No. 09 Guides, filed under Guide
Is Cold Email Legal? US, UK, EU, Canada and Australia Compared (2026)
Usually yes. The US needs no prior consent; Canada and Australia do; the UK and EU depend on who you email. Your recipient’s law applies, and often yours.
On this page 16 sections
This page is for small teams deciding whether they may email a business prospect in the US, UK, EU, Canada or Australia, and what that email must contain. The answer depends on where the recipient is, and often on where you send from.
Quick answer
Usually yes, if you follow your recipient’s country’s rules, and often your own. The US needs no prior consent, but each email needs a postal address, ad disclosure and opt-out. Canada and Australia need consent. The UK and EU need it for individuals, and some EU countries, such as Germany, for business addresses too. Law checked October 2, 2026.
Not legal advice. This page summarizes laws and regulator guidance as we read them between September 29 and October 2, 2026. No lawyer has reviewed it. For a specific campaign, ask a lawyer who practices in your recipient’s country.
This page covers business-to-business email to prospects. It doesn’t cover consumer newsletters, SMS or phone calls (other rules apply), or recipients outside these five places.
Cold email laws by country, at a glance
The biggest difference is consent: the US lets you send the first email without permission, Canada and Australia don’t, and the UK and EU split recipients into individuals and organizations.
| Recipient in | Consent before the first email | Business (B2B) addresses | Opt-out deadline | Maximum penalty |
|---|---|---|---|---|
| United States CAN-SPAM (FTC guide1) | Not required | Covered: no B2B exception | 10 business days | $53,088 per email (16 CFR 1.98) |
| United Kingdom PECR, UK GDPR (ICO10) | Required for individuals, including sole traders (PECR reg. 22) | Companies and LLPs: no consent needed | No day count: without undue delay, within one month (ICO; UK GDPR art. 12(3), 12A) | £17.5 million or 4% of global turnover under PECR |
| European Union ePrivacy, GDPR (art. 1315) | Required for individuals (ePrivacy art. 13(1)) | Each country decides (art. 13(5)); Germany requires consent | No day count: without undue delay, within one month (GDPR art. 12(3)) | GDPR: €20 million or 4% of worldwide turnover (art. 83(5)); e-marketing: set by each country |
| Canada CASL (Act21) | Required, express or implied (s. 6(1)) | A published address implies consent only under three conditions (s. 10(9)(b)) | 10 business days (s. 11(3)) | C$10 million per violation; C$1 million for an individual (s. 20(4)) |
| Australia Spam Act 2003 (Act23) | Required, express or inferred (s. 16) | A published work address can imply consent (sch. 2, cl. 4) | 5 business days (sch. 2, cl. 6) | Set in penalty units: up to A$3.64 million a day for a repeat company (s. 25) |
Law checked October 2, 2026. Each row links its main source; the country sections below link every rule cited. Laws and penalty amounts change, so check the source before you rely on a number.
Which law applies: your recipient’s country, and often yours
Start with the law where your recipient is. Then check the law where you send from, because each of these five can also reach some email sent from inside it:
- United States: CAN-SPAM sets the federal rules, but state laws survive where they prohibit “falsity or deception” in commercial email (15 U.S.C. 7707(b)(1)5). By their text, at least three of them cover email sent from the state, wherever the recipient is: Washington’s reaches email sent “from a computer located in Washington” (RCW 19.190.020), California’s email “sent from California” (B&P 17529.5; see United States) and Maryland’s email “from a computer in the State” (Md. Commercial Law 14-3002(b)(1)9). CAN-SPAM’s own rules apply to email sent to a “protected computer” (15 U.S.C. 7704(a)5), a term that includes “a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States” (7702(13)5; 18 U.S.C. 1030(e)(2)(B)6), so it can also reach some email a US business sends abroad.
- Canada: CASL’s rules on consent, sender identification and unsubscribing (s. 6) apply when a computer system in Canada is used to send or access the message (s. 12(1)), so they cover a US sender emailing Toronto. They don’t cover a Canadian sender emailing abroad who reasonably believes the message will be opened in a country on the regulations’ list, which includes the US, UK, Australia and every EU country, if the message meets that country’s law on similar conduct (SOR/2013-221, s. 3(f)22).
- Australia: the Spam Act covers messages with an “Australian link”: sent from Australia or by someone there, or opened on a device there or by an organization doing business there (s. 7).
