ON THIS PAGE
By Efe Berke Colaker, Founder at GetleadReviewed by the Getlead editorial team for accuracy. Last updated August 2026.
Most compliance advice for outbound is either a shrug or a wall of warnings. Neither helps, because the real question is narrow: if someone asks about one contact in your database, what can you produce?
This is not legal advice, and rules differ by jurisdiction. It is the operational version: which records to keep, where they go, and what each one answers.
The two regimes you are usually working under
US and EU rules solve different problems, which is why teams that learn one are surprised by the other.
CAN-SPAM regulates the commercial message rather than the collection of the address, requiring accurate headers, a valid physical postal address and an opt-out honored within 10 business days.
The GDPR regulates the processing itself. B2B outreach usually relies on legitimate interest under Article 6, which is a real basis and a documented one rather than an assumption.
The five records that answer almost every question
Each of these is a field or a document, not a policy statement, and each maps to a question somebody may actually ask.
- Lawful basis, recorded per market rather than per campaign. For EU B2B outreach this is usually a written legitimate interest assessment.
- Provenance per contact: where this specific record came from and when, not which vendor the file came from.
- Notice: what you tell the recipient about the source of their details, which Article 14 expects when data came from a third party.
- Suppression state: opt-outs, complaints and do not contact flags, applied globally and at send time.
- Retention rule: how long an unengaged record is kept before it is deleted, and evidence the rule runs.
For example, a prospect who asks where you got their address should be answerable from the record itself in under a minute. If the honest answer is that it came in a file from a vendor who will not say, that is a sourcing problem rather than a paperwork one.
Provenance is the per record answer to where a contact came from, and it is the single field that makes all the others usable.
You do not inherit the vendor's position
This is the most expensive misunderstanding in the category. A supplier's compliance claims describe their processing, not yours.
When a file lands in your database you become the controller for what you do next. The balancing test, the notice and the response to an objection are all yours, whatever the vendor's website says.
There is a practical overlap with deliverability here. Complaint rate is capped at 0.3% of delivered messages by the mailbox providers, and the behaviour that produces complaints is usually the same behaviour that produces regulatory attention.
Data quality is part of the same picture. Sending to records nobody can trace, where 23.9% of raw addresses are invalid in our verification, produces exactly the pattern that draws scrutiny from both directions.
Suppression is where good intentions fail
Every team believes it honors opt-outs. The failures are structural rather than deliberate.
- Campaign scoped opt-outs, so the next sequence from another rep reaches the same person.
- Import time suppression, which misses anyone who opted out after the list was loaded.
- Per mailbox suppression in a rotation setup, where seven other senders never learn about it.
- Merge loss, where deduplication keeps a newer record and discards the older opted out one.
The fix for all four is one global suppression list applied at send time and propagated through every merge. That last clause matters: an opt-out must survive deduplication, or the cleanup quietly undoes the compliance.
Honor requests immediately rather than at the outer limit. CAN-SPAM allows 10 business days and mailbox providers expect 48 hours, so same day suppression satisfies both without needing a policy discussion.
Retention, the rule nobody writes down
Keeping records forever is a choice with a cost, and it is usually made by omission rather than by decision.
Set a rule you can defend and automate it. A common shape is deleting prospect records that have been unreachable and unengaged for a defined period, while retaining suppression entries permanently so an opt-out is never lost.
For example, a record that has bounced twice, never opened anything and has no source recorded is not an asset. It inflates your database count, distorts every rate you measure and adds exposure for nothing.
Deleting it also improves the numbers you actually manage by. Bounce and complaint rates are computed on what you send, so retiring dead records lifts the metrics that decide whether your mail reaches anyone.
Sources and method
First-party data (Getlead, 2026): the verification split of 43.4% confirmed valid, 23.9% invalid, 16.7% catch-all and 16.0% unknown comes from 383,368 addresses analyzed through live SMTP verification, and the 0.51% bounce rate comes from 34,973 tracked sends, aggregated and anonymized at campaign level. Full method in our cold email benchmark study.
External sources: header accuracy, the physical address requirement and the 10 business day opt-out window come from the FTC CAN-SPAM compliance guide; lawful bases including legitimate interest are set out in Article 6 of the GDPR, and third party notice duties in Article 14; the 0.3% spam complaint ceiling comes from the Google Workspace sender guidelines.
This article is operational guidance rather than legal advice, and requirements differ by jurisdiction and change over time. Checked in August 2026.
Frequently asked questions
Is B2B cold email legal?
In the US, the EU and the UK, yes, subject to conditions. CAN-SPAM regulates the message itself with accurate headers, a physical postal address and an opt-out honored within 10 business days. The GDPR regulates the processing, where B2B outreach usually relies on a documented legitimate interest assessment.
Do I inherit my data vendor's compliance position?
No. When a file enters your database you become the controller for what you do next, so the balancing test, the notice to recipients and the response to objections are all yours regardless of what the vendor's website claims.
What records should I keep per contact?
Five: the lawful basis for that market, provenance showing where the specific record came from and when, what notice the recipient receives, suppression state, and a retention rule with evidence that it actually runs.
How fast must I honor an opt-out?
CAN-SPAM allows up to 10 business days and mailbox providers expect requests honored within 48 hours. Same day suppression satisfies both, and it avoids the situation where a compliant delay produces a spam complaint anyway.
Why do suppression lists fail in practice?
Four structural reasons: opt-outs recorded per campaign, suppression applied at import rather than at send, per mailbox suppression in rotation setups, and deduplication that keeps a newer record while discarding an older opted out one.
How long should I keep prospect records?
Set a defensible rule and automate it. A common shape deletes prospect records that have been unreachable and unengaged for a defined period while retaining suppression entries permanently, so an opt-out is never lost when the underlying record is removed.
