CRM Solid logo
Home/Blog/Cold Outreach Compliance in 2026: Legal Under GDPR, Still Banned by the Platform

Cold Outreach Compliance in 2026: Legal Under GDPR, Still Banned by the Platform

Your outreach can satisfy GDPR, CAN-SPAM and CASL and still get your account closed on a Tuesday morning. A working guide to the four rulebooks that govern a cold message: data protection law, ePrivacy and PECR, platform terms of service, and the mailbox providers. With a jurisdiction comparison table and the November 2025 CJEU ruling that changed the consent argument.

Written by

Emirhan Güven

July 16, 2026
48 min read
Article
Share this article:

Your outreach program can satisfy GDPR, CAN-SPAM and CASL at the same time and still get your LinkedIn account permanently closed on a Tuesday morning with no warning and no appeal. The law and the platform are two separate authorities running two separate rulebooks, and they do not consult each other. Most compliance guides cover the first one and quietly pretend the second does not exist, which is how teams end up with a beautiful legitimate interest assessment on file and a dead account.

This piece covers both, plus the two layers underneath them that decide whether your message is ever seen. It is written for people who actually send cold messages: sales teams, founders doing their own prospecting, agencies running outreach for clients. The goal is not to scare you off cold outreach. The goal is to tell you precisely which rule you are breaking, who enforces it, and how fast.

This is not legal advice. We are a software company, not a law firm. Nothing here creates a lawyer-client relationship, and none of it is a substitute for advice from a qualified practitioner in your jurisdiction about your specific facts. Data protection law is fact-dependent, national implementations differ, and regulators change their guidance. Every primary source is linked so you can read it yourself and take it to counsel. If your outreach volume is meaningful or your market is regulated, get a real opinion.

One cold message, four rulebooks

A single DM to a stranger passes through four independent authorities before it lands. Each one can stop you. None of them accepts compliance with another as a defence.

Layer one is data protection law. In the EU and UK that is the GDPR. It governs whether you are allowed to hold and use that person's data at all: the name, the email, the company, the fact that they posted about hiring last week. This layer does not care whether you send anything. Building the list is already processing.

Layer two is marketing and communications law. In the EU this is the ePrivacy Directive, implemented nationally. In the UK it is PECR. In the US it is CAN-SPAM. In Canada it is CASL. This layer governs the act of sending: whether this specific message, to this specific person, on this specific channel, is permitted.

Layer three is the platform's terms of service. LinkedIn, Telegram, WhatsApp, X, Instagram. This is a private contract you accepted when you made the account. It is not law. It binds you anyway, and it is enforced by a machine that does not read your legitimate interest assessment.

Layer four is the delivery infrastructure. Gmail, Outlook, Yahoo. They decide whether your compliant, lawful, contractually permitted email lands in an inbox or a spam folder. No court is involved. No appeal exists.

Here is the part that catches people out, and it is the single most useful idea in this article: enforcement speed runs opposite to legal force. The GDPR is the most powerful of the four and the slowest to touch you. A DPA complaint takes months and usually starts with correspondence. Platform terms of service are the weakest instrument and the fastest: a LinkedIn restriction lands in seconds, applied by an automated system, with a support queue instead of a hearing.

So the layer most teams spend all their compliance effort on is the one least likely to hurt them this quarter, and the layer they treat as a technicality is the one that ends their program. Both matter. They just fail on completely different timescales.

LayerWho enforcesTypical triggerTime to consequenceWorst case
Data protection (GDPR, UK GDPR)National DPAA complaint from one annoyed recipientMonths to yearsFine, order to delete your database
Marketing law (ePrivacy, PECR, CAN-SPAM, CASL)DPA, FTC, CRTC, state AGsComplaint volume, patternMonths to yearsFine per message
Platform terms of serviceAutomated abuse systemsReport rate, automation signatureSeconds to daysPermanent account loss
Mailbox providersGmail, Yahoo, Outlook filtersSpam complaint rateHours to weeksDomain reputation destroyed

Read that table again with your own program in mind. If your entire compliance effort is a footer link and a paragraph in a privacy policy, you have addressed roughly one quarter of your actual exposure, and not the fast-moving quarter.

What a lawful basis actually requires, as opposed to what a template says

Under the GDPR you need a lawful basis under Article 6 to process personal data. For cold outreach, in practice, you have two candidates: consent, or legitimate interests. Consent for a cold list is close to a contradiction, because you cannot ask for consent without already processing the data you need in order to ask. So legitimate interests, Article 6(1)(f), carries almost every cold program in Europe.

People cite Recital 47 as if it settles the matter. It says the processing of personal data for direct marketing purposes "may be regarded as carried out for a legitimate interest". Read the verb. It says may. It is a signal that direct marketing is capable of being a legitimate interest, not a declaration that it always is. Treating Recital 47 as a permission slip is the most common mistake in this area.

The EDPB Guidelines 1/2024 on legitimate interest set out a three-step test, and all three must pass. Not two.

  1. The interest must be legitimate. The EDPB applies three cumulative criteria: the interest must be lawful, clearly and precisely articulated, and real and present rather than speculative. "We want more customers" is real but not precise. "We want to reach operations managers at logistics firms with 50 to 500 staff about a scheduling product they have a live budget line for" is precise.
  2. The processing must be necessary. This is where most assessments quietly fail. Necessary means strictly necessary, not useful. If a reasonable, less intrusive route to the same interest exists, the processing is unlikely to qualify. Enriching a prospect record with their personal mobile number when a work email achieves the same outreach goal is not necessary. It is convenient. Those are different words in this test.
  3. The balancing test must come out in your favour. Your interest is weighed against the rights, interests and freedoms of the person. It is fact-dependent every time and it is not a formality.

