All posts

Is It Legal to Collect Business Email Addresses? US, UK and EU

··7 min read

Collecting business email addresses is generally lawful in the US, UK and EU, but each region regulates a different thing. The US mostly regulates sending, under CAN-SPAM. The UK and EU regulate the collection itself whenever an address identifies a person, and the UK and several EU countries then add separate rules on whether you may email it unasked.

This is not legal advice. It sets out what the regulators and the statutes actually say, with links, so you can see where your own process sits and what to ask a lawyer.

The short answer by region

Question US UK EU
Is a named work email personal data? Under state privacy laws, often yes Yes (UK GDPR) Yes (GDPR)
Need a lawful basis to collect it? No federal rule Yes, often legitimate interests Yes, often legitimate interests
Must you tell the person you collected it? California, if in scope Yes, within one month or at first contact Yes, within one month or at first contact
Consent to email a company unasked? No No, for limited companies and LLPs Varies by country
Consent to email a sole trader unasked? No Yes, or soft opt-in Varies by country
Opt-out in every message? Yes Yes Yes

The rest of this post is the source for each cell.

United States: CAN-SPAM regulates how you send

US federal law does not require consent for commercial email, B2B or otherwise, but it sets rules for every message and penalises harvested addresses. The FTC's compliance guide is plain about scope:

The law makes no exception for business-to-business email.

Its main requirements, following the FTC's headings:

  1. Don't use false or misleading header information.
  2. Don't use deceptive subject lines.
  3. Identify the message as an ad.
  4. Tell recipients where you're located.
  5. Tell recipients how to opt out of receiving future email.
  6. Honour opt-out requests promptly, within 10 business days.
  7. Monitor what others are doing on your behalf.

Each separate email in violation is subject to penalties of up to $53,088, per the same page.

Where collection itself becomes a problem

CAN-SPAM makes how you obtained an address relevant in two specific cases. Under 15 U.S.C. 7704(b)(1), it is an aggravated violation to send commercial email that is otherwise unlawful to an address that was:

  • Harvested: "obtained using an automated means from an Internet website or proprietary online service operated by another person", where that site displayed a notice that it will not give, sell or transfer addresses for email marketing.
  • Generated by a dictionary attack: "obtained using an automated means that generates possible electronic mail addresses by combining names, letters, or numbers into numerous permutations".

The FTC notes these can carry criminal penalties. The practical reading: scraping a directory that tells you not to, or blasting every first.last permutation at a domain to see what sticks, turns an ordinary CAN-SPAM breach into a worse one. Checking one likely address with a verifier before sending a single message is a different activity from mass-generating addresses and mailing them, but keep the distinction in mind when designing any automated finder workflow.

State privacy law: California

California's privacy law now covers business contact data. The CCPA's temporary exemption for B2B personal information expired on 1 January 2023, so a work email of a California resident collected by a business that meets the CCPA's thresholds carries the usual notice, access, deletion and opt-out rights. Smaller businesses below those thresholds are outside the CCPA; check the current thresholds before assuming either way.

United Kingdom: two laws, two questions

In the UK, UK GDPR decides whether you may collect and hold a named address, and PECR decides whether you may email it. Both apply, separately.

UK GDPR: collecting the address

A work email that identifies a person is personal data. The ICO's business-to-business marketing guidance gives firstname.lastname@company.com as the example. Generic addresses like info@ that identify no one are generally not personal data, though PECR still applies to them.

For named addresses, the ICO says that where PECR does not require consent, "in many cases it is likely that legitimate interests will be the appropriate lawful basis". That means doing, and keeping, a three-part assessment: a legitimate interest, the processing is necessary for it, and it is not overridden by the person's interests.

If you collected the address from somewhere other than the person, such as their company's website, a directory or a data vendor, you must give them privacy information. The ICO puts it as: "within a reasonable period of obtaining the data and no later than one month from the date of collection". Article 14(3)(b) adds that if you are going to use the data to communicate with them, it must be "at the latest at the time of the first communication". In practice, that is a short privacy line and link in your first email.

If they object to direct marketing, you stop. The ICO: "If an individual withdraws their consent or objects, you must stop processing their personal data for B2B marketing purposes."

PECR: sending the email

PECR's consent rule for email applies to individual subscribers, not corporate ones. From the ICO's electronic mail guidance:

You can send unsolicited electronic mail marketing to corporate subscribers without consent or a soft opt-in.

Corporate subscribers include companies, LLPs, Scottish partnerships and some government bodies. Sole traders and ordinary partnerships are individual subscribers, so emailing them unasked needs consent or the soft opt-in. This matters most for small-business prospecting: a plumber trading under their own name is not a company for PECR purposes.

