Short answer: in the US you can send cold email to companies without asking first, as long as every email meets the CAN-SPAM rules. In the UK you can email limited companies and LLPs without consent, but not sole traders or ordinary partnerships, and UK GDPR applies on top. Below is where those rules come from and what they mean for your emails.
Two countries, two systems
The US works on an opt-out basis. You may send the first email, and the law tells you how that email has to look and what you must do when someone says stop.
The UK asks two questions, and you have to pass both.
PECR answers: may I send this message to this recipient?
UK GDPR answers: may I use the personal data I need to send it?
If you sell into both countries, you build your campaign to meet both sets of rules. That is less work than it sounds, because most of the requirements overlap.
United States: what CAN-SPAM requires
Commercial email in the US falls under the CAN-SPAM Act, enforced by the Federal Trade Commission. You do not need consent before you send. The FTC is explicit that the law makes no exception for business-to-business email, so every cold email to a company is covered. The requirements, as the FTC lists them in its CAN-SPAM compliance guide for business:
- No false or misleading header information. Your From, To, Reply-To and routing information must accurately identify the person or business sending the email.
- No deceptive subject lines. The subject line has to reflect what the email is about.
- Identify the message as an ad. The law gives you leeway in how you do that, but it has to be clear.
- Tell recipients where you are located. Every email needs your valid physical postal address: a street address, a PO box registered with the US Postal Service, or a private mailbox registered with a commercial mail receiving agency.
- Tell recipients how to opt out. A clear explanation, for example a return email address or another easy internet-based way to say stop.
- Honor opt-outs promptly. Within 10 business days. Your opt-out route must keep working for at least 30 days after you send. You may not charge a fee, ask for more than an email address, or sell or pass on the addresses of people who opted out.
- Monitor what others do on your behalf. If you hire an agency to send for you, you remain responsible. Both the company being promoted and the company that sends can be held liable.
The stakes are real: according to the FTC, each separate email in violation of the law can lead to a penalty of up to $53,088.
United Kingdom: PECR and who you are emailing
In the UK, the question whether you may send at all is answered by the Privacy and Electronic Communications Regulations 2003 (PECR), enforced by the Information Commissioner's Office (ICO). The email marketing rule in regulation 22 does not look at your message. It looks at the recipient.
- Corporate subscribers. Companies, limited liability partnerships, Scottish partnerships and some government bodies. The PECR consent rule for email does not apply to them, so you can send cold email without prior consent. That includes the address of a named employee, because for PECR the subscriber is the employer.
- Individual subscribers. Sole traders and non-limited partnerships get the same protection as consumers. You may only email them if they specifically consented or the soft opt-in applies, and the soft opt-in only covers your own existing customers. In practice: no cold email to sole traders and ordinary partnerships.
For every recipient, corporate or not, you must not disguise or hide who you are, and you must give a valid address where they can opt out.
This is the part most senders from outside the UK miss. A UK list built from websites and directories contains plenty of sole traders: consultants, tradespeople, small agencies. Check the legal form before a UK business goes into your campaign. Limited companies and LLPs are on the Companies House register. If you cannot establish the legal form, leave the business out.
Source: ICO guidance on business-to-business marketing, accessed 4 October 2026.
United Kingdom: what UK GDPR adds
A business email address with a person's name in it is personal data. So UK GDPR applies, even when PECR allows the email and the context is entirely business.
Legal basis. The usual basis for B2B cold email is legitimate interests, Article 6(1)(f) UK GDPR. Since February 2026, Article 6(11) names direct marketing as an example of processing that may be carried out for legitimate interests. May be, not is: you still have to weigh your interest against the recipient's and be able to show that assessment.
Duty to inform. This is the requirement that gets skipped most often. You did not get the data from the person themselves, so Article 14 UK GDPR applies: you must tell the recipient who you are, why you process their data, where you got it and what rights they have. If you use the data to contact them, you do that at the latest in your first email. In practice: a privacy notice that explicitly covers cold outreach and the source of the data, linked in the email.
Right to object. For direct marketing the right to object is absolute, Article 21(2) and (3) UK GDPR. If someone objects, processing for that purpose stops. Immediately, with no balancing. That calls for a suppression list that works across all your campaigns, not per campaign.
What the Data (Use and Access) Act 2025 changed
The Data (Use and Access) Act 2025 became law in June 2025. The parts that matter for cold email came into force on 5 February 2026:
- Higher fines under PECR. The maximum used to be £500,000. It is now the UK GDPR level: £17.5 million or 4 percent of global annual turnover, whichever is higher.
- Direct marketing written into UK GDPR. The new Article 6(11) mentioned above. It confirms direct marketing can be a legitimate interest. It does not remove the balancing test.
