You're about to launch a cold email campaign to prospects in three different countries. You've got your list built, your copy written, your infrastructure set up. Then someone mentions compliance, and suddenly you're wondering if you're about to break the law in the UK, Canada, and Australia simultaneously.
This is the reality for any B2B company doing outreach beyond their home country - compliance rules aren't one-size-fits-all, and the penalties for getting it wrong aren't small.
The problem is that most "compliance guides" treat every country the same way. They don't. Some require explicit consent before you email anyone. Some let you email almost anyone as long as you have an unsubscribe button. Some have fines that reach into the millions. Others are barely enforced.
Here's what actually matters when you're sending cold emails across borders.
The Three Compliance Buckets (And Which Countries Fall Into Each)
Instead of looking at every country individually, bucket them into three categories based on how much friction they create for cold email:
Bucket 1: Consent-Required Markets (Opt-In)
These countries require explicit permission before you send a cold email. No exceptions. No "legitimate interest" loophole.
- EU (and UK separately) - GDPR applies. You need documented consent or a lawful basis that's harder to establish than most people think. Maximum fine: 20 million euros or 4% of global turnover, whichever is higher.
- Canada - CASL (Canada's Anti-Spam Law) is the strictest in North America. You need explicit consent, and it's strictly enforced. Fines: up to 15 million CAD for organizations.
- Australia - Spam Act requires consent for commercial emails. Less aggressively enforced than EU/Canada, but the rule is clear.
- South Africa - POPIA (Protection of Personal Information Act) requires consent. Enforcement is ramping up.
If you're targeting these countries, cold email as a volume play doesn't work the same way. You need either:
- Documented prior consent (LinkedIn connections, downloaded resources, previous business contact)
- A legitimate business relationship already established
- Or you're sending to corporate email addresses where the company has a reasonable expectation that business development emails arrive
The third option is where most B2B cold email agencies operate - it's the gray area where you're sending to, say, the marketing director at a company, and treating that as a reasonable commercial communication. It works because enforcement typically focuses on B2C spam (newsletters, promotions), not B2B outreach. But it's not bulletproof.
Bucket 2: Opt-Out Markets (Send First, Comply Later)
- United States - CAN-SPAM lets you send unsolicited emails as long as you have a working unsubscribe link and valid physical address in the email. That's it. No consent needed upfront. Enforcement exists but is sporadic.
- New Zealand - Similar to Australia in theory, but enforcement is lighter and many cold emailers treat it like an opt-out market.
These are the "send and include an unsubscribe" markets. You can cold email anyone with minimal friction. The risk is lower, the compliance is simpler.
Bucket 3: The In-Between Markets
- Singapore, Hong Kong, UAE - Rules exist but are either newer, less clear, or less enforced. Most B2B cold email happens here without incident, but you should still include unsubscribe options and keep records of your outreach rationale.
The Actual Compliance Checklist (By Market)
Stop doing generic compliance - do it by where you're actually sending.
If You're Targeting Bucket 1 (EU, UK, Canada, Australia, South Africa)
- Document your lawful basis for each email sent. This means: either you have prior consent on file, or you have a legitimate business relationship, or the email is to someone in a business development role where this is expected communication.
- Have a working unsubscribe link in every email. Make it obvious, not hidden in gray text at the bottom.
- Include your business physical address and contact information.
- Keep outreach records (dates, who you emailed, what you sent) for 12+ months. If you get a complaint, you need to show your basis for sending.
- If anyone unsubscribes or objects, honor it immediately. Don't send them anything else.
- For GDPR specifically, get granular: if you're emailing EU residents, know whether they're in GDPR scope. Spoiler: most are.
Real example: You're emailing a marketing manager at a UK SaaS company. Your lawful basis could be "legitimate business interest" - you're offering a service relevant to their role, they don't have an "expect no contact" flag, and you're not buying their data from a random list. Document that reasoning and you're defensible.
If You're Targeting Bucket 2 (United States)
- Include a clear, working unsubscribe mechanism (not "reply with STOP" - actual unsubscribe link).
- Include your business address and phone number.
- Include your email address.
- Honor unsubscribe requests within 10 business days.
- Don't use deceptive subject lines (this is the main CAN-SPAM rule that actually gets enforced).
- That's actually it. No consent needed.
This is why US cold email is so much simpler - CAN-SPAM is designed for scale. You send emails, you make it easy to opt out, you're compliant. The catch: ISP filtering and spam complaints matter more here because volume senders get blocked by Gmail/Outlook filters faster.
The Practical Reality: Where Most People Mess Up
Compliance failures don't usually come from not knowing the rules. They come from:
- Not maintaining unsubscribe requests - Someone replies "remove me," and you keep emailing them. This is how you get complaints. Have a system for this. A simple spreadsheet works if you're small.
- Treating all countries the same - Sending a US campaign to UK prospects without adjusting your unsubscribe mechanism or documentation. The email might get delivered, but you're technically not compliant.
- Buying email lists and assuming they're consented - They almost never are. B2C lists are especially bad. Even B2B lists sold as "opted-in" are often questionable. If you're going to use bought data in Bucket 1 countries, you need proof of consent from the list provider, and even then, it's risky.
- No unsubscribe link at all - Some email builders make this easy to skip. Don't. Even in US opt-out markets, ISPs flag emails without unsubscribe options as spam.
Multi-Country Campaigns: The Easiest Approach
If you're running the same campaign to prospects across multiple countries, here's the path of least resistance:
Use the strictest standard for everyone. This means: treat every email like it needs to comply with GDPR, even if you're only sending to 20% GDPR-scoped recipients. It's simpler operationally and you eliminate risk.
That means:
- Have a documented reason for each email (who are you emailing and why)
- Clear unsubscribe link in every email
- Business address and contact info
- Honor unsubscribe requests immediately
This adds almost nothing to your operational load and keeps you compliant everywhere.
When Compliance Gets Complicated
Cold email compliance is straightforward until you're running campaigns across countries at scale. Then you're managing different unsubscribe processes, tracking legal bases per recipient, handling jurisdiction-specific requests, and making sure your email infrastructure is set up correctly for each market. That's where the actual execution starts to slip - not because you don't know the rules, but because managing it across 5+ countries simultaneously while also running replies and optimization is a lot.
If you've got campaigns targeting multiple countries and you want someone to handle the compliance infrastructure so it doesn't become a liability, BEC Growth manages this end-to-end. We structure campaigns by jurisdiction, track compliance documentation, manage unsubscribes correctly per country, and keep your reputation intact while you focus on closing deals.
Related Guides