Cold Outreach Compliance: CAN-SPAM, TCPA, and GDPR Rules for Outbound Sales

Callia Peterson

Rox blog article thumbnail image for How AI Is Transforming Email Productivity: AI Email Filler’s Benefits
Summarize this article with your favorite LLM
Table of contents

Summarize article with your LLM

Cold outreach compliance is the set of legal requirements that govern how a business may contact prospects by email or phone without a prior relationship or consent.

In the United States, CAN-SPAM governs cold email and the TCPA governs cold calling; in the European Union and United Kingdom, GDPR and ePrivacy rules govern both, generally under a legitimate interest basis for B2B contacts.

CAN-SPAM: Cold email in the united states

CAN-SPAM permits cold email without prior consent, provided the sender follows specific disclosure and opt-out rules.

It is an opt-out regime, not an opt-in regime, and it does not distinguish between B2B and B2C recipients.

  • Accurate header information: From, To, and Reply-To fields must correctly identify the sender.

  • No deceptive subject lines; the subject must reflect the email's actual content.

  • A clear identification that the message is an advertisement.

  • A valid physical postal address included in the message.

  • A working opt-out mechanism, honored within 10 business days and functional for at least 30 days after sending.

The maximum civil penalty is assessed per violating email, not per campaign, which is why a large send list with a broken unsubscribe link carries outsized regulatory exposure.

TCPA: Cold Calling in the United States

The Telephone Consumer Protection Act governs cold calls and is the law under which most U.S. cold-calling lawsuits are filed.

Business-to-business calls to business numbers are generally exempt from the consumer Do Not Call Registry, but auto-dialers and prerecorded messages to wireless numbers require prior express consent regardless of B2B status.

  • No calls before 8 AM or after 9 PM in the called party's local time.

  • The caller must identify themselves, their company, and provide a callback number.

  • An opt-out request must be added to the internal Do Not Call list within 30 days and retained for at least five years.

  • Penalties range from $500 per violation up to $1,500 per willful violation, and TCPA claims are frequently filed as class actions.

GDPR and ePrivacy: Cold outreach in the EU and UK

GDPR does not prohibit B2B cold outreach, but it requires a documented lawful basis for processing a contact's personal data, which a business phone number or work email address qualifies as.

Most B2B senders rely on legitimate interest under GDPR Article 6(1)(f) rather than consent, though country-level ePrivacy implementation varies.

Jurisdiction

Consent model for B2B outreach

Enforcement body

Headline penalty

United States (CAN-SPAM, cold email)

Opt-out; no consent required to send

Federal Trade Commission

Up to roughly $53,000 per violating email

United States (TCPA, cold calling)

Consent required for auto-dialed or prerecorded calls

FCC / FTC

$500 to $1,500 per call

European Union (GDPR, ePrivacy)

Legitimate interest for B2B, with country variation (Germany and Italy require stricter consent)

National data protection authorities

Up to 4% of global annual revenue

United Kingdom (UK GDPR, PECR)

Legitimate interest for B2B; consumer lists (TPS/CTPS) require screening

Information Commissioner's Office

Fines in the hundreds of thousands of pounds

Cold calling compliance outside the US: UK, Canada, and Australia

Cold calling rules extend well beyond U.S. borders, and the differences between jurisdictions are consequential.

A program built for TCPA compliance will still violate UK, Canadian, or Australian law if it ignores the local registry screening obligations, calling-hour windows, and B2B carve-outs specific to each country.

