Skip to content

Cold Email Laws by Country: The 28-Country Comparison Table (2026)

September 27, 2026. Cold email to a business contact needs prior consent in 12 of the 28 countries covered in this table, is allowed on the strength of a conspicuously published business address in 4, is allowed to businesses without prior consent in 7 provided the sender is identified and opt-outs are honoured, and sits under general data protection or consumer law rather than an anti-spam statute in the remaining 5. Those four groups, not "GDPR or not", are the split that decides whether a sequence is lawful. Every row below links to the full country guide, which quotes the statute, the regulator's own guidance and the published cases.

Cold email laws by country: the 28-country comparison table

Key numbers

ItemNumber
Countries requiring prior consent for B2B email, no business exception (of 28)12
Countries where a published business address can supply consent4
Countries allowing B2B email with identification and opt-out duties7
Countries with no email-specific anti-spam statute5
United States, civil penalty per email (CAN-SPAM, 2025 adjustment)USD 53,088
United Kingdom, PECR fine ceiling since 5 Feb 2026GBP 17.5m or 4%
Canada, maximum per violation for an organisation (CASL)CAD 10,000,000
Netherlands, ACM maximum per violationEUR 900,000 or 1%
Shortest unsubscribe deadline in the table (Qatar mainland)2 business days
New Zealand unsubscribe deadline5 working days
United States, Singapore and Hong Kong unsubscribe deadline10 business or working days

Statutes and regulator pages read on 26 and 27 September 2026; the linked country guides cite each provision.

The table: 28 countries, one row each

Each country name links to its full guide. Read the third column first. "No" means a prior, provable consent is required before the first email to a business contact, and the guide explains the narrow exceptions. "Yes" means the law permits the send to a business without prior consent, and the fourth and fifth columns tell you who enforces it and what a breach costs on paper. Penalties are quoted as the law writes them, in the local currency, and the linked guide records what regulators have actually imposed.