What actually moves the balancing test, in the direction you want:

  • Professional context. Messaging a named buyer at a work address about something inside their job description sits far better than messaging a private individual at a personal account.
  • Reasonable expectations. A procurement lead expects vendor contact. A nurse on a personal Instagram account does not expect a pitch for warehouse software.
  • Relevance. Genuine relevance to that person's role is not a copywriting tip here. It is a legal argument. Sending the same message to 4,000 people who share only a country makes the relevance claim collapse.
  • Data minimisation. Holding name, work email, employer and job title is defensible. Holding a scraped record of their last 200 posts, their inferred seniority, their estimated salary band and their personal phone number is a very different conversation.
  • Safeguards. A working opt-out, a hard frequency cap, real deletion on request, and a documented retention period all count in your favour.

Write it down. A legitimate interest assessment is not a filing exercise for its own sake: it is the artefact that proves you performed the balance at the time, not retroactively after a complaint. Three paragraphs on a page beats nothing, and nothing is what most teams have. If you cannot write down why a specific person would reasonably expect to hear from you, you have not passed the test, you have skipped it.

One more thing that surprises people: the legal basis argument and the sending argument are separate questions. Legitimate interest can make it lawful for you to hold the data and even to send in some circumstances, and ePrivacy can still require consent for the transmission itself. Passing Article 6 does not end the analysis. That is the next section, and it is the one that decides whether your program is legal at all.

Is a DM "electronic mail"? The question that decides your entire program

Article 13 of the ePrivacy Directive is the rule that actually governs sending. It says unsolicited communications for direct marketing by "electronic mail" require the recipient's prior consent, with one narrow exception. If your channel is electronic mail, you are in an opt-in regime, and your lovely legitimate interest assessment does not get you out of it.

So: is a LinkedIn DM electronic mail? An Instagram DM? A Telegram message? Most outreach teams have never asked. They assume the rule is about email because it has the word mail in it, and they treat DM channels as an unregulated frontier where the email rules do not reach.

That assumption is wrong, and the UK regulator says so in writing.

The ICO's guidance on electronic mail marketing defines electronic mail as any text, voice, sound or image message sent over a public electronic communications network that can be stored in the network or the recipient's terminal equipment until collected. The ICO states the term has an intentionally broad meaning designed to cover new forms of messaging, and it lists what falls inside: email, text messages, picture and video messages, voicemail, in-app messages, and direct messaging on social media.

That is not a grey area. That is the regulator naming your channel.

The distinction the ICO draws is between a private message stored for a specific intended recipient to collect, and something displayed publicly. A banner ad is not electronic mail. A targeted ad in a news feed is not electronic mail, even though it is targeted at a particular user, because it is displayed openly and not stored for a specific recipient to collect. A DM sitting in someone's message requests folder is exactly a stored message awaiting collection by a named person. It is electronic mail.

The practical consequence is blunt. In the UK, and in the EU member states that read Article 13 the same way, a cold DM to an individual is subject to the same consent rule as a cold email. Telegram, Instagram, X, WhatsApp, LinkedIn: the channel novelty buys you nothing legally. It buys you a temporary attention advantage, which is a real commercial fact and covered in our piece on what actually gets a reply in a cold DM, but it is not a legal exemption.

The corporate subscriber gap, and why it is narrower than you think

Regulation 22 of PECR applies the consent rule to individual subscribers. Corporate subscribers, meaning limited companies and LLPs, sit outside regulation 22. This is the basis of the standard UK B2B email argument, and it is genuinely correct as far as it goes.

It does not go as far as people think. Three reasons.

First, the subscriber is the person or entity who contracts for the service, and sole traders and many partnerships count as individual subscribers, not corporate ones. Your list does not know which is which. A meaningful share of any B2B list in a country with lots of small businesses is composed of individual subscribers wearing a business hat.

Second, and this is the part that gets skipped: the corporate subscriber carve-out is a PECR point, not a GDPR point. [email protected] identifies a living individual. It is personal data. You still need an Article 6 basis, you still owe transparency, and the person still has a right to object. PECR letting you send does not mean the GDPR lets you process. The UK government reviewed this during the Data (Use and Access) Act 2025 and chose not to extend PECR's marketing rules to B2B, so the gap survives, but it never covered the data protection layer in the first place.

Third, the carve-out is a UK and national implementation quirk. Several EU member states applied Article 13 to legal persons as well. If your list spans Europe, the country of the recipient decides the rule, and you are running whichever national regime is strictest across your target set unless you segment by country. Most teams do not segment by country. They should.

The soft opt-in, and the trap inside it

Article 13(2), and regulation 22(3) in the UK, contains the only real exception: the soft opt-in. You may market by electronic mail without prior consent where you obtained the contact details in the course of a sale or negotiations for a sale to that person, the marketing concerns only your own similar products or services, and you gave a simple free means of refusing both at collection and in every subsequent message.

Every one of those conditions is load-bearing. "In the course of a sale or negotiations for a sale" means a real commercial conversation with that person, not a conference badge scan and not a list purchase. "Similar products or services" means similar to what they were buying, not everything you sell. And the opt-out must be in every message, not just the first.

The trap: soft opt-in is a warm exception. It applies to people who nearly bought from you. It has nothing to do with cold outreach and cannot be stretched to cover it, no matter how the vendor of your sending tool phrases it. If someone tells you soft opt-in makes your cold list legal, they are either confused or selling you something.

