Compliance · 22 August 2026
Is cold outreach legal?
Contacting businesses is lawful in most countries, but only on conditions, and the conditions follow the recipient rather than you. Broadly: identify yourself, make the opt-out real and easy, keep records of who asked not to be contacted, and screen phone numbers against the local do-not-call register.
This is a plain-language summary written by a software company, not legal advice. The rules differ by country and change. Half an hour with the regulator's own page for the market you are selling into is worth more than anything on this page.
The three regimes you are most likely to meet
| Where the recipient is | What governs it | Email to a business | The catch |
|---|---|---|---|
| UK | PECR, alongside UK GDPR | Generally allowed to corporate subscribers | Must identify yourself and honour opt-outs; calls must be screened against TPS/CTPS |
| EU | ePrivacy, alongside GDPR | Varies by member state; several are stricter than the UK | A named person's work address is personal data and needs a lawful basis |
| United States | CAN-SPAM | Allowed | Real postal address, honest subject line, working unsubscribe honoured within 10 days |
| Canada | CASL | Largely consent-based — the strictest of the four | Limited exceptions; penalties are substantial |
The distinction that does most of the work
A generic business address is not the same thing as a person.
info@thaisalon.co.uk or a shop's published phone number is, in most readings,
business contact information. priya.sharma@thaisalon.co.uk identifies a human
being, which makes it personal data in the UK and EU and brings GDPR properly into play — you
need a lawful basis, usually legitimate interest, and you need to be able to articulate it if
asked.
This is one reason our exports are business records. The dataset carries company names, addresses, switchboard numbers and published business emails, not the names and direct lines of the staff inside.
The six things that keep you out of trouble
- Say who you are. Real name, real business, real address in the footer.
- Make the opt-out one click and honour it immediately. Not a form. Not a login.
- Keep a suppression list and check every send against it. Contacting someone twice after they asked you not to is the complaint that actually gets escalated.
- Screen phone numbers against the do-not-call register for that country before dialling.
- Be relevant. Offering a website to a business with no website is defensible. Offering it to a dentist who already has one is harder to justify as legitimate interest.
- Keep a record of where the data came from. Ours is openly licensed and you can point at the licence — see data licensing.
Where the data comes from matters too
A scraped list from Google Maps breaks that platform's terms before you have sent anything. A bought list of ten thousand addresses of unknown origin cannot be defended at all, because you cannot say how it was collected. Openly licensed sources — Overture Maps under CDLA-Permissive-2.0, All The Places under CC0-1.0 — can be pointed at, which is the whole difference when someone asks.
Questions
Is cold emailing businesses legal?
In most countries yes, with conditions. The EU and UK generally permit unsolicited email to corporate addresses but require you to identify yourself and offer an opt-out; the US CAN-SPAM Act permits it with a real postal address and a working unsubscribe; Canada's CASL is stricter and largely consent-based. The conditions are not optional and they differ by where the recipient is, not where you are.
Does GDPR ban cold email?
No. GDPR governs personal data, and a generic address like info@ or a company's own switchboard number is usually not personal data. A named individual's work address — firstname.lastname@ — usually is, and needs a lawful basis, most often legitimate interest, which you must be able to explain. In the UK and EU the marketing rules in PECR sit alongside GDPR and are what actually govern the sending.
Can I cold call a business?
Usually, but many countries run do-not-call registers that cover business numbers too — the TPS and CTPS in the UK, the National Do Not Call Registry in the US, similar schemes elsewhere. Screening your list against the relevant register before dialling is the part people skip and it is the part that carries the fine.
Is the data itself legal to use?
The data we supply comes from Overture Maps (CDLA-Permissive-2.0) and All The Places (CC0-1.0), both openly licensed for commercial use including resale, and it contains business locations rather than personal records about individuals. That makes the source clean. What you then do with it is governed by the marketing law where the recipient lives.
Not legal advice. This is a summary for orientation. For anything that matters, read the regulator's own guidance for your market — the ICO in the UK, your national DPA in the EU, the FTC in the US, the CRTC in Canada — or ask a solicitor who does this properly.
The list this article is about
22,407,542 businesses with a phone number and no real website, filterable by country, city and trade. Ten free, no card.
Start free See the data