Cold Outreach Compliance: CAN-SPAM, TCPA, and GDPR Rules for Outbound Sales
Callia Peterson

Cold outreach compliance is the set of legal requirements that govern how a business may contact prospects by email or phone without a prior relationship or consent.
In the United States, CAN-SPAM governs cold email and the TCPA governs cold calling; in the European Union and United Kingdom, GDPR and ePrivacy rules govern both, generally under a legitimate interest basis for B2B contacts.
CAN-SPAM: Cold email in the united states
CAN-SPAM permits cold email without prior consent, provided the sender follows specific disclosure and opt-out rules.
It is an opt-out regime, not an opt-in regime, and it does not distinguish between B2B and B2C recipients.
Accurate header information: From, To, and Reply-To fields must correctly identify the sender.
No deceptive subject lines; the subject must reflect the email's actual content.
A clear identification that the message is an advertisement.
A valid physical postal address included in the message.
A working opt-out mechanism, honored within 10 business days and functional for at least 30 days after sending.
The maximum civil penalty is assessed per violating email, not per campaign, which is why a large send list with a broken unsubscribe link carries outsized regulatory exposure.
TCPA: Cold Calling in the United States
The Telephone Consumer Protection Act governs cold calls and is the law under which most U.S. cold-calling lawsuits are filed.
Business-to-business calls to business numbers are generally exempt from the consumer Do Not Call Registry, but auto-dialers and prerecorded messages to wireless numbers require prior express consent regardless of B2B status.
No calls before 8 AM or after 9 PM in the called party's local time.
The caller must identify themselves, their company, and provide a callback number.
An opt-out request must be added to the internal Do Not Call list within 30 days and retained for at least five years.
Penalties range from $500 per violation up to $1,500 per willful violation, and TCPA claims are frequently filed as class actions.
GDPR and ePrivacy: Cold outreach in the EU and UK
GDPR does not prohibit B2B cold outreach, but it requires a documented lawful basis for processing a contact's personal data, which a business phone number or work email address qualifies as.
Most B2B senders rely on legitimate interest under GDPR Article 6(1)(f) rather than consent, though country-level ePrivacy implementation varies.
Jurisdiction | Consent model for B2B outreach | Enforcement body | Headline penalty |
|---|---|---|---|
United States (CAN-SPAM, cold email) | Opt-out; no consent required to send | Federal Trade Commission | Up to roughly $53,000 per violating email |
United States (TCPA, cold calling) | Consent required for auto-dialed or prerecorded calls | FCC / FTC | $500 to $1,500 per call |
European Union (GDPR, ePrivacy) | Legitimate interest for B2B, with country variation (Germany and Italy require stricter consent) | National data protection authorities | Up to 4% of global annual revenue |
United Kingdom (UK GDPR, PECR) | Legitimate interest for B2B; consumer lists (TPS/CTPS) require screening | Information Commissioner's Office | Fines in the hundreds of thousands of pounds |
Cold calling compliance outside the US: UK, Canada, and Australia
Cold calling rules extend well beyond U.S. borders, and the differences between jurisdictions are consequential.
A program built for TCPA compliance will still violate UK, Canadian, or Australian law if it ignores the local registry screening obligations, calling-hour windows, and B2B carve-outs specific to each country.
Jurisdiction | Governing Law | B2B Treatment | Key Requirement |
|---|---|---|---|
United Kingdom | UK GDPR, PECR, OFCOM rules | B2B calls may rely on legitimate interest, but TPS/CTPS screening is required; no B2B blanket exemption from CTPS | Screen against TPS (consumers) and CTPS (businesses) at least every 28 days; abandoned or silent calls must not exceed 3% of live answered calls per campaign under OFCOM rules; the ICO enforces fines for non-compliant calling |
Canada | National Do Not Call List (DNCL) under the Telecommunications Act, enforced by the CRTC | Existing business relationships (defined by CRTC) are exempt; pure cold B2B calls to registered numbers are not automatically exempt | Permitted calling hours are 9 AM to 9:30 PM local time on weekdays and 10 AM to 6 PM on weekends; callers must register with the DNCL operator and screen lists before calling |
Australia | Do Not Call Register Act 2006, enforced by ACMA | B2B calls are exempt where the number is used solely or primarily for business purposes; residential and mixed-use numbers are not exempt | Calls must display caller ID; calling hours and days are restricted under the Telecommunications (Do Not Call Register) (Telemarketing and Research Calls) Industry Standard; ACMA may issue infringement notices per unlawful call |
The pattern across all three jurisdictions is the same: registry screening is not a one-time task at list creation, it is a recurring operational obligation.