Inteligo: what the CJEU changed in November 2025

On 13 November 2025 the Court of Justice of the European Union decided Inteligo Media SA v ANSPDCP (C-654/23), on a reference from the Bucharest Court of Appeal. It is the most consequential email marketing judgment in years and it barely registered outside privacy circles.

The facts are ordinary, which is why the ruling reaches so far. Inteligo published a Romanian legal news site. Readers got six free articles a month. Create a free account and you got two more articles plus a free daily newsletter. The newsletter contained genuine editorial content: legislative summaries, links to free articles. It also linked to paid content and was built to push free readers toward the paid subscription. The Romanian DPA fined them for sending it without consent.

The Court held three things, and each one matters to a different group of people.

One: editorial content does not launder a marketing email. The Court found the newsletter was a communication "for the purposes of direct marketing" despite its informative content, because it pursued a commercial objective and addressed recipients individually. The functional aim decides it. If the reason the email exists is to move someone toward a paid offering, it is direct marketing, and dressing it in a legislative digest changes nothing.

Anyone running a "value-first newsletter" that exists to warm a list should read that sentence twice. The 90/10 educational content ratio is a good tactic. It is not a legal category.

Two: a free account can be a "sale". Article 13(2) requires the details to be obtained "in the context of the sale of a product or a service", and everyone assumed that meant money changed hands. The Court held that "sale" does not require direct remuneration and that indirect remuneration can suffice. Creating a free account that grants limited content and a newsletter, as part of a business model that leads to a paid service, can count.

That is a real widening of the soft opt-in for freemium and tiered products. If you have a free tier, the people on it may be reachable under 13(2) for marketing your own similar services, subject to the other conditions. It does not touch cold lists. Nobody on a bought list ever created an account with you.

Three, and the structural one: where Article 13(2) applies, you do not need a separate Article 6(1) GDPR basis. Reading Article 13(2) with Article 95 GDPR, the Court held that the conditions for lawful processing in Article 6(1) do not apply where the controller uses the address in accordance with Article 13(2). The ePrivacy rule is exhaustive on its own subject matter.

This cuts both ways, and the second way is the one that matters to you. Yes, it kills the double-jeopardy problem where you had to satisfy both regimes for the same send. But it also confirms that on the question of transmission, ePrivacy wins. Where ePrivacy addresses the same topic as the GDPR, ePrivacy's provisions apply. You cannot argue your way from Article 6(1)(f) into a send that Article 13(1) requires consent for. The legitimate interest route does not override the consent rule for electronic mail. It never did, and now there is a judgment saying so in terms.

The short version for cold outreach: Inteligo is good news if you have a free tier and a warm list. It is neutral-to-bad if your plan was to use legitimate interest as a universal key to unsolicited DMs, because it confirms which lock that key does not open.

The Article 14 notice almost nobody sends

Here is an obligation that is in the text of the GDPR, applies to virtually every cold outreach program in Europe, and is ignored by approximately all of them.

When you collect personal data directly from someone, Article 13 tells you what to disclose. When you obtain it from somewhere else, which is what every cold program does, Article 14 applies. Scraped a profile? Bought a list? Pulled it from a data provider? Enriched it from a public directory? Article 14.

Article 14 requires you to tell the person: who you are, the purposes and the legal basis, the categories of data, where you got it from (including whether it came from a publicly accessible source), who you will share it with, how long you will keep it, and their rights including the right to object.

The timing rule in Article 14(3) is the sharp end. You must provide it within a reasonable period after obtaining the data and at the latest within one month. And if you are using the data to communicate with the person, at the latest at the time of the first communication.

Read that again with your sequence in mind. Your first cold message is the deadline. Not a follow-up, not a page they might visit. The first message has to carry the notice or point clearly to it.

Add Article 21(4) on top, which says the right to object must be brought explicitly to the person's attention at the latest at the time of the first communication, and presented clearly and separately from any other information. Two independent provisions land on the same moment: message one.

What that means for a 300 character DM

This is where it gets genuinely hard, and where honest advice diverges from the usual "just add a footer" answer. You cannot fit an Article 14 notice into a Telegram DM. Nobody can. The character budget does not exist and cramming it in destroys the message.

What people actually do that holds up reasonably well:

  • A short, plain line plus a link. "I found you via your company's site. Reply STOP and I won't message again. Where your data came from and how to remove it: example.com/privacy/outreach". That is roughly 150 characters and it does real work: it identifies the source, gives a separate and clear objection route, and links a layered notice.
  • A dedicated outreach privacy page. Not your general privacy policy. A page that answers the Article 14 list specifically for prospects: the sources you use, the categories, the retention period, the objection route. Linking your 4,000 word general policy and hoping is weaker than a 400 word page that answers the actual questions.
  • A one-click objection route that is not "reply and hope". Reply-based opt-out on a DM channel only works if someone reads the replies and acts on them. Which brings us to the next section.

On the "disproportionate effort" exemption in Article 14(5): people reach for it constantly and it almost never applies here. It is aimed at archiving, research and statistical processing, and it is hard to argue that telling someone is a disproportionate effort when you are already, by definition, in the middle of sending them a message. The effort is one line.

Data subject rights on a channel that was never built for them

Rights are where compliance stops being a document and starts being an operations problem. A prospect can exercise them, they usually do it in the reply, and the reply is where nobody is looking.

The right to object to direct marketing is absolute. Article 21(2) gives the right to object at any time to processing for direct marketing, including profiling related to it. Article 21(3) says that when they object, the data "shall no longer be processed for such purposes". Full stop. There is no balancing test, no compelling grounds argument, no "but our interest". Unlike the general Article 21(1) objection, you cannot push back. You stop.

