Something Inc.LoginSchedule a free consultation
STRATEGY

Cold email compliance in 2026: the country by country decision table

Most outbound teams are following one rulebook when there are two. The law says who you may email. The mailbox providers say who reaches the inbox. They have different triggers, different penalties, and confusing them is how a compliant campaign still gets filtered and a delivered campaign still gets a complaint.

STRATEGYCOLD EMAILSEP 2026

Ask an outbound team whether their sending is compliant and you will usually get an answer about authentication records and unsubscribe links. Both of those are real requirements. Neither of them answers the question, because the question has two halves that people keep collapsing into one.

The first half is legal. It asks whether you are permitted to send an unsolicited commercial message to this person in this jurisdiction, and it is answered by statute. The second half is operational. It asks whether a mailbox provider will place your message in an inbox, and it is answered by policy that the provider writes and can change without notice. Cold email compliance means clearing both. Most programs we audit are clearing one and assuming it covers the other.

$53,088
the maximum civil penalty per violating email under the United States CAN-SPAM Act, adjusted for inflation
$10M
the ceiling for corporate penalties under Canada's anti-spam legislation, in Canadian dollars
4%
of global annual turnover, the upper bound for the most serious tier of data protection fines in the European Union
5,000
daily messages to consumer mailboxes, the threshold where provider bulk sender rules bite regardless of any law

Two rulebooks, not one

The legal rulebook varies by the recipient's country and, in some cases, by whether the recipient is a company or a sole trader. It carries real penalties, enforced rarely but publicly. Its remedy when you get it wrong is a complaint, an investigation, or a fine.

The provider rulebook is written by Google, Microsoft and Yahoo, applies to their consumer mailboxes, triggers on volume rather than on geography, and carries no legal penalty at all. Its remedy when you get it wrong is that your mail stops arriving. That is a worse outcome for most outbound programs than any fine they will realistically face, which is why teams optimize for it and then assume the legal question is handled.

THE PRACTICAL CONSEQUENCEA campaign can be fully authenticated, under every provider threshold, landing in the inbox, and still be unlawful in the recipient's country. It can also be legally impeccable and completely undeliverable. These failures look nothing alike in your reporting, and the deliverability half is the one we have written about most, including which published thresholds are actually evidence. This piece is about the half that never shows up in a dashboard.

Two more framing notes before the table. Jurisdiction usually follows the recipient rather than the sender, so a United States company emailing a prospect in Toronto is operating under Canadian rules. And none of this is legal advice. It is the decision structure we use to scope a program and to know when a real lawyer needs to be in the room, which for most teams is at the point of entering a new market rather than at every campaign.

Cold email compliance by jurisdiction, in one table

JURISDICTIONGOVERNING RULEPRIOR CONSENT FOR B2BALWAYS REQUIREDPENALTY CEILING
United StatesCAN-SPAM ActNoAccurate sender identity, honest subject line, physical postal address, working opt-out honored within 10 business daysUp to $53,088 per email
CanadaAnti-spam legislation, enforced by the CRTCYes, express or implied. A conspicuously published business address can supply implied consent when the message is relevant to the roleSender identification, contact information, functional unsubscribeUp to $1M individuals, $10M organizations, in Canadian dollars
European UnionData protection law plus each member state's electronic communications rulesVaries by state. Several permit business contact outreach on a legitimate interest basis, others require prior consentA documented lawful basis, identity disclosure, opt-out, and the ability to answer a data subject requestUp to 4% of global annual turnover at the highest tier
United KingdomElectronic communications regulations plus data protection lawNo for corporate subscribers such as companies and limited liability partnerships. Yes for sole traders and unincorporated partnerships, who are treated as individualsIdentity disclosure, opt-out, lawful basis for the personal dataData protection fines at the same top tier as the European Union
AustraliaSpam Act 2003, enforced by the ACMAYes, express or inferred. A work address published without a no-unsolicited statement can supply inferred consent when the message relates to the roleSender identification, accurate contact details, functional unsubscribeCivil penalties per contravention, escalating with repetition
IndiaDigital Personal Data Protection Act 2023Yes, processing requires a lawful purpose and noticeNotice, purpose limitation, a route to withdrawPenalties set per contravention under the Act

Read down the consent column and the pattern is clear. The United States is the outlier that most outbound tooling was designed around, and the United Kingdom's corporate subscriber carve out is the other genuinely permissive position. Canada and Australia both allow a form of consent you do not have to collect, which is the detail teams miss most often, because the phrase implied consent sounds like a loophole and is in fact a specific, documented, and auditable condition.

That condition is worth stating carefully, because it is the difference between a defensible program and an indefensible one in two large markets. The address has to be published where you found it, published without any statement refusing unsolicited commercial messages, and your message has to be relevant to the role that address represents. Guidance on the Canadian version is published by the CRTC and the United Kingdom's business to business position is set out by the ICO. Both are short and worth reading in full once.

The word published is doing enormous work in that sentence. An address you inferred from a naming pattern was not published. An address a data vendor sold you may or may not have been published, and you cannot demonstrate which. That distinction is not academic once someone complains, and it is the reason we treat guessed addresses as a separate risk category entirely, which we set out in what a guessed address costs you under European rules.

Where the mailbox providers draw a different line

Now the other rulebook. Google, Yahoo and Microsoft each publish bulk sender requirements that bite at roughly 5,000 messages a day to their consumer mailboxes. They require authentication records, alignment, one click unsubscribe, and a spam complaint rate kept below a published ceiling. None of that is law. All of it is enforced far more aggressively than any statute in this article, because the enforcement is automatic and immediate.