- Soft opt-in for charities. Charities can now use the soft opt-in for their supporters. That does not affect B2B cold email.
Sources: The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 on legislation.gov.uk, accessed 4 October 2026. The ICO notes that its direct marketing guidance is under review because of the Act, so check ico.org.uk for the latest version.
What every cold email must contain
- A recognizable sender. A real person's name and a company name that checks out, on a domain that leads to a real website. Required in both countries.
- An honest subject line. Required in the US, and in the UK a misleading subject line sits badly with the rule not to disguise who you are.
- Your physical postal address. Required in the US for every commercial email.
- A clear way to opt out, which you actually process. Required in both countries. In our case that is a reply address we process daily, with a suppression list that the address really ends up on.
- A link to your privacy notice covering cold outreach and the source of the data. Required for UK recipients under Article 14 UK GDPR.
- Relevance. An offer that fits the recipient's role, and a limited number of follow-ups. Not a legal requirement, but it is what keeps complaints away.
What you need to be able to do when someone sends a request
Sooner or later a running campaign gets a message from someone who is not asking for information but for accountability: where did you get my data, and I want you to delete it.
What you then need to be able to do within a day:
- Show where the address came from. Source and date. That means you record the origin per record while you build your list, rather than reconstructing it afterwards. This is why buying a file is a bigger risk than it looks: with those you often cannot answer that question. That is why, with the lead files we sell separately, we include per record where the address came from and when it was checked.
- State the legal basis. In the UK: legitimate interests, together with your balancing assessment. In the US: that you meet CAN-SPAM, and that you honor the opt-out.
- Delete and suppress the address. Removing it from the campaign is not enough. Without a suppression list that works across everything, the same address simply comes back with the next list. That is what makes a request escalate.
- Confirm that it has been done, in plain language, without a legal discussion.
Checklist for your own campaign
- Business addresses only
- UK: only limited companies, LLPs and other corporate subscribers, no sole traders or ordinary partnerships
- Origin recorded per lead, source and date
- Offer relevant to the recipient's role
- Sender name and company name are correct and traceable
- US: a valid physical postal address in every email
- A working opt-out route in every email that is actually processed, well within 10 business days
- Privacy notice that explicitly covers cold outreach, including the source of the data
- UK: a documented legitimate interests assessment
- Suppression list that works across all campaigns and clients
- Limited number of messages per recipient
- Retention period for lead data recorded
- A fixed procedure for when a request comes in
How we do this
On behalf of clients we send thousands of emails a day, and we have handled a formal privacy request in a running campaign from start to finish. What has remained from that as a fixed way of working: recording the origin per lead, a suppression list across all campaigns, handling every request within one working day with deletion and suppression, and informing the client straight away instead of resolving it quietly.
Frequently asked questions
Is cold email legal in the US?
Yes. The CAN-SPAM Act does not require consent before you send, and it makes no exception for business-to-business email. Every email must have accurate header information, a subject line that is not deceptive, a clear indication that it is an ad, your valid physical postal address and a clear way to opt out. You must honor opt-outs within 10 business days. According to the FTC, each email in violation can lead to a penalty of up to $53,088.
Is cold email legal in the UK?
To corporate subscribers, yes. Under PECR you can email limited companies, LLPs, Scottish partnerships and some government bodies without prior consent, including named employees there, as long as you do not hide who you are and you give a valid address to opt out. Sole traders and non-limited partnerships count as individual subscribers: you need their consent or the soft opt-in, so cold email to them is not allowed. UK GDPR applies on top whenever the address identifies a person.
What did the Data (Use and Access) Act 2025 change for cold email?
Since 5 February 2026 the maximum PECR fine is £17.5 million or 4 percent of global annual turnover, up from £500,000. UK GDPR now names direct marketing as an example of processing that may be carried out for legitimate interests (Article 6(11)), but you still need the balancing test. The split between corporate and individual subscribers did not change.
Does there have to be an unsubscribe link at the bottom of my cold email?
Not necessarily a link. In the US you need a clear explanation of how to opt out, for example a return email address, that keeps working for at least 30 days, and you must honor requests within 10 business days. In the UK you need a valid address where the recipient can opt out. A reply address works in both countries, as long as you mention it in the email and every request actually ends up on a suppression list that works across all your campaigns.
May I use a purchased company database for cold email?
Neither country bans it. It is, however, the biggest practical risk. For UK recipients you have to tell people where you got their data, and in the event of a complaint you have to be able to show within a day where an address came from and when it was collected. With a purchased database you often cannot answer that question. UK lists also tend to contain sole traders, whom you may not cold email at all.
Not sure whether your campaign has this in order?
Ask your question and we will look at the legal basis, the opt-out route and the origin of your list free of charge. Also if you are with another provider.
Rather email first? That works too: info@link2leads.nl