Now think about how that arrives on a DM channel. It does not arrive as a form submission with a clean field. It arrives as:

  • "not interested"
  • "please remove me"
  • "how did you get my number"
  • "stop"
  • A block, with no message at all
  • An angry voice note
  • The same thing in a language your team does not read

Some of those are objections. Some are not. "Not interested" is a soft no to the offer. "Please remove me" is unambiguously an Article 21(2) objection and it binds you across every channel you hold that person on, not just the one they said it in. That last part is the bit teams get wrong constantly: an objection sent by Telegram DM also stops the email sequence. The right attaches to the person, not the channel. If your Telegram tool and your email tool are separate systems with separate lists, you have just failed, and you will not know for six weeks.

This is a real argument for keeping identity in one place rather than one list per tool. A unified inbox where every channel resolves to the same contact record is not only an efficiency question. If your contact record is the single object that carries the suppression state, one "remove me" can stop everything at once. If you have six tools with six lists, you have six chances to fail and one complaint is all it takes to find out.

Access requests are worse than you expect. Article 15 gives the right to a copy of the data and information about sources. On a cold outreach program the honest answer to "where did you get this" is often "an enrichment vendor bought it from someone who scraped it", and you may not know the chain. If you cannot answer, you have a transparency problem that predates the request. The fix is upstream: record the source on the record at import time. It costs one field. Retrofitting it later is impossible.

Erasure has a trap. If someone asks to be deleted and you delete every trace, you lose the record that they asked, so they come back into the next scrape and you message them again. That is a worse outcome and a repeat violation. The standard practice is a suppression list: keep the minimum needed (usually a hash of the identifier plus the date and the fact of the objection) to honour the request, and delete the rest. Retaining data to comply with a legal obligation is a different purpose from marketing, and it is the right call.

Retention: the quiet violation sitting in your database right now

Storage limitation, Article 5(1)(e), says you keep personal data no longer than necessary for the purpose. There is no number in the GDPR. That is not permission to keep it forever. It is an instruction to decide, write it down, and enforce it.

The prospecting database is where this rots invisibly. Nobody deletes a lead. Leads are assets. So a CRM accumulates people who never replied, in 2022, at companies that no longer exist, for a product that has changed twice. Every one of them is a record you are processing on the theory that they might buy one day, and that theory gets less credible every month.

A defensible way to set the period, and to be able to explain it:

  • Tie it to the interest, not to convenience. If your legitimate interest is reaching people about a product relevant to their current role, the interest expires when the role plausibly does. B2B job tenure is a few years, so a two to three year clock on unengaged prospects is arguable. Ten years is not.
  • Different clocks for different states. Never engaged: shortest. Engaged then went quiet: longer. Objected: suppression only, forever, minimal fields. Customer: a different basis entirely, usually contract, plus tax retention rules that may be seven years or more depending on your country.
  • Write the number down and make something enforce it. A retention policy nobody executes is worse than none, because it documents that you knew and did not act.

The uncomfortable question worth asking your own team: if a regulator asked today why you still hold 40,000 people who never once replied, what is the sentence you would say out loud? If there is no sentence, the answer is not to write a better policy. It is to delete them. They were never going to convert anyway. Contacts you cannot justify are not assets, they are unpriced liabilities sitting in a database you pay for.

CAN-SPAM and CASL: the two North American extremes

North America runs the widest spread of any two neighbouring jurisdictions on earth. The US has the most permissive regime in the developed world. Canada has one of the strictest. The border between them is 8,891 kilometres long and your list does not know where it is.

CAN-SPAM: opt-out, not opt-in

The US does not require consent to send commercial email. This genuinely surprises Europeans. Under CAN-SPAM you may email a stranger cold, provided you follow the rules, and the rules are a conduct code rather than a permission regime.

Per the FTC's own compliance guide, the requirements are: do not use false or misleading header information; do not use deceptive subject lines; identify the message as an ad; include your valid physical postal address; tell recipients how to opt out; honour opt-outs within 10 business days; and monitor what others do on your behalf. That last one matters: hiring an agency does not transfer the liability. Both the company whose product is promoted and the company that sends can be held responsible.

The number people quote is real. The FTC states each separate email in violation is subject to penalties of up to $53,088, set by its inflation adjustment effective 17 January 2025, up from $51,744. Per email. Not per campaign.

Keep perspective on it, though, because the "$53,088 per email times your list size" arithmetic in every scare-post is not how enforcement works. The FTC does not chase theoretical maximums against a startup sending 500 emails. It brings cases against real deception at scale, and settlements are negotiated against conduct, volume and ability to pay. The realistic CAN-SPAM risk for an honest B2B sender who forgot a postal address is not a nine-figure judgment. It is that you are technically in violation and have no defence if someone decides to make it a problem.

Three things CAN-SPAM does not do, which is where the false comfort lives:

  • It does not cover DMs. CAN-SPAM is about email. Your Instagram DM strategy is not made legal by it, because it was never in scope. It does not fill the gap: it just is not there.
  • It does not preempt everything. State law and other federal law still bite. If your outreach touches phone numbers or texting you are in a different and far more litigious regime, and California, Washington and others have their own rules.
  • It does not protect you from the platform or the mailbox provider. Perfect CAN-SPAM compliance and a 4% spam complaint rate ends the same way: your domain stops delivering. See below.

CASL: consent required, and you carry the burden of proof

Canada is the mirror image. CASL requires consent, express or implied, before you send a commercial electronic message. And unlike almost every other regime, the sender has the onus of proving consent, as the CRTC states directly. You are not presumed compliant. You are presumed to be able to show your work.

