Quick disclaimer before anything else: this is a practical overview for sales and RevOps teams, not legal advice. Email compliance law varies by jurisdiction, changes over time, and a rule of thumb that's directionally right can still get a specific campaign wrong. If you're sending meaningful volume into the EU, UK, or Canada, get an actual compliance review from someone licensed to give one. With that said, here's what the primary sources actually say.
The most common misconception: "B2B email is exempt"
It isn't, at least not in the US. The FTC's own CAN-SPAM compliance guide states plainly that the law "makes no exception for business-to-business email." Every commercial email sent to a business contact in the US has to meet the same statutory requirements as a consumer marketing email. That surprises a lot of sales teams who assume cold outreach to a corporate inbox lives in some separate, lighter-touch category. It doesn't.
United States: an opt-out regime, but not a free pass
CAN-SPAM doesn't require consent before you send a first cold email. What it requires is that the email be honest about who sent it, easy to opt out of, and that you actually honor the opt-out. In practice, that means: an accurate "From" line that identifies a real sender, a subject line that isn't deceptive, a functioning unsubscribe mechanism, and a valid physical postal address somewhere in the message.
The stakes for getting this wrong are real. The FTC's maximum civil penalty for a CAN-SPAM violation increased to $53,088 per non-compliant email, effective January 17, 2025, under the FTC's annual inflation adjustment. Penalties apply per email, so the theoretical exposure on a large batch scales fast, though it's worth being clear that this is a statutory ceiling, not a typical outcome; actual settlements have landed far below it. In August 2024, the FTC secured a $2.95 million settlement against security vendor Verkada, the largest CAN-SPAM penalty on record, over more than 30 million commercial emails sent across three years that lacked a working opt-out mechanism, a physical address, and timely processing of unsubscribe requests. It's current, real evidence that CAN-SPAM enforcement against B2B senders isn't a dormant law.
EU and UK: consent isn't required, but you need a documented reason
GDPR flips the default. Rather than an opt-out framework, most lawful B2B cold email in the EU and UK relies on "Legitimate Interest" under GDPR Article 6(1)(f). Recital 47 of the regulation explicitly states that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest," which is the legal hook that makes B2B outreach workable without prior consent in the first place.
The catch: legal commentary is consistent that this isn't automatic. Relying on legitimate interest as your legal basis means you should be able to show you considered why the outreach is a genuine business purpose, why the data you're using is necessary and proportionate to that purpose, and why your interest doesn't override the recipient's privacy expectations. Practically, that means keeping outreach relevant to the recipient's actual professional role, not scraping and blasting broad lists, and giving people a clear way to object.
The UK raised the stakes on this in 2025. The Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025, raised the ICO's maximum fine for electronic marketing violations from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher, aligning email marketing penalties with the headline UK GDPR fine structure. That's a meaningful jump for anyone still budgeting compliance risk against the old £500k ceiling.
Canada: opt-in by default, and the exceptions are narrow
CASL is the strictest of the three. Unlike CAN-SPAM's opt-out model, Canada requires express or implied consent before you send a commercial electronic message, and even the email you'd send to ask for consent counts as a commercial message under the law, so "cold emailing to ask permission" doesn't work as a loophole.
The main practical path for prospecting into Canada without prior consent is what CASL calls conspicuous publication: the recipient's business address has to be publicly published (a company website, a professional directory), that publication can't be accompanied by any statement indicating they don't want unsolicited commercial email, and the message has to be directly relevant to their business role. All three conditions have to hold, not just one. Pitching a CISO on security software fits; pitching the same person on office catering doesn't, because it fails the relevance test.
Canadian enforcement is active. The CRTC's Spam Reporting Centre logged 208,083 complaints between October 2024 and March 2025 alone, and CASL penalties can reach CAD $10 million per violation for organizations. The Government of Canada's own guidance on getting consent and the CRTC's guidance on implied consent are worth reading directly if you're building a Canadian outreach program, since the burden of proving you had a valid basis to send sits with the sender, not the recipient.
The practical takeaway for a cross-border sales motion
The three regimes aren't variations on the same idea, they start from opposite defaults. The US assumes you can send until told to stop. Canada assumes you can't send until you have a basis to. The EU and UK sit in between, permitting outreach without prior consent but expecting you to be able to justify it if asked. A sales team running outreach across all three needs to treat this as a routing problem: US contacts can generally follow an opt-out model, Canadian contacts need a documented consent basis before the first send, and EU/UK contacts need outreach that's genuinely relevant to their role, with a clear, honored opt-out.
One notable UK wrinkle worth knowing: under PECR, the ICO's own guidance distinguishes corporate entities, which can generally be emailed about their business role without prior consent, from sole traders and non-incorporated partnerships, which are treated more like individual consumers and need opt-in consent. It's an easy distinction to miss if your list-building process doesn't separate business structure types.
None of this replaces a proper legal review for your specific program, jurisdictions, and volume. What it should do is make clear that the fastest way to trip one of these rules is the same across all three regimes: sending outreach that isn't genuinely relevant, to lists you can't account for, without an honest way to opt out. That's also, not coincidentally, the same outreach that grades poorly on relevance and quality before it ever gets to a compliance question, which is exactly why catching a weak or overly broad draft before it sends is worth doing regardless of which jurisdiction it's headed to.