The overlap between the two rulebooks is smaller than people assume. Authentication is not a legal requirement anywhere in the table above. A physical postal address is a legal requirement in the United States and is not something any provider checks. One click unsubscribe is a provider requirement whose legal cousin, a functional opt-out, is satisfied by a plain link. Teams that built their compliance checklist from provider documentation therefore have gaps in exactly the places the law cares about, and teams that built it from statute have gaps in exactly the places their delivery rate cares about.

REQUIREMENTSOURCETRIGGERCONSEQUENCE OF FAILURE
Prior or implied consentStatute, varies by countryRecipient location and entity typeComplaint, investigation, fine
Physical postal address in the messageStatute, United StatesAny commercial messagePer message civil penalty
Opt-out honored within a set windowStatute, most jurisdictionsAny commercial messagePer message civil penalty
SPF, DKIM and DMARC alignmentProvider policyVolume to consumer mailboxesFiltering or rejection
One click unsubscribe headerProvider policyBulk sendingFiltering or rejection
Spam complaint rate under the published ceilingProvider policyAll sendingReputation damage, then filtering

One nuance that saves a lot of wasted effort. The provider bulk thresholds are written against consumer mailboxes, and most business to business outbound is landing in corporate tenants rather than in personal accounts. That does not make the requirements optional, because filtering decisions still draw on the same reputation signals, but it does mean the specific 5,000 a day trigger is often not the constraint teams think it is. We took that argument apart separately in why the sending domain threshold most teams use is the wrong one.

Where teams actually get caught

In practice, enforcement and damage rarely come from the exotic edge of the rules. Four patterns account for nearly everything we see.

01One template, every marketA sequence written for United States recipients, with no postal address because the writer did not know it was required, sent unchanged into Canada, the United Kingdom and Australia. It fails the American rule it was written for and ignores the consent question everywhere else. The fix costs an hour: one template variant per legal region, with the required elements built into the layout rather than remembered.
02Consent that cannot be evidencedThe team believes the addresses were published. Nobody recorded where. When a complaint arrives, the only available answer is that a vendor supplied the list, which is not a defense in a jurisdiction requiring implied consent to be demonstrable. Record the source and the date at import, as a field, not as a shared understanding.
03Unsubscribe handled by the tool, not by the businessThe sending platform suppresses the address. The customer relationship system does not know, so a different team emails the same person six weeks later from a different sender. Suppression has to be global and it has to survive a tool migration, which is the moment it usually breaks.
04Compliance treated as a launch taskThe rules were checked when the program started and never since. Provider policy changed twice in the intervening year and one market was added without review. Compliance is a quarterly review of a short checklist, not a one time clearance, and thirty minutes a quarter is genuinely enough to keep it current.

Notice that three of those four are record keeping failures rather than legal misunderstandings. That is the general shape of this problem at the scale most outbound teams operate. The rules are not especially hard. Proving after the fact that you followed them is hard, and it is only hard because nobody built the field that would have made it easy.

Running cold email compliance without a lawyer on retainer

Four controls. They are cheap, they are one time work with a quarterly review, and together they cover the realistic risk for a business to business program.

Segment the list by legal region before anything elseNot by country, by rule. United States. United Kingdom corporate subscribers. Canada and Australia, which share an implied consent shape. European Union member states, which need per state handling. Everything else, held until reviewed. Four segments cover most books of business and each one gets its own template variant.
Make provenance a required field at importSource URL and capture date on every record, populated at import or the import fails. This is the single highest value control in the list because it converts an unanswerable question into a lookup, and because it also quietly improves list quality by making bad sources visible.
Put the required elements in the template, not the checklistPhysical address, sender identity and opt-out belong in the layout so they cannot be forgotten by an individual writer under deadline. Anything that depends on a person remembering will eventually be forgotten by a person in a hurry.
Keep one suppression list, above the toolsGlobal, permanent, owned by the business rather than by whichever platform you are using this year. Every sending system reads from it. This is also the control that survives a tooling change, which is when most suppression failures happen.

For most teams that is the whole program, and the residual risk left over is acceptable and understood. Bring in actual counsel for three situations: entering the European Union at volume, any consumer facing sending, and any market not in the table above. Those are the cases where the general shape stops being a reliable guide and the specifics start to matter more than the pattern.

It is worth saying plainly that compliance work of this kind has a return beyond risk. Provenance fields improve targeting. Regional segmentation improves relevance. A global suppression list stops the single most reliable way to annoy a prospect, which is emailing them again after they asked you not to. The credibility cost of getting this wrong is now higher than it used to be, because a prospect who is unsure about you increasingly checks in an answer engine rather than on your site, which we covered in what happens to sender credibility when buyers verify you in AI answers.

DO THIS NEXTOpen your list and check whether a source field exists and is populated. If it is not, that is the first fix, because everything else in this article depends on being able to answer where an address came from. Then split the sequence into region variants and confirm the United States variant carries a postal address. Both jobs fit in an afternoon. If outbound is a material channel and nobody owns this, it is the first thing we scope on a cold email engagement, and it is usually the cheapest risk reduction available to a B2B team in a quarter.

See where you are cited today

A free snapshot audit of your rankings and AI citations before we ever talk.

TT
Tyler TruffiMANAGING PARTNER, SOMETHING INC.

Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.

Free consultation

Let us be the last SEO agency you ever work with

A 30 minute call and a free audit of your SEO and GEO position. You keep the findings either way.