Allowing a call list to go unscreened for more than a few weeks creates legal exposure even when the original list was clean.
Building a cross-channel compliance program
A compliant outbound program is not a set of separate email rules and separate calling rules. It is a unified framework that applies the right rule to the right channel in the right jurisdiction, automatically.
The steps below apply whether outreach is run by a human sales team, a partially automated sequence, or a fully AI-driven agent.
Document a lawful basis per jurisdiction before any outreach begins. For U.S. email under CAN-SPAM this is straightforward; for EU and UK contacts under GDPR and PECR it requires a written legitimate interest assessment or, in stricter markets such as Germany and Italy, evidence of consent.
Maintain one unified opt-out and suppression list across email and phone. A prospect who opts out through any channel must be suppressed from all channels immediately. Separate lists per tool or per rep are a compliance liability.
Screen against national DNC, TPS, CTPS, and DNCL registries on a recurring schedule. For the UK, that schedule must be at least every 28 days. For Canada and Australia, screening must occur before each new campaign wave, not only at initial list build.
Set jurisdiction-aware calling-hour and sending logic so that outreach cannot be dispatched outside permitted windows. This logic should be enforced at the platform level, not left to individual rep judgment.
Train reps and configure agents on required disclosures. Every call must include caller identification and a callback number. Every email must include a physical address and a working unsubscribe mechanism. Agents executing outreach autonomously must have these disclosures encoded as non-negotiable outputs, not optional behaviors.
Conduct periodic compliance audits. Pull a sample of sent emails and placed calls, verify that required disclosures were present, confirm that opt-out requests were honored within the legally required window, and check that suppression lists were up to date at the time of the send or call.
Common Cold Outreach Compliance Mistakes
Even experienced outbound teams make predictable compliance errors.
The following mistakes account for a significant share of regulatory enforcement actions and private litigation in cold outreach programs.
Treating a single global opt-out list as compliant everywhere. Different jurisdictions define opt-out obligations differently. A suppression list that satisfies CAN-SPAM does not automatically satisfy GDPR erasure rights or PECR consent withdrawal requirements. Global suppression must be built to the strictest applicable standard.
Assuming B2B is universally exempt from consumer protection lists. In the UK, the CTPS covers business telephone numbers, and screening is required regardless of whether the called party is a consumer or a company. In Canada, a business-to-business relationship exemption exists but is narrowly defined by the CRTC; an unrelated cold call to a registered business number is still a violation.
Missing country-specific ePrivacy strictness in Germany and Italy. Both countries require opt-in consent for electronic marketing to business contacts, not merely a legitimate interest basis. Running a standard EU B2B sequence built around legitimate interest into German or Italian contacts is non-compliant.
Letting a suppression list go stale. A suppression list that was current at list build but has not been refreshed will inevitably re-contact people who subsequently opted out, registered on a DNC list, or whose data was subject to a deletion request. Suppression is not an event; it is a continuous process.
Using auto-dialers without verifying TCPA consent requirements. Under the TCPA, an automated telephone dialing system used to call a wireless number requires prior express consent even for B2B outreach.
Many sales teams deploy power dialers or predictive dialers without confirming whether the dialing technology meets the TCPA definition of an auto-dialer and whether the recipient's consent was obtained.
Compliance and AI-Run outbound programs
When an AI agent is sending emails and placing calls at scale, the compliance stakes change in one important direction: errors scale just as fast as outreach does.
A human rep who forgets a disclosure on one call creates one violation. An agent that is not configured with the correct disclosure behavior creates that violation on every call it places until the problem is caught.
This means the compliance framework for an AI-run outbound program must be encoded into the agent's behavior directly, not delegated to a downstream review process.
Jurisdiction-specific calling-hour restrictions cannot be a policy document that reps are trained on; they must be enforced logic that the agent cannot override. Opt-out and suppression checks cannot be a pre-campaign step that a manager performs; they must run automatically before each individual send or call.
Required disclosures cannot be a reminder in a call script; they must be a mandatory element of every AI-generated opening.
