Skip to content

Which Cold Email Law Applies to You? The Inbox Decides

The law that governs a cold email is the law of the inbox it lands in, not the law of the country your company is registered in. Australia, Canada and the European Union each publish an explicit territorial test for marketing email, and on all three the recipient's side alone is enough to trigger it.

Founders ask me whether cold email is legal where they are based, as though that settles it. I have built outbound infrastructure across 500+ projects in 30 countries, and I have never once seen a list that respects a border. The company is in one country, the domains are registered in another, the sending servers are in a third, and the recipients are spread across twenty. There is no single "our law" in that picture, and the one jurisdiction that almost never decides the answer is your own.

Your registered address is the one fact in your compliance story that nobody is asking about.

The mistake: you looked up your own country

The research almost everyone does is the research of their own jurisdiction. It feels responsible and it answers a question no regulator asked. Nothing in the drafting of these statutes turns on where you incorporated, because if it did, every sender would incorporate somewhere else by Friday. The drafters saw that coming.

The question you researched

Is cold email legal in the country where my company is registered?

Answers a question that appears in none of the territorial tests below.

The question that decides it

Whose inbox is this, and where is that person when they open it?

This is the fact the statutes are actually written around.

Three regulators publish the test. All three point at the recipient

Australia is the clearest, because it puts the whole test in one section. Section 7 of the Spam Act 2003 says a commercial electronic message has an Australian link if, and only if, any one of five things is true. Two of the five are about you: the message originates in Australia, or the sender is physically present there or centrally managed there. The other three are about the person receiving it. The message has an Australian link if "the computer, server or device that is used to access the message is located in Australia", or if the account holder is an individual physically present in Australia when the message is accessed.

Then there is the fifth limb, which is worth reading twice. If the message cannot be delivered because the address does not exist, the test asks whether, assuming it had existed, "it is reasonably likely that the message would have been accessed using a computer, server or device located in Australia". A dead address on a stale list still carries the link. The bounce does not save you.

5limbs in Australia's test, any one of which is enough
3of those five turn on the recipient, not on you
0mentions of country or jurisdiction in the FTC's guide

Canada reads like a limit and is not one. Section 12(1) of CASL states that "a person contravenes section 6 only if a computer system located in Canada is used to send or access the electronic message". The word only is doing reassuring work there, right up to the phrase "or access". Your servers can sit anywhere on earth. The laptop that opens the message finishes the sentence for you.

The European Union gets there by a different route. Article 3(2) of the GDPR applies the Regulation to a controller or processor "not established in the Union" where the processing relates to "the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union". A pitch is an offering of services. Article 3(1) closes the other side: an establishment in the Union brings you in "regardless of whether the processing takes place in the Union or not". The consent rule for the email itself lives in the ePrivacy regime that each member state writes into its own statute, which is why a German, Belgian, Austrian or Swiss send can be three different conversations with the same list.

The one that never mentions geography

The United States is the interesting case, because the document a business is actually pointed at says nothing about borders at all. I read the FTC's CAN-SPAM compliance guide for business end to end and searched it: the words country, jurisdiction, territorial, foreign and abroad appear zero times in roughly 18,000 characters. The only instance of "United States" on the page is the federal website banner, and the only "International" is an item in the site menu.

What the guide does say is aimed squarely at anyone running outbound. The Act "covers all commercial messages", and in the FTC's own words, "the law makes no exception for business-to-business email". Each separate email in violation carries a maximum the FTC publishes on that page as 53,088 dollars and adjusts for inflation, so quote the live page and not a blog. Silence about geography is not an exemption, and reading it as one is a decision you are making, not one the FTC made for you. The practical version of all this is on our United States page, and the question of who carries the risk when you hire someone to send for you is on this one.

Applying to you and collecting from you are different questions

Here is the honest part that the compliance posts skip. A law applying to you is not the same as a regulator reaching you. Cross-border enforcement is slow and awkward, and an authority with no entity of yours inside its borders has a genuinely harder job. Anyone who tells you otherwise is selling something.