Jurisdiction

Governing Law

B2B Treatment

Key Requirement

United Kingdom

UK GDPR, PECR, OFCOM rules

B2B calls may rely on legitimate interest, but TPS/CTPS screening is required; no B2B blanket exemption from CTPS

Screen against TPS (consumers) and CTPS (businesses) at least every 28 days; abandoned or silent calls must not exceed 3% of live answered calls per campaign under OFCOM rules; the ICO enforces fines for non-compliant calling

Canada

National Do Not Call List (DNCL) under the Telecommunications Act, enforced by the CRTC

Existing business relationships (defined by CRTC) are exempt; pure cold B2B calls to registered numbers are not automatically exempt

Permitted calling hours are 9 AM to 9:30 PM local time on weekdays and 10 AM to 6 PM on weekends; callers must register with the DNCL operator and screen lists before calling

Australia

Do Not Call Register Act 2006, enforced by ACMA

B2B calls are exempt where the number is used solely or primarily for business purposes; residential and mixed-use numbers are not exempt

Calls must display caller ID; calling hours and days are restricted under the Telecommunications (Do Not Call Register) (Telemarketing and Research Calls) Industry Standard; ACMA may issue infringement notices per unlawful call

The pattern across all three jurisdictions is the same: registry screening is not a one-time task at list creation, it is a recurring operational obligation.

Allowing a call list to go unscreened for more than a few weeks creates legal exposure even when the original list was clean.

Building a cross-channel compliance program

A compliant outbound program is not a set of separate email rules and separate calling rules. It is a unified framework that applies the right rule to the right channel in the right jurisdiction, automatically.

The steps below apply whether outreach is run by a human sales team, a partially automated sequence, or a fully AI-driven agent.

  1. Document a lawful basis per jurisdiction before any outreach begins. For U.S. email under CAN-SPAM this is straightforward; for EU and UK contacts under GDPR and PECR it requires a written legitimate interest assessment or, in stricter markets such as Germany and Italy, evidence of consent.

  2. Maintain one unified opt-out and suppression list across email and phone. A prospect who opts out through any channel must be suppressed from all channels immediately. Separate lists per tool or per rep are a compliance liability.

  3. Screen against national DNC, TPS, CTPS, and DNCL registries on a recurring schedule. For the UK, that schedule must be at least every 28 days. For Canada and Australia, screening must occur before each new campaign wave, not only at initial list build.

  4. Set jurisdiction-aware calling-hour and sending logic so that outreach cannot be dispatched outside permitted windows. This logic should be enforced at the platform level, not left to individual rep judgment.

  5. Train reps and configure agents on required disclosures. Every call must include caller identification and a callback number. Every email must include a physical address and a working unsubscribe mechanism. Agents executing outreach autonomously must have these disclosures encoded as non-negotiable outputs, not optional behaviors.

Conduct periodic compliance audits. Pull a sample of sent emails and placed calls, verify that required disclosures were present, confirm that opt-out requests were honored within the legally required window, and check that suppression lists were up to date at the time of the send or call.

Common Cold Outreach Compliance Mistakes

Even experienced outbound teams make predictable compliance errors.

The following mistakes account for a significant share of regulatory enforcement actions and private litigation in cold outreach programs.

  • Treating a single global opt-out list as compliant everywhere. Different jurisdictions define opt-out obligations differently. A suppression list that satisfies CAN-SPAM does not automatically satisfy GDPR erasure rights or PECR consent withdrawal requirements. Global suppression must be built to the strictest applicable standard.

  • Assuming B2B is universally exempt from consumer protection lists. In the UK, the CTPS covers business telephone numbers, and screening is required regardless of whether the called party is a consumer or a company. In Canada, a business-to-business relationship exemption exists but is narrowly defined by the CRTC; an unrelated cold call to a registered business number is still a violation.

  • Missing country-specific ePrivacy strictness in Germany and Italy. Both countries require opt-in consent for electronic marketing to business contacts, not merely a legitimate interest basis. Running a standard EU B2B sequence built around legitimate interest into German or Italian contacts is non-compliant.

  • Letting a suppression list go stale. A suppression list that was current at list build but has not been refreshed will inevitably re-contact people who subsequently opted out, registered on a DNC list, or whose data was subject to a deletion request. Suppression is not an event; it is a continuous process.

  • Using auto-dialers without verifying TCPA consent requirements. Under the TCPA, an automated telephone dialing system used to call a wireless number requires prior express consent even for B2B outreach.

Many sales teams deploy power dialers or predictive dialers without confirming whether the dialing technology meets the TCPA definition of an auto-dialer and whether the recipient's consent was obtained.

