Extracting an address from a public web page is a technical act. Sending a commercial message to it is a regulated one, and the rules differ sharply depending on where the recipient is, whether they are a person or a company, and what you are writing to them about.
This guide sets out how the main regimes treat addresses that were collected rather than volunteered, and what that means in practice for a list you assembled yourself. It is a practitioner’s summary written to help you ask the right questions — it is not legal advice, and a lawyer in the relevant jurisdiction should sign off anything at scale.
Public does not mean free to use
The most expensive misconception in cold outreach is that an address published on a website has been offered for any purpose. It has not. Publication makes an address available; it does not grant consent, and under EU and UK law a business email address that identifies an individual — dana.wright@acme.io — is personal data regardless of where you found it.
The corollary is that “I did not buy this list, I built it” is not a defence. What matters is the lawful basis for processing and the disclosures in the message, not the provenance of the file.
Notice, though, the second half of that: “identifies an individual”. Generic company addresses like info@acme.io or sales@acme.io generally do not identify a person, and are treated more permissively in most European regimes. That is a rare instance where the deliverability advice (strip role accounts) and the compliance advice (role accounts carry less risk) point in opposite directions.
The EU and UK: GDPR and legitimate interests
Two separate instruments apply to European B2B email, and conflating them causes most of the confusion. GDPR governs the processing of personal data. The ePrivacy rules — implemented nationally, and in the UK as PECR — govern electronic marketing messages specifically.
Under GDPR you need a lawful basis. For unsolicited B2B outreach the realistic one is legitimate interests, and relying on it requires you to actually perform and document a three-part assessment:
- Purpose. Is there a genuine business interest in contacting this person?
- Necessity. Is email the reasonable way to achieve it, or would something less intrusive do?
- Balance. Does your interest override the recipient’s rights and reasonable expectations?
The balancing test is where relevance earns its keep. Writing to a named procurement lead about a product their department plainly buys is a defensible position. Blasting an entire scraped directory with something unrelated to any of them is not, and no amount of paperwork fixes it.
Under ePrivacy, whether you need prior consent depends on the recipient. Marketing to individual subscribers — consumers, and in several member states sole traders and partnerships — generally requires opt-in consent. Marketing to corporate subscribers, meaning named employees at incorporated companies, generally does not, provided you identify yourself and offer opt-out. National implementations vary meaningfully: Germany and Italy are markedly stricter than the UK or Ireland, and “EU rules” is not a single answer.
GDPR also gives the recipient rights you must be able to service: access, rectification, erasure, objection. Article 14 additionally requires that when you obtain personal data from somewhere other than the person themselves, you tell them — including where you got it — within a reasonable period, and at the latest in your first communication with them. In practice, one honest line naming the source belongs in your first email.
The United States: CAN-SPAM
CAN-SPAM is materially more permissive and structured completely differently. It is not a consent regime: you do not need permission before sending a commercial message to a US recipient. It is a conduct regime, and it sets out what a message must and must not do.
Requirements, all of which are enforced:
- Header information — From, To, Reply-To and routing — must be accurate.
- Subject lines must not mislead about the message’s contents.
- The message must be identifiable as an advertisement, though the wording is flexible.
- It must include your valid physical postal address.
- It must include a clear, working opt-out mechanism.
- Opt-outs must be honoured within ten business days, and the mechanism must keep working for at least 30 days after sending.
- You remain liable for what an agency or contractor sends on your behalf.
Penalties are per message, not per campaign, which is what makes carelessness expensive at volume. Several US states also layer additional requirements on top, and California’s privacy statutes create separate obligations around data collected about residents.
Canada: CASL, and why it is different
CASL is the strictest of the three and catches people out because Canadian addresses are indistinguishable from US ones in a list. It requires consent — express, or implied in defined circumstances — before sending a commercial electronic message.