- EU and UK: the GDPR and UK GDPR cover a business established there, wherever its recipients are, and a business elsewhere that offers goods or services to people there (art. 3(1)–(2) of the GDPR16 and UK GDPR14).
If your list mixes countries, record each recipient’s country and apply each row, or hold the whole list to the strictest rule that applies to anyone on it.
Is cold email legal in the US?
Yes, cold email is legal in the US: CAN-SPAM doesn’t require the recipient’s permission before your first email, but every commercial email must meet its rules. The FTC says the law “covers all commercial messages,” not just bulk email, and “makes no exception for business-to-business email.”
Every email needs accurate From and routing details, a subject line that matches the content, a postal address (a registered PO box counts) and a working opt-out, and you stay responsible if someone sends for you. Don’t drop the ad disclosure because a cold email reads like a personal note: the law gives you “a lot of leeway” in how, “but you must disclose clearly and conspicuously that your message is an advertisement” (FTC guide).
CAN-SPAM gives recipients no right to sue; the FTC, some other federal agencies, state attorneys general and internet access providers enforce it (15 U.S.C. 77065). But state laws against deceptive email can let recipients sue. Two examples:
- Washington: a disguised point of origin or a false or misleading subject line, in email sent from Washington or to an address you know, or have reason to know, belongs to a resident (RCW 19.190.0207), costs $100 per message or actual damages, whichever is greater (RCW 19.190.0407). A 2026 amendment cut that from $500 and added a knowledge test for subject lines, for lawsuits filed on or after June 11, 2026 (2026 c 1357).
- California: falsified or forged headers, or a subject line likely to mislead, in an email ad sent from California or to a California address: $1,000 per email, up to $1,000,000 per incident, or at most $100 if the court finds you had careful procedures to prevent it (Business and Professions Code 17529.58).
United Kingdom: companies vs sole traders
You can email UK companies without consent, but the ICO says sole traders and some partnerships are treated as individuals, so you need their consent unless they already bought something similar from you and didn’t opt out.
- “Corporate bodies” are companies, Scottish partnerships, limited liability partnerships and government bodies (ICO). The consent rule covers “individual subscribers” (PECR reg. 2213), and the soft opt-in “does not apply to prospective customers or new contacts” (ICO).
- Named work addresses (firstname.lastname@company) may bring in data protection, the ICO says. Then the UK GDPR’s art. 14 notice rules apply, as in the EU (see the sample footer).
- Objections: comply “without undue delay and at the latest within one month”; for direct marketing there are no exemptions (ICO11).
- Legitimate interests: since February 5, 2026 the UK GDPR lists direct marketing as an example of processing that may be necessary for a legitimate interest (art. 6(11)14), but the balancing test in art. 6(1)(f) still applies, and the ICO says to record it (ICO11).
The ICO enforces PECR, and its fining limit rose in February 2026 (see myth 2). Its email marketing guidance is “under review” after the Data (Use and Access) Act, so check it again before a UK campaign.
European Union: GDPR plus national e-marketing rules
In the EU, “can I send this email?” and “can I use this person’s data?” are separate questions, answered by different laws.
- Sending: each country’s version of the ePrivacy Directive. Email marketing to individuals needs prior consent, except to your own customers for similar products (art. 13(1)–(2)). For business subscribers, the Directive only asks countries to protect their “legitimate interests,” so the rule differs by country (art. 13(5)).
- Using the data: the GDPR. Legitimate interests works only where the recipient’s interests or rights don’t override yours (art. 6(1)(f)16); recital 4716 says direct marketing “may be regarded as” one, and that a legitimate interest “would need careful assessment.” Write that balancing test down.
- Telling recipients: if you didn’t collect the data from them, give the art. 1416 information, including the source, within one month of getting the data, or at your first email if that comes sooner (art. 14(3)(a)–(b)), and point out their right to object separately from anything else (art. 21(4)16).
- Objections: stop using their data for marketing (art. 21(3)) and tell them what you did without undue delay and within one month (art. 12(3)16).
- Bought lists: first check the data was obtained in line with the GDPR, can be used for advertising and excludes people who objected (European Commission17).
