Two Regimes, Two Different Tests
CAN-SPAM and GDPR are frequently discussed as if they were one compliance problem, but they run on different logic. CAN-SPAM is a US federal statute built around disclosure and opt-out mechanics, it does not require consent before the first email, it requires honesty and an exit once you have sent one. GDPR is a rights-based EU regulation that asks whether you had a valid lawful basis to process the recipient's data at all before you ever hit send. A SaaS company selling into both markets needs to satisfy both tests, not one generalized "cold email compliance" checklist.
CAN-SPAM Has No B2B Exemption
A common misconception is that CAN-SPAM only governs consumer marketing email. It does not, per sender.net's compliance guide, the statute applies in full to B2B email with no business-to-business carve-out. The core mechanical requirements are a functional one or two-click opt-out that is honored within 10 business days and stays live for at least 30 days, a real physical mailing address, street address, PO box, or CMRA, and non-deceptive subject lines and headers. None of the three is difficult to implement, which is part of why non-compliance is treated as avoidable rather than an understandable oversight when penalties are assessed.
The Penalty Number, With a Verify Caveat
sender.net's guide reports the current CAN-SPAM maximum penalty at $53,088 per non-compliant email, reflecting the January 2025 inflation adjustment. That figure is worth taking seriously as a scale reference, a violation is not a nominal fine, but this research could not independently confirm the exact number directly against the FTC's own compliance page, which returned a blocked response on two direct-fetch attempts during research. Anyone relying on the precise dollar figure for a compliance decision should verify it against ftc.gov's current CAN-SPAM guidance before treating it as final.
GDPR's Legitimate Interest Basis and the Three-Part Test
For outreach into the EU, legitimate interest under GDPR Article 6(1)(f) is the standard lawful basis cited for B2B cold email, per Salesforce Europe's guidance, subject to a three-part test: a genuine business purpose behind the outreach, necessity, meaning email is a reasonably needed channel to achieve that purpose, and a balancing test weighing the outreach against the recipient's privacy rights. All three parts have to hold, not just one, and the balancing test in particular is where generic outreach tends to fail even when the first two parts are easily satisfied.
What the Balancing Test Actually Penalizes
The balancing test tips against outreach the less personalized and signal-based it is. A generic "Hi [First Name]" template sent to a purchased list is a harder position to defend under Article 6(1)(f) than outreach built around a specific, researched, business-relevant reason for contacting that particular recipient. Practical requirements described in the Salesforce Europe guidance include a one-click unsubscribe and a documented Legitimate Interest Assessment per campaign, both of which double as evidence that the balancing test was actually considered rather than assumed.
How a Human-Delivered, SMS-First Model Sits Against Both Regimes
VA Horizon's SaaS demos are booked through SMS conversations run by Human + AI SDRs, not bulk cold email, which sidesteps CAN-SPAM's email-specific mechanics entirely for VA Horizon's own delivery, though a client running its own separate email program still carries its own CAN-SPAM and GDPR obligations independent of how its demos get booked. The broader principle holds either way: manually operated, consent-aware, personalized outreach is inherently easier to defend under a GDPR balancing test than generic mass sending, a genuine compliance advantage worth building a channel strategy around, not just a marketing claim.
Building a Compliance Checklist You Can Actually Audit
Turn both regimes into a short, auditable checklist rather than a general policy statement nobody actually checks against. On the CAN-SPAM side, confirm every commercial email carries a working one or two-click opt-out honored within 10 business days, a real physical address, and a subject line that matches the actual content, then spot-check a sample of recent sends against all three rather than assuming a template is compliant forever. On the GDPR side, confirm a Legitimate Interest Assessment exists for the specific campaign, not a generic one written once and reused, that the outreach is personalized enough to survive the balancing test, and that a one-click unsubscribe is present and functional. A checklist that can be audited in ten minutes against any given campaign is worth more than a compliance policy document nobody has reopened since it was written.
Assign an owner to both checklists, not just a document. A checklist with no one accountable for actually running it against live campaigns tends to drift out of date the same way an unread policy document does, and the gap usually only surfaces after a complaint or an audit has already found it. Reviewing a small, rotating sample of recent campaigns against both checklists on a fixed cadence, monthly or quarterly depending on send volume, keeps the compliance posture verified against what is actually going out, not just what the original policy intended.
What this means for you
- CAN-SPAM applies in full to B2B email with no business exemption; its reported maximum penalty is $53,088 per email as of the January 2025 inflation adjustment, per sender.net, worth verifying directly against ftc.gov before relying on the exact figure.
- GDPR's legitimate interest basis (Article 6(1)(f)) requires a three-part test, genuine business purpose, necessity, and a privacy balancing test, per Salesforce Europe's guidance, and all three must hold, not just one.
- The GDPR balancing test tips against generic, list-based outreach and rewards personalized, signal-based outreach with a documented Legitimate Interest Assessment per campaign.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
- Sender.net, CAN-SPAM compliance guide
- Salesforce Europe, what is legitimate interest for GDPR cold email B2B rules