It is still a weak thing to build a business on, because three parties reach you immediately and none of them needs a regulator. The mailbox providers can stop delivering you without telling you why. Your sending platform has terms you already agreed to and enforces them in hours, not years. And your buyer, increasingly, checks. The reason I care about the territorial tests is not that I expect a letter from Canberra. It is that the same facts decide all four outcomes, and only one of them is slow.

Four moves before your next international send

None of this needs a lawyer to start. It needs one column added to a spreadsheet.

01

Segment by recipient country before you segment by persona

Your obligations follow the inbox, so the country column decides which sequence a row is allowed to receive. Most teams have this field already and sort by job title instead. If a country in your list has no page yet, our Australia and Canada write-ups show the shape of what you are looking for.

02

Send the strictest common denominator to everyone

A truthful sender identity and headers, a subject line that matches the message, a working opt-out you honour fast, and a real postal address. That set satisfies the opt-out regimes outright and costs you nothing in reply rate. Do it on every send rather than per country, because the per country version is the one that gets skipped at volume.

03

Keep your evidence per recipient, not per campaign

In the opt-in regimes the burden of showing a lawful basis sits on the sender, and "we bought a list that said it was compliant" is not evidence. Store where each address came from, on what date, against that row. It takes one more column and it is the only artefact that helps you later.

04

Split the sending infrastructure by regime

Run the opt-in markets on separate domains and separate inboxes from the opt-out markets. One complaint in one country then costs you one pool instead of every domain you own, which is the failure mode I get called in to fix. This is most of what we do when we build cold email infrastructure for a team selling into more than one market.

The bottom line

Stop asking whether cold email is legal where you are. Ask where your recipients are, and then read the rule for each of those places, because that is the rule that was written about your message. Three of the four regimes put that test in the statute itself. The fourth never raises the subject in the guide it hands to businesses, which is not the same as telling you it stops at your border. None of this is legal advice, and a serious cross-border programme is worth an hour with a lawyer in the markets you actually sell into. But the spreadsheet work in front of that hour is yours, and almost nobody has done it.

Frequently Asked Questions

In the three regimes that publish an explicit test, the recipient's side is enough on its own. Australia's Spam Act 2003 gives a message an Australian link if the device used to access it is in Australia, or if the account holder is in Australia when it is accessed. Canada's CASL says a person contravenes section 6 only if a computer system located in Canada is used to send or access the message, and access is the half most senders forget. The EU's GDPR applies to a controller not established in the Union where the processing relates to offering goods or services to people in the Union. None of the three asks where your company is registered.
Yes, on the face of Article 3(2), which applies the Regulation to controllers and processors not established in the Union where the processing activities relate to the offering of goods or services to data subjects who are in the Union. A sales pitch is an offering of services. Article 3(1) catches the other direction: if you do have an establishment in the Union, the Regulation applies regardless of whether the processing takes place in the Union or not. Note that the consent rule for marketing email itself sits in the ePrivacy regime, which each member state implements in its own statute, so the country pages still matter.
No. The FTC's own compliance guide for business states that the Act covers all commercial messages and that the law makes no exception for business-to-business email. It also puts the maximum at up to 53,088 dollars for each separate email in violation, a figure the FTC adjusts for inflation, so check the live page rather than quoting an old blog. The United States is opt-out rather than opt-in, which makes the send lawful to start with and makes the opt-out mechanics the part you have to get right.
Whether a law applies to you and whether a regulator can collect from you are two different questions, and most articles blur them. Cross-border enforcement is slow, and a regulator with no entity to reach in your jurisdiction has a harder job. That is a weak thing to build a business on, because three other parties reach you immediately and without any regulator: the mailbox providers who can quietly stop delivering you, the sending platform whose own terms you agreed to, and the buyer who checks. This is general information rather than legal advice, and a real cross-border programme is worth an hour with a lawyer in the markets you sell into.

Selling into more than one country?

I will take your list, map it by recipient country, and tell you which segments your current setup can safely send to and which ones need their own infrastructure. One call, no deck.

Book a 30-Minute Call

Or email [email protected].