Country (links to the guide)Governing lawB2B cold email without prior consent?RegulatorMaximum penalty as written
Austria
Prior consent, no business exception
Telecommunications Act 2021, s.174No. Prior consent for every recipient, business included; the ECG list is a refusal list, not a permission listFernmeldebuero (telecom offices); RTR keeps the ECG listUp to EUR 50,000 per case (s.188 TKG); published cases 500 to 800 euro per email
Belgium
Prior consent, no business exception
Code of Economic Law, Art. XII.13 and the Royal Decree of 4 April 2003No for named addresses (firstname.lastname@). Impersonal company addresses such as info@ are exempt; the DPA rejected legitimate interest in 2025Data Protection Authority; FPS EconomyCriminal fine of 26 to 25,000 euro, multiplied by ten since 1 Feb 2026, or 6 percent of turnover if higher; 50,000 euro base for bad faith
Denmark
Prior consent, no business exception
Marketing Practices Act, s.10(1)No. "Anyone" covers consumers, companies and public bodies; named and generic addresses treated the sameConsumer OmbudsmanTariff from DKK 20,000 per count (1 to 30 contacts), rising with volume; each campaign and each sender identity is a separate count
Germany
Prior consent, no business exception
Act against Unfair Competition (UWG), s.7(2) no. 2No. Email advertising without prior express consent is an unacceptable nuisance for any addressee; s.7(3) existing-customer exception onlyCourts, on action by competitors and consumer bodies; data protection authorities for the GDPR sideInjunctions, warning-letter costs and damages under the UWG; GDPR fines up to 4 percent of turnover for the data side
Italy
Prior consent, no business exception
Privacy Code (Legislative Decree 196/2003), Art. 130No. Consent required, and since 2012 companies are covered too; no legitimate-interest route (Garante, 12 Feb 2026)Garante per la protezione dei dati personaliGDPR ceiling: EUR 20 million or 4 percent of worldwide turnover
Netherlands
Prior consent, no business exception
Telecommunicatiewet, Art. 11.7No. Sender must prove prior consent, businesses included; two narrow exceptions for addresses a company published specifically for offersAuthority for Consumers and Markets (ACM)Up to EUR 900,000 per violation or 1 percent of turnover, doubled for a repeat within five years
Spain
Prior consent, no business exception
LSSI (Ley 34/2002), Art. 21No. Prior express permission, no B2B exemption, no legitimate-interest route (AEPD report 0164/2018)AEPDThree bands: up to EUR 30,000, 30,001 to 150,000, 150,001 to 600,000 (Art. 38 to 40 LSSI)
Switzerland
Prior consent, no business exception
Federal Act on Unfair Competition, Art. 3(1)(o)No. Prior consent, correct sender and a free refusal route; no business carve-outSECO on complaint; criminal courts under Art. 23Wilful breach is a criminal offence: up to three years custodial sentence or a monetary penalty
South Africa
Prior consent, no business exception
POPIA, s.69No. Direct marketing by email only with consent or to an existing customer; one consent request allowed (Form 4); companies are protected tooInformation RegulatorAdministrative fine up to R10 million (s.109); ignoring an enforcement notice carries up to 10 years (s.107)
South Korea
Prior consent, no business exception
Network Act, Art. 50No. Express prior consent; the only exceptions are recent customers (six months) and voice telemarketing under the Door-to-Door Sales Act; consent re-verified every two yearsKorea Communications CommissionAdministrative fine up to KRW 30 million (Art. 76)
Qatar
Prior consent, no business exception
Law No. 13 of 2016, Art. 22 (mainland); QFC Data Protection Regulations 2021 (QFC)No on the mainland: prior consent, no B2B carve-out. Inside the Qatar Financial Centre firms may send on legitimate interests and must stop on objectionNational Cyber Security Agency (mainland); QFC Data Protection OfficeUp to QAR 1,000,000 (Art. 23), the same ceiling for a legal person (Art. 25); mainland marketing barred 21:00 to 09:00
Saudi Arabia
Prior consent, no business exception
CST Regulations for Curbing SPAM Messages and Calls; Telecommunications and IT Law (Royal Decree M/106)No. Promotional messages are blocked by default and need an express, recorded choice; consent buried in a privacy policy is disregardedCommunications, Space and Technology Commission (CST); SDAIA for the PDPLUp to SAR 25 million under Art. 27 of the Telecommunications and IT Law
Australia
Consent, but a published business address can supply it
Spam Act 2003, Schedule 2 cl. 4Consent required, but it may be inferred from an address conspicuously published for a work role, if the message relates to that role and no "no unsolicited messages" statement accompanies the addressACMACivil penalties in penalty units, up to 10,000 units a day for a body corporate with a prior record (s.25); one unit is AUD 330
Canada
Consent, but a published business address can supply it
CASL (S.C. 2010, c. 23), s.6 and s.10(9)Consent required, but implied where the address was conspicuously published without a no-unsolicited-messages statement and the message is relevant to the recipient's business roleCRTCUp to CAD 10,000,000 per violation for an organisation, CAD 1,000,000 for an individual
New Zealand
Consent, but a published business address can supply it
Unsolicited Electronic Messages Act 2007, s.4 and s.9 to 11Consent required; deemed for an address conspicuously published in a business capacity, with no refusal statement, where the message is relevant to that role. A .nz address alone creates a New Zealand linkDepartment of Internal AffairsUp to NZD 500,000 for an organisation (s.45(4)); unsubscribe must take effect within 5 working days
Japan
Consent, but a published business address can supply it