Compliance and AI-Run outbound programs

When an AI agent is sending emails and placing calls at scale, the compliance stakes change in one important direction: errors scale just as fast as outreach does.

A human rep who forgets a disclosure on one call creates one violation. An agent that is not configured with the correct disclosure behavior creates that violation on every call it places until the problem is caught.

This means the compliance framework for an AI-run outbound program must be encoded into the agent's behavior directly, not delegated to a downstream review process.

Jurisdiction-specific calling-hour restrictions cannot be a policy document that reps are trained on; they must be enforced logic that the agent cannot override. Opt-out and suppression checks cannot be a pre-campaign step that a manager performs; they must run automatically before each individual send or call.

Required disclosures cannot be a reminder in a call script; they must be a mandatory element of every AI-generated opening.

Auditability becomes more important, not less, when an agent is executing at scale. Every email sent and every call placed by an AI agent should be logged with the compliance basis that authorized it: the lawful basis under GDPR, the consent record under TCPA, the DNC screening timestamp, and the opt-out status at the time of contact.

Without that log, a regulator's inquiry or a litigation discovery request becomes exponentially harder to respond to, and the burden of proof shifts to the company to demonstrate compliance it cannot document.

The practical implication is that teams deploying AI for outbound sales need to treat compliance configuration as a first-class engineering and operational task, not an afterthought.

The agent's jurisdiction rules, opt-out logic, calling-hour windows, and disclosure templates should be reviewed on the same cadence as the rest of the program, updated when regulations change, and tested before new markets or new contact types are added to the agent's scope.

A practical compliance checklist

Use this checklist as a baseline before launching or auditing any cold outreach program. It covers the major requirements across all jurisdictions addressed in this article.

  • Every outbound email includes an accurate From address, a non-deceptive subject line, a physical postal address, and a working unsubscribe mechanism (CAN-SPAM)

  • Opt-out requests are processed and honored within 10 business days, and the unsubscribe mechanism remains functional for at least 30 days after each send (CAN-SPAM)

  • A unified suppression list is maintained across all channels and is updated in real time when an opt-out is received from any source

  • A written legitimate interest assessment is documented before running B2B email or call outreach into EU or UK contacts

  • Germany and Italy contacts are handled under a consent-based framework, not legitimate interest alone

  • TPS and CTPS screening is completed at least every 28 days for UK calling programs

  • CRTC DNCL screening is completed before each campaign wave for Canadian calling programs, and calling hours respect the 9 AM to 9:30 PM weekday and 10 AM to 6 PM weekend limits

  • Australian call lists are screened against the Do Not Call Register, caller ID is enabled, and calling hours comply with the ACMA industry standard

  • Auto-dialer or prerecorded message use against wireless numbers is confirmed to be covered by prior express consent under TCPA, even for B2B contacts

  • Internal DNC opt-out records are retained for at least five years (TCPA)

  • Every call includes caller name, company name, and a callback number

  • AI agents or automated sequences have calling-hour enforcement, opt-out suppression checks, and required disclosures built into their execution logic, not left to human review

  • Compliance audits are conducted periodically, covering a sample of sent emails and placed calls, with findings documented and remediated

Frequently Asked Questions

Is cold calling legal in the EU?

Cold calling is not prohibited in the EU, but it is regulated. B2B cold calls to business numbers may be permitted under a legitimate interest basis, though member states implement ePrivacy rules differently and some countries impose stricter opt-in requirements.

Consumer cold calls face significantly tighter restrictions. Callers must comply with local ePrivacy laws in addition to GDPR, and any contact whose number appears on a national do-not-call registry must be suppressed.

Do B2B emails need consent under GDPR?

Not always. Most B2B senders rely on legitimate interest under GDPR Article 6(1)(f) as the lawful basis for processing business contact data for cold outreach.

However, legitimate interest requires a documented balancing test weighing the sender's interest against the recipient's rights, and country-level ePrivacy rules can override this: Germany and Italy, for example, require opt-in consent for electronic marketing even in B2B contexts.

