Blog · Compliance
Handle data like it matters
Multi-tenant isolation, credential encryption, data retention, and the regional rules — GDPR, CCPA, CASL, LGPD — that actually apply to cold email.
Compliance articles
10 articles
Compliance7 min
Cold email under Australia's Spam Act: consent, identification, and inferred consent for B2B
The Spam Act 2003 requires consent before you send. Here's how inferred consent works for B2B outreach, what a designated commercial electronic message actually is, and the ID rules.
Compliance7 min
Cold email under Brazil's LGPD: legitimate interest and how it compares to GDPR
LGPD is modeled closely on GDPR, and legitimate interest works for B2B cold email in Brazil too. Here's the ANPD's own balancing-test guidance and where LGPD actually diverges from GDPR.
Compliance7 min
CCPA/CPRA and cold email: it's a privacy law, not an anti-spam law
California's CCPA/CPRA gives residents rights over their data, but it doesn't set cold-email consent rules like CASL or GDPR. Here's what it actually changes for a B2B sender.
ComplianceAnalysis9 min
CAN-SPAM vs. GDPR vs. CASL: the cold-email compliance landscape compared
CAN-SPAM, GDPR, and CASL run on three different consent models. A practical comparison on consent, unsubscribe timing, and penalties — not legal advice, just the landscape.
ComplianceAnalysis7 min
Data minimization for cold email: collect less, keep less, risk less
Every field on a contact record can leak, go stale, or need erasing later. Why keeping less data is a deliverability and security strategy, not just a compliance checkbox.
Compliance7 min
Cold email under CASL: how implied consent actually works for B2B outreach
CASL is opt-in by default, but implied consent covers real B2B outreach. Here's the existing-business-relationship window, the conspicuous-publication test, and required message content.
Compliance8 min
Cold email under the GDPR: legitimate interest, the balancing test, and ePrivacy
GDPR doesn't ban B2B cold email. Here's the legitimate-interest basis senders actually rely on, what the balancing test requires, and how ePrivacy layers on top.
Compliance8 min
Cold email in the UK post-Brexit: UK GDPR, PECR, and the corporate-subscriber rule
UK GDPR started as a copy of EU GDPR but is diverging under the Data (Use and Access) Act 2025. Here's what changed, and PECR's corporate vs. individual subscriber split for B2B email.
Compliance7 min
The right to erasure and cold email: what actually has to disappear
A policy guide to GDPR erasure requests in cold outreach: what personal data must go, what aggregate data can stay, and why the erased address gets suppressed forever.
Compliance8 min
What a real data export looks like when you leave a cold-email platform
What a real data export should include when you leave a platform, using Norbelys's actual export bundle — plus the suspend-vs-delete distinction and grace period behind it.