You're running a cold email campaign, and your prospect opens your email. First thing they do? Check your footer. They see no privacy policy link, no unsubscribe button, just a domain name.
That's a legal problem waiting to happen.
Most cold email practitioners either ignore privacy policy requirements entirely or add a generic link to a boilerplate template that doesn't actually address what's in their cold emails. Both approaches cost you deals.
This post is about what your privacy policy actually needs to say when you're sending cold emails, why it matters, and the exact structure that keeps you compliant without burying your prospects in legal jargon.
Why Your Privacy Policy Gets Scrutinized in Cold Email
Privacy policies aren't just nice-to-have legal documents. They're part of how regulators and prospects evaluate whether you're trustworthy.
When someone gets your cold email, they're seeing you for the first time. They don't know your company. If your email footer points to a broken privacy link, or the policy doesn't explain what you do with their email address, they flag you as unprofessional or sketchy. That kills the deal before they even read your value prop.
More importantly, regulators care. The FTC, various state attorneys general, and EU data protection authorities all use privacy policy language as evidence of intent. If your policy says one thing but your email practices say another, you've got a compliance problem.
The specifics depend on your location and your prospect's location. Cold email legal requirements in the US differ from EU rules. But in both cases, transparency is non-negotiable.
What Your Privacy Policy Needs to Cover for Cold Email
1. How You Collected the Email Address
This is the first thing your policy needs to address - and most policies skip it entirely.
You need to state plainly that you source prospect email addresses from public business databases, LinkedIn, company websites, or wherever you actually get them. Not in vague terms. Specifically.
Example language:
We obtain business email addresses from publicly available sources including LinkedIn, ZoomInfo, Apollo.io, Apollo, industry directories, and publicly listed company websites. These addresses are business contact information associated with job titles and companies.
This matters because it distinguishes between scraping (problematic), cold outreach to legitimate business addresses (acceptable in most jurisdictions), and consent-based lists (different category entirely). Your policy clarifies which one you do.
2. What You Do With the Data
This needs to be specific. Not "we use your data to improve our service." That's meaningless.
Your policy should state:
- You send cold emails to the address
- You track whether they open your email and click links (if you do)
- You track replies and forward them to sales staff
- You store the email address in your CRM for follow-up
- You do not sell the email address to third parties
- You delete the address if they unsubscribe (and when)
This transparency actually reduces friction. Prospects respect honesty about how you work.
3. Your Legal Basis for Sending
In the US, your basis is typically "legitimate business interest" - you're reaching out about a relevant service to someone at their work email. You don't need affirmative consent for cold B2B email.
In the EU, the legal basis is narrower and more regulated. Cold email legal requirements in the EU require your privacy policy to explicitly state the legal ground under GDPR - usually that you're relying on legitimate interest, with details about why your outreach is relevant.
Your policy should include:
We send cold emails based on legitimate business interest. Our outreach targets business professionals at companies and agencies where our services are relevant. This constitutes a lawful basis under applicable data protection law because: (1) the recipient has a professional email address associated with their job function, (2) the communication addresses business needs relevant to their role, and (3) the recipient has the right to opt out immediately at no cost.
This language is specific enough to satisfy regulators without being defensive.
4. Retention and Deletion
You need to state how long you keep the email address after they opt out or after the campaign ends.
A reasonable approach: keep the email for 30-90 days after they unsubscribe (to ensure they're actually off your list), then delete it. Keep unopened addresses for 12 months from the last campaign, then delete them. Keep engaged addresses for as long as you're in an active business relationship.
Most cold email platforms (Mailshake, HubSpot, Lemlist, etc.) have built-in retention settings. Your policy should document what you actually do.
5. International Data Transfers (if relevant)
If you're in the US sending to EU addresses, or you're a UK company using US infrastructure, your policy needs to address data transfers.
This gets complex. The short version: you need a legal mechanism (Standard Contractual Clauses, adequacy decision, etc.) and your policy needs to mention it. Most cold email platforms handle this in their own privacy policies, but your company's policy should acknowledge it.
Where to Put This Information
Don't bury this in a massive privacy policy that no one reads. Instead, create a dedicated section:
Privacy Policy Structure:
- Introduction (what this covers)
- Information We Collect (email addresses)
- How We Collect It (public sources - be specific)
- How We Use It (cold outreach, tracking, storage)
- Legal Basis (legitimate business interest, with explanation)
- Your Rights (opt out, deletion request)
- Data Retention (specific timelines)
- Contact Info (who they email if they have concerns)
This should be 400-600 words. It's short enough that prospects actually read it.
The Unsubscribe Connection
Your privacy policy and opt-out requirements are linked. Your policy should state clearly that recipients can unsubscribe from the email footer, and what that means. If your policy says you delete data after unsubscribe but your email footer just removes them from one list, you've created a compliance gap.
Make sure the two actually align.
Why This Matters for Your Campaign Performance
Beyond compliance, this is about signal and conversion.
When a prospect lands on your website from an email and sees a legitimate privacy policy that explains exactly what you're doing, they trust you more. They're more likely to reply, more likely to schedule a call, and more likely to become a client.
When your policy is missing, broken, or vague, they assume the worst. The deal dies in the footer.
The Gap Between Knowing This and Running It at Scale
You can write this policy yourself in a few hours. But when you're running multiple campaigns targeting different regions, to lists from different sources, with different compliance requirements, keeping all of this aligned gets complicated fast.
Your policy needs to actually match what you're doing in every campaign. Prospects click that footer link. If your policy contradicts your email practices, you lose credibility and create legal exposure. That's where most teams stumble - not because they don't understand the requirements, but because they don't have someone ensuring every campaign actually complies with what the policy says.
Related Guides
- Cold Email Data Privacy Guide 2026: What You Actually Need to Know
- Cold Email Opt Out Requirements: What You Actually Need to Do
- Cold Email Legal Requirements in the EU - What You Actually Need to Know
- Cold Email Legal Requirements in the US: What You Actually Need to Know
- Cold Email Privacy Regulations 2026 Outlook: What's Actually Changing (And What Isn't)