For both kinds of subscriber: "You must not disguise or hide your identity in messages to either type of subscriber. You must provide a valid contact address for recipients to opt out or unsubscribe."

What changed in 2026

The Data (Use and Access) Act 2025 raised PECR fines on 5 February 2026. Maximum PECR fines moved from £500,000 to UK GDPR levels, £17.5 million or 4% of global annual turnover. The ICO's B2B guidance page currently carries a note that it is under review because of the Act, so check it for updates before relying on the detail above.

European Union: GDPR plus national email rules

GDPR's collection rules are the same as the UK's, but whether you may email a business unasked depends on the member state. The EU ePrivacy Directive left B2B email largely to national law, and the results differ.

Under GDPR, the position on collection mirrors the UK: a named work address is personal data, Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest", Article 14 notice applies when you did not collect the data from the person, and the right to object to direct marketing is absolute.

On sending, two contrasting examples:

Country B2B cold email without consent Source
France Allowed if the message relates to the recipient's profession, they were informed, and can object CNIL
Germany Generally not allowed; prior express consent required, existing-customer exception only UWG section 7

The CNIL says prospecting professionals "peut être fondée sur l'intérêt légitime de l'organisme lorsque l'objet de la sollicitation est en rapport avec la profession de la personne démarchée": it can rest on legitimate interest when the subject relates to the person's job.

Germany's Unfair Competition Act, section 7(2) no. 2, treats advertising "unter Verwendung ... elektronischer Post, ohne dass eine vorherige ausdrückliche Einwilligung des Adressaten vorliegt" (by electronic mail without the addressee's prior express consent) as an unreasonable nuisance, without a business-recipient carve-out. Section 7(3) allows email to existing customers under strict conditions.

So "B2B email is fine in the EU" is not a safe assumption. Check the rule in each country you are mailing.

A collection process that holds up in all three

The common ground is: collect from legitimate public sources, record where each address came from, tell people, and honour objections immediately.

  1. Record the source of every address: the URL, directory or vendor, and the date. You need this for an Article 14 notice and for any complaint.
  2. Respect site notices and terms. Do not scrape sites that prohibit it, including LinkedIn. In the US that is also the harvesting test.
  3. Prefer published and role addresses for small businesses, and know whether the target is a company or a sole trader if you mail the UK.
  4. Verify instead of guessing in bulk. Confirm one likely address with an SMTP check rather than mailing permutations. It is better for deliverability as well as for the law.
  5. Put identity, a postal address, a privacy link and a working opt-out in every message.
  6. Keep a suppression list and check it before every send. An objection in the UK or EU, or an opt-out under CAN-SPAM, is permanent.
  7. Check country rules before mailing Germany or other consent-first markets.

The takeaway

Collecting business emails is usually lawful; the risk is in how. In the US, avoid harvested and generated addresses and follow CAN-SPAM on every message. In the UK and EU, treat named work addresses as personal data: have a lawful basis, tell people within a month or at first contact, and know which recipients need consent. For list hygiene that keeps you clear of spam traps and bounces as well, start with our guide to building a local business email list.

Common questions

Is it legal to scrape business email addresses from websites?

In the US, collecting addresses is not itself banned, but CAN-SPAM treats sending to addresses harvested by automated means from a site that says it will not share them as an aggravated violation. In the UK and EU, a named work address is personal data, so collecting it requires a lawful basis and you must tell the person within a month or at first contact.

Do I need consent to email a business in the UK?

Not for a limited company or LLP. The ICO says you can send unsolicited electronic mail marketing to corporate subscribers without consent or a soft opt-in. Sole traders and ordinary partnerships are individual subscribers, so they do need consent or a soft opt-in, and every message must identify you and give an opt-out address.

Is a work email address personal data under GDPR?

Yes if it identifies a person. The ICO gives firstname.lastname@company.com as an example of an address that is personal data. A generic address such as info@ or sales@ that does not identify anyone is generally not.

Does the US require consent for B2B cold email?

No. CAN-SPAM is an opt-out law and, in the FTC's words, makes no exception for business-to-business email: every commercial message must meet its requirements, including a working opt-out honoured within 10 business days, a physical postal address and honest headers and subject lines.

Can I email business contacts in Germany without consent?

Generally not. Section 7(2) of Germany's Unfair Competition Act treats advertising by electronic mail without the recipient's prior express consent as an unreasonable nuisance, and it does not carve out business recipients. The narrow exception in section 7(3) covers existing customers only.

Verify unlimited addresses for $29.99/month

Real SMTP mailbox checks. No credits, no per-email fees.

Get Started