Implied consent is the route that matters for extracted lists, and it has a specific, narrow shape: if a person has conspicuously published their business address without a statement that they do not want unsolicited messages, you may contact them — provided your message is relevant to their business role. An address on a corporate contact page usually qualifies. An address in a personal blog’s footer usually does not. Implied consent from a published address does not expire, but implied consent arising from an existing business relationship generally lapses after two years.
Every message must also identify the sender, give contact details valid for at least 60 days, and provide an unsubscribe mechanism that works for at least 60 days and is actioned within ten business days. Penalties run to millions of dollars, and enforcement has been real.
Other jurisdictions worth knowing about
- Australia (Spam Act 2003). Consent-based, similar in shape to CASL. Conspicuous publication of a business address can constitute inferred consent where the message is relevant to the person’s role. Sender identification and functional unsubscribe are mandatory.
- Brazil (LGPD). Closely modelled on GDPR, including a legitimate-interests basis and equivalent data-subject rights.
- Switzerland. Outside the EU but with a revised federal data protection act that tracks GDPR closely, plus its own unfair-competition rules on unsolicited mail.
- Japan, South Korea, Singapore. All operate opt-in or notification-based regimes for commercial email, with meaningful local specifics.
Because a raw address rarely tells you where its owner sits, segmenting by country before sending is not a nicety. Domain TLD is a weak proxy — a .de domain is probably German, a .com tells you nothing — so where the regime materially changes what you may send, confirm the location rather than infer it.
What every outreach message needs
The union of the regimes above is not onerous, and building it into your template once means you stop thinking about it:
- A truthful From line and subject. No fake reply chains, no “Re:” on a first contact, no display name pretending to be someone else.
- Who you are. Legal entity name and a real postal address.
- Where you got the address. One sentence. It satisfies GDPR Article 14 and, in practice, measurably reduces complaint rates — people object far less when the answer is not a mystery.
- A working opt-out. One click, no login, no “reply with REMOVE in the subject line”. A list-unsubscribe header as well as a visible link.
- Relevance you could defend out loud. If you cannot articulate why this message makes sense for this specific recipient, the legitimate-interests balancing test has already failed.
Handling opt-outs and erasure requests
An unsubscribe is permanent and global, not per-campaign. The address goes onto a suppression list that survives platform migrations, list rebuilds and new data sources — because the same person will reappear in the next directory you extract, and mailing them again after they opted out is both a violation and the fastest route to a spam complaint.
Erasure requests under GDPR are a slightly different mechanism with an awkward interaction: deleting every trace of someone means you cannot recognise them if they reappear in a future extract. The accepted resolution is to keep a minimal suppression record — typically a hash of the address plus the date — for the specific purpose of not contacting them again, and delete everything else. Document that reasoning; it is a question a regulator will ask.
Speed matters. Ten business days is the CAN-SPAM and CASL ceiling, not a target. Automate it so the answer is “immediately” and the question never arises.
What to record, and for how long
If you are ever asked to justify a send, the useful evidence is contemporaneous and boring:
- The source of each address and the date it was collected.
- Your legitimate-interests assessment, written down before the campaign, not after.
- A copy of the message as sent, including the unsubscribe mechanism.
- Suppression list history, with dates.
- Any complaint or request received, and what you did about it.
Exporting extraction results with a source label and a date is a cheap way to start this habit, and it is the single record most people wish they had kept when a question finally arrives.
A pre-send checklist
- Do I know, or can I determine, roughly where these recipients are?
- Is my basis for contacting them one I could state in a sentence?
- Have I removed everyone on my suppression list?
- Does the message identify my company and carry a real postal address?
- Does it say where I got the address?
- Does the unsubscribe link work — have I clicked it myself, today?
- Is the content genuinely relevant to this recipient’s job?
- Have I written down why I believe all of the above?
Compliance and deliverability pull in the same direction far more often than people expect. Relevant, honest, easy-to-leave email produces fewer complaints, and fewer complaints is what keeps you in the inbox. The mechanical side of getting there is covered in how to clean an email list before your first campaign.