Implied consent is the route most B2B senders use, and the CRTC's guidance on implied consent is specific about how it arises and when it expires:

  • Existing business relationship: implied consent runs for two years following the last transaction, contract or membership.
  • Inquiry or application: a much shorter six months from the date of the inquiry.
  • Existing non-business relationship: two years, from donations, volunteer work or membership in a club or association.
  • Conspicuous publication: the route cold outreach actually depends on. If the person published their address publicly, you may rely on it only if there is no statement attached saying they do not want to receive commercial electronic messages, and your message is relevant to that person's business, role, functions or duties in a business or official capacity.

That second condition is the one that kills generic blasting. A publicly listed info@ address on a plumbing company's website does not give you implied consent to pitch enterprise HR software. It gives you implied consent to talk to them about plumbing. Relevance is not a suggestion in CASL, it is a condition of the consent existing at all.

The "business card rule" is similar: if someone hands you their card or tells you their address, you have implied consent, but the CRTC's guidance is that you should document it, which in practice means sending a confirmation referencing the conversation and the date it happened, and keeping the record. Because when it is challenged, the burden is yours.

The maximum penalty under section 20(4) is $1 million for an individual and $10 million for any other person. Enforcement is real but not indiscriminate. The CRTC's enforcement report for 1 April to 30 September 2025 shows the shape of it: 153 notices to produce, 123 warning letters, 5 preservation demands, and 1 notice of violation carrying a $50,000 penalty. The Spam Reporting Centre took 152,603 complaints in those six months, about 5,869 a week.

Look at the ratio. Roughly 152,000 complaints, 123 warning letters, one notice of violation. The CRTC is not fining people at random. It escalates, and the warning letter is the system telling you it has noticed. Most senders never find out they were noticed, because most senders never generate enough complaints to matter. Which is the theme of this whole article: the volume that triggers regulators is far above the volume that triggers platforms.

One historical footnote worth knowing because it still appears in outdated advice: CASL's private right of action, sections 47 to 51, which would have allowed lawsuits for up to $200 per occurrence to a maximum of $1 million per day, was suspended indefinitely by an Order in Council in 2017 before it took effect. It has not been revived. If a compliance post is warning you about CASL class actions, it was written from a 2017 draft and you should distrust everything else in it too.

Which country's rules apply, and what each one says

The rule that governs a message is set by where the recipient is, not where you are. A Turkish company emailing a German buyer is inside the GDPR and inside German ePrivacy implementation. This is the single most common misunderstanding in international outreach, and it is why "we're not an EU company" is not a defence anyone has ever won with.

Jurisdiction Cold email to a business Cold DM to an individual Burden of proof Maximum penalty Practical read
EU (ePrivacy + GDPR) Consent for individual subscribers. Some member states extend to legal persons. GDPR applies regardless Treated as electronic mail. Consent rule applies Controller must demonstrate compliance (Art. 5(2)) Up to 20m EUR or 4% global turnover under GDPR; ePrivacy penalties set nationally Strictest in aggregate. Varies by member state. Segment by country
UK (PECR + UK GDPR) Corporate subscribers outside reg. 22. Sole traders and many partnerships are individual subscribers. UK GDPR still applies ICO: in-app messages and social media DMs are electronic mail. Consent rule applies to individuals Sender must show consent or exemption PECR raised from ??500,000 to ??17.5m or 4% of global turnover on 5 February 2026 The B2B gap is real but narrow, and the penalty ceiling just moved 35x
United States (CAN-SPAM) Permitted. No consent needed. Conduct rules apply Not covered. CAN-SPAM is an email statute Regulator must prove violation Up to $53,088 per email (FTC, effective 17 Jan 2025) Most permissive. The real constraint is deliverability, not law
Canada (CASL) Express or implied consent required. Conspicuous publication needs role relevance Covered. CASL applies to commercial electronic messages broadly Sender bears the onus of proving consent $1m individual, $10m other persons (s. 20(4)) Strictest single statute. Consent records are mandatory, not optional

If you sell into more than one of these, you have two options. Segment by recipient country and run four different programs, which is correct and which almost nobody does. Or run everything to the strictest standard in your target set, which is simpler, costs you some volume in the US, and is what most serious teams settle on. Both are defensible. Running the US playbook globally and hoping is neither.

The layer that actually bans you: platform terms of service

Everything above is law. Now the part that will actually affect you this month.

When you created your LinkedIn account you accepted a contract. It is not legislation, no parliament debated it, and no regulator enforces it. It is enforced by the counterparty, unilaterally, by switching off your account. There is no proportionality requirement, no right to a hearing, and no obligation to tell you which rule you broke. In the hierarchy of legal instruments this sits near the bottom. In the hierarchy of things that will destroy your pipeline on a random Tuesday, it is first by a distance.

And here is the asymmetry that makes the whole thing bite: the platform's rules are stricter than the law, and they apply to conduct the law expressly permits. There is no jurisdiction on earth where sending a relevant, honest, opt-out-bearing DM to a business contact is illegal in the US. LinkedIn will still restrict you for it if you did it with a tool.

LinkedIn: the most restrictive terms in the industry

Section 8.2 of the LinkedIn User Agreement, effective 3 November 2025, says you agree not to:

  • "Develop, support or use software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services"
  • "Use bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement"
  • "Override any security feature or bypass or circumvent any access controls or use limits of the Services (such as search results, profiles, or videos)"

Read what that actually forbids. Not spam. Not volume. Not irrelevance. It forbids the method. Automated connection requests, automated messages, automated profile visits, automated exports, browser extensions that do any of it. The content of your message is irrelevant to this rule. A single automated connection request is a breach. A thousand hand-typed ones are not.

