Vendor Evaluation

Evaluating a B2B outbound agency on compliance: GDPR, CAN-SPAM and the Spam Act compared

Done-for-you B2B outbound · Original data

In short

A B2B outbound agency selling into Europe, the United States and Australia is operating under three different legal regimes for the same activity. This page, third in a five-part vendor-evaluation series, compares GDPR, CAN-SPAM and Australia's Spam Act 2003 side by side, states what eight named agencies' head office locations are as of 2026-09-08, and sets out the specific document to ask each vendor for under each regime.

On this page
  1. Three regimes, one outbound campaign
  2. GDPR in one paragraph
  3. CAN-SPAM in one paragraph
  4. Australia's Spam Act in one paragraph
  5. Comparing the three side by side
  6. What HQ location tells you, and what it does not
  7. Where Ripe Leads sits, and how to test any vendor's answer

Three regimes, one outbound campaign

A B2B outbound agency selling into Europe, the United States and Australia at the same time is operating under three separate legal regimes for the same activity, cold commercial email and, in some jurisdictions, cold calling. None of the three regimes is interchangeable with the others, and a vendor that treats compliance as one generic policy applied everywhere is very likely getting at least one of the three wrong.

This is the third page in a five-part series evaluating B2B outbound agencies on a single criterion each. Pricing transparency and data quality came first; results proof and SME fit follow. As with the rest of the series, this page states facts a buyer can check rather than ranking any vendor.

The site already publishes a detailed explainer on Australia's Spam Act 2003 and on German cold-email legality specifically; this page sits above both, as a side-by-side comparison and a vendor-vetting criterion, and links out to each for the fuller detail on that single jurisdiction.

The regimes described below are summarised for the purpose of vendor evaluation, not as legal advice for a company's own outreach; a company with a specific compliance question about its own campaigns should confirm the current requirement with its own legal counsel or the relevant regulator, since laws in this area are amended periodically.

GDPR in one paragraph

GDPR governs the processing of personal data for any company selling into the European Economic Area, regardless of where the vendor sending the email is based. For B2B cold outreach specifically, the commonly relied-on legal basis is legitimate interest rather than prior consent, but that basis carries its own conditions: the contact must be able to object easily, the outreach must be relevant to their professional role, and the sender must be able to show it weighed the contact's rights before relying on that basis. A vendor's GDPR process should be checkable in the form of a data processing agreement and a stated legal-basis record, not just a claim of compliance on a marketing page.

The distinction between B2B and B2C outreach matters under GDPR specifically because legitimate interest is more commonly accepted for a business contact acting in a professional capacity than for a private individual, but the assessment still has to be documented per campaign, not assumed once and reused indefinitely. A vendor unable to produce that documentation on request has a compliance claim, not a compliance process.

CAN-SPAM in one paragraph

The US CAN-SPAM Act takes a different approach: commercial email is broadly permitted without prior consent, but the law imposes strict requirements on the message itself, no false or misleading header information, a clear identification that the message is an advertisement where applicable, a valid physical postal address, and a working opt-out mechanism that must be honoured promptly. A vendor operating under CAN-SPAM should be able to show its standard opt-out handling process on request, since that is the part of the law most directly tested by a recipient complaint.

CAN-SPAM's lighter consent requirement is sometimes read by vendors as no compliance obligation at all for US outreach, which is not accurate; the header, identification and opt-out requirements are enforceable, and a vendor's actual practice around suppression lists, keeping an opt-out list current across every subsequent campaign, is the part worth asking about directly, since it is the part most likely to lapse quietly over time.

Suppression-list handling also intersects with data quality, covered on the previous page in this series: a vendor reusing a stale contact list is more likely to email someone who already opted out, which is as much a data-hygiene failure as a legal one.

Australia's Spam Act in one paragraph

Australia's Spam Act 2003 sits closer to GDPR's consent-oriented model than to CAN-SPAM's, requiring consent for commercial electronic messages, with a business-to-business exemption that applies narrowly and depends on the specifics of the relationship and the content of the message, covered in full on the site's dedicated Spam Act explainer. It is also the only one of the three regimes among these that draws a sharp distinction between email, which the consent requirement applies to, and cold calling, which sits under separate telemarketing rules, meaning a vendor's compliance answer needs to specify which channel it is describing.

Because the B2B exemption depends on the specifics of the message and the relationship rather than applying automatically to any commercial contact, a vendor selling outbound services into Australia should be able to explain, specifically, which of its messages it relies on the exemption for and which it treats as requiring consent, rather than asserting blanket B2B coverage.

Cold calling in Australia sits under a separate regime, the Do Not Call Register Act, not the Spam Act, and a vendor's answer about email compliance says nothing about whether its calling process is compliant; the two channels need separate answers.

