September 27, 2026. Cold email to a business contact needs prior consent in 12 of the 28 countries covered in this table, is allowed on the strength of a conspicuously published business address in 4, is allowed to businesses without prior consent in 7 provided the sender is identified and opt-outs are honoured, and sits under general data protection or consumer law rather than an anti-spam statute in the remaining 5. Those four groups, not "GDPR or not", are the split that decides whether a sequence is lawful. Every row below links to the full country guide, which quotes the statute, the regulator's own guidance and the published cases.

Key numbers
| Item | Number |
|---|---|
| Countries requiring prior consent for B2B email, no business exception (of 28) | 12 |
| Countries where a published business address can supply consent | 4 |
| Countries allowing B2B email with identification and opt-out duties | 7 |
| Countries with no email-specific anti-spam statute | 5 |
| United States, civil penalty per email (CAN-SPAM, 2025 adjustment) | USD 53,088 |
| United Kingdom, PECR fine ceiling since 5 Feb 2026 | GBP 17.5m or 4% |
| Canada, maximum per violation for an organisation (CASL) | CAD 10,000,000 |
| Netherlands, ACM maximum per violation | EUR 900,000 or 1% |
| Shortest unsubscribe deadline in the table (Qatar mainland) | 2 business days |
| New Zealand unsubscribe deadline | 5 working days |
| United States, Singapore and Hong Kong unsubscribe deadline | 10 business or working days |
Statutes and regulator pages read on 26 and 27 September 2026; the linked country guides cite each provision.
The table: 28 countries, one row each
Each country name links to its full guide. Read the third column first. "No" means a prior, provable consent is required before the first email to a business contact, and the guide explains the narrow exceptions. "Yes" means the law permits the send to a business without prior consent, and the fourth and fifth columns tell you who enforces it and what a breach costs on paper. Penalties are quoted as the law writes them, in the local currency, and the linked guide records what regulators have actually imposed.
| Country (links to the guide) | Governing law | B2B cold email without prior consent? | Regulator | Maximum penalty as written |
|---|---|---|---|---|
| Austria Prior consent, no business exception | Telecommunications Act 2021, s.174 | No. Prior consent for every recipient, business included; the ECG list is a refusal list, not a permission list | Fernmeldebuero (telecom offices); RTR keeps the ECG list | Up to EUR 50,000 per case (s.188 TKG); published cases 500 to 800 euro per email |
| Belgium Prior consent, no business exception | Code of Economic Law, Art. XII.13 and the Royal Decree of 4 April 2003 | No for named addresses (firstname.lastname@). Impersonal company addresses such as info@ are exempt; the DPA rejected legitimate interest in 2025 | Data Protection Authority; FPS Economy | Criminal fine of 26 to 25,000 euro, multiplied by ten since 1 Feb 2026, or 6 percent of turnover if higher; 50,000 euro base for bad faith |
| Denmark Prior consent, no business exception | Marketing Practices Act, s.10(1) | No. "Anyone" covers consumers, companies and public bodies; named and generic addresses treated the same | Consumer Ombudsman | Tariff from DKK 20,000 per count (1 to 30 contacts), rising with volume; each campaign and each sender identity is a separate count |
| Germany Prior consent, no business exception | Act against Unfair Competition (UWG), s.7(2) no. 2 | No. Email advertising without prior express consent is an unacceptable nuisance for any addressee; s.7(3) existing-customer exception only | Courts, on action by competitors and consumer bodies; data protection authorities for the GDPR side | Injunctions, warning-letter costs and damages under the UWG; GDPR fines up to 4 percent of turnover for the data side |
| Italy Prior consent, no business exception | Privacy Code (Legislative Decree 196/2003), Art. 130 | No. Consent required, and since 2012 companies are covered too; no legitimate-interest route (Garante, 12 Feb 2026) | Garante per la protezione dei dati personali | GDPR ceiling: EUR 20 million or 4 percent of worldwide turnover |
| Netherlands Prior consent, no business exception | Telecommunicatiewet, Art. 11.7 | No. Sender must prove prior consent, businesses included; two narrow exceptions for addresses a company published specifically for offers | Authority for Consumers and Markets (ACM) | Up to EUR 900,000 per violation or 1 percent of turnover, doubled for a repeat within five years |