That is worth sitting with, because it inverts the mental model most people carry. On LinkedIn, how you sent it matters more than what you sent. LinkedIn's help pages are explicit that using such tools puts a member in violation of the User Agreement and risks accounts being restricted or shut down. They also warn, pointedly, that prohibited tools may stop working without notice. That has happened repeatedly to entire automation vendors and their customers at once, which is the risk nobody prices in: your compliance depends on a third party's continued evasion of detection.

If your outreach strategy requires LinkedIn automation, you do not have a strategy. You have a bet on detection, and the house updates its models on its own schedule.

WhatsApp: opt-in is contractual, not just legal

The WhatsApp Business Messaging Policy states it plainly: "You may only contact people on WhatsApp if: (a) they have given you their mobile phone number; and (b) you have received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from you."

Both conditions. They gave you the number, and they opted in. A scraped number fails (a). A number they gave you for a delivery notification fails (b) for marketing. The policy also requires you to respect all requests to opt out, including requests made off WhatsApp, which is another cross-channel suppression obligation arriving from a completely different direction than the GDPR one.

Meta layers business verification and privacy policy requirements on top for template messaging. The upshot: WhatsApp cold outreach is not a compliance problem you can solve. It is contractually prohibited at the first step. There is no configuration, no warmup schedule and no unofficial API that changes this, and the unofficial APIs are themselves an additional breach that gets numbers banned rather than throttled. If someone is selling you WhatsApp cold outreach, they are selling you a number that will be banned. We go deeper into how the two channels differ in practice in Telegram vs WhatsApp for business.

Telegram: no published thresholds, and that is the point

Telegram is the most permissive major DM channel and the most misunderstood. Its Spam FAQ is refreshingly direct about the mechanism: when users press Report Spam, the messages go to moderators. If moderators agree, the account gets limited. Telegram's own framing is that "people usually don't like it when strangers contact them, so they will report you if they find your messages annoying".

Three details from that page that matter more than any blog's numbers:

  • Limited accounts can still message people who have their number saved as a contact, and can always reply to anyone who messaged first. A limit is not a ban. It is a surgical removal of exactly the capability cold outreach depends on.
  • A first offence, if you are not an industrial-scale spammer, typically means a few days. Repeats extend it.
  • Telegram publishes no numeric threshold. None. Not in the FAQ, not anywhere.

That last one deserves emphasis because the internet is full of confident numbers: "40 to 80 DMs per day is safe", "5 to 7 reports triggers a block". Those numbers are invented. They are not in Telegram's documentation, Telegram has never published them, and they get copied between SEO posts until they look like consensus. Do not build a sending policy on them.

What the FAQ actually implies is a reports-per-message model, not a messages-per-day model. The system is driven by complaint signal, not volume. Which means the honest guidance is uncomfortable: there is no safe number. Sending 30 messages that annoy 30 people is more dangerous than sending 300 that annoy nobody. Relevance is the rate limiter. Everything else is a proxy. Our guide to avoiding Telegram bans and the flood wait entry go into the technical side.

X: automated DMs are out

X's automation rules prohibit sending automated posts or Direct Messages that are spam, and prohibit automated DMs that amount to unsolicited contact, including to people who follow you. Automating replies and mentions to reach many users on an unsolicited basis is called out specifically as an abuse of the feature. Enforcement can include suspension of associated accounts and termination of API access.

The nuance people miss: a follow is not consent on X. "They followed us so we DM'd them" is not a defence under the rules. There is a legitimate use of DM tooling on X, and it is conversational: answering people who message you, managing real threads at scale. That is a different activity from automated cold DMs, and the rules treat it differently. See our X DM guide for where the line sits.

Meta: scraping is prohibited even when you are logged in

Meta's terms, updated for 2025, close the loophole people used to argue: you may not access or collect data from Meta products using automated means without prior permission, "regardless of whether such automated access or collection is undertaken while logged in to a Facebook account". Instagram restricts accounts for data scraping and treats collecting information in an automated way without express permission as a violation. Meta's Automated Data Collection Terms make clear that accepting them is not itself the required written permission: that has to be obtained separately.

Translation: there is no compliant path to bulk Instagram DM outreach from scraped audiences. The scraping breaches the terms before you send anything.

The pattern across all five

Every platform prohibits some combination of three things: automation of contact, collection of data by automated means, and contacting people who did not ask. The law prohibits roughly the third one, and only in some places, and only for some recipients. The platforms prohibit all three, everywhere, for everyone. The platform layer is a strict superset of the legal layer, and it is enforced in seconds by software rather than in years by lawyers.

The fourth rulebook: mailbox providers and the 0.3% rule

You can be lawful under the GDPR, permitted under CAN-SPAM, contractually fine because email has no platform to ban you, and still fail completely. Gmail decides whether your email exists.

Google's sender requirements set the bar. If you send more than 5,000 messages per day to Gmail accounts you are a bulk sender, and since 1 February 2024 bulk senders must set up SPF and DKIM plus DMARC for their sending domain, support one-click unsubscribe on marketing and subscribed messages using the List-Unsubscribe-Post and List-Unsubscribe headers, and keep the spam rate reported in Postmaster Tools below 0.3%, with Google recommending you stay under 0.10%.

Do the arithmetic on 0.10%, because it reframes everything. One complaint per thousand delivered. Send 2,000 cold emails and two people hitting the spam button puts you at the recommended ceiling. Not two hundred. Two.

That is a stricter constraint than any statute in this article, and it arrives faster than any of them. No regulator will ever contact you about a 0.4% complaint rate. Gmail will simply stop delivering your mail, including to the customers you already have, including your invoices and password resets if you share a domain. There is no notice, no appeal, and no fine. Just silence, and a pipeline that quietly stops working while your dashboard says "delivered".