Act on Regulation of Transmission of Specified Electronic Mail, Art. 3Opt-in since 2008, with a statutory exception for an organisation or business individual that has disclosed its own email address; records of the basis must be keptMinistry of Internal Affairs and Communications; Consumer Affairs AgencyUp to JPY 1 million or one year for the sender (Art. 34); up to JPY 30 million for the company (Art. 37)
United States
Allowed to businesses with identification and opt-out duties
CAN-SPAM Act of 2003Yes. Opt-out regime: truthful headers and subject, physical postal address, working unsubscribe honoured within 10 business days, no sending after opt-outFederal Trade CommissionCivil penalty up to USD 53,088 per email (2025 inflation adjustment)
United Kingdom
Allowed to businesses with identification and opt-out duties
PECR 2003, reg. 22 and 23; UK GDPR for the personal dataYes to corporate bodies (companies, LLPs, public bodies) with sender identity and an opt-out route. Individuals and sole traders need consent or the soft opt-inInformation Commissioner's OfficeSince 5 Feb 2026, up to GBP 17.5 million or 4 percent of worldwide turnover for PECR reg. 19 to 24 breaches
Ireland
Allowed to businesses with identification and opt-out duties
S.I. 336/2011, reg. 13Yes for company addresses until the company objects; a named work address may be emailed when it is used mainly for the recipient's commercial activity and the message relates solely to itData Protection CommissionEUR 5,000 per email on summary conviction; up to EUR 250,000 on indictment
Sweden
Allowed to businesses with identification and opt-out duties
Marketing Act (2008:486), s.19 and 20Yes to legal persons, provided every email carries a valid opt-out address and objections are honoured. Natural persons, including sole traders, need prior consentConsumer Ombudsman (Konsumentverket)Market disruption fee of SEK 10,000 up to 4 percent of turnover (s.31), or up to EUR 2 million where turnover is unknown
France
Allowed to businesses with identification and opt-out duties
CPCE Art. L34-5 and CNIL doctrine (page dated 10 June 2026)Yes on legitimate interest when the message relates to the recipient's profession, with information at collection and a simple, free objection route; generic addresses such as info@ are outside the ruleCNILCNIL sanctions up to the GDPR ceiling of EUR 20 million or 4 percent of turnover
Hong Kong
Allowed to businesses with identification and opt-out duties
Unsolicited Electronic Messages Ordinance (UEMO); Personal Data (Privacy) Ordinance (PDPO)Yes under the UEMO opt-out rules: accurate sender details, working unsubscribe honoured within 10 working days, honest subject line. Using a named person's data for direct marketing engages the PDPOOFCA (UEMO); Privacy Commissioner (PDPO)UEMO: enforcement notice, then HKD 100,000, HKD 500,000 on repeat. PDPO direct-marketing offences: HKD 500,000 and three years
Singapore
Allowed to businesses with identification and opt-out duties
Spam Control Act 2007 (bulk unsolicited commercial email)Yes. Bulk unsolicited commercial email must carry the label "<ADV>" in the subject, accurate header information, a working unsubscribe facility honoured within 10 business daysCivil action by recipients; IMDA and PDPC for the wider frameworkStatutory damages up to SGD 25 per message, capped at SGD 1 million (s.14)
India
No email-specific anti-spam statute
No anti-spam email statute; Digital Personal Data Protection Act 2023 (substantive duties from 13 May 2027 under the 2025 Rules)No email-specific consent rule today. TRAI rules cover commercial calls and SMS, not email. The DPDP Act will make consent the main basis for personal data once in forceData Protection Board of India (being constituted); TRAI for calls and SMSDPDP Act Schedule penalties, up to INR 250 crore for the most serious breaches, once in force
United Arab Emirates
No email-specific anti-spam statute
No email-specific statute; PDPL (Federal Decree-Law 45/2021) right to object; TDRA Unsolicited Electronic Communications policy binds licensees; separate DIFC and ADGM regimesNo consent rule specific to email. A recipient may object to direct marketing under the PDPL, and calls and SMS need consent under Cabinet Decision 56/2024 and the TDRA policyTDRA; UAE Data Office; DIFC and ADGM commissioners inside the free zonesNo email-specific fine; PDPL and TDRA sanctions apply
Mexico
No email-specific anti-spam statute
Federal Consumer Protection Law (LFPC), Art. 17 and 18 BIS; LFPDPPP (2025) for personal dataNo prior consent rule. Every commercial email must state the provider's and sender's name, address and phone, and PROFECO's own contact details; no sending to anyone who has said stop. Companies buying for their own use count as consumersPROFECO; Secretaria Anticorrupcion y Buen Gobierno for data protectionCoercive PROFECO measures (fines from 380.44 to 38,044.47 pesos for disobeying its orders); no separate spam tariff quoted in the law
Brazil
No email-specific anti-spam statute
LGPD (Law 13.709/2018), Art. 7 IX and Art. 10; no anti-spam statuteNo prior consent rule. Legitimate interest is available with a documented balancing test limited to strictly necessary data; the first ANPD fine ever issued concerned a contact listANPD2 percent of Brazilian revenue, capped at BRL 50 million per infraction (Art. 52)
Philippines
No email-specific anti-spam statute
Data Privacy Act 2012 (RA 10173); NPC Advisory Opinion 2023-016; no anti-spam statuteNo prior consent rule. The NPC accepts legitimate interest for contacting potential customers; consent becomes mandatory the moment the record holds sensitive data such as education or ageNational Privacy CommissionUnauthorised processing: one to three years and PHP 500,000 to 2,000,000 (s.25(a)); maximum mandatory when 100 or more people are affected