| Spain Prior consent, no business exception | LSSI (Ley 34/2002), Art. 21 | No. Prior express permission, no B2B exemption, no legitimate-interest route (AEPD report 0164/2018) | AEPD | Three bands: up to EUR 30,000, 30,001 to 150,000, 150,001 to 600,000 (Art. 38 to 40 LSSI) |
| Switzerland Prior consent, no business exception | Federal Act on Unfair Competition, Art. 3(1)(o) | No. Prior consent, correct sender and a free refusal route; no business carve-out | SECO on complaint; criminal courts under Art. 23 | Wilful breach is a criminal offence: up to three years custodial sentence or a monetary penalty |
| South Africa Prior consent, no business exception | POPIA, s.69 | No. Direct marketing by email only with consent or to an existing customer; one consent request allowed (Form 4); companies are protected too | Information Regulator | Administrative fine up to R10 million (s.109); ignoring an enforcement notice carries up to 10 years (s.107) |
| South Korea Prior consent, no business exception | Network Act, Art. 50 | No. Express prior consent; the only exceptions are recent customers (six months) and voice telemarketing under the Door-to-Door Sales Act; consent re-verified every two years | Korea Communications Commission | Administrative fine up to KRW 30 million (Art. 76) |
| Qatar Prior consent, no business exception | Law No. 13 of 2016, Art. 22 (mainland); QFC Data Protection Regulations 2021 (QFC) | No on the mainland: prior consent, no B2B carve-out. Inside the Qatar Financial Centre firms may send on legitimate interests and must stop on objection | National Cyber Security Agency (mainland); QFC Data Protection Office | Up to QAR 1,000,000 (Art. 23), the same ceiling for a legal person (Art. 25); mainland marketing barred 21:00 to 09:00 |
| Saudi Arabia Prior consent, no business exception | CST Regulations for Curbing SPAM Messages and Calls; Telecommunications and IT Law (Royal Decree M/106) | No. Promotional messages are blocked by default and need an express, recorded choice; consent buried in a privacy policy is disregarded | Communications, Space and Technology Commission (CST); SDAIA for the PDPL | Up to SAR 25 million under Art. 27 of the Telecommunications and IT Law |
| Australia Consent, but a published business address can supply it | Spam Act 2003, Schedule 2 cl. 4 | Consent required, but it may be inferred from an address conspicuously published for a work role, if the message relates to that role and no "no unsolicited messages" statement accompanies the address | ACMA | Civil penalties in penalty units, up to 10,000 units a day for a body corporate with a prior record (s.25); one unit is AUD 330 |
| Canada Consent, but a published business address can supply it | CASL (S.C. 2010, c. 23), s.6 and s.10(9) | Consent required, but implied where the address was conspicuously published without a no-unsolicited-messages statement and the message is relevant to the recipient's business role | CRTC | Up to CAD 10,000,000 per violation for an organisation, CAD 1,000,000 for an individual |
| New Zealand Consent, but a published business address can supply it | Unsolicited Electronic Messages Act 2007, s.4 and s.9 to 11 | Consent required; deemed for an address conspicuously published in a business capacity, with no refusal statement, where the message is relevant to that role. A .nz address alone creates a New Zealand link | Department of Internal Affairs | Up to NZD 500,000 for an organisation (s.45(4)); unsubscribe must take effect within 5 working days |
| Japan Consent, but a published business address can supply it | Act on Regulation of Transmission of Specified Electronic Mail, Art. 3 | Opt-in since 2008, with a statutory exception for an organisation or business individual that has disclosed its own email address; records of the basis must be kept | Ministry of Internal Affairs and Communications; Consumer Affairs Agency | Up to JPY 1 million or one year for the sender (Art. 34); up to JPY 30 million for the company (Art. 37) |
| United States Allowed to businesses with identification and opt-out duties | CAN-SPAM Act of 2003 | Yes. Opt-out regime: truthful headers and subject, physical postal address, working unsubscribe honoured within 10 business days, no sending after opt-out | Federal Trade Commission | Civil penalty up to USD 53,088 per email (2025 inflation adjustment) |
