The maximum statutory penalty for a cold email violation ranges from roughly $53,000 per email in the US to a percentage-of-global-revenue fine with no practical ceiling for very large companies in the EU and UK. The numbers alone don't tell the full story — how each law actually gets enforced matters just as much as what the statute allows.
| Jurisdiction | Maximum penalty |
|---|---|
| Canada (CASL) | $1,000,000 per violation (individuals) / $10,000,000 per violation (organizations) |
| United States (CAN-SPAM) | $53,088 per separate email violation |
| EU general (GDPR) | €20,000,000 or 4% of global annual turnover, whichever is higher |
| United Kingdom (PECR, from 2025–26) | £17,500,000 or 4% of global turnover, whichever is higher |
| Australia (Spam Act) | Scales with volume — A$313,000 for 1,000 penalty units; real fines have reached A$3,550,000 |
| Germany (UWG) | No single statutory cap — Abmahnung legal costs plus GDPR fine exposure if personal data mishandled |
CASL sets a maximum of $1,000,000 per violation for individuals and $10,000,000 per violation for organizations, with the CRTC also able to seek disgorgement of profits earned through non-compliant campaigns. Full detail, including how enforcement has actually been applied in practice: Cold Email Laws in Canada.
CAN-SPAM's penalty is calculated per email, currently up to $53,088 per violation under the FTC's most recent inflation adjustment. Because it's per-message rather than per-campaign, a bulk send with systemic non-compliance can generate exposure far beyond what a single-violation figure suggests. Full detail: CAN-SPAM Act Explained.
GDPR's ceiling is €20 million or 4% of a company's total global annual turnover, whichever is higher — the "whichever is higher" structure is what makes this uncapped in real terms for large multinational senders, since 4% of global revenue can exceed €20 million by a wide margin for a large enough company. Full detail: GDPR and Cold Email.
This is the biggest recent change in this comparison: under the Data (Use and Access) Act 2025, phased in through June 2026, PECR's maximum fine rises from a flat £500,000 to £17.5 million or 4% of global turnover — the same structure as UK GDPR. Cold email violations that used to sit under a comparatively modest cap now carry the same financial exposure as a major data breach. Full detail: UK PECR and Cold Email.
Australia's penalties scale with volume: 1,000 penalty units (A$313,000 at current value) applies to a business sending more than 50 non-compliant messages in a single day, and the calculation can compound across multiple days of contravention. ACMA has issued real fines reaching A$3.55 million, and enforcement has touched large, recognizable companies, not just small operators. Full detail: Australia's Spam Act.
Germany doesn't have a single statutory cap the way the other jurisdictions here do. Instead, non-compliant email marketing typically triggers an Abmahnung — a cease-and-desist letter from a competitor or consumer-protection body that usually requires covering the sender's legal costs, without needing a court to get involved first — on top of separate GDPR fine exposure if personal data was mishandled alongside the consent violation. Full detail: Cold Email Compliance in Germany.
Statutory maximums are worth knowing, but enforcement patterns are what actually predict risk. CASL's enforcement has concentrated on large-scale spammers rather than small B2B senders with legitimate outreach. ACMA, by contrast, has been enforcing the Spam Act against household-name companies with real financial penalties in recent years — this isn't a dormant law. The UK's penalty increase is fresh enough, still phasing in through mid-2026, that enforcement patterns under the new ceiling aren't established yet, which is its own reason for caution rather than complacency.
The practical read: "the maximum penalty is theoretical" is a weaker argument in 2026 than it was a few years ago — Australia's enforcement record and the UK's penalty increase both point toward these laws being treated as live risk, not paperwork.
In percentage terms, GDPR and the UK's newly increased PECR penalty both cap at 4% of global annual turnover or a fixed amount (€20 million / £17.5 million), whichever is higher — which has no practical ceiling for a large multinational sender.
Yes, consistently. Recent enforcement has produced penalties exceeding A$8 million across nine investigations in one 12-month period, with a record single fine of A$3.55 million, and cases have touched large companies including DoorDash, Woolworths Group, and Uber.
Under the Data (Use and Access) Act 2025, phased in through June 2026, the ICO's maximum PECR fine rose from £500,000 to £17.5 million or 4% of global turnover — a roughly 35-fold increase, aligning PECR with UK GDPR's penalty structure.
Not a single statutory cap in the same form. Violations of Germany's UWG typically trigger an Abmahnung — a cease-and-desist letter requiring the sender to cover legal costs — rather than a fixed regulatory fine, with separate GDPR fine exposure possible if personal data was also mishandled.
Related guides
Written by
Scott Holmes
AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has advised B2B senders on compliance risk across every jurisdiction compared in this guide.
Answer four quick questions and get a tool recommendation for your setup.