Auditability becomes more important, not less, when an agent is executing at scale. Every email sent and every call placed by an AI agent should be logged with the compliance basis that authorized it: the lawful basis under GDPR, the consent record under TCPA, the DNC screening timestamp, and the opt-out status at the time of contact.
Without that log, a regulator's inquiry or a litigation discovery request becomes exponentially harder to respond to, and the burden of proof shifts to the company to demonstrate compliance it cannot document.
The practical implication is that teams deploying AI for outbound sales need to treat compliance configuration as a first-class engineering and operational task, not an afterthought.
The agent's jurisdiction rules, opt-out logic, calling-hour windows, and disclosure templates should be reviewed on the same cadence as the rest of the program, updated when regulations change, and tested before new markets or new contact types are added to the agent's scope.
A practical compliance checklist
Use this checklist as a baseline before launching or auditing any cold outreach program. It covers the major requirements across all jurisdictions addressed in this article.
Every outbound email includes an accurate From address, a non-deceptive subject line, a physical postal address, and a working unsubscribe mechanism (CAN-SPAM)
Opt-out requests are processed and honored within 10 business days, and the unsubscribe mechanism remains functional for at least 30 days after each send (CAN-SPAM)
A unified suppression list is maintained across all channels and is updated in real time when an opt-out is received from any source
A written legitimate interest assessment is documented before running B2B email or call outreach into EU or UK contacts
Germany and Italy contacts are handled under a consent-based framework, not legitimate interest alone
TPS and CTPS screening is completed at least every 28 days for UK calling programs
CRTC DNCL screening is completed before each campaign wave for Canadian calling programs, and calling hours respect the 9 AM to 9:30 PM weekday and 10 AM to 6 PM weekend limits
Australian call lists are screened against the Do Not Call Register, caller ID is enabled, and calling hours comply with the ACMA industry standard
Auto-dialer or prerecorded message use against wireless numbers is confirmed to be covered by prior express consent under TCPA, even for B2B contacts
Internal DNC opt-out records are retained for at least five years (TCPA)
Every call includes caller name, company name, and a callback number
AI agents or automated sequences have calling-hour enforcement, opt-out suppression checks, and required disclosures built into their execution logic, not left to human review
Compliance audits are conducted periodically, covering a sample of sent emails and placed calls, with findings documented and remediated
Frequently Asked Questions
Is cold calling legal in the EU?
Cold calling is not prohibited in the EU, but it is regulated. B2B cold calls to business numbers may be permitted under a legitimate interest basis, though member states implement ePrivacy rules differently and some countries impose stricter opt-in requirements.
Consumer cold calls face significantly tighter restrictions. Callers must comply with local ePrivacy laws in addition to GDPR, and any contact whose number appears on a national do-not-call registry must be suppressed.
Do B2B emails need consent under GDPR?
Not always. Most B2B senders rely on legitimate interest under GDPR Article 6(1)(f) as the lawful basis for processing business contact data for cold outreach.
However, legitimate interest requires a documented balancing test weighing the sender's interest against the recipient's rights, and country-level ePrivacy rules can override this: Germany and Italy, for example, require opt-in consent for electronic marketing even in B2B contexts.
Legitimate interest is not a blanket permission; it is a legal basis that must be assessed and recorded.
What is the penalty for a CAN-SPAM violation?
The FTC can assess civil penalties for CAN-SPAM violations on a per-email basis, with the statutory maximum applying to each non-compliant email in a send.
A large campaign with a broken unsubscribe link or a missing physical address can generate significant aggregate exposure quickly. In practice, enforcement actions often result in settlements in the hundreds of thousands of dollars range, and CAN-SPAM violations can also accompany state-law claims that carry additional penalties.
How often should Do Not Call lists be re-screened?
The required frequency depends on the jurisdiction. In the UK, PECR and ICO guidance require TPS and CTPS screening at least every 28 days. In the US, the FTC recommends screening the national DNC Registry at least every 31 days for active calling programs.
In Canada and Australia, screening should occur before each new campaign wave. In all cases, screening only at list creation is insufficient; contacts can register on a DNC list after your initial pull, and calling them after they have registered creates a violation.
See how a governed outbound program tracks consent and opt-outs automatically. Start free.
Similar Articles
We build with the best to make sure we exceed the highest standards and deliver real value.
Get started today
See how the Rox agent can put your pipeline generation, deal management, and account expansion on autopilot.
