Outbound Atlas

Atlas/The law/The platform's own exposure

Platform liability: what the sequencer itself risks

A cold-email platform is shielded as a conduit and GDPR processor until it writes the copy, sells the data, supplies the inboxes or ignores abuse; past that line it becomes a sender, a controller or an aider.

Lawmedium confidence9 minupdated 2026-10-0511 sources
Jurisdiction
US, Canada, EU
Regime
n/a
Cold B2B email
Platform liability turns on the platform's role, not on the recipient's regime
Penalty
CAN-SPAM $53,088/email if the platform 'initiates'; CASL s.9 up to C$10M; GDPR up to 4% as controller; DSA up to 6% of turnover
Enforced by
FTC, CRTC, EU data protection authorities, DSA Digital Services Coordinators

A sequencer's legal safety rests on one claim: the user sends, the platform only carries. In the US that is the CAN-SPAM "routine conveyance" carve-out. In the EU it is GDPR's processor role. In Canada it is staying outside CASL's "aiding" provision. Every incumbent writes this into its terms. Instantly's terms (updated 22 September 2026) make subscribers "the sole 'sender' and 'initiator'" of all messages, "whether created by humans or AI". lemlist's T&Cs state that "lemlist processes personal data on your behalf as a processor".

The claim holds less well as platforms do more. The current product race to AI-written copy, bundled lead databases, done-for-you inboxes and shared warmup networks (The AI shift, AI SDR layer) moves the platform from conduit towards co-sender, from processor towards controller, and from tool towards aider. This page maps where each line sits.

So what

Each feature that makes a sequencer more valuable (it picks the leads, writes the email, owns the inboxes, learns from every customer's data) also weakens the legal shield. An entrant should decide which features it will build as a controller or sender and design for that role, rather than keep the "we're just a tool" claim and hope.

United States: initiator or conveyor

Under 15 U.S.C. §7702, liability attaches to whoever initiates a message ("to originate or transmit such message or to procure the origination or transmission"). Procure means "intentionally to pay or provide other consideration to, or induce, another person to initiate such a message on one's behalf". Routine conveyance, meaning "transmission, routing, relaying, handling, or storing, through an automatic technical process", is excluded from initiating. The FTC adds that "both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible".

Platform activityLikely CAN-SPAM roleWhy
Relays user-written emails from user-connected inboxesConveyorAutomatic technical process
Suggests copy the user edits and approvesProbably conveyorUser still originates
Autonomous AI SDR picks recipients, writes and sendsArguably initiator / co-originatorPlatform originates the content and the decision to send
Done-for-you service: platform runs campaigns for a feeInitiatorPlatform "transmits" on the advertiser's behalf for consideration
Platform registers domains and mailboxes under invented identitiesCriminal exposure under 18 U.S.C. §1037Five or more accounts or two or more domains with falsified registrant identity

Only the FTC, other federal agencies, state attorneys general and internet access providers can sue under CAN-SPAM, so platform risk is regulatory, not class-action. California is the exception that matters. Its §17529.5 lets recipients and email service providers sue for $1,000 per email over misleading subject lines or headers. A platform that generates the subject line has a harder time disclaiming it. See United States: CAN-SPAM and state email laws.

Not verified

The table is our reading of the statutory definitions. We found no reported case applying CAN-SPAM initiator liability to a modern cold-email SaaS or an AI SDR vendor, and Instantly's clause assigning AI-written output to the user is untested.

Canada: section 9 "aiding"

CASL s.9 prohibits aiding, inducing or procuring a violation, and the CRTC has used it against intermediaries. In July 2018 it fined Datablocks C$100,000 and Sunlight Media C$150,000 for enabling malvertising. It singled out the missing written contracts requiring CASL compliance, monitoring of client use, and compliance policies. This is the clearest regulator-written checklist for a sending platform anywhere: terms, monitoring, policy. See Canada: CASL.

EU: processor by default, controller by drift

Under GDPR the user is the controller and the sequencer is its processor under an Art. 28 data processing agreement. Instantly's terms describe exactly this: Instantly as "Processor", subscribers responsible as "Controller" for lawfulness and for obtaining consent or another lawful basis (terms). lemlist's DPA is incorporated by reference under French law, with Paris courts (T&Cs, updated 17 September 2025).

A processor becomes a controller for any processing whose purposes it decides itself (GDPR Art. 28(10)). Four common sequencer features cross that line:

FeatureWhy it makes the platform a controllerLink
Bundled B2B contact databasePlatform collects and sells personal data for its own purposeBuilt-in lead database, Data sourcing law
Shared warmup networkPlatform moves other customers' mailbox content and engagement for its own reputation systemBuilt-in warmup
Cross-customer suppression or "global blocklist"Platform reuses customer data across tenantsBounce protection
Training AI models on customer emails and repliesNew purpose decided by the platformAI personalisation

Both Instantly and lemlist market built-in B2B lead databases (detail on Built-in lead database; not re-verified in this pass) while their terms present them as processors. Instantly's terms treat customer "Data Resale Activity" as a non-curable breach, which shows how much the company cares about its own data supply. lemlist's Sending Policy says bought or scraped lists "could negatively impact deliverability" and must "follow the local privacy regulations". That is guidance, not a ban.