Two operational consequences that follow directly:

  • Never cold-send from your primary domain. The reputation damage is not contained to the campaign. Use a separate sending domain so a bad campaign cannot take your transactional mail down with it.
  • One-click unsubscribe is not the same as an opt-out link. Google requires the header-based mechanism. A link in your footer that leads to a preference centre with three steps does not satisfy it, and the friction directly converts unsubscribes into spam complaints, which is the metric that actually kills you. Making it hard to leave is how you get reported.

Legal and banned, banned and legal: the four quadrants

Put the legal axis and the platform axis on a grid and you get four boxes. Most teams believe they are choosing between two of them. They are actually moving between all four, usually by accident, and the two systems fail in opposite directions.

Permitted by the platformProhibited by the platform
Lawful Manual, relevant DMs to business contacts in the US. Replies to inbound. Messaging your free-tier users about your own similar service. The target. LinkedIn automation to US prospects. Automated X DMs to followers. No law broken. Account gone.
Unlawful Cold email to EU individuals from your own SMTP server. No platform to stop you. Nothing stops you at all, actually. Scraped WhatsApp blasts. Bulk Instagram DMs from a scraped audience. Both systems, both failing.

The top-right box is the one nobody models. It is enormous, it contains most of the LinkedIn outreach industry, and every message in it is legal. Legality is simply not the binding constraint there, and a team that measures compliance only by legal risk will walk into it with a clean conscience and lose the account.

The bottom-left box is the one that should worry Europeans, and it produces the most dangerous advice in this whole area.

Why "just use email, it is safer" is backwards

Here is the obvious answer, and it is wrong. Teams that get burned by a LinkedIn restriction conclude that DM channels are risky and retreat to cold email, because email has no platform that can ban them. You own the server. You own the domain. Nobody can switch you off.

That reasoning is correct about the platform layer and exactly inverted on the legal one. For an EU or UK individual recipient, cold email is the channel with the clearest legal prohibition and the weakest technical enforcement. Article 13(1) is unambiguous about electronic mail. There is simply no automated system that will stop you, so nothing pushes back until a complaint does, months later, in writing, from a regulator.

DM channels are the opposite: the law is the same, but the enforcement is immediate and automatic. So people feel the constraint on Telegram and do not feel it on email, and they mistake the absence of a felt constraint for the absence of a real one. Fleeing to email does not reduce your legal risk. It removes the feedback that was telling you about it.

Why "only use publicly available data" is also backwards

The second piece of well-meaning bad advice: stick to public data and you are fine. It sounds principled. It is precisely wrong on both axes.

Legally, public does not mean unregulated. Personal data published on a website is still personal data. Article 14 specifically requires you to disclose when data came from a publicly accessible source, which only makes sense because using public data is a regulated activity. The GDPR has no public-domain exemption. CASL's conspicuous publication route is the closest thing to one and it still demands role relevance and no attached objection statement.

And on the platform axis it is worse. Gathering "publicly available" profile data at any scale is exactly what LinkedIn's section 8.2 and Meta's automated data collection terms prohibit in their most explicit language. Public visibility is not permission to collect. The data being visible to a logged-in human is the reason it feels acceptable and has nothing to do with whether the collection is permitted.

So the two most common instincts, retreat to email and stick to public data, each move you out of one failure mode and directly into the other. The only thing that reduces risk on both axes at once is the boring one: send fewer, more relevant messages to people who have a plausible reason to hear from you, using methods the platform allows. That is not a compliance hack. It is the same thing that makes outreach work, which is the actual punchline of this article and the reason the compliant program and the effective program keep converging.

A compliance stack you can actually operate

Principles are cheap. Here is the concrete version, in the order you should build it.

  1. Record the source on every contact, at import time. One field. Where did this record come from, on what date, and by what method. Without it you cannot answer an Article 15 request or write a truthful Article 14 notice, and you cannot retrofit it later. This is the single highest-value thing on this list and it costs nothing.
  2. Segment by recipient country before you write copy. Not after. The rule is set by where they are. If you cannot determine the country, treat the record as EU. That is the conservative default and it costs you nothing but volume you were probably not converting.
  3. Write the legitimate interest assessment. Three paragraphs. Who you are targeting and why they would expect it, what data you hold and why each field is necessary, what safeguards you run. Date it. Redo it when the targeting changes.
  4. Build the outreach privacy page before the first send. Not the general policy. A page for prospects that answers the Article 14 list: sources, categories, purpose, basis, retention, rights, objection route.
  5. Put the notice line and the objection route in message one. Both Article 14(3) and Article 21(4) point at the first communication. One line, plainly worded, with the objection separated from the pitch.
  6. Make suppression global and permanent. One person, one record, every channel. An objection on Telegram stops the email sequence. Keep a minimal suppression list forever so deletion does not resurrect them on the next import.
  7. Set the retention clock and make something enforce it. Two to three years for unengaged prospects is arguable. Pick a number, write why, and have a job that acts on it.
  8. Separate your sending domain from your primary domain. Deliverability containment. Non-negotiable if you cold email at all.
  9. Watch complaint rate, not volume. Postmaster Tools for email, report rate for DMs. Complaint rate is the metric both the platform layer and the mailbox layer actually enforce on, and it is the earliest signal you have that your targeting is wrong.
  10. Keep the records. In Canada the burden is explicitly yours. Under Article 5(2) the controller must be able to demonstrate compliance. "We were compliant" without evidence is a sentence, not a defence.

