Compliance
Cold Email Compliance Checklist for the US, UK, and EU
A practical jurisdiction-aware checklist for sender identity, lawful contact, transparency, opt-out, objections, suppression, and record keeping.
Cold email compliance depends on who receives the message, where they are, what data you use, and why you contact them. The US focuses on truthful commercial email and opt-out duties. UK rules distinguish corporate from individual subscribers and add data-protection requirements. EU outreach requires country-specific ePrivacy analysis alongside GDPR transparency and objection rights.
This guide is a practical risk checklist, not legal advice. Use the Email Compliance Checker as a message-level review checklist and obtain qualified advice for your audience, jurisdiction, and business model.
The universal operating baseline
Apply these controls to every commercial outreach program:
- identify the real sender and business
- use accurate From, Reply-To, routing information, and subject lines
- document the source of each address
- record why the recipient and message are relevant
- determine the applicable jurisdiction and subscriber type
- provide required privacy information at the correct time
- offer a clear, easy, free way to stop marketing
- suppress opt-outs, objections, bounces, and negative intent
- control what vendors and agencies do on your behalf
- keep evidence of the decision and suppression process
Deliverability and compliance overlap here. A message that surprises or traps a recipient can create objections and spam complaints even when the sender believes the targeting is valid.
United States: CAN-SPAM applies to B2B commercial email
The FTC says CAN-SPAM covers commercial messages and makes no exception for business-to-business email.
The operational checklist includes:
- accurate From, To, Reply-To, and routing information
- a subject that reflects the message
- clear disclosure that the message is an advertisement, using a method appropriate to the message
- a valid physical postal address
- a clear and conspicuous opt-out explanation
- an opt-out mechanism that remains available for at least 30 days after the send
- honoring opt-out requests within 10 business days
- no fee, extra personal data, or more than a reply or single web page to opt out
- oversight of vendors sending on your behalf
The FTC guide should control your final review; do not rely on a template copied from another campaign.
United Kingdom: identify the subscriber type first
UK PECR rules treat corporate subscribers differently from individual subscribers such as sole traders and some partnerships.
The ICO says PECR does not require consent for electronic mail marketing to corporate subscribers, but data-protection law still applies when you use personal data such as a named business contact's address. Consent or legitimate interests may be relevant depending on the circumstances, and legitimate interests requires a three-part assessment.
For individual subscribers, unsolicited electronic marketing normally requires consent unless a valid soft opt-in applies. Public availability of an address does not automatically create consent.
The UK checklist:
- classify corporate versus individual subscriber
- document the data-protection lawful basis
- complete a legitimate interests assessment when relying on legitimate interests
- provide required privacy information
- identify the sender
- include a valid contact address and easy opt-out
- stop when the person objects
- keep a do-not-contact record so the address is not re-added
Use the ICO's current guidance because UK rules changed recently and can continue to evolve.
European Union: GDPR plus national ePrivacy rules
There is no single sentence that makes all EU B2B cold email lawful. GDPR governs personal-data processing, while electronic-marketing rules are implemented through national laws. Consent and legitimate-interest analysis can differ by country and context.
At minimum:
- identify each target country
- check its electronic-marketing rule for the recipient type
- document the GDPR lawful basis
- collect only data necessary for the outreach purpose
- provide transparency information no later than the required first-contact point
- make the right to object clear and free
- stop direct-marketing processing when the person objects
- maintain suppression without using the data for new marketing
- review international data transfers and vendor roles where relevant
The European Commission explains that an individual can object at any time to processing for direct marketing and that the organization may no longer process the data for that purpose after the objection.
Compliance by workflow stage
| Stage | Required question | Evidence to keep |
|---|---|---|
| Data collection | Where did the address and personal data come from? | Source, date, fields, provider |
| Targeting | Why is this recipient relevant? | Segment rule and trigger |
| Legal review | Which law, subscriber type, and lawful basis apply? | Assessment and counsel notes where needed |
| Drafting | Is identity, subject, purpose, and opt-out clear? | Approved template version |
| Sending | Are authentication and suppression active? | Test results and system controls |
| Response | How are objections and opt-outs processed? | Timestamped suppression event |
| Review | Did complaints or negative intent expose a flaw? | Incident and corrective action |
Connect this checklist to the one-click unsubscribe guide, the 2026 deliverability checklist, and the Email Complaint Rate Calculator.
Make suppression global, not campaign-specific
The most common operational failure is a valid opt-out followed by a fresh import from another system.
Maintain one enforceable suppression source across the CRM, sales engagement platform, enrichment pipeline, manual sends, and agencies. Store only what is necessary to honor the choice and protect it with appropriate access controls.
For EU and UK programs, distinguish stopping marketing from deleting every record. A limited suppression record may be necessary to ensure the person is not contacted again; the legal and retention design should be reviewed for the specific program.
Is B2B cold email legal in the United States?
US B2B commercial email is covered by CAN-SPAM rather than exempt from it. The sender must meet requirements including accurate identity and subject information, a postal address, a clear opt-out method, timely suppression, and vendor oversight.
Do I need consent for B2B cold email in the UK?
It depends on the subscriber type and data use. PECR generally does not require consent for electronic marketing to corporate subscribers, but individual subscribers receive stronger protection, and UK GDPR still applies when personal data is used. Document the specific analysis.
Does GDPR allow cold email based on legitimate interests?
Legitimate interests may be available in some direct-marketing contexts, but it is not automatic permission. The organization must complete the purpose, necessity, and balancing tests, provide transparency, respect national ePrivacy rules, and stop direct-marketing processing when the person objects.
Sources and next step
Primary sources: the FTC CAN-SPAM compliance guide, ICO business-to-business marketing guidance, ICO electronic-mail marketing guidance, and the European Commission's direct-marketing objection guidance.
Map your audience by country and subscriber type, get legal review where needed, and review the visible message against the Email Compliance Checker before launch.
Folderly Research
Deliverability and cold email strategy team
Folderly Research studies cold email quality, sender reputation, and deliverability patterns across outbound workflows so teams can ship sharper messages without guessing.
Before launch
Review the visible compliance signals in the draft.
Use Folderly's checklist to review sender identity, subject, opt-out, and other message-level controls. Jurisdiction-specific legal review still belongs with qualified counsel.