ComplianceApril 3, 2026·6 min read

Is cold outreach legal? A plain-English guide for India, EU, and US

GDPR, DPDP, CAN-SPAM — what actually applies to B2B cold email, and the three lines that keep you compliant.

Cold B2B outreach is legal in India, the US, and — with caveats — the EU. But the caveats are where founders get burned.

India's DPDP Act (in force 2024) allows B2B contact for legitimate business purposes without prior consent, as long as you honor opt-outs promptly. Keep a suppression list and process removal requests within 7 days.

US CAN-SPAM requires: a real physical address in the footer, a working unsubscribe link, no deceptive subject lines. That's it. B2B cold email is explicitly permitted.

EU GDPR is stricter. You need a 'legitimate interest' basis, which for B2B typically holds if you're contacting someone in their professional capacity about something clearly relevant to their role. Personal Gmail addresses are riskier than work emails. Always honor opt-outs on first request, and never use scraped personal data.

OpenOutreach ships with an auto-suppression list, footer address block, and per-region rate limits by default. But compliance is your obligation, not your tool's — read the actual laws for your target market.