Caution

A non-EU vendor offering services to EU users also needs an Art. 27 EU representative, plus a DSA legal representative (below). Instantly contracts as Foo Monk, LLC of Sheridan, Wyoming, under US arbitration (terms). We did not check whether it names EU or UK representatives. For an EU-incorporated entrant, being in the jurisdiction is a selling point to EU buyers' procurement teams, not a burden.

EU: the Digital Services Act

The DSA applies to "intermediary services". It excludes interpersonal communication services "such as emails or private messaging services" from the definition of online platforms (Recital 14), and Recital 28 confirms that web-based email services can benefit from the liability exemptions. A sequencer therefore does not carry platform-tier DSA duties. It probably does qualify as a hosting service for the templates, lead lists and content it stores at users' request. That brings baseline duties: a point of contact, a legal representative if established outside the EU, terms that describe content moderation, a notice-and-action mechanism (Art. 16), and statements of reasons when restricting users. Penalties are set by member states up to 6% of worldwide turnover (Art. 52).

Not verified

How the DSA classifies a cold-email SaaS is our analysis, not settled guidance. We found no Digital Services Coordinator statement on email sequencers. The ePrivacy/EECC question of whether a sequencer is itself an "electronic communications service" is also open.

How incumbents handle it

InstantlylemlistSmartlead
Who is the "sender"Subscriber is "sole sender and initiator", including AI outputUser; must follow Sending PolicyNot verified
GDPR roleProcessor (DPA)Processor (DPA, French law)Not verified
Purchased listsRestricted via Sending Policy; data resale banned"Has to follow the local privacy regulations"Not verified
Enforcement leverSuspension for "suspected abuse or misuse"; indemnities incl. TCPA/TSR for AI featuresRate limits, suspension, termination on bounce/complaint/spamtrap thresholdsNot verified
Governing lawUS, AAA arbitration, class waiverFrance, Paris courtsNot verified

Sources: Instantly terms, lemlist T&Cs, lemlist Sending Policy.

Gap in the record

Smartlead's terms of service and DPA were not reachable at the URLs we tried (three variants returned 404). Instantly's separate Sending Policy was also not found at the URLs we tried. Neither platform's abuse-desk process (complaint intake, KYC at signup, response times) is publicly documented anywhere we found.

Abuse desks and KYC: who actually polices

In practice the policing for cold email is done by Google and Microsoft, not by the sequencers. Most volume runs through user-owned Workspace and Microsoft 365 mailboxes, so complaints and bounces land on those accounts and get them throttled or suspended (Provider rules: Google, Microsoft and the ESPs, Microsoft rules: Outlook.com and Microsoft 365 limits). The sequencer's own shared assets are its tracking domains, warmup pool and any sending IPs it operates (Custom tracking domains, Warmup networks). Those are where it carries ESP-style abuse risk: blocklisting, complaints and provider pressure.

Transactional ESPs show what full abuse obligations look like. Twilio SendGrid requires customers to keep "proof of all affirmative consents" and produce it on request. AWS SES reviews accounts at 5% bounces or 0.1% complaints. A sequencer that runs its own SMTP infrastructure (Sending architecture) inherits that job and needs an abuse@ mailbox, feedback-loop processing, signup KYC and a suspension process.

What this means for an entrant

  • Pick your role per feature, deliberately. Ship the core sequencer as a processor with a clean DPA. If you add a lead database, warmup network or model training, document them as controller activities: legitimate-interest assessments, Art. 14 notices, opt-out handling. Don't hide them inside a processor DPA. EU buyers' legal teams increasingly check.
  • Build the CRTC checklist as product. Terms that require compliance, monitoring that detects abuse (complaint spikes, spamtrap hits, list-source anomalies), and a published policy. That covers CASL s.9, DSA notice-and-action and the provider expectations in one system, and it is a sales asset for regulated buyers.
  • Be careful with autonomous AI sending. An AI SDR that picks recipients and writes and sends without human approval is the clearest route from conveyor to initiator. Keep a human approval step as an option, log who approved what, and make sure the "user is the sender" clause is backed by product behaviour.
  • Avoid done-for-you inbox farms with fake identities. Registering mailboxes and domains in invented names engages 18 U.S.C. §1037. Register in the customer's real legal identity, even if competitors do otherwise. See Infrastructure strategy: build or partner.
  • Use EU establishment as a selling point. A German or EU entity with an EU DPA, EU hosting and named DSA contact points is something US incumbents can match only with effort. For mid-market EU buyers (Enterprise RevOps buyers, Non-English markets) that is a real purchase criterion.
11 sources cited on this page · 9 domains
  1. terms (updated 22 September 2026) instantly.ai
  2. T&Cs lemlist.com
  3. 15 U.S.C. §7702 law.cornell.edu
  4. both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible ftc.gov
  5. 18 U.S.C. §1037 law.cornell.edu
  6. $1,000 per email law.justia.com
  7. written contracts requiring CASL compliance, monitoring of client use, and compliance policies blg.com
  8. Sending Policy lemlist.com
  9. such as emails or private messaging services eur-lex.europa.eu
  10. proof of all affirmative consents twilio.com
  11. 0.1% complaints docs.aws.amazon.com