Cold Email Laws by CountryA practical guide for B2B outreach in 2026
CAN-SPAM, GDPR, CASL and more, in plain English. How the rules apply when your list starts as public business data from Google Maps.
Legal··7 min read
Key takeaways
Cold email rules split into two broad families: opt-out models like the US CAN-SPAM Act, and consent-first models like the EU, Canada and Australia
Collecting public business data and sending email are separate legal questions. Compliance for the message sits with the sender
Nearly every regime shares three rules: identify yourself, tell the truth, and give a working unsubscribe. This is educational content, not legal advice
Start here
Two questions, not one
People often ask if cold email is "legal" as though there is a single yes or no answer. In practice there are two separate questions. First, is the way you built your list allowed. Second, is the message you send allowed where the recipient lives.
Building a list from a public source like Google Maps is mostly about the first question. You are noting business names, categories, public phone numbers and addresses. That is generally treated differently from harvesting private personal data, a distinction we cover in is it legal to scrape Google Maps and personal vs business data scraping.
The second question is where country-specific email law lives. A perfectly sourced list can still break the rules if the message ignores local requirements. That is what this guide focuses on.
Build your list from public business data
The Vonsel Chrome extension captures Google Maps business listings straight into your dashboard, so your outreach starts from clean, public data.
Laws change and enforcement varies, so treat the table below as an orientation rather than a checklist. It shows the general posture each region takes toward business-to-business cold email.
Region
Main framework
B2B posture
United States
CAN-SPAM Act
Opt-out
European Union
GDPR + ePrivacy
Varies by state
United Kingdom
UK GDPR + PECR
Corporate lenient
Canada
CASL
Consent-first
Australia
Spam Act 2003
Consent-first
Two clusters emerge. The United States takes an opt-out approach: you may send without prior permission if you meet strict content and unsubscribe rules. Canada and Australia sit at the other end, generally expecting some form of consent before the first message.
United States
CAN-SPAM: an opt-out model
The US CAN-SPAM Act does not require prior consent to send a commercial email. Instead it sets rules for how the message must look and behave. The Federal Trade Commission maintains a clear CAN-SPAM compliance guide that spells out the basics.
In short: no deceptive subject lines or headers, a clear disclosure that the message is an ad where relevant, a valid physical postal address, and a working opt-out that you honor promptly. We go deeper on how this touches scraped lists in CAN-SPAM and scraped leads.
Europe
GDPR and ePrivacy: consent and legitimate interest
Europe is the most nuanced region. The General Data Protection Regulation governs how you handle personal data, while the ePrivacy rules govern electronic marketing. For B2B, some member states allow contacting a business role address under a legitimate interest basis, while others are stricter.
A named individual's work email can still be personal data, which means transparency, a lawful basis, and the right to object all matter. For the interaction between scraping and GDPR, see Google Maps scraping and GDPR and the broader question in do you need consent to email businesses.
The United Kingdom follows a related path under UK GDPR and PECR. Messages to corporate subscribers, meaning companies rather than named people, tend to be treated more leniently than messages to individuals and sole traders, though an easy opt-out is always expected.
A useful mental model: the United States asks "did you give people an easy way out", while much of Europe, Canada and Australia also ask "did you have a good reason to email in the first place". Design your outreach to satisfy both questions and you travel well across borders.
Canada and Australia
Consent-first regimes
Canada's Anti-Spam Legislation is one of the strictest frameworks in the world. It generally expects express or implied consent before you send a commercial electronic message, along with clear identification and a functioning unsubscribe. The regulator publishes guidance on the CASL requirements.
Australia's Spam Act 2003 takes a similar consent-based stance, again pairing permission with sender identification and an unsubscribe option. Implied consent can exist in some business contexts, for example where a business has published an address without a "no unsolicited email" note, but the safe reading is to treat these markets as consent-first.
The common ground
Rules that travel almost everywhere
Rather than memorize every statute, build outreach that respects the shared core. If you do these four things, you are aligned with the spirit of most regimes at once.
Identify yourself
Use a real sender name and a valid physical or business address. Do not hide who is behind the message. Anonymity is a red flag under almost every framework.
Tell the truth
Accurate subject lines and headers, no misleading "Re:" tricks, and honest claims. Deception is the fastest way to turn a legal message into an unlawful one.
Offer an easy exit
Include a clear unsubscribe that works without extra hoops, and process opt-outs promptly. This single rule is close to universal.
Respect consent where required
In consent-first markets, have a basis to contact before you send, and keep records. When in doubt, treat the stricter rule as your default.
Turn public listings into a workable list
Capture Google Maps businesses with the Vonsel extension, then organize and prioritize them inside the mapped dashboard before you write a single email.
The extension is the means, the dashboard is the end
The Vonsel Chrome extension is a way to gather public business data from Google Maps without copying rows by hand. It is free, with no trial and no card, because capturing listings is only the first step. The value is in what you do next.
Inside the Vonsel dashboard, those businesses land in a mapped CRM. Email Intelligence can draft a message tailored to each business, and Reviews Intelligence surfaces the context that makes outreach relevant rather than generic. That relevance matters legally too, since a targeted, useful message is easier to justify than a blast.
The law rarely punishes a relevant, honest, easy-to-leave message. It punishes noise.
Practical footing
A simple way to stay on the right side
Know where your recipient is and apply the stricter of the two frameworks in play, yours and theirs. Keep your list clean, keep records of opt-outs, and never reuse a stale list you cannot account for. Our safe scraping checklist pairs well with this on the data side.
Finally, remember scope. This article explains general concepts and cannot cover every jurisdiction, exception, or recent update. For anything with real stakes, talk to a qualified lawyer in the relevant country before you press send.
Start from clean, public data
Add the Vonsel extension and capture Google Maps businesses into a dashboard built for relevant, organized outreach. Explore features or browse the Legal blog.
In many countries B2B cold email is permitted when you follow local rules. The United States uses an opt-out model under CAN-SPAM, while the European Union, Canada and Australia lean toward consent-based frameworks with strict identification and unsubscribe requirements. The exact obligations depend on where the recipient is located and whether you are contacting a business address or a named individual. This article is educational and not legal advice.
Does scraping business data from Google Maps make my cold email illegal?
Collecting public business details and sending email are two separate legal questions. Gathering names, categories, phone numbers and public addresses of businesses is generally different from processing private personal data, but how you then contact people is governed by email and privacy law. Compliance for the message sits with the sender: honor unsubscribe requests, identify yourself, and respect consent rules where they apply.
What are the common requirements across cold email laws?
Most regimes share a core set of rules: identify who you are with a real physical or business address, do not use misleading subject lines or headers, provide a working and easy unsubscribe mechanism, and stop contacting people who opt out. Consent requirements vary, but transparency and an easy exit are nearly universal.