiser's behalf for consideration |
| Platform registers domains and mailboxes under invented identities | Criminal exposure under 18 U.S.C. §1037 | Five or more accounts or two or more domains with falsified registrant identity |
Only the FTC, other federal agencies, state attorneys general and internet access providers can sue under CAN-SPAM, so platform risk is regulatory, not class-action. California is the exception that matters. Its §17529.5 lets recipients and email service providers sue for $1,000 per email over misleading subject lines or headers. A platform that generates the subject line has a harder time disclaiming it. See United States: CAN-SPAM and state email laws.
The table is our reading of the statutory definitions. We found no reported case applying CAN-SPAM initiator liability to a modern cold-email SaaS or an AI SDR vendor, and Instantly's clause assigning AI-written output to the user is untested.
Canada: section 9 "aiding"
CASL s.9 prohibits aiding, inducing or procuring a violation, and the CRTC has used it against intermediaries. In July 2018 it fined Datablocks C$100,000 and Sunlight Media C$150,000 for enabling malvertising. It singled out the missing written contracts requiring CASL compliance, monitoring of client use, and compliance policies. This is the clearest regulator-written checklist for a sending platform anywhere: terms, monitoring, policy. See Canada: CASL.
EU: processor by default, controller by drift
Under GDPR the user is the controller and the sequencer is its processor under an Art. 28 data processing agreement. Instantly's terms describe exactly this: Instantly as "Processor", subscribers responsible as "Controller" for lawfulness and for obtaining consent or another lawful basis (terms). lemlist's DPA is incorporated by reference under French law, with Paris courts (T&Cs, updated 17 September 2025).
A processor becomes a controller for any processing whose purposes it decides itself (GDPR Art. 28(10)). Four common sequencer features cross that line:
| Feature | Why it makes the platform a controller | Link |
|---|---|---|
| Bundled B2B contact database | Platform collects and sells personal data for its own purpose | Built-in lead database, Data sourcing law |
| Shared warmup network | Platform moves other customers' mailbox content and engagement for its own reputation system | Built-in warmup |
| Cross-customer suppression or "global blocklist" | Platform reuses customer data across tenants | Bounce protection |
| Training AI models on customer emails and replies | New purpose decided by the platform | AI personalisation |
Both Instantly and lemlist market built-in B2B lead databases (detail on Built-in lead database; not re-verified in this pass) while their terms present them as processors. Instantly's terms treat customer "Data Resale Activity" as a non-curable breach, which shows how much the company cares about its own data supply. lemlist's Sending Policy says bought or scraped lists "could negatively impact deliverability" and must "follow the local privacy regulations". That is guidance, not a ban.
A non-EU vendor offering services to EU users also needs an Art. 27 EU representative, plus a DSA legal representative (below). Instantly contracts as Foo Monk, LLC of Sheridan, Wyoming, under US arbitration (terms). We did not check whether it names EU or UK representatives. For an EU-incorporated entrant, being in the jurisdiction is a selling point to EU buyers' procurement teams, not a burden.
EU: the Digital Services Act
The DSA applies to "intermediary services". It excludes interpersonal communication services "such as emails or private messaging services" from the definition of online platforms (Recital 14), and Recital 28 confirms that web-based email services can benefit from the liability exemptions. A sequencer therefore does not carry platform-tier DSA duties. It probably does qualify as a hosting service for the templates, lead lists and content it stores at users' request. That brings baseline duties: a point of contact, a legal representative if established outside the EU, terms that describe content moderation, a notice-and-action mechanism (Art. 16), and statements of reasons when restricting users. Penalties are set by member states up to 6% of worldwide turnover (Art. 52).
How the DSA classifies a cold-email SaaS is our analysis, not settled guidance. We found no Digital Services Coordinator statement on email sequencers. The ePrivacy/EECC question of whether a sequencer is itself an "electronic communications service" is also open.
How incumbents handle it
| Instantly | lemlist | Smartlead | |
|---|---|---|---|
| Who is the "sender" | Subscriber is "sole sender and initiator", including AI output | User; must follow Sending Policy | Not verified |
| GDPR role | Processor (DPA) | Processor (DPA, French law) | Not verified |
| Purchased lists | Restricted via Sending Policy; data resale banned | "Has to follow the local privacy regulations" | Not verified |
| Enforcement lever | Suspension for "suspected abuse or misuse"; indemnities incl. TCPA/TSR for AI features | Rate limits, suspension, termination on bounce/complaint/spamtrap thresholds | Not verified |
| Governing law | US, AAA arbitration, class waiver | France, Paris courts | Not verified |
Sources: Instantly terms, lemlist T&Cs, lemlist Sending Policy.
Smartlead's terms of service and DPA were not reachable at the URLs we tried (three variants returned 404). Instantly's separate Sending Policy was also not found at the URLs we tried. Neither platform's abuse-desk process (complaint intake, KYC at signup, response times) is publicly documented anywhere we found.
Abuse desks and KYC: who actually polices
In practice the policing for cold email is done by Google and Microsoft, not by the sequencers. Most volume runs through user-owned Workspace and Microsoft 365 mailboxes, so complaints and bounces land on those accounts and get them throttled or suspended (Provider rules: Google, Microsoft and the ESPs, Microsoft rules: Outlook.com and Microsoft 365 limits). The sequencer's own shared assets are its tracking domains, warmup pool and any sending IPs it operates (Custom tracking domains, Warmup networks). Those are where it carries ESP-style abuse risk: blocklisting, complaints and provider pressure.
Transactional ESPs show what full abuse obligations look like. Twilio SendGrid requires customers to keep "proof of all affirmative consents" and produce it on request. AWS SES reviews accounts at 5% bounces or 0.1% complaints. A sequencer that runs its own SMTP infrastructure (Sending architecture) inherits that job and needs an abuse@ mailbox, feedback-loop processing, signup KYC and a suspension process.
What this means for an entrant
- Pick your role per feature, deliberately. Ship the core sequencer as a processor with a clean DPA. If you add a lead database, warmup network or model training, document them as controller activities: legitimate-interest assessments, Art. 14 notices, opt-out handling. Don't hide them inside a processor DPA. EU buyers' legal teams increasingly check.
- Build the CRTC checklist as product. Terms that require compliance, monitoring that detects abuse (complaint spikes, spamtrap hits, list-source anomalies), and a published policy. That covers CASL s.9, DSA notice-and-action and the provider expectations in one system, and it is a sales asset for regulated buyers.
- Be careful with autonomous AI sending. An AI SDR that picks recipients and writes and sends without human approval is the clearest route from conveyor to initiator. Keep a human approval step as an option, log who approved what, and make sure the "user is the sender" clause is backed by product behaviour.
- Avoid done-for-you inbox farms with fake identities. Registering mailboxes and domains in invented names engages 18 U.S.C. §1037. Register in the customer's real legal identity, even if competitors do otherwise. See Infrastructure strategy: build or partner.
- Use EU establishment as a selling point. A German or EU entity with an EU DPA, EU hosting and named DSA contact points is something US incumbents can match only with effort. For mid-market EU buyers (Enterprise RevOps buyers, Non-English markets) that is a real purchase criterion.