Comparing the three side by side

The table below compares the three regimes at the level a buyer needs to evaluate a vendor, not as a substitute for legal advice specific to a company's own outreach.

RegimeApplies toDefault basis for B2B cold outreachWhat to ask a vendor
GDPR (EU/EEA)Any company processing EU/EEA contact dataLegitimate interest, with an easy objection routeAsk for the data processing agreement and the legitimate-interest assessment
CAN-SPAM (US)Commercial email sent to US recipientsOpt-out, no prior consent requiredAsk for the standard opt-out handling process and its turnaround time
Spam Act 2003 (Australia)Commercial electronic messages sent to Australian recipientsConsent-based, narrow B2B exemptionAsk which channel, email or calling, the process covers and how consent basis is recorded

None of the eight named vendors in this series publish a jurisdiction-by-jurisdiction compliance breakdown on their marketing sites as of 2026-09-08; compliance claims across the group are general statements rather than the kind of regime-specific detail in the table above, which is why the direct questions in the right-hand column matter more than the marketing copy.

What HQ location tells you, and what it does not

Head office location is a starting clue, not a full answer. Belkins positions itself as a US agency, SalesAR is headquartered in Yerevan, Armenia, Martal Group is commonly cited as Canada-headquartered, CIENCE Technologies is based in Denver with additional offices including Germany and Ukraine, Cleverly is Los Angeles-based, Pearl Lemon Leads is London-based, SalesNash is headquartered in Ottawa with US and UK offices, and Ripe Leads is headquartered in Vilnius, Lithuania. A vendor's own jurisdiction affects which regulator can act against it directly, but every one of these vendors sends outreach into other jurisdictions too, and it is the recipient's location, not the sender's, that determines which regime actually governs a given message.

A vendor with a single-country office can still run fully compliant multi-jurisdiction campaigns, and a vendor with offices in several countries is not automatically compliant everywhere it operates. HQ location is useful only as the first thing to ask about, not the last.

This series draws no conclusion about any vendor's actual compliance from HQ location alone. The table and this section report the regimes each office sits under and where those offices are, both public facts. What a vendor does inside its own process is something a buyer establishes on the call, by asking it to walk one opt-out through end to end.

Where Ripe Leads sits, and how to test any vendor's answer

Ripe Leads is headquartered in Vilnius, Lithuania, inside the EU, and its published Australian activity is new: its campaigns into that market started in September 2026, with the Spam Act's business-to-business exemption the specific regime that applies there, detailed in full on the site's own Spam Act explainer. That fact is stated here on the same terms as the other seven vendors' HQ facts above, not as a claim of superior compliance.

The practical test for any vendor on this criterion, including Ripe Leads, is the same: ask which regime applies to the specific market being sold into, ask to see the process document that regime requires, a DPA for GDPR, an opt-out SLA for CAN-SPAM, a consent record for the Spam Act, and treat a vague, single generic answer covering all three as the compliance gap it usually is.

A buyer running outreach into more than one of these three jurisdictions at once should expect a vendor to name a different process for each, not a single blended answer, since a compliance process built for one regime rarely satisfies the other two without adjustment.

The next page in this series covers results proof: how to check whether a vendor's case studies and review counts are genuine evidence of outcomes, or activity metrics presented as if they were outcomes.

Frequently asked

What is the main legal difference between GDPR and CAN-SPAM for B2B cold outreach?
GDPR requires a documented legal basis, commonly legitimate interest for B2B contacts, with an easy objection route. CAN-SPAM permits commercial email without prior consent but requires accurate headers, clear identification and a working, promptly honoured opt-out.
Does Australia's Spam Act 2003 apply the same way as GDPR?
It is closer to GDPR's consent-based model than to CAN-SPAM's, but its business-to-business exemption is narrow and depends on the specifics of the message and relationship, not a blanket rule. It also treats cold calling under a separate regime from cold email.
Does a vendor's head office location tell you which compliance rules it follows?
Only partly. It affects which regulator can act against the vendor directly, but the recipient's location, not the sender's, determines which regime actually governs a given message, and every vendor compared in this series sends outreach across more than one jurisdiction.
What should I ask an outbound agency to prove its compliance process is real?
Ask for the specific document each regime requires: a data processing agreement and legitimate-interest assessment for GDPR, a stated opt-out handling process and turnaround time for CAN-SPAM, and a consent-recording process for the Spam Act, specified by channel, email versus calling.
Where is Ripe Leads based, and which compliance regime applies to its own outreach?
Vilnius, Lithuania, inside the EU, so GDPR is its home regime. Its Australian campaigns started in September 2026, with the Spam Act's business-to-business exemption the specific regime that applies there.

Want the accounts behind these numbers?

Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.

Book a strategy call