Every cold email compliance question in this cluster eventually comes back to one of three legal concepts: express consent, implied (or inferred) consent, and — a category that gets conflated with implied consent but isn't the same thing — legitimate interest. Knowing which one a given law relies on is what makes the rest of that law's requirements make sense.
Express consent is an affirmative, unambiguous action by the recipient — checking a box, replying "yes," signing up on a form. Implied consent is inferred from context or relationship rather than a direct action — a business relationship, a publicly listed contact detail, conduct that reasonably suggests the person would expect contact. Legitimate interest is different from both: it's not a form of consent at all, it's a separate legal basis that lets you process someone's data without their permission, provided you can justify the processing against their rights.
Express consent is the cleanest compliance position across every jurisdiction in this guide, because you have a direct record of the recipient agreeing. It's the standard Germany's UWG requires for all commercial email, and it's what UK PECR's soft opt-in and CASL's exemptions are trying to approximate through indirect means when express consent isn't practical to collect up front.
Implied consent shows up differently in each law that recognizes it:
The common thread: implied consent is a real legal basis, not a workaround, but it puts the burden of justification on the sender rather than giving you a signed record like express consent does.
GDPR's legitimate interest basis (Article 6(1)(f)) is the one most likely to get mislabeled as "implied consent" — it isn't. Legitimate interest doesn't require inferring that the person consented at all; it requires the business to demonstrate the processing serves a genuine interest, is necessary, and doesn't override the individual's rights. See our GDPR guide for how that balancing test actually works. The UK runs a parallel structure: PECR's corporate subscriber exemption clears the messaging-rule question without consent or a balancing test, while UK GDPR still needs its own lawful basis — usually legitimate interest — for the underlying personal data.
| Jurisdiction | Primary basis for B2B cold email | Consent model |
|---|---|---|
| Canada (CASL) | Implied consent (conspicuous publication exemption) | Implied |
| United States (CAN-SPAM) | No consent requirement — content and opt-out rules instead | Neither required |
| EU general (GDPR) | Legitimate interest | Not consent-based |
| Germany (UWG §7) | Prior express consent required | Express only |
| United Kingdom (PECR) | Corporate subscriber exemption; soft opt-in for individuals | Mixed |
| Australia (Spam Act) | Express or inferred consent | Both, express preferred |
Before emailing a contact in any of these jurisdictions, work through three questions: does this jurisdiction require a form of consent at all, or does it rely on a legitimate-interest-style basis instead; if consent is required, does an implied/inferred path apply to this specific contact, or do you need express consent; and if express consent is required — as it is for German contacts under UWG — do you have a documented trail proving it, not just an assumption that GDPR compliance covers it.
The mistake this framework prevents: treating "we have a GDPR-compliant database" as a single answer that clears every jurisdiction. GDPR-compliant data sourcing and a valid legal basis to email a specific contact in a specific country are related but separate questions — our country-by-country reference walks through each jurisdiction's answer individually.
Implied consent infers the recipient's permission from context, like a publicly listed email or an existing relationship. Legitimate interest, GDPR's Article 6(1)(f) basis, doesn't infer consent at all — it's a separate justification that lets you process data without consent if the business interest is real, necessary, and doesn't override the individual's rights.
Germany, under UWG §7. Unlike most of the rest of the EU, which relies on GDPR's legitimate interest basis, German law requires prior express consent for commercial email regardless of whether the recipient is a business or consumer contact.
No. CAN-SPAM doesn't require consent before sending a commercial email — it regulates message content and requires a working opt-out mechanism instead, which is a fundamentally different compliance model from consent-based laws like CASL or UWG.
Not necessarily. A GDPR-compliant database establishes a lawful basis for holding the data, but individual countries can layer additional requirements on top — Germany's UWG §7 is the clearest example, requiring prior express consent independent of GDPR's legitimate interest allowance.
Related guides
Written by
Scott Holmes
AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has structured multi-jurisdiction outbound consent frameworks for B2B senders operating across several of the regions covered here.
Answer four quick questions and get a tool recommendation for your setup.