Germany shows why the country matters. Its Act against Unfair Competition treats email advertising without the addressee’s prior express consent as unacceptable harassment (UWG §7(2) no. 220). Unlike the phone rule, which lets you call businesses with presumed consent (no. 1), the email rule requires prior express consent from businesses and consumers alike. The main exception is existing customers (§7(3)).
Enforcement is split too: each country’s data protection authority enforces the GDPR (art. 5116), and its competent national authority the e-marketing rules, under penalties it sets (ePrivacy art. 15a15). In Germany, competitors, registered trade and consumer associations and chambers of commerce can sue for an injunction (UWG §820).
Canada: CASL’s consent rules
Canada requires consent before a commercial email, express or implied, and the sender has to prove it (CASL ss. 6(1), 13). For cold outreach, the implied consent that matters is a published address, and all three conditions must hold (s. 10(9)(b)):
- Conspicuously published: the person published the address, or had it published, where it’s easy to see.
- No opt-out note: the publication doesn’t say they don’t want unsolicited commercial messages.
- Relevant to their role: your message relates to their business, role, functions or duties.
- Asking by email needs a route too. A message that contains a request for consent “is also considered to be a commercial electronic message” (s. 1(3)), so you can send one only where you already have implied consent, such as a published address that meets the three conditions or an address the person gave you (s. 10(9)(b)–(c)), or where an exemption applies, such as a first email after a referral from someone who knows you both, naming them (SOR/2013-221, s. 422).
- The B2B exclusion is narrow. It covers messages between employees of organizations that “have a relationship,” about the recipient organization’s activities (SOR/2013-221, s. 3(a)(ii)22), not a first email to a stranger.
- Every message: your business name, your mailing address and a phone number, email address or web address (SOR/2012-36, s. 222), set out “clearly and prominently” (s. 3), plus an unsubscribe mechanism. Contact details and the unsubscribe address or link must stay valid for 60 days after you send (CASL ss. 6(3), 11(2)); unsubscribes take effect within 10 business days (s. 11(3)).
The CRTC enforces these rules through notices of violation (ss. 14, 22). The Act text is current to September 21, 2026, last amended January 1, 2026 (Justice Laws Website).
Australia: the Spam Act 2003
Australia requires consent too, express or inferred, and the ACMA says it’s up to you to prove it (ACMA25).
- Published addresses: publication alone doesn’t imply consent (sch. 2, cl. 4(1)). A conspicuously published work address does if it’s reasonable to assume it was published with the person’s agreement, it carries no “no spam” statement, and your message relates to their work (cl. 4(2)).
- No asking by email: the ACMA says you can’t send a message to ask for consent, because that is itself a marketing message.
- Every message: who authorized it and how to contact them, valid for at least 30 days (s. 17), and a clear unsubscribe facility that works for at least 30 days (s. 18). A withdrawal takes effect after 5 business days (sch. 2, cl. 6).
- Lists: no lists built with address-harvesting software, and you’re responsible for consent on any list you buy (ACMA).
Penalties are set in penalty units (s. 25). For breaking the consent rule, a company with no prior record faces up to 100 units per contravention and 2,000 for two or more on one day; with a prior record, 500 and 10,000. A unit is A$364 for offenses on or after July 1, 2026 (ASIC24), so by our arithmetic A$728,000 a day for a first-time company and A$3.64 million for a repeat one. These are ceilings: the ACMA brings the case and the Federal Court sets the penalty (s. 26).
Six claims ranking pages repeat, checked against the law
We read the pages ranking for “is cold email legal” on Google, and its AI Overview, on September 28 and 29, 2026. Each claim below appears in at least one of them and is wrong or out of date:
- “CAN-SPAM fines are $51,744 (or ‘over $43,000’) per email.” $51,744 was the 2024 figure (FTC4). Since January 17, 2025 it’s $53,088 (16 CFR 1.982), kept for 2026 (91 FR 58446, September 15, 20263).
- “UK PECR fines are capped at £500,000.” Since most of the Data (Use and Access) Act 2025’s remaining data protection provisions came into force on February 5, 2026, the ICO says it can fine up to £17.5 million or 4% of global turnover under PECR (ICO statement12). The old figure survives on the ICO’s “What are PECR?” page, marked under review (ICO10).
- “Australia can fine you A$2.22 million a day.” That’s 10,000 penalty units at A$222, the value from July 1, 2020 to December 31, 2022. A unit is now A$364, and that ceiling applies only to a company with a prior record (see Australia).