Legitimate interest is not a blanket permission; it is a legal basis that must be assessed and recorded.

What is the penalty for a CAN-SPAM violation?

The FTC can assess civil penalties for CAN-SPAM violations on a per-email basis, with the statutory maximum applying to each non-compliant email in a send.

A large campaign with a broken unsubscribe link or a missing physical address can generate significant aggregate exposure quickly. In practice, enforcement actions often result in settlements in the hundreds of thousands of dollars range, and CAN-SPAM violations can also accompany state-law claims that carry additional penalties.

How often should Do Not Call lists be re-screened?

The required frequency depends on the jurisdiction. In the UK, PECR and ICO guidance require TPS and CTPS screening at least every 28 days. In the US, the FTC recommends screening the national DNC Registry at least every 31 days for active calling programs.

In Canada and Australia, screening should occur before each new campaign wave. In all cases, screening only at list creation is insufficient; contacts can register on a DNC list after your initial pull, and calling them after they have registered creates a violation.

See how a governed outbound program tracks consent and opt-outs automatically. Start free.

Summarize this article with your favorite LLM

Get started today

See how the Rox agent can put your pipeline generation, deal management, and account expansion on autopilot.

Rox is committed to the privacy and security of its users. Customer data processed through the Rox platform is encrypted in transit and at rest using AES-256 encryption and is never used to train generalized machine learning models. Rox maintains SOC 2 Type II compliance and undergoes independent third-party security audits on an annual basis. All AI-generated outputs, including but not limited to prospect recommendations, message drafts, meeting summaries, and pipeline scoring, are provided for informational purposes and should be reviewed by authorized personnel before any action is taken. Performance metrics referenced on this website, including pipeline generation figures, response rates, and revenue impact, reflect results reported by individual customers under specific configurations and may not be representative of all deployments. Actual results will vary based on factors including but not limited to data quality, CRM configuration, outreach volume, market conditions, and target audience. Rox does not guarantee specific revenue outcomes. The Rox platform integrates with third-party services including Salesforce, HubSpot, Gmail, Microsoft Outlook, Slack, and others; availability and functionality of third-party integrations are subject to the respective providers' terms of service and may change without notice. Features described as "autopilot," "autonomous," or "automated" operate within user-defined parameters and require initial configuration and ongoing oversight. Rox, the Rox logo, and "Revenue on Autopilot" are trademarks of Rox Data Corp. All other trademarks are the property of their respective owners. Service availability is subject to the terms outlined in your enterprise agreement. For questions regarding data processing, compliance certifications, or platform capabilities, contact security@rox.com.

Rox is committed to the privacy and security of its users. Customer data processed through the Rox platform is encrypted in transit and at rest using AES-256 encryption and is never used to train generalized machine learning models. Rox maintains SOC 2 Type II compliance and undergoes independent third-party security audits on an annual basis. All AI-generated outputs, including but not limited to prospect recommendations, message drafts, meeting summaries, and pipeline scoring, are provided for informational purposes and should be reviewed by authorized personnel before any action is taken. Performance metrics referenced on this website, including pipeline generation figures, response rates, and revenue impact, reflect results reported by individual customers under specific configurations and may not be representative of all deployments. Actual results will vary based on factors including but not limited to data quality, CRM configuration, outreach volume, market conditions, and target audience. Rox does not guarantee specific revenue outcomes. The Rox platform integrates with third-party services including Salesforce, HubSpot, Gmail, Microsoft Outlook, Slack, and others; availability and functionality of third-party integrations are subject to the respective providers' terms of service and may change without notice. Features described as "autopilot," "autonomous," or "automated" operate within user-defined parameters and require initial configuration and ongoing oversight. Rox, the Rox logo, and "Revenue on Autopilot" are trademarks of Rox Data Corp. All other trademarks are the property of their respective owners. Service availability is subject to the terms outlined in your enterprise agreement. For questions regarding data processing, compliance certifications, or platform capabilities, contact security@rox.com.