Evaluating a B2B outbound agency on compliance: GDPR, CAN-SPAM and the Spam Act compared
In short
A B2B outbound agency selling into Europe, the United States and Australia is operating under three different legal regimes for the same activity. This page, third in a five-part vendor-evaluation series, compares GDPR, CAN-SPAM and Australia's Spam Act 2003 side by side, states what eight named agencies' head office locations are as of 2026-09-08, and sets out the specific document to ask each vendor for under each regime.
On this page
Three regimes, one outbound campaign
A B2B outbound agency selling into Europe, the United States and Australia at the same time is operating under three separate legal regimes for the same activity, cold commercial email and, in some jurisdictions, cold calling. None of the three regimes is interchangeable with the others, and a vendor that treats compliance as one generic policy applied everywhere is very likely getting at least one of the three wrong.
This is the third page in a five-part series evaluating B2B outbound agencies on a single criterion each. Pricing transparency and data quality came first; results proof and SME fit follow. As with the rest of the series, this page states facts a buyer can check rather than ranking any vendor.
The site already publishes a detailed explainer on Australia's Spam Act 2003 and on German cold-email legality specifically; this page sits above both, as a side-by-side comparison and a vendor-vetting criterion, and links out to each for the fuller detail on that single jurisdiction.
The regimes described below are summarised for the purpose of vendor evaluation, not as legal advice for a company's own outreach; a company with a specific compliance question about its own campaigns should confirm the current requirement with its own legal counsel or the relevant regulator, since laws in this area are amended periodically.
GDPR in one paragraph
GDPR governs the processing of personal data for any company selling into the European Economic Area, regardless of where the vendor sending the email is based. For B2B cold outreach specifically, the commonly relied-on legal basis is legitimate interest rather than prior consent, but that basis carries its own conditions: the contact must be able to object easily, the outreach must be relevant to their professional role, and the sender must be able to show it weighed the contact's rights before relying on that basis. A vendor's GDPR process should be checkable in the form of a data processing agreement and a stated legal-basis record, not just a claim of compliance on a marketing page.
The distinction between B2B and B2C outreach matters under GDPR specifically because legitimate interest is more commonly accepted for a business contact acting in a professional capacity than for a private individual, but the assessment still has to be documented per campaign, not assumed once and reused indefinitely. A vendor unable to produce that documentation on request has a compliance claim, not a compliance process.
CAN-SPAM in one paragraph
The US CAN-SPAM Act takes a different approach: commercial email is broadly permitted without prior consent, but the law imposes strict requirements on the message itself, no false or misleading header information, a clear identification that the message is an advertisement where applicable, a valid physical postal address, and a working opt-out mechanism that must be honoured promptly. A vendor operating under CAN-SPAM should be able to show its standard opt-out handling process on request, since that is the part of the law most directly tested by a recipient complaint.
CAN-SPAM's lighter consent requirement is sometimes read by vendors as no compliance obligation at all for US outreach, which is not accurate; the header, identification and opt-out requirements are enforceable, and a vendor's actual practice around suppression lists, keeping an opt-out list current across every subsequent campaign, is the part worth asking about directly, since it is the part most likely to lapse quietly over time.
Suppression-list handling also intersects with data quality, covered on the previous page in this series: a vendor reusing a stale contact list is more likely to email someone who already opted out, which is as much a data-hygiene failure as a legal one.
Australia's Spam Act in one paragraph
Australia's Spam Act 2003 sits closer to GDPR's consent-oriented model than to CAN-SPAM's, requiring consent for commercial electronic messages, with a business-to-business exemption that applies narrowly and depends on the specifics of the relationship and the content of the message, covered in full on the site's dedicated Spam Act explainer. It is also the only one of the three regimes among these that draws a sharp distinction between email, which the consent requirement applies to, and cold calling, which sits under separate telemarketing rules, meaning a vendor's compliance answer needs to specify which channel it is describing.