- “B2B cold email is legal anywhere in the EU under legitimate interest.” Legitimate interest is a GDPR basis for using data, subject to a balancing test. Whether you may email a business is left to each country, and Germany requires prior express consent (see EU).
- “Canada has a B2B exception, so any published business address is fair game.” A published address implies consent only when all three conditions in s. 10(9)(b) hold, and the B2B exclusion needs an existing relationship (see Canada).
- “Recipients can sue you under CASL.” The private right of action never started: sections 47 to 51 each read “[Repealed before coming into force, 2008, c. 20, s. 3]” in the current Act. The CRTC enforces the email rules.
Also not law: Gmail’s unsubscribe rules. Google requires one-click unsubscribe only from senders of more than 5,000 messages a day to Gmail accounts (Google26). Its FAQ recommends fulfilling unsubscribe requests within 48 hours, and for those bulk senders, requests not honored within 48 hours are one of the issues that make Google’s delivery support or mitigations unavailable (Google FAQ26). Our deliverability guide sets Gmail’s sender rules beside Yahoo’s and Outlook.com’s, and says which of them apply to cold outreach.
Before you send: a checklist that works in all five
If you meet the strictest version of each rule, one setup covers all five places:
- Record each recipient’s country, and where you send from. Both decide which rules apply, for US senders too: at least three state laws against misleading email, including Washington’s, California’s and Maryland’s, cover email sent from those states, and CAN-SPAM can reach some email sent abroad (see which law applies).
- Add the sample footer to every email and use an honest From name and subject line. The US and Canada require the mailing address (FTC; SOR/2012-36 s. 2), and CAN-SPAM the ad disclosure.
- Keep the opt-out working for at least 60 days after each send (CASL s. 11(2); the US and Australia require 30).
- Suppress opt-outs within 5 business days. That’s Australia’s deadline and the shortest here; the US and Canada allow 10 business days, the UK and EU “without undue delay” and within one month.
- Record where each address came from. In Canada and Australia you must prove consent (CASL s. 13; ACMA). In the UK and EU, say where you got the data within one month of getting it, or in your first email if that comes sooner (art. 14(3)(a)–(b)), and tell them in that first email that they can object (art. 21(4)). Art. 14 also requires your identity, purpose, lawful basis and their rights, including to complain to the regulator; the ICO lists a short notice with a link to the rest as one way to give it (ICO11).
- If you rely on legitimate interests, write down the balancing test before emailing named people in the UK or EU (art. 6(1)(f); ICO).
- For UK and EU recipients, turn off open and click tracking unless you have consent. In the UK, storing or reading information on the recipient’s device is banned unless a Schedule A1 exception, such as consent, applies (PECR reg. 613), and the ICO says that rule covers tracking pixels in marketing email that store or read such information, for every type of subscriber, companies included (ICO10). In the EU, the same storing or reading needs consent unless it’s strictly necessary (ePrivacy art. 5(3)15), and the EDPB says pixels and tracked links in email do both (Guidelines 2/202318). Judge those campaigns by replies instead.
- Get consent first where it’s needed: UK sole traders and some partnerships, EU individuals, businesses in EU countries that require it, such as Germany, and Canadian or Australian addresses no consent route or exemption covers. In Australia, don’t email them to ask (ACMA); in Canada, an email asking for consent is itself a commercial message, so it needs a route of its own (CASL s. 1(3); see Canada).
- Vet any list you didn’t build. No harvested lists (ACMA), check how bought data was obtained (European Commission), and you’re responsible for anyone sending for you (FTC; ACMA).
A sample footer that covers all five
With an honest From name and subject line, these lines cover the per-message requirements described on this page. They don’t give you consent where a law requires it.
[Your name], [role], [Business name]
[Street address or registered PO box]
[City, postal code, country]
[Phone, email or website]
This is a sales email. Reply "unsubscribe"
and I won't email you again.
We got your work address from [source].
