Deliverability

Cold outreach rules beyond GDPR: US, canada and more

Cold outreach compliance beyond Europe, in plain terms

Published 1 October 2026 · 6 min read · By Ripe Leads

The short answer

Different regions have different cold email laws: the EU has GDPR, the US has CAN-SPAM, Canada has CASL, and others vary. The details differ, but the safe habits are the same everywhere: identify yourself honestly, target a genuine business reason, make opting out easy, and honour it. Follow the strictest rule that applies and you are broadly safe across markets.

On this page
  1. There is no single global rule
  2. The EU: GDPR and consent-or-interest
  3. The US: CAN-SPAM
  4. Canada: CASL
  5. The habits that travel
  6. Other markets worth knowing: UK, Australia, Switzerland
  7. Common compliance mistakes in cross-border outreach
  8. A pre-send compliance checklist
  9. When in doubt, follow the strictest

Outbound rarely stops at a border, and the rules do not either. You do not need to be a lawyer, but sending across markets means knowing that the compliance bar moves, and that a few universal habits keep you on the right side of most of it.

There is no single global rule

Cold email is governed regionally, and the regimes differ in both letter and spirit. What is routine in one market can be a violation in another, so where your recipient is matters as much as where you are.

The practical response is not to memorise every statute, but to understand the shape of the main ones and adopt habits that satisfy the strictest.

In Europe, GDPR governs, and B2B cold outreach generally rests on legitimate interest: contacting someone about their professional role, with identification and an easy opt-out. The full picture for Europe is in the GDPR guide; the key point here is that it is one of the stricter regimes.

The US: CAN-SPAM

The US takes a lighter, opt-out approach under CAN-SPAM. Broadly: do not use deceptive headers or subject lines, identify the message honestly, include a valid physical postal address, and provide a working way to opt out that you honour promptly.

It is more permissive than GDPR, but the honesty and opt-out requirements are real and enforced.

Canada: CASL

Canada's CASL is among the strictest, leaning toward requiring consent, with some business-relationship exceptions, and carrying significant penalties. If you send into Canada, treat it as a high-bar market and understand the specifics rather than assuming a US-style opt-out approach is enough.

The habits that travel

You can satisfy most regimes at once with a few consistent practices.

  1. Identify yourself and your company honestly, no deceptive headers or subjects.
  2. Have a genuine, business-related reason to contact this person.
  3. Include a real, easy way to opt out, and honour it immediately and permanently.
  4. Where required, include a physical postal address.
1Follow the strictest rule that applies to any recipient, and one honest, easy-opt-out standard keeps you broadly compliant across markets.

Other markets worth knowing: UK, Australia, Switzerland

Three more regimes come up often for European senders. The UK kept GDPR after leaving the EU, and layers PECR on top: for corporate email addresses, B2B outreach on a legitimate-interest basis remains workable, with the same honesty and opt-out duties. Australia's Spam Act leans toward consent, with an inferred-consent route for messages closely tied to the recipient's role; treat it closer to Canada than to the US. Switzerland sits outside the EU but runs its own data protection law alongside unfair-competition rules that make unsolicited mass email risky, so most senders hold Swiss recipients to the strictest standard on their list. If a market is small in your pipeline and its rules are unclear, the cheapest option is often to exclude it rather than research it.

Germany deserves its own mention even inside the EU. Its unfair-competition law (UWG) sets a higher practical bar for unsolicited email than GDPR alone, which is why campaigns into the DACH market often shift weight toward LinkedIn and phone rather than relying on email volume. What that stricter bar means in practice is set out in the rules for cold email in Germany.

Common compliance mistakes in cross-border outreach

Most violations are not deliberate. They come from habits copied from a single home market and applied everywhere.

A pre-send compliance checklist

Run this before any campaign that crosses a border. It takes minutes and covers most of the exposure.

  1. Map recipients by country and note which regime applies to each segment.
  2. Confirm the lawful basis for each segment: legitimate interest in the EU, opt-out honesty in the US, consent or inferred consent in Canada and Australia.
  3. Check the message: honest sender name, accurate subject, clear business reason, physical address, working opt-out.
  4. Check the data: business-context contacts only, sourced from public or licensed data, screened against your suppression list.
  5. Check the plumbing: authentication records pass, unsubscribe link resolves, replies route to a monitored inbox.

None of this slows a well-run operation down. Teams that build these checks into their workflow send with more confidence, not less, and their reply rates do not suffer for it.

When in doubt, follow the strictest

The simplest safe policy for cross-border outbound is to hold yourself to the strictest standard that could apply to any recipient, usually the European or Canadian bar. Do that and you are compliant almost everywhere by default. The same principle carries to the phone, where cold calling rules differ country by country across Europe.

This is general guidance, not legal advice. For significant or high-volume cross-border sending, confirm the specifics for your markets. But honest identification and a respected opt-out will keep most senders on the right side of most laws.

Frequently asked

Is cold email legal outside the EU?
Generally yes, under region-specific rules that differ from GDPR. The US allows cold email under CAN-SPAM on an opt-out basis, provided you are honest and include a valid postal address and working opt-out. Canada's CASL is stricter and leans toward consent. The rules vary by market, but honest identification and an easy, respected opt-out keep you broadly compliant.
What is the difference between GDPR and CAN-SPAM?
GDPR, in the EU, is stricter and requires a lawful basis such as legitimate interest for B2B contact, with identification and an easy opt-out. CAN-SPAM, in the US, is more permissive and opt-out based: do not deceive, identify the message honestly, include a physical address, and honour opt-outs promptly. GDPR sets a higher bar, so meeting it usually covers CAN-SPAM too.
How do I stay compliant when emailing multiple countries?
Follow the strictest standard that could apply to any recipient, usually the European or Canadian bar, and you are compliant almost everywhere by default. In practice that means identifying yourself honestly, having a genuine business reason to make contact, including an easy opt-out you honour immediately, and adding a postal address where required. For large cross-border sending, confirm the specifics for your markets.

Rather not build this yourself?

We run the targeting, data, copy and follow-up as a done-for-you service, and send the interested replies straight to your inbox. You bring the close.

Book a strategy call