| United Kingdom Allowed to businesses with identification and opt-out duties | PECR 2003, reg. 22 and 23; UK GDPR for the personal data | Yes to corporate bodies (companies, LLPs, public bodies) with sender identity and an opt-out route. Individuals and sole traders need consent or the soft opt-in | Information Commissioner's Office | Since 5 Feb 2026, up to GBP 17.5 million or 4 percent of worldwide turnover for PECR reg. 19 to 24 breaches |
| Ireland Allowed to businesses with identification and opt-out duties | S.I. 336/2011, reg. 13 | Yes for company addresses until the company objects; a named work address may be emailed when it is used mainly for the recipient's commercial activity and the message relates solely to it | Data Protection Commission | EUR 5,000 per email on summary conviction; up to EUR 250,000 on indictment |
| Sweden Allowed to businesses with identification and opt-out duties | Marketing Act (2008:486), s.19 and 20 | Yes to legal persons, provided every email carries a valid opt-out address and objections are honoured. Natural persons, including sole traders, need prior consent | Consumer Ombudsman (Konsumentverket) | Market disruption fee of SEK 10,000 up to 4 percent of turnover (s.31), or up to EUR 2 million where turnover is unknown |
| France Allowed to businesses with identification and opt-out duties | CPCE Art. L34-5 and CNIL doctrine (page dated 10 June 2026) | Yes on legitimate interest when the message relates to the recipient's profession, with information at collection and a simple, free objection route; generic addresses such as info@ are outside the rule | CNIL | CNIL sanctions up to the GDPR ceiling of EUR 20 million or 4 percent of turnover |
| Hong Kong Allowed to businesses with identification and opt-out duties | Unsolicited Electronic Messages Ordinance (UEMO); Personal Data (Privacy) Ordinance (PDPO) | Yes under the UEMO opt-out rules: accurate sender details, working unsubscribe honoured within 10 working days, honest subject line. Using a named person's data for direct marketing engages the PDPO | OFCA (UEMO); Privacy Commissioner (PDPO) | UEMO: enforcement notice, then HKD 100,000, HKD 500,000 on repeat. PDPO direct-marketing offences: HKD 500,000 and three years |
| Singapore Allowed to businesses with identification and opt-out duties | Spam Control Act 2007 (bulk unsolicited commercial email) | Yes. Bulk unsolicited commercial email must carry the label "<ADV>" in the subject, accurate header information, a working unsubscribe facility honoured within 10 business days | Civil action by recipients; IMDA and PDPC for the wider framework | Statutory damages up to SGD 25 per message, capped at SGD 1 million (s.14) |
| India No email-specific anti-spam statute | No anti-spam email statute; Digital Personal Data Protection Act 2023 (substantive duties from 13 May 2027 under the 2025 Rules) | No email-specific consent rule today. TRAI rules cover commercial calls and SMS, not email. The DPDP Act will make consent the main basis for personal data once in force | Data Protection Board of India (being constituted); TRAI for calls and SMS | DPDP Act Schedule penalties, up to INR 250 crore for the most serious breaches, once in force |
| United Arab Emirates No email-specific anti-spam statute | No email-specific statute; PDPL (Federal Decree-Law 45/2021) right to object; TDRA Unsolicited Electronic Communications policy binds licensees; separate DIFC and ADGM regimes | No consent rule specific to email. A recipient may object to direct marketing under the PDPL, and calls and SMS need consent under Cabinet Decision 56/2024 and the TDRA policy | TDRA; UAE Data Office; DIFC and ADGM commissioners inside the free zones | No email-specific fine; PDPL and TDRA sanctions apply |
| Mexico No email-specific anti-spam statute | Federal Consumer Protection Law (LFPC), Art. 17 and 18 BIS; LFPDPPP (2025) for personal data | No prior consent rule. Every commercial email must state the provider's and sender's name, address and phone, and PROFECO's own contact details; no sending to anyone who has said stop. Companies buying for their own use count as consumers | PROFECO; Secretaria Anticorrupcion y Buen Gobierno for data protection | Coercive PROFECO measures (fines from 380.44 to 38,044.47 pesos for disobeying its orders); no separate spam tariff quoted in the law |
| Brazil No email-specific anti-spam statute | LGPD (Law 13.709/2018), Art. 7 IX and Art. 10; no anti-spam statute | No prior consent rule. Legitimate interest is available with a documented balancing test limited to strictly necessary data; the first ANPD fine ever issued concerned a contact list | ANPD | 2 percent of Brazilian revenue, capped at BRL 50 million per infraction (Art. 52) |