How we use your data: [privacy notice link]
You can object to our use of your data
for marketing at any time: reply "object".
| Line | Rule it meets |
|---|---|
| Name and business | Accurate sender details (FTC); don’t hide who you are (PECR reg. 23; ePrivacy art. 13(4)); your business name (SOR/2012-36 s. 2); who authorized the message (Spam Act s. 17) |
| Address and contact | A valid postal address (FTC); a mailing address plus phone, email or web address (SOR/2012-36 s. 2), valid 60 days (CASL s. 6(3)) or 30 in Australia (s. 17) |
| “This is a sales email” | The CAN-SPAM ad disclosure (FTC) |
| Unsubscribe line | A reply opt-out, which the FTC and the ACMA both describe; a valid address for opt-out requests (PECR reg. 23; ePrivacy art. 13(4)); unsubscribe by the same means (CASL s. 11(1)); a functional unsubscribe (Spam Act s. 18) |
| Source and privacy link | Where the data came from, within one month of getting the data or at the first email if that comes sooner (GDPR art. 14(2)(f), 14(3)(a)–(b)); the linked notice carries the rest of art. 14 |
| Right to object, on its own | Stated “clearly and separately from any other information” by the first email (GDPR art. 21(4)) |
In Canada, if you send for a client, name both and say who is sending on whose behalf (SOR/2012-36 s. 2(1)(b)–(c)).
How we researched this
This page is based on the laws and regulator guidance listed in Sources, read on September 29, 2026 and checked again on October 2, 2026 (the ACMA page didn’t load on October 2, so the points we attribute to the ACMA rest on the September 29 reading): CAN-SPAM (with the “protected computer” definition it borrows from 18 U.S.C. 1030) and three state laws (Washington’s RCW 19.190, California’s Business and Professions Code 17529.5, Maryland’s Commercial Law 14-3002), PECR and the UK GDPR, the ePrivacy Directive, the GDPR and Germany’s UWG, CASL and both sets of its regulations, and the Spam Act, plus the FTC, ICO, European Commission, EDPB, ACMA and ASIC guidance. EU texts come from the Publications Office of the European Union: the ePrivacy Directive’s consolidated text of December 19, 2009, and the GDPR as published in the Official Journal. The CRTC’s CASL FAQ didn’t load (a bot check blocked it), so the Canada section rests on the Act and regulations. Tool features and plan conditions come from each vendor’s help center and Instantly’s pricing page, read on the same days; where Instantly’s pages disagree, the tools table gives both.
The only first-hand observation is from the owner’s 14-day Close trial (clicks made by an AI assistant in the owner’s account on September 27, 2026), cited in the tools section. We sent no emails and didn’t check how any tool processes unsubscribes. We opened the ranking pages only to see which claims they repeat; none is used as a source. No lawyer has reviewed this page.
The bottom line
- Check where each recipient is, and where you send from.
- Meet every rule in those rows, plus the footer above. In the US, that includes state laws against misleading email.
- If you can’t tell, or you’d need consent you don’t have, get it another way or leave them off the list. In Australia you can’t email someone to ask (ACMA). In Canada, an email asking for consent counts as a commercial message, so you can send it only where a consent route or an exemption covers it (CASL s. 1(3)).
The rules are one part of the setup. For the domains, mailboxes, sending tool and CRM around them, see the five layers of a solo founder’s outbound stack.
Tools that help you comply
No tool makes a message legal; these features only make the rules above easier to follow.
You may not need one. For a handful of one-to-one emails from Gmail or Outlook, put the sample footer in your signature and check a do-not-contact sheet before every send. Consent records and the data-source notice depend on how you build the list, tool or not.
Once you send sequences from several mailboxes, a suppression list that updates itself matters most; check which plan includes it. How we picked: each feature maps to a rule above, is documented in the vendor’s help center, and fits one way small teams send (email only, email plus LinkedIn or phone, or calls plus email). Commission doesn’t decide which tools appear or their order.
| Tool | What its help center documents | What you still do |
|---|---|---|
| Instantly | A workspace-wide Global Blocklist for addresses and whole domains, with a toggle that adds unsubscribed leads to it (help article, updated July 13, 202627); Instantly’s own pages disagree on which plan includes the blocklist (pricing page28; plan comparison27). An unsubscribe link you insert in an email step marks the lead “Unsubscribed” (help article, July 8, 202627) | Before you pay, ask Instantly’s support which plan gives you the blocklist and the automatic adds; turn the toggle on; add the unsubscribe link and footer |
| lemlist | An unsubscribe link you add yourself; a click puts the lead on the Unsubscribe list and stops all their campaigns (help article, July 23, 202629). “Do not contact” blocks a person on all channels in all campaigns, and this unsubscribe system is listed as available on all plans (help article29) | Add the unsubscribe link and footer to every email |
| Close | An unsubscribe link below your email signature; unsubscribed contacts skip workflow email steps and bulk emails. Not available on the Solo, Essentials and Base (legacy) plans, and off by default until someone with the Admin role turns it on under Settings > Email (help article30) | Check your plan includes it and have an admin turn it on; add the footer; clear an unsubscribe flag only if the contact asks |
Features as documented in each vendor’s help center, plus the feature table on Instantly’s pricing page, read October 2, 2026. Vendors change features and plans often.