The rows were compiled from our 28 country guides. The ten guides published in March 2026 (Australia, Canada, France, Germany, India, Singapore, Sweden, the UAE, the United Kingdom and the United States) were re-checked for this table against the statute or regulator page on 26 and 27 September 2026, and the penalty figures above are the current ones, not the ones in those older guides.

Bar chart of the number of countries in each cold email regime
Our 28 country guides, re-checked against primary sources. Source: imisofts.com, September 2026.

Group A: prior consent, no business exception (12 countries)

Austria, Belgium, Denmark, Germany, Italy, Netherlands, Spain, Switzerland, South Africa, South Korea, Qatar, Saudi Arabia. In every one of these, a published info@ or firstname.lastname@ address is not consent, an unsubscribe link does not cure an unsolicited email, and the sender carries the burden of proof. Three details from the guides matter more than the headline rule. Belgium and Denmark both treat an email that asks for marketing consent as marketing in itself, so you cannot email to obtain permission. Austria and Denmark both count fines per email or per sender identity, which prices the standard three-step sequence across rotating domains rather than the campaign as a whole. Italy is the outlier that lets you use the phone first: a live operator call to a number in a public directory, not on the opposition register, may be used to ask for email consent.

Group B: consent, but a published business address can supply it (4 countries)

Australia, Canada, New Zealand, Japan. All four statutes contain the same three-part test in slightly different words: the address was conspicuously published by that person in a business or official capacity, the publication does not say the holder refuses unsolicited messages, and the message is relevant to that person's role, business, functions or duties. A scraped list fails the test whenever any of the three parts is missing, and a purchased list fails it by default because you cannot show where each address was published. Japan adds a record-keeping duty: the basis for each send has to be stored in the form the ordinance prescribes.

Group C: allowed to businesses with identification and opt-out duties (7 countries)

United States, United Kingdom, Ireland, Sweden, France, Hong Kong, Singapore. These are the markets most outbound teams treat as "open", and the duties are real. The United States wants truthful headers, a postal address and an unsubscribe honoured within ten business days. Singapore wants the literal label "<ADV>" in the subject line of bulk unsolicited commercial email and an unsubscribe facility honoured within ten business days. Hong Kong gives ten working days, New Zealand in Group B gives five, Qatar's mainland spam regulation gives two. The United Kingdom, Ireland and Sweden draw the line at the recipient's legal form rather than at the address: a company can be emailed, a sole trader or an individual cannot without consent. France allows business prospecting on legitimate interest only where the offer relates to the person's profession, and the CNIL page that says so was last updated on 10 June 2026.

Group D: no email-specific anti-spam statute (5 countries)

India, United Arab Emirates, Mexico, Brazil, Philippines. The absence of a spam law is not the absence of rules. Mexico's consumer law requires the email itself to carry the provider's details and PROFECO's own contact details, and treats a company buying for its own use as a consumer. Brazil and the Philippines both accept legitimate interest and both punished the list, not the email, in their first enforcement actions. India's Digital Personal Data Protection Act takes full effect on 13 May 2027 under the Rules notified on 13 November 2025, so a sequence built today should already keep a consent or legitimate-interest record per contact. The UAE regulates calls and SMS through the TDRA and Cabinet Decision 56/2024 and leaves email to the general right to object under the PDPL, with separate regimes inside the DIFC and ADGM.

