Skip to content
← BlogComplianceAnalysis

CAN-SPAM vs. GDPR vs. CASL: the cold-email compliance landscape compared

CAN-SPAM, GDPR, and CASL run on three different consent models. A practical comparison on consent, unsubscribe timing, and penalties — not legal advice, just the landscape.

By Gabriel Lara, Developer Relations, Norbelys

Founder-reviewed ·How we research and correct articles

Ask “is cold email legal” and the honest answer is “under which law, sent to whom, from where.” Three different regimes govern the same activity — sending an unsolicited commercial email — and they don’t agree on the basic starting point. One assumes you can email someone until they say stop. Another assumes you can’t email them until they say go ahead. The third sits in between, with a specific, time-boxed exception for exactly the kind of message a B2B sales team sends.

This is a comparison, not a legal opinion. Genuinely useful compliance work for cold email usually needs a real read of how these rules apply to your specific list, your specific recipients’ locations, and your specific message — that’s what a lawyer is for. What this piece can do is lay out the actual shape of each law side by side, because most of the confusion around “is this legal” comes from applying one regime’s mental model (most often CAN-SPAM’s opt-out default) to a jurisdiction that runs on a different one.

The three regimes at a glance

CAN-SPAM (US)GDPR + ePrivacy (EU)CASL (Canada)
Consent modelOpt-out — you can send until they say stopOpt-in — consent generally required before sendingOpt-in, with time-boxed implied-consent windows and a B2B exemption
Unsubscribe honoring window10 business days"Without delay" — the right to object is immediate10 business days
Unsubscribe mechanism must stay valid forAt least 30 days after sendOngoing — the right to object never expiresAt least 60 days after send
Maximum penaltyUp to $53,088 per violating emailUp to €20M or 4% of global annual turnover, whichever is higherUp to $10M (organizations) / $1M (individuals) per violation
Who it applies toCommercial email sent to a U.S. recipient, regardless of sender locationAnyone processing an EU resident's personal data, regardless of sender locationCommercial electronic messages sent to or from a computer system in Canada
General B2B carve-out?No — B2B commercial email is fully in scopeNo blanket carve-out; legitimate-interest arguments are narrower and vary by contextYes — a specific exemption for messages between employees of organizations with an existing relationship

CAN-SPAM: opt-out, and the bar is honoring the opt-out

CAN-SPAM’s starting assumption is the most permissive of the three: you’re allowed to send a first cold email without prior consent. The law’s actual weight sits entirely on what happens after that message lands — accurate sender information, a non-deceptive subject line, a working opt-out mechanism honored within 10 business days, and (where applicable) a valid physical postal address. It doesn’t ask “did this person agree to be contacted.” It asks “can they stop it easily, and did you stop when they did.”

That’s the regime most cold-email tooling in the U.S. is built against, and it’s also the one with the steepest headline penalty — up to $53,088 per individual violating email, which is per-message, not per-campaign. For the full mechanics of how CAN-SPAM’s requirements map onto an actual sending platform — headers, the opt-out machinery, the data-broker-adjacent privacy questions that sit next to it — our dedicated CAN-SPAM breakdown goes deep on just that one law; this piece stays at the comparison level on purpose.

GDPR + ePrivacy: opt-in is the default, and it travels with the data

GDPR flips the starting assumption. The general expectation for marketing email to an individual is consent obtained before the first message — freely given, specific, informed, and unambiguous. GDPR itself technically permits a “legitimate interest” basis for some processing, but the ePrivacy Directive layers a stricter rule on top specifically for electronic marketing messages, and in most real scenarios that means prior opt-in, not opt-out, is the safer and more defensible baseline.

Two details matter more than the headline consent rule:

  • The right to object is unconditional and immediate. A recipient can object to direct marketing at any time, for any reason, and processing for that purpose has to stop without delay — there’s no 10-business-day grace window here, because the framing isn’t “process my opt-out request,” it’s “you no longer have a basis to keep emailing me, effective now.” That’s a distinct right from erasure, worth not conflating: objecting to marketing stops future sends, while erasure is the separate, further request to have the underlying personal data destroyed outright.
  • It applies based on whose data you’re processing, not where you’re sending from. A company with zero EU presence that emails people in the EU is still in scope. Location of the sender is irrelevant; location (or more precisely, residency) of the data subject is what triggers it.

