Building Cold Email Infrastructure: What GDPR and CAN-SPAM Actually Require
"You can't send cold email" is cargo-cult advice repeated so often that many developers building outbound tools assume it's law. It's not. B2B cold email operates legally across the US, UK, and most of the EU—but on specific foundations with real constraints attached. If you're building a sales tool, outbound platform, or email system, understanding these rules means the difference between a feature that ships and a liability.
GDPR's Legitimate Interest: The Three-Part Test
Optional prior consent is one lawful basis under GDPR. But for B2B prospecting, there's another: legitimate interest. The regulation explicitly permits direct marketing on this basis—and it works because you're targeting people in a professional capacity, not their personal inbox.
Legitimate interest isn't magic. GDPR requires a documented three-part test:
- Purpose: You have a genuine business reason (selling a relevant product to their company).
- Necessity: Direct contact to this person is a proportionate way to reach a decision-maker.
- Balancing: Your interest doesn't override their rights and reasonable expectations.
The third prong is where your system design matters. A logistics director receiving one, individually addressed message about freight software—from an identified sender with a clear unsubscribe—falls within professional expectations. The same person hammered with daily blasts from a scraped list about random products does not. Targeting quality and relevance aren't marketing optimization; they're legal requirements. If you're building the system, make relevance (industry, job title, company size) a first-class constraint, not an afterthought.
What Developers Actually Need to Implement
For GDPR compliance, your system should enforce:
- Country-level routing (strict list): Germany, Austria require consent-like rules even for B2B. Softer regimes (Ireland, Netherlands, UK, France) allow unsolicited B2B. Don't send the same email to all EU addresses—segment by jurisdiction.
- Named individual addresses (not
info@orsales@roles) get more protection. Prioritize them in your targeting quality score. - One objection = permanent suppression. When someone replies "remove me" or clicks unsubscribe, erase them everywhere, immediately. Build this as a synchronous operation, not a background job.
- Sender identity and transparency. Include your company name and contact info in the email itself, not just headers.
- Logging: keep records of why you're sending to each person (their role, relevance).
For CAN-SPAM (US market):
- No opt-in required. Unsolicited commercial email is lawful.
- The law requires: truthful headers, clear sender identity, accurate subject lines, working unsubscribe (respond within 10 days).
- CAN-SPAM is simpler than GDPR, but the unsubscribe is legally binding—honor it.
The EU Patchwork Problem
GDPR is EU-wide. The e-Privacy Directive, which governs electronic marketing specifically, was implemented country by country. Some member states carved out stricter rules for B2B email than the GDPR baseline suggests.
When building an EU campaign: don't assume one global playbook. Use country as a filtering dimension in your prospect database (alongside industry and title). For stricter jurisdictions, route high-value accounts to phone, LinkedIn, or in-person events instead of cold email. This isn't avoidance—it's design that respects local law.
The Obligations That Enforce Compliance
Legitimate interest isn't a free pass. It comes with standing duties that are non-negotiable:
- Right to object: Any direct-marketing objection is absolute. No counter-offer, no waiting period. Implement this as an immediate hard delete.
- Transparency: Document where you got each email address. A privacy policy linked in the email covers much of this.
- Data access and erasure: Respect access requests and deletions (GDPR Articles 15, 17). Build this into your admin panel or API.
These aren't theoretical. Regulators actively enforce them. The GDPR fine structure makes this real cost: up to €20M or 4% of global revenue, whichever is higher.
Targeting Quality as Competitive Moat
The legal requirements are also product differentiation. A system that enforces country-level segmentation, maintains relevance scoring, honors objections instantly, and logs compliance reasoning will outperform spray-and-pray platforms on deliverability and sender reputation alike. Compliance and conversion quality align.
The practical outcome: if you're building outbound infrastructure, treat compliance as a technical specification you code to, the same way you'd implement rate-limiting or HTTPS. Understand GDPR's three-part test and CAN-SPAM's simpler opt-out model. Segment by country. Make relevance and objection handling core to your data model. When you do, cold email isn't a gray area—it's a lawful channel with known constraints.
Full breakdown with sample funnel and selection parameters in the original: Cold Email Without Opt-In: What Legitimate Interest Covers.
Top comments (0)