Cold Email Compliance for Small Business: What You Must Know
In the US, cold email to business prospects is legal under CAN-SPAM as long as you identify yourself honestly, include a physical address, and honour opt-out requests promptly. If you email anyone in the UK or EU, GDPR applies and the requirements are stricter — you need a documented legitimate-interest basis before you send.
Cold email compliance for small business means following CAN-SPAM, understanding GDPR basics, and keeping records. Here is what the rules actually require.
Cold email to business prospects is legal in most jurisdictions, but the rules are specific enough that small mistakes — a missing unsubscribe link, an inaccurate sender name — can result in complaints, deliverability damage, or regulatory attention. Understanding the framework takes less time than you might expect.
The US baseline: CAN-SPAM
The CAN-SPAM Act governs commercial email sent from or to people in the United States. It applies to business-to-business outreach as well as consumer email. The core requirements are straightforward:
- Identify yourself accurately. The From name, reply-to address, and subject line must not be deceptive. You cannot pretend to be someone else or imply a personal relationship that does not exist.
- Include a physical postal address. This can be a registered business address or a P.O. box. It must appear in every commercial email.
- Provide an opt-out mechanism. The recipient must be able to opt out, and you must process that request within ten business days. Once someone has opted out, you cannot email them again.
- Label commercial messages clearly. If the primary purpose of the email is commercial, it must be identifiable as such — though this does not mean you need to write "ADVERTISEMENT" in the subject line.
CAN-SPAM does not require prior consent for cold email, which is why business-to-business outreach is common and legal in the US when done correctly.
UK and EU: GDPR changes the picture
If you are emailing anyone whose data is subject to the General Data Protection Regulation — broadly, anyone located in the UK or EU — the rules are materially different. GDPR does not ban cold email outright, but it requires that you have a lawful basis for processing the recipient's personal data, which includes their email address.
For B2B cold email, most senders rely on legitimate interests as their lawful basis. To do this properly, you need to:
- Document that you have conducted a legitimate interests assessment (LIA) before sending.
- Be able to demonstrate that the outreach is relevant to the recipient's professional role and that a reasonable person in that role would not be surprised to receive it.
- Include an easy opt-out in every email.
- Stop contacting anyone who opts out or objects — immediately, not within ten days.
Sending generic bulk email to a purchased list of EU contacts without this documentation is where most small businesses run into problems. The risk is not just regulatory — complaints can damage your sender reputation faster than a regulator can issue a fine.
Record-keeping: the part most people skip
Compliance is not just about what you send — it is about what you can prove. Maintain records of:
- Where each contact's data came from and when you obtained it
- Any opt-outs received and when they were processed
- The content of emails sent, especially if you are relying on legitimate interests under GDPR
For a small business managing this manually, even a well-maintained spreadsheet is better than nothing. For outreach at any meaningful scale, the record-keeping burden grows quickly.
Practical compliance checklist
| Requirement | CAN-SPAM (US) | GDPR (UK/EU) |
|---|---|---|
| Prior consent required | No | No (if legitimate interests documented) |
| Physical address in email | Yes | Recommended |
| Opt-out mechanism | Yes | Yes |
| Opt-out processing time | 10 business days | Immediately |
| Lawful basis documentation | Not required | Required |
| Data source records | Not required | Required |
What "personalisation" has to do with compliance
There is a practical connection between personalisation and compliance that is easy to miss. A genuinely personalised cold email — one that references the recipient's specific business or role — is far more defensible under a legitimate interests argument than a mass template. It signals that you identified a real reason to contact this specific person, not just that you had their address in a list.
This is one reason that individually written emails tend to perform better on both compliance and response rate grounds. It is also one reason that outreach at scale is harder than it looks: writing genuinely personalised emails to hundreds of prospects, while maintaining opt-out records, managing bounces, and keeping your sending domain healthy, requires more infrastructure than most small business owners have time to build.
What to take away
- CAN-SPAM permits cold B2B email in the US with no prior consent, but you must identify yourself honestly, include a postal address, and honour opt-outs within ten business days.
- GDPR requires a documented legitimate-interests basis before you email UK or EU prospects — silence on this is not a lawful basis.
- Keep records of where contact data came from and every opt-out you receive. You need to be able to demonstrate compliance, not just intend it.
- Genuine personalisation strengthens your legal position under GDPR and improves reply rates at the same time.
- The operational overhead of compliant outreach at scale — sourcing, record-keeping, opt-out management, deliverability monitoring — is substantial and ongoing.