What CRM Solid does about this, and what it does not

We build outreach tooling, so we have a conflict of interest here and you should read this section knowing that. We would rather be straight with you than sell you comfort.

What genuinely helps. Our multi-channel sequences stop automatically when someone replies, so a person who says "not interested" does not receive step three. Pacing is rate-limit-aware with automatic flood wait backoff, which keeps you inside the technical envelope. Every channel resolves to one contact record in a unified inbox, so an objection arriving by Telegram DM is visible against the same person you are emailing, which is the structural precondition for global suppression. Custom fields mean you can store the data source on the record, which is step one above. AI Agents have per-contact pause and human handoff, so a conversation that needs a person gets one.

What does not help, and what we will not pretend.

  • We do not ship a consent management platform. There is no consent ledger, no proof-of-consent capture, no jurisdiction-aware sending gate that blocks an EU record. If you need to prove consent under CASL, you need something else or a disciplined process in a custom field. We are not going to describe our contact fields as a compliance product.
  • Auto-stop-on-reply is not an opt-out mechanism. It stops a sequence. It does not record an Article 21(2) objection, it does not propagate suppression to your other tools, and it does not stop a human from messaging that person again next quarter. Those are separate things and only one of them is automatic.
  • Our Telegram scraper and bulk messaging can absolutely be used in ways that breach Telegram's terms. The rate limiter reduces the chance of a limit. It does not make the activity permitted, and it is not a compliance feature. A tool that paces your messages is managing a symptom. If your list is people who never asked to hear from you, we have made you slower, not lawful.
  • We have no LinkedIn automation and are not going to build it. Not on principle. Because section 8.2 makes it a breach on the method alone, and a feature whose value depends on evading detection is a feature we would be selling you a liability with. LinkedIn is in our list of inbox channels for conversations, which is a different activity from automated cold contact.
  • WhatsApp Learning is read-only by design. It reads exported chats to learn how your team writes and it never sends anything. That is not a limitation we are apologising for: given WhatsApp's opt-in rule, a sending feature would be a product that gets our users' numbers banned.

The honest summary: software can help you run a compliant program and cannot make a non-compliant one lawful. No vendor can give you a lawful basis. If the plan is to buy a tool that makes cold outreach legal, the tool does not exist, and anyone claiming otherwise is describing a rate limiter and calling it compliance.

Frequently asked questions

Is cold email legal under GDPR?

Sometimes, and the GDPR is only half the question. The GDPR governs whether you may hold and use the data, and legitimate interest under Article 6(1)(f) can cover that for relevant B2B outreach. But ePrivacy governs the send, and it requires consent for electronic mail to individual subscribers. Passing the GDPR does not get you past ePrivacy. Both have to work.

Do GDPR rules apply to LinkedIn or Instagram DMs?

Yes, and so do the marketing rules. The ICO defines electronic mail broadly enough to include in-app messages and direct messaging on social media, which puts DMs in the same consent regime as email. The channel being newer does not create an exemption. Separately, the platform's own terms usually prohibit automated DMs regardless of what the law permits.

Can I email a work address without consent in the UK?

Often, yes. PECR regulation 22 applies to individual subscribers, and limited companies and LLPs are corporate subscribers, so they sit outside it. Two catches: sole traders and many partnerships count as individual subscribers, and UK GDPR still applies to a named person's work address regardless. You need a lawful basis, a transparency notice and an objection route either way.

What is the penalty for cold outreach violations?

It depends on which rulebook. The FTC lists up to $53,088 per email under CAN-SPAM. CASL allows up to $1 million for an individual and $10 million for other persons. UK PECR moved from ??500,000 to ??17.5 million or 4% of global turnover on 5 February 2026. Realistically, the consequence you will actually meet first is an account restriction or a dead sending domain.

Does buying a list ever comply?

Almost never in the EU or UK, and it is hard in Canada. You inherit an Article 14 obligation you usually cannot fulfil because you do not know the real source, the recipient never had a relationship with you so soft opt-in cannot apply, and under CASL you carry the burden of proving a consent you were never given. In the US it is lawful under CAN-SPAM and still likely to wreck your deliverability.

How long can I keep prospect data if they never reply?

As long as the purpose lasts, which is not forever. There is no number in the GDPR. Tie it to the interest you claimed: if you are targeting people about their current role, the interest fades as roles change, so two to three years for an unengaged prospect is arguable and ten is not. Pick a number, document the reasoning, and enforce it automatically.

Where to start

If you do one thing from this article, make it the source field. Record where every contact came from, on what date, by what method, starting with the next import. It takes an afternoon, it is the foundation of every other obligation here, and it is the only item on the list that becomes impossible if you delay it.

If you do two things, add global suppression across channels. One person, one record, one off switch. It is the difference between a mistake and a pattern.

Then go and read the actual sources. Not summaries of them, including this one. Telegram's Spam FAQ is under 800 words and will tell you more about your ban risk than any blog. LinkedIn's section 8.2 takes four minutes and settles the automation question permanently. The FTC's compliance guide is genuinely readable. The rules that will actually affect you are all published, all free, and almost never read by the people they apply to.

If you want to see how the pieces fit in one system, our bulk messaging best practices guide covers the sending side and contact and lead scoring covers targeting the smaller, more relevant list that solves most of this by making it unnecessary. There is a free plan if you want to try the structure before committing to it: see the plans. And take the legal questions to an actual lawyer, because we are not one.

Enjoyed this article?

More research-backed writing on omnichannel sales, AI agents, and outreach that survives contact with the platforms.

Explore More Articles

We value your privacy

We use cookies to improve our site, analyze traffic, and personalize ads. You can accept all, reject non-essential, or customize your choices. Read our Cookie Policy.