Because the B2B exemption depends on the specifics of the message and the relationship rather than applying automatically to any commercial contact, a vendor selling outbound services into Australia should be able to explain, specifically, which of its messages it relies on the exemption for and which it treats as requiring consent, rather than asserting blanket B2B coverage.
Cold calling in Australia sits under a separate regime, the Do Not Call Register Act, not the Spam Act, and a vendor's answer about email compliance says nothing about whether its calling process is compliant; the two channels need separate answers.
Comparing the three side by side
The table below compares the three regimes at the level a buyer needs to evaluate a vendor, not as a substitute for legal advice specific to a company's own outreach.
| Regime | Applies to | Default basis for B2B cold outreach | What to ask a vendor |
|---|---|---|---|
| GDPR (EU/EEA) | Any company processing EU/EEA contact data | Legitimate interest, with an easy objection route | Ask for the data processing agreement and the legitimate-interest assessment |
| CAN-SPAM (US) | Commercial email sent to US recipients | Opt-out, no prior consent required | Ask for the standard opt-out handling process and its turnaround time |
| Spam Act 2003 (Australia) | Commercial electronic messages sent to Australian recipients | Consent-based, narrow B2B exemption | Ask which channel, email or calling, the process covers and how consent basis is recorded |
None of the eight named vendors in this series publish a jurisdiction-by-jurisdiction compliance breakdown on their marketing sites as of 2026-09-08; compliance claims across the group are general statements rather than the kind of regime-specific detail in the table above, which is why the direct questions in the right-hand column matter more than the marketing copy.
What HQ location tells you, and what it does not
Head office location is a starting clue, not a full answer. Belkins positions itself as a US agency, SalesAR is headquartered in Yerevan, Armenia, Martal Group is commonly cited as Canada-headquartered, CIENCE Technologies is based in Denver with additional offices including Germany and Ukraine, Cleverly is Los Angeles-based, Pearl Lemon Leads is London-based, SalesNash is headquartered in Ottawa with US and UK offices, and Ripe Leads is headquartered in Vilnius, Lithuania. A vendor's own jurisdiction affects which regulator can act against it directly, but every one of these vendors sends outreach into other jurisdictions too, and it is the recipient's location, not the sender's, that determines which regime actually governs a given message.
A vendor with a single-country office can still run fully compliant multi-jurisdiction campaigns, and a vendor with offices in several countries is not automatically compliant everywhere it operates. HQ location is useful only as the first thing to ask about, not the last.
This series draws no conclusion about any vendor's actual compliance from HQ location alone. The table and this section report the regimes each office sits under and where those offices are, both public facts. What a vendor does inside its own process is something a buyer establishes on the call, by asking it to walk one opt-out through end to end.
Where Ripe Leads sits, and how to test any vendor's answer
Ripe Leads is headquartered in Vilnius, Lithuania, inside the EU, and its published Australian activity is new: its campaigns into that market started in September 2026, with the Spam Act's business-to-business exemption the specific regime that applies there, detailed in full on the site's own Spam Act explainer. That fact is stated here on the same terms as the other seven vendors' HQ facts above, not as a claim of superior compliance.
The practical test for any vendor on this criterion, including Ripe Leads, is the same: ask which regime applies to the specific market being sold into, ask to see the process document that regime requires, a DPA for GDPR, an opt-out SLA for CAN-SPAM, a consent record for the Spam Act, and treat a vague, single generic answer covering all three as the compliance gap it usually is.
A buyer running outreach into more than one of these three jurisdictions at once should expect a vendor to name a different process for each, not a single blended answer, since a compliance process built for one regime rarely satisfies the other two without adjustment.
The next page in this series covers results proof: how to check whether a vendor's case studies and review counts are genuine evidence of outcomes, or activity metrics presented as if they were outcomes.
Frequently asked
What is the main legal difference between GDPR and CAN-SPAM for B2B cold outreach?
Does Australia's Spam Act 2003 apply the same way as GDPR?
Does a vendor's head office location tell you which compliance rules it follows?
What should I ask an outbound agency to prove its compliance process is real?
Where is Ripe Leads based, and which compliance regime applies to its own outreach?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call