| Philippines No email-specific anti-spam statute | Data Privacy Act 2012 (RA 10173); NPC Advisory Opinion 2023-016; no anti-spam statute | No prior consent rule. The NPC accepts legitimate interest for contacting potential customers; consent becomes mandatory the moment the record holds sensitive data such as education or age | National Privacy Commission | Unauthorised processing: one to three years and PHP 500,000 to 2,000,000 (s.25(a)); maximum mandatory when 100 or more people are affected |
The rows were compiled from our 28 country guides. The ten guides published in March 2026 (Australia, Canada, France, Germany, India, Singapore, Sweden, the UAE, the United Kingdom and the United States) were re-checked for this table against the statute or regulator page on 26 and 27 September 2026, and the penalty figures above are the current ones, not the ones in those older guides.

Group A: prior consent, no business exception (12 countries)
Austria, Belgium, Denmark, Germany, Italy, Netherlands, Spain, Switzerland, South Africa, South Korea, Qatar, Saudi Arabia. In every one of these, a published info@ or firstname.lastname@ address is not consent, an unsubscribe link does not cure an unsolicited email, and the sender carries the burden of proof. Three details from the guides matter more than the headline rule. Belgium and Denmark both treat an email that asks for marketing consent as marketing in itself, so you cannot email to obtain permission. Austria and Denmark both count fines per email or per sender identity, which prices the standard three-step sequence across rotating domains rather than the campaign as a whole. Italy is the outlier that lets you use the phone first: a live operator call to a number in a public directory, not on the opposition register, may be used to ask for email consent.
Group B: consent, but a published business address can supply it (4 countries)
Australia, Canada, New Zealand, Japan. All four statutes contain the same three-part test in slightly different words: the address was conspicuously published by that person in a business or official capacity, the publication does not say the holder refuses unsolicited messages, and the message is relevant to that person's role, business, functions or duties. A scraped list fails the test whenever any of the three parts is missing, and a purchased list fails it by default because you cannot show where each address was published. Japan adds a record-keeping duty: the basis for each send has to be stored in the form the ordinance prescribes.
Group C: allowed to businesses with identification and opt-out duties (7 countries)
United States, United Kingdom, Ireland, Sweden, France, Hong Kong, Singapore. These are the markets most outbound teams treat as "open", and the duties are real. The United States wants truthful headers, a postal address and an unsubscribe honoured within ten business days. Singapore wants the literal label "<ADV>" in the subject line of bulk unsolicited commercial email and an unsubscribe facility honoured within ten business days. Hong Kong gives ten working days, New Zealand in Group B gives five, Qatar's mainland spam regulation gives two. The United Kingdom, Ireland and Sweden draw the line at the recipient's legal form rather than at the address: a company can be emailed, a sole trader or an individual cannot without consent. France allows business prospecting on legitimate interest only where the offer relates to the person's profession, and the CNIL page that says so was last updated on 10 June 2026.
Group D: no email-specific anti-spam statute (5 countries)
India, United Arab Emirates, Mexico, Brazil, Philippines. The absence of a spam law is not the absence of rules. Mexico's consumer law requires the email itself to carry the provider's details and PROFECO's own contact details, and treats a company buying for its own use as a consumer. Brazil and the Philippines both accept legitimate interest and both punished the list, not the email, in their first enforcement actions. India's Digital Personal Data Protection Act takes full effect on 13 May 2027 under the Rules notified on 13 November 2025, so a sequence built today should already keep a consent or legitimate-interest record per contact. The UAE regulates calls and SMS through the TDRA and Cabinet Decision 56/2024 and leaves email to the general right to object under the PDPL, with separate regimes inside the DIFC and ADGM.