The penalty ceiling reflects that GDPR isn’t an email-specific law — it’s a general data protection regulation, and unsolicited marketing email is one narrow way to violate it. €20 million or 4% of global annual turnover, whichever is higher, is the statutory maximum for the most serious tier of violation; actual fines issued in practice are typically far below that ceiling, but the number sets the outer bound regulators are working with.

CASL: opt-in by default, with a real B2B door

CASL sits closer to GDPR’s opt-in default than to CAN-SPAM’s opt-out one, but with a detail that matters specifically for B2B cold outreach: implied consent isn’t just a narrow, temporary exception here — it has defined windows (an existing business relationship, or a recent inquiry), and there’s a distinct business-to-business exemption for messages sent between employees, representatives, or consultants of organizations that have an existing relationship, where the message concerns the business of the organization receiving it. A B2B cold email that doesn’t fit either the implied- consent window or the organizational-relationship exemption needs express consent — CASL doesn’t default back to “opt-out is fine” the way CAN-SPAM does.

Where CASL and CAN-SPAM converge is unsubscribe mechanics: both require honoring an opt-out within 10 business days, though CASL requires the mechanism itself to stay valid for 60 days versus CAN-SPAM’s 30. In practice, honoring an opt-out on either timeline means the address lands on a suppression list that’s checked again at every future send, not just removed from the one list it happened to be on. The penalty structure is administrative monetary penalties (AMPs) rather than per-message civil fines — up to $10 million for an organization, $1 million for an individual, per violation, enforced by the CRTC.

What’s actually consistent across all three

Underneath the differences, all three regimes converge on the same operational floor:

  • A working, honored opt-out. Every regime requires it, even the opt-out-model one — the difference is only whether consent is also required before the first message.
  • Honest sender identification. None of the three tolerates a spoofed “from” address or deceptive routing information — the same authentication problem DMARC monitoring exists to catch, independent of which law is in play.
  • A record of why you were allowed to contact someone. Whether that’s a documented legitimate-interest basis, an implied-consent window, or simply “they hadn’t opted out,” every regime effectively expects you to be able to explain your basis for the message if asked — which in practice means the source recorded against a contact when it was added isn’t a nice-to-have field, it’s the answer to that question when it comes up.

Practically, that convergence is why building the opt-out machinery, the suppression list, and the sender-authentication story correctly gets you most of the way toward compliance with all three at once — the parts that diverge (consent timing, penalty structure, who’s in scope) are exactly the parts a lawyer, not a platform, needs to weigh in on for your specific list. Whichever regime is asking, being able to actually produce your own send and suppression history and engagement analytics on request is what turns “we believe we were compliant” into something you can demonstrate.

CAN-SPAM, GDPR, and CASL — common questions

Which law applies if I'm a U.S. company emailing prospects in Canada?

CASL, because it applies based on where the message is sent or received, not where the sender is incorporated. A U.S. company emailing a Canadian recipient is subject to CASL's consent and unsubscribe rules for that message, separately from any CAN-SPAM obligations for U.S. recipients on the same list.

Does GDPR ever allow cold B2B email without prior consent?

It's genuinely contested and context-dependent — some interpretations of legitimate interest can support relevant, well-targeted B2B outreach, but the ePrivacy Directive's stricter consent requirement for electronic marketing narrows that in practice for most cold email. This is one of the clearest cases where you need jurisdiction-specific legal advice rather than a general rule.

Is a physical postal address required under all three laws?

No — that's specifically a CAN-SPAM requirement for commercial email to U.S. recipients. GDPR and CASL don't impose the same postal-address rule, though both require clear sender identification by other means.

If my opt-out mechanism works instantly, am I automatically compliant with all three?

No. A fast, working opt-out satisfies the unsubscribe requirement common to all three, but it doesn't establish that you had a valid basis to send the first message in the first place — which is where CAN-SPAM, GDPR, and CASL actually diverge.