In the owner’s 14-day Close trial (clicks made by an AI assistant in the owner’s account on September 27, 2026), a new workflow email template came with a default unsubscribe link in its footer, but the trial ran on Close’s top plan, Scale, so check your own plan against the table; the notes from that trial list its other defaults.
Which fits: if a tool you already use has built-in unsubscribe handling, use it, once you’ve checked your plan includes it. In Close, that means a plan other than Solo, Essentials or Base (legacy), with an admin turning the setting on. Otherwise lemlist suits sequences with LinkedIn or phone steps, since “Do not contact” covers every channel, and Instantly suits email-only sequences from several mailboxes, once you’ve confirmed which plan gives you the blocklist and the automatic adds (see the table). To weigh the two on channels and price, see when to choose Instantly or lemlist; for what each lemlist plan costs, see lemlist’s plans and prices.
Why lemlist is the one shown below: its help center says an unsubscribe applies across all campaigns (a click on the link stops every campaign the lead is in) and “Do not contact” blocks a person on every channel, which is what the checklist’s opt-out step needs once you run several campaigns. It lists that unsubscribe system as available on all plans. If you send email only, compare it with Instantly first.
lemlist
Best fit if you want unsubscribes honored across all your campaigns, and a “Do not contact” option for every channel, whichever plan you’re on. lemlist’s help center says a click on your unsubscribe link stops all of that lead’s campaigns, and lists its unsubscribe system, including “Do not contact,” as available on all plans. You still add the link to each email yourself (checked October 2026).
Visit lemlistDirect link to lemlist. We don’t earn anything from it.
FAQ
Is B2B cold email legal?
Usually, but a business address doesn’t exempt you from the rules. The US needs no prior consent, though CAN-SPAM “makes no exception for business-to-business email”; the UK lets you email companies and LLPs without consent, but not sole traders; the EU leaves business addresses to each country, and Germany requires consent; Canada and Australia need consent, which a published work address can imply only under conditions (see the table).
Do I need consent to email a business address that’s published online?
In the US, no, and in the UK not for companies or LLPs. In Canada, a conspicuously published address implies consent only if it carries no statement refusing unsolicited messages and your email relates to the person’s role (CASL s. 10(9)(b)); in Australia, publication alone isn’t enough, and a published work address implies consent only under similar conditions (Spam Act sch. 2, cl. 4). In Germany you need prior express consent however you found the address, existing customers aside (UWG §7(2) no. 2, §7(3)).
Can you get sued for sending a cold email?
Sometimes. CAN-SPAM itself gives recipients no right to sue, but state laws against false or misleading emails survive it. For example, Washington gives recipients $100 or actual damages per message, and California up to $1,000 per email (see United States). In the UK and EU, a person who suffers damage can claim compensation (PECR reg. 3013; GDPR art. 8216), and in Germany competitors can sue under UWG §8. Canada’s private right of action never came into force.
Do I need an unsubscribe link, or is “reply to opt out” enough?
The laws accept a reply: the FTC lets you ask people to reply by email or visit a single web page, and the ACMA gives “reply to this email with ‘unsubscribe’” as an example. Gmail is stricter for bulk senders: above 5,000 messages a day to Gmail accounts, marketing messages need one-click unsubscribe and a visible link (Google).
Is cold email the same as spam?
Not in US law: CAN-SPAM sets rules for commercial email rather than banning unsolicited email. In Australia, the Spam Act bans unsolicited commercial messages with an Australian link unless the recipient consented (s. 16), so a cold email without express or inferred consent is exactly what it prohibits.