What every sequence needs regardless of country
Four duties appear in almost every statute in the table, so a sequence that skips any of them is unlawful somewhere in the list before you even reach the consent question: a sender who is identified by name and a working reply address; a free, one-step way to stop, honoured within the shortest deadline in your target list; suppression that is applied per address and per sender domain, because Denmark and Austria count each sending identity separately; and a record per contact of the basis you rely on, which Japan and the Netherlands require in terms and the ACM says you must be able to produce five years later. Those duties are technical as much as legal. Domains, mailboxes, one-click unsubscribe headers and suppression lists are set up once in the sending layer, which is the part of the stack our cold email infrastructure setup builds before any copy is written.
The four mistakes the guides keep finding
First, treating "GDPR" as one rule. The GDPR governs the address as personal data; the email itself is governed by national ePrivacy law, and Spain, Italy and the Netherlands have all held that a legitimate-interest assessment does not unlock the send. Second, treating an unsubscribe link as a licence. It is a duty in Group C and D countries and no defence at all in Group A. Third, buying a list and inheriting its consent. Austria fined a director who argued that buying directory data implied consent, and the Philippines makes the buyer answerable for how the seller built the file. Fourth, assuming the law stops at the border. Austria, Denmark, Japan, New Zealand, Brazil and Hong Kong all reach a foreign sender through the recipient, the mailbox location or the domain, and New Zealand does it with nothing more than a .nz address.
What it means for operators
Segment the list by country before the sequence is written, not after the first complaint. Group C countries can run a standard sequence with a compliant footer and a five-day unsubscribe service level. Group B countries need the published-address test documented per contact, which in practice means enrichment that records the source page, not a CSV from a vendor. Group A countries are phone-first, referral-first or event-first markets where the email is the second touch, and where a consent request by email is itself a breach in at least two of them. Group D countries run on legitimate interest with a written balancing test and a record per contact. If a single sequence has to cover more than one group, build it to the strictest rule in the list, because the sending domain is the same for all of them and so is the fine.
Frequently Asked Questions
Seven in this table allow email to businesses without prior consent, subject to identification and opt-out duties: the United States, the United Kingdom (corporate bodies), Ireland (company addresses and role-relevant work addresses), Sweden (legal persons), France (legitimate interest tied to the profession), Hong Kong and Singapore. Four more accept a conspicuously published business address as consent on conditions: Australia, Canada, New Zealand and Japan.
No. In opt-out regimes such as the United States, Singapore and Hong Kong the unsubscribe facility is a duty you must meet, not a permission. In prior-consent countries such as the Netherlands, Spain, Denmark and South Africa the regulators have said in terms that an unsubscribe link does not cure an unsolicited email.
Only where the statute says so and only on its conditions. Australia, Canada, New Zealand and Japan each accept an address that the person or organisation published conspicuously in a business capacity, without a refusal statement, for messages relevant to that role. The Netherlands, Austria and South Korea reject the idea outright, and Austria fined a director who argued that buying directory data implied consent.
Not in Belgium or Denmark, where the regulators treat a consent request sent by email as marketing in itself. South Africa allows exactly one approach, in the prescribed Form 4 manner. Italy points you to the phone instead: a live operator call to a directory-listed number that is not on the opposition register may be used to ask for email consent.
Usually yes. Austria deems the offence committed where the message reaches the user, Denmark applies its law to marketing aimed at Danish recipients, Japan covers transmissions to facilities located in Japan, New Zealand is engaged by a .nz address alone, Brazil's LGPD applies wherever the offer targets people in Brazil, and Hong Kong's UEMO applies where the message has a Hong Kong link.
The United States, at up to USD 53,088 per email under CAN-SPAM after the 2025 inflation adjustment. Ireland writes EUR 5,000 per email on summary conviction, and Austria's published cases run 500 to 800 euro per email. The largest single ceilings are turnover-based: the United Kingdom's GBP 17.5 million or 4 percent since February 2026, and the GDPR ceilings applied by Italy and France.