What every sequence needs regardless of country

Four duties appear in almost every statute in the table, so a sequence that skips any of them is unlawful somewhere in the list before you even reach the consent question: a sender who is identified by name and a working reply address; a free, one-step way to stop, honoured within the shortest deadline in your target list; suppression that is applied per address and per sender domain, because Denmark and Austria count each sending identity separately; and a record per contact of the basis you rely on, which Japan and the Netherlands require in terms and the ACM says you must be able to produce five years later. Those duties are technical as much as legal. Domains, mailboxes, one-click unsubscribe headers and suppression lists are set up once in the sending layer, which is the part of the stack our cold email infrastructure setup builds before any copy is written.

The four mistakes the guides keep finding

First, treating "GDPR" as one rule. The GDPR governs the address as personal data; the email itself is governed by national ePrivacy law, and Spain, Italy and the Netherlands have all held that a legitimate-interest assessment does not unlock the send. Second, treating an unsubscribe link as a licence. It is a duty in Group C and D countries and no defence at all in Group A. Third, buying a list and inheriting its consent. Austria fined a director who argued that buying directory data implied consent, and the Philippines makes the buyer answerable for how the seller built the file. Fourth, assuming the law stops at the border. Austria, Denmark, Japan, New Zealand, Brazil and Hong Kong all reach a foreign sender through the recipient, the mailbox location or the domain, and New Zealand does it with nothing more than a .nz address.

What it means for operators

Segment the list by country before the sequence is written, not after the first complaint. Group C countries can run a standard sequence with a compliant footer and a five-day unsubscribe service level. Group B countries need the published-address test documented per contact, which in practice means enrichment that records the source page, not a CSV from a vendor. Group A countries are phone-first, referral-first or event-first markets where the email is the second touch, and where a consent request by email is itself a breach in at least two of them. Group D countries run on legitimate interest with a written balancing test and a record per contact. If a single sequence has to cover more than one group, build it to the strictest rule in the list, because the sending domain is the same for all of them and so is the fine.

Want a sequence built to the strictest rule on your country list?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Seven in this table allow email to businesses without prior consent, subject to identification and opt-out duties: the United States, the United Kingdom (corporate bodies), Ireland (company addresses and role-relevant work addresses), Sweden (legal persons), France (legitimate interest tied to the profession), Hong Kong and Singapore. Four more accept a conspicuously published business address as consent on conditions: Australia, Canada, New Zealand and Japan.

No. In opt-out regimes such as the United States, Singapore and Hong Kong the unsubscribe facility is a duty you must meet, not a permission. In prior-consent countries such as the Netherlands, Spain, Denmark and South Africa the regulators have said in terms that an unsubscribe link does not cure an unsolicited email.

Only where the statute says so and only on its conditions. Australia, Canada, New Zealand and Japan each accept an address that the person or organisation published conspicuously in a business capacity, without a refusal statement, for messages relevant to that role. The Netherlands, Austria and South Korea reject the idea outright, and Austria fined a director who argued that buying directory data implied consent.

Not in Belgium or Denmark, where the regulators treat a consent request sent by email as marketing in itself. South Africa allows exactly one approach, in the prescribed Form 4 manner. Italy points you to the phone instead: a live operator call to a directory-listed number that is not on the opposition register may be used to ask for email consent.

Usually yes. Austria deems the offence committed where the message reaches the user, Denmark applies its law to marketing aimed at Danish recipients, Japan covers transmissions to facilities located in Japan, New Zealand is engaged by a .nz address alone, Brazil's LGPD applies wherever the offer targets people in Brazil, and Hong Kong's UEMO applies where the message has a Hong Kong link.

The United States, at up to USD 53,088 per email under CAN-SPAM after the 2025 inflation adjustment. Ireland writes EUR 5,000 per email on summary conviction, and Austria's published cases run 500 to 800 euro per email. The largest single ceilings are turnover-based: the United Kingdom's GBP 17.5 million or 4 percent since February 2026, and the GDPR ceilings applied by Italy and France.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us