You're building a cold email operation. You've got a list of 10,000 prospects, you're sending thousands of emails per month, and you're collecting replies, scheduling meetings, and storing client information in your CRM. Here's what nobody wants to say out loud: most agencies and service businesses doing cold email are not handling data the way they should be.
This isn't about being paranoid. It's about understanding what regulations actually apply to your business, what that means operationally, and how to set it up so you're not creating compliance risk while you're trying to grow revenue.
Which regulations actually apply to you?
There are four major frameworks you need to care about:
- GDPR (EU/UK) - applies if you're emailing anyone in the EU or UK, regardless of where your business is located. Heavy fines for violations.
- CAN-SPAM (US) - applies if you're emailing US residents. Much lighter on requirements than GDPR, but people get it wrong anyway.
- CASL (Canada) - applies if you're emailing Canadian residents. Similar strictness to GDPR on the consent side.
- CCPA (California) - applies to California residents. Data handling and deletion rights.
If you're a US-based agency sending mostly to US businesses, CAN-SPAM is your floor. But if your prospect list has any EU contacts - and most B2B lists do - you need GDPR compliance.
CAN-SPAM: the actual requirements
CAN-SPAM is the one most US agencies think they understand but don't. Here's what you actually need:
- Accurate header information - your "From" name and email address must be real and accurate. This is non-negotiable.
- Truthful subject lines - the subject line must relate to the email content. You can't say "Re: Our conversation" if there was no conversation.
- Physical address - you need a real business address in every cold email. Not a PO box, but an actual street address where mail could be received.
- Unsubscribe mechanism - every email needs a working unsubscribe link that actually removes people from your list within 10 business days.
- Monitoring third parties - if you use an email platform or agency to send on your behalf, you're liable for their violations too.
Most people get tripped up on the physical address requirement. It needs to be in every single email - subject line, body, footer, doesn't matter where, but it has to be there. If you're running a distributed team with no office, use your registered business address or a virtual office address (which is legal, as long as it's real).
GDPR: where most people actually fail
GDPR is stricter on a fundamental level. The rule is simple: you need affirmative consent to email someone. No consent = no email, period. No gray area, no "maybe they said yes once," no "they didn't say no."
In practice, this means:
- You can only email EU contacts if they explicitly opted in to receive marketing emails from you.
- A LinkedIn connection is not consent.
- Being on a public prospect list is not consent.
- Someone responding to your first email does not retroactively give you consent for that first email.
- You need to document where and when consent was given.
Here's the practical approach: segment your prospect list geographically. If you have EU contacts, either (a) don't email them, or (b) use an inbound channel first - like LinkedIn messaging or a web form - to establish the relationship and get consent before you email them.
Some agencies get creative here and set up a simple landing page asking "Can we email you about [specific topic]?" Then they only email people who click yes. It works, and it's compliant.
Data handling: what you need to know
Email addresses and prospect information are personal data under both GDPR and CCPA. This creates three operational requirements:
1. Document how you got the data
You need a record of where each prospect list came from. If someone asks (or if regulators ask), you need to explain why you have their email address.
- List broker purchase - keep the receipt and the broker's documentation
- Website form - log the date and the form source
- Manual research - at minimum, document that it was manual
- API/integration - keep records of the data transfer
2. Set data retention limits
You don't keep data forever just because you have it. Under GDPR and CCPA, you keep data "as long as necessary" for its purpose. For a cold email list where someone never replied, that's typically 1-2 years maximum. If they replied and became a lead, you can keep it longer. But set a policy and stick to it.
In practice: delete non-responsive prospects 18 months after the last email. Move responsive prospects/clients to a different retention bucket with a 3-year retention period. Document this policy in writing.
3. Have a deletion/export mechanism
Under GDPR and CCPA, if someone asks you to delete their data or send them a copy of what you have, you have 30 days to do it. Your CRM and email platform need to make this easy, not a nightmare manual process.
Set up a simple form on your website or just put an email address ("[email protected]") that routes deletion requests to someone who can actually execute them in your system. Test it once to make sure it works.
Your infrastructure checklist
Here's what you need in place right now:
- Email platform that supports unsubscribe management (Mailchimp, ActiveCampaign, Lemlist, etc. - the reputable ones all do this)
- CRM with access controls - not everyone on your team needs to see all prospect data
- A documented data source log - where did each list segment come from?
- A written retention policy - how long do you keep non-responsive vs. responsive data?
- Unsubscribe links that actually work and automatically suppress future sends within 10 days
- Business address in your email footer
If you're already running cold email infrastructure that's working, you likely have most of this. The missing piece is usually the documentation.
One thing nobody talks about: list cleaning
Bad data creates compliance risk. When you email an invalid address, it bounces. When you send to role accounts that are monitored by IT departments, they can flag you. When you email the same person twice from different domains because your data is messy, it looks suspicious.
Clean your list regularly. Run it through a verification service before you send. Remove duplicates. Remove known spam traps. This isn't just about deliverability - it's about reducing compliance footprint.
The standard here: bounce rate under 5%, and re-verify lists every 6 months if you're not actively emailing them.
What about third-party tools and platforms?
Your email platform, list broker, and CRM vendor all have access to your prospect data. Under GDPR, you need a "Data Processing Agreement" with each of them. Under CCPA, similar requirement.\p>
Most reputable platforms have a standard DPA template. Just ask them for it. It's a legal document that says "you're handling this data on our behalf and you agree to follow the same rules we do." They usually provide it without pushback.
If a vendor refuses to sign a DPA and you're emailing GDPR-regulated contacts, don't use them.
The gap between knowing this and actually executing it
This guide gives you the framework. What most agencies find is that understanding the regulation is one thing - actually implementing it across email sending, list management, CRM, reply handling, and data retention is another thing entirely.
It's not complicated, but it requires discipline. You need someone or a process ensuring every new campaign meets these requirements, every reply gets properly documented, every unsubscribe is honored, and your data stays clean. If you're managing your cold email operation manually or with a scattered set of tools, that becomes a real operational burden - which is exactly the part most agencies get wrong.