Sources
- CAN-SPAM Act: A Compliance Guide for Business — Federal Trade Commission, accessed October 2, 2026
- 16 CFR 1.98, Adjustment of civil monetary penalty amounts — eCFR, accessed October 2, 2026
- Civil Penalty Inflation Adjustments, 91 FR 58446 (September 15, 2026) — Federal Trade Commission, Federal Register, accessed October 2, 2026
- FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 2025 and for 2024 — Federal Trade Commission, accessed October 2, 2026
- 15 U.S.C. 7702, Definitions, 7704, Other protections for users of commercial electronic mail, 7706, Enforcement generally and 7707, Effect on other laws — US Government Publishing Office (govinfo.gov), accessed October 2, 2026
- 18 U.S.C. 1030, Fraud and related activity in connection with computers (definition of “protected computer,” (e)(2)(B)) — US Government Publishing Office (govinfo.gov), accessed October 2, 2026
- RCW 19.190, Commercial electronic mail (sections 19.190.020 and 19.190.040) and Engrossed Substitute House Bill 2274, chapter 135, Laws of 2026 — Washington State Legislature, accessed October 2, 2026
- Business and Professions Code section 17529.5 — California Legislative Information, accessed October 2, 2026
- Maryland Code, Commercial Law section 14-3002 — Maryland General Assembly, accessed October 2, 2026
- Electronic mail marketing and What are PECR? (Guide to PECR), and Business-to-business marketing — Information Commissioner’s Office, accessed October 2, 2026
- Right to object, Right to be informed and How do we apply legitimate interests in practice? — Information Commissioner’s Office, accessed October 2, 2026
- Statement on the commencement of the Data (Use and Access) Act (February 5, 2026) — Information Commissioner’s Office, accessed October 2, 2026
- Privacy and Electronic Communications (EC Directive) Regulations 2003, regulations 6, 22, 23 and 30 and Schedule A1 — legislation.gov.uk, accessed October 2, 2026
- UK GDPR, articles 3, 6, 12, 12A, 14, 21 and 82 — legislation.gov.uk, accessed October 2, 2026
- Directive 2002/58/EC (ePrivacy Directive), consolidated text of December 19, 2009, articles 5(3), 13 and 15a (the latest consolidation in the Publications Office’s records) — Publications Office of the European Union, accessed October 2, 2026
- Regulation (EU) 2016/679 (GDPR), OJ L 119, May 4, 2016 (PDF), recital 47 and articles 3, 6, 12, 14, 21, 51, 82 and 83, checked against the English corrigendum of May 23, 2018 — Publications Office of the European Union, accessed October 2, 2026
- Can data received from a third party be used for marketing? — European Commission, accessed October 2, 2026
- Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, version 2.0 (adopted October 7, 2024), paragraphs 47–51 — European Data Protection Board, accessed October 2, 2026
- Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), paragraph 27 (timing of the art. 14 notice) — endorsed by the European Data Protection Board, accessed October 2, 2026
- Gesetz gegen den unlauteren Wettbewerb (UWG), §7 and §8 — German Federal Ministry of Justice (gesetze-im-internet.de), accessed October 2, 2026
- An Act to promote the efficiency and adaptability of the Canadian economy… (CASL), S.C. 2010, c. 23 — Justice Laws Website, current to September 21, 2026, last amended January 1, 2026, accessed October 2, 2026
- Electronic Commerce Protection Regulations (CRTC), SOR/2012-36 and Electronic Commerce Protection Regulations, SOR/2013-221 — Justice Laws Website, both current to September 21, 2026, accessed October 2, 2026
- Spam Act 2003 (Compilation No. 10) and Crimes Act 1914, section 4AA (penalty units) — Federal Register of Legislation, accessed October 2, 2026
- Fines and penalties (penalty unit values) — Australian Securities and Investments Commission, accessed October 2, 2026
- Avoid sending spam — Australian Communications and Media Authority, last updated November 29, 2024, accessed September 29, 2026
- Email sender guidelines and Email sender guidelines FAQ — Google, Gmail Help, accessed October 2, 2026
- Global Blocklist, Email Outreach Plans Comparison (both updated July 13, 2026) and How to Add Unsubscribe Link — Instantly Help Center, accessed October 2, 2026
- Pricing (“Compare features” table) — Instantly, accessed October 2, 2026
- How to add and manage unsubscribe links and Use the Unsubscribes section — lemlist Help Center, accessed October 2, 2026
- Managing unsubscribe requests — Close Help Center, accessed October 2, 2026