Penalties for Cold Email Violations: CASL, CAN-SPAM & GDPR Fines Compared (2026) | AI Email Tools
Legal Guide · Penalties

Penalties for Cold Email Violations: CASL, CAN-SPAM & GDPR Fines Compared

Updated July 2026 10 min read By Scott Holmes

The maximum statutory penalty for a cold email violation ranges from roughly $53,000 per email in the US to a percentage-of-global-revenue fine with no practical ceiling for very large companies in the EU and UK. The numbers alone don't tell the full story — how each law actually gets enforced matters just as much as what the statute allows.

The Comparison Table

JurisdictionMaximum penalty
Canada (CASL)$1,000,000 per violation (individuals) / $10,000,000 per violation (organizations)
United States (CAN-SPAM)$53,088 per separate email violation
EU general (GDPR)€20,000,000 or 4% of global annual turnover, whichever is higher
United Kingdom (PECR, from 2025–26)£17,500,000 or 4% of global turnover, whichever is higher
Australia (Spam Act)Scales with volume — A$313,000 for 1,000 penalty units; real fines have reached A$3,550,000
Germany (UWG)No single statutory cap — Abmahnung legal costs plus GDPR fine exposure if personal data mishandled

Canada — CASL

CASL sets a maximum of $1,000,000 per violation for individuals and $10,000,000 per violation for organizations, with the CRTC also able to seek disgorgement of profits earned through non-compliant campaigns. Full detail, including how enforcement has actually been applied in practice: Cold Email Laws in Canada.

United States — CAN-SPAM

CAN-SPAM's penalty is calculated per email, currently up to $53,088 per violation under the FTC's most recent inflation adjustment. Because it's per-message rather than per-campaign, a bulk send with systemic non-compliance can generate exposure far beyond what a single-violation figure suggests. Full detail: CAN-SPAM Act Explained.

European Union — GDPR

GDPR's ceiling is €20 million or 4% of a company's total global annual turnover, whichever is higher — the "whichever is higher" structure is what makes this uncapped in real terms for large multinational senders, since 4% of global revenue can exceed €20 million by a wide margin for a large enough company. Full detail: GDPR and Cold Email.

United Kingdom — PECR's 2026 Shift

This is the biggest recent change in this comparison: under the Data (Use and Access) Act 2025, phased in through June 2026, PECR's maximum fine rises from a flat £500,000 to £17.5 million or 4% of global turnover — the same structure as UK GDPR. Cold email violations that used to sit under a comparatively modest cap now carry the same financial exposure as a major data breach. Full detail: UK PECR and Cold Email.

Australia — Spam Act

Australia's penalties scale with volume: 1,000 penalty units (A$313,000 at current value) applies to a business sending more than 50 non-compliant messages in a single day, and the calculation can compound across multiple days of contravention. ACMA has issued real fines reaching A$3.55 million, and enforcement has touched large, recognizable companies, not just small operators. Full detail: Australia's Spam Act.

Germany — UWG and the Abmahnung

Germany doesn't have a single statutory cap the way the other jurisdictions here do. Instead, non-compliant email marketing typically triggers an Abmahnung — a cease-and-desist letter from a competitor or consumer-protection body that usually requires covering the sender's legal costs, without needing a court to get involved first — on top of separate GDPR fine exposure if personal data was mishandled alongside the consent violation. Full detail: Cold Email Compliance in Germany.

What Actually Gets Enforced

Statutory maximums are worth knowing, but enforcement patterns are what actually predict risk. CASL's enforcement has concentrated on large-scale spammers rather than small B2B senders with legitimate outreach. ACMA, by contrast, has been enforcing the Spam Act against household-name companies with real financial penalties in recent years — this isn't a dormant law. The UK's penalty increase is fresh enough, still phasing in through mid-2026, that enforcement patterns under the new ceiling aren't established yet, which is its own reason for caution rather than complacency.

The practical read: "the maximum penalty is theoretical" is a weaker argument in 2026 than it was a few years ago — Australia's enforcement record and the UK's penalty increase both point toward these laws being treated as live risk, not paperwork.

FAQ

Which cold email law has the highest maximum penalty?

In percentage terms, GDPR and the UK's newly increased PECR penalty both cap at 4% of global annual turnover or a fixed amount (€20 million / £17.5 million), whichever is higher — which has no practical ceiling for a large multinational sender.

Has Australia's Spam Act actually been enforced with real fines?

Yes, consistently. Recent enforcement has produced penalties exceeding A$8 million across nine investigations in one 12-month period, with a record single fine of A$3.55 million, and cases have touched large companies including DoorDash, Woolworths Group, and Uber.

What changed with UK PECR penalties in 2026?

Under the Data (Use and Access) Act 2025, phased in through June 2026, the ICO's maximum PECR fine rose from £500,000 to £17.5 million or 4% of global turnover — a roughly 35-fold increase, aligning PECR with UK GDPR's penalty structure.

Does Germany have a maximum fine for cold email violations like the other countries?

Not a single statutory cap in the same form. Violations of Germany's UWG typically trigger an Abmahnung — a cease-and-desist letter requiring the sender to cover legal costs — rather than a fixed regulatory fine, with separate GDPR fine exposure possible if personal data was also mishandled.

Related guides

→ Cold Email Laws in Canada: CASL Compliance Guide → GDPR and Cold Email: Is B2B Outreach Legal in the EU? → Australia's Spam Act: Cold Email Rules for B2B Senders

Written by

Scott Holmes

AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has advised B2B senders on compliance risk across every jurisdiction compared in this guide.

Ready to run compliant outreach?

Answer four quick questions and get a tool recommendation for your setup.