Yes. Cold email to business contacts is legal in the US under CAN-SPAM, and it's generally permitted in the EU and UK under GDPR and PECR, if you follow the rules: truthful headers, no deceptive subject line, a real physical address, and an honest, easy opt-out that you actually honor.

That "if" is the whole ballgame. The laws that govern cold email don't ban outreach, they ban deceptive and unwanted outreach that ignores the recipient. For an independent recruiter emailing hiring managers about roles you can fill, staying on the right side of the line is genuinely straightforward once you know what each rule actually requires. This guide walks through the two frameworks that matter most for recruiters, US CAN-SPAM and EU/UK GDPR/PECR, plus a note on Canada's stricter regime.

Quick disclaimer: this is general information, not legal advice. Email law varies by jurisdiction and changes over time, and your specific situation may differ. Consult a qualified attorney before building your compliance approach.

The US rule: CAN-SPAM

In the United States, commercial email is governed by the CAN-SPAM Act, enforced by the Federal Trade Commission. The most important thing recruiters misunderstand about it: CAN-SPAM is not consent-based. You do not need someone's permission before sending them a first cold email. You can email a hiring manager you've never met about a role you can help fill, that is legal.

What the law does require is that the message be honest and give the recipient a clean way out. Concretely, a compliant cold email under CAN-SPAM must:

  • Use accurate "From," "Reply-To," and routing information. The header must truthfully identify you or your business as the sender. No spoofing, no disguising who the email is really from.
  • Have a non-deceptive subject line. The subject must reflect what the email is actually about. "Re: our call yesterday" when you've never spoken is exactly the kind of deception the law targets.
  • Identify the message as an outreach message. The email should make clear it's a solicitation, you don't need a giant "ADVERTISEMENT" banner for B2B recruiting outreach, but the recipient shouldn't be misled about why you're writing.
  • Include a valid physical postal address. A real street address, a registered P.O. box, or an equivalent qualifying mailing address for your business must appear in the email. This trips up a lot of solo recruiters working from home, you still need a legitimate postal address on record.
  • Provide a clear, working opt-out. Every message needs an obvious way to tell you to stop, typically an unsubscribe link or a reply-to-opt-out instruction that plainly works.
  • Honor opt-outs promptly. Once someone opts out, you must stop emailing them within 10 business days, and you can't charge a fee, make them log in, or ask for anything beyond an email address to unsubscribe.
  • Not sell or transfer their address after they opt out. An opted-out contact's email can't be sold or handed off to another sender.

One more point worth stressing: you're responsible even when someone else does the sending. If you hire a service or a virtual assistant to run outreach on your behalf, you can't outsource away your CAN-SPAM obligations. Penalties for violations are real and assessed per offending email, so this is not a corner to cut, but you don't need to memorize dollar figures to stay safe. Follow the checklist and you simply won't be in that territory.

The EU and UK rules: GDPR and PECR

Europe is where recruiters get nervous, and often needlessly so. B2B cold email is not banned in the EU or UK. But the framework is different from the US: instead of a "you can email until they say stop" model, GDPR treats an email address that identifies a person as personal data, so you need a lawful basis to process it, and PECR (the UK's ePrivacy rules, mirrored across the EU) governs the electronic marketing message itself.

For B2B outreach to a named individual at a company, the lawful basis most senders rely on is legitimate interest rather than prior consent. Legitimate interest is not a free pass, it requires that your outreach be genuinely relevant to the person's professional role and that their interests don't override yours. For a recruiter, that usually means:

  • Email people whose job actually relates to what you're offering. Writing to a hiring manager or department head about roles in their team is defensible. Blasting a generic info@ list or emailing people whose role has nothing to do with hiring is far weaker ground.
  • Be transparent about who you are and where you got their details. GDPR expects the person to be able to understand why they're hearing from you and how their data is being used, usually via a link to your privacy notice.
  • Offer an easy opt-out in every message, the same practical requirement as the US, and a core PECR obligation.
  • Honor data-subject rights. Under GDPR, people can ask what data you hold, ask you to correct it, or ask you to erase it. You need to be able to act on those requests.

Nuances exist, some EU member states apply stricter interpretations, and messaging a personal-style address (like a sole trader's individual email) can pull you closer to consent territory than emailing a clearly corporate role-based contact. When in doubt on European outreach, keep it tightly relevant, keep the volume sane, and get local advice.

US vs EU at a glance

  US, CAN-SPAM EU / UK, GDPR & PECR
Legal basis to send No prior consent needed; you may send unless the person has opted out. Usually "legitimate interest" for B2B; must be relevant to the recipient's role.
Opt-out Clear opt-out required; honor within 10 business days. Easy opt-out required in every message; honor promptly, plus data-subject rights (access, erasure).
Physical address Valid physical postal address required in every email. Identify who you are and, on request, where data came from; privacy notice expected.
Key risk Deceptive headers/subject lines and ignoring opt-outs. Irrelevant targeting, no lawful basis, or ignoring erasure/opt-out requests.

Canada is stricter: CASL

If you email into Canada, the rules change meaningfully. Canada's Anti-Spam Legislation (CASL) is consent-based: as a default, you need consent, express or, in some cases, implied, before sending a commercial electronic message. Implied consent can arise from an existing business relationship or, in some circumstances, from a business email address a person has published without a "no unsolicited email" notice, but the bar is higher and the exceptions are narrower than US cold email. CASL penalties are significant. If Canadian prospects are part of your desk, treat that segment with extra care and get specific guidance.

The practical compliance checklist

Every cold email you send should: come from an accurate "From" and "Reply-To" that identify you; carry a subject line that honestly reflects the message; be relevant to the recipient's actual role; include your real physical postal address; contain a clear, working opt-out; and be backed by a process that stops emailing anyone who opts out, promptly, and without asking them to jump through hoops. Get those six things right and you're compliant with the substance of both CAN-SPAM and the core of GDPR/PECR.

How the mechanics get handled

Notice that compliance is mostly mechanical: accurate sender identity, a working unsubscribe, and never emailing someone who has opted out. Those are exactly the parts that break when recruiters run outreach by hand, a forgotten address, a unsubscribe request that slips through the cracks, a prospect who said "stop" but gets email number three anyway.

This is one place tooling genuinely helps. GridMail sends from your own Gmail or Google Workspace identity, so the "From" is truthfully you, not a spoofed relay, includes a working one-click unsubscribe in every message, and automatically suppresses anyone who opts out so they never get emailed again. Those are precisely the mechanics compliance requires, handled for you instead of tracked in a spreadsheet you'll eventually forget to check.

Compliance and deliverability are close cousins, too, the same honesty and hygiene that keep you legal also keep you out of the spam folder. If you want to go deeper on the technical side, our guide to cold email deliverability for recruiters covers authentication and inbox placement, the FAQ answers common compliance and setup questions, and our privacy policy shows how we handle data on the platform.

Run compliant outreach without the busywork

GridMail sends from your own inbox, includes a working unsubscribe in every email, and suppresses opt-outs automatically. Get started, plans from $25/mo.

Get started