Cold Email Compliance Policy
This policy sets out Filesie’s compliance framework for B2B cold email outreach. It is designed to operate alongside the Filesie Privacy Policy, Cookie Policy and applicable client engagement terms.
Filesie does not treat cold email as a single global legal activity. Before launch, each campaign should be assessed by destination market, recipient type, data source, purpose, message content, sender identity, opt-out requirements and sector-specific restrictions.
- Define the client, offer, ICP and countries being targeted.
- Classify recipients, including corporate entities, sole traders, partnerships and individuals where relevant.
- Document the source and intended use of prospect data.
- Determine applicable marketing and privacy requirements for each market.
- Configure sender identity, contact information and unsubscribe mechanism as required.
- Configure suppression and opt-out handling before launch.
- Review claims, subject lines, personalisation and links for accuracy.
- Configure and test sending infrastructure and authentication.
- Launch with controlled volumes and monitor bounces, complaints and opt-outs.
- Retain reasonable evidence of data source, consent or other applicable legal basis, campaign configuration and opt-out actions where required.
United States
CAN-SPAM requires accurate header information, non-deceptive subject lines, identification of commercial messages, a valid physical postal address and a clear opt-out mechanism for commercial email. Opt-outs must be honoured within the statutory period. The FTC also states that businesses remain responsible when email marketing is performed by another company on their behalf.
United Kingdom
PECR treats corporate subscribers differently from individual subscribers such as sole traders and certain partnerships. The ICO states that the electronic-mail marketing rule does not apply to corporate subscribers, while sender identity and a valid opt-out address are still required. Where personal data is processed, UK GDPR obligations also apply, including the right to object to direct marketing.
Canada
CASL generally requires prior consent—express or implied—plus sender identification/contact information and a functioning unsubscribe mechanism for commercial electronic messages. Filesie should maintain evidence supporting the consent relied upon and should not assume that a publicly available business email automatically provides unrestricted consent.
Australia
Australia’s Spam Act framework generally requires consent for commercial electronic messages, sender identification/contact details and an easy unsubscribe mechanism. ACMA states that businesses remain responsible even where another provider sends messages on their behalf.
New Zealand
New Zealand’s Unsolicited Electronic Messages Act 2007 requires consent, accurate sender identification and a functional unsubscribe facility for commercial electronic messages. The Department of Internal Affairs also restricts address-harvesting software. Deemed or inferred consent has specific conditions, including relevance to the person’s business or official role.
United Arab Emirates
The UAE Personal Data Protection Law establishes controls for processing personal data and generally requires consent unless an applicable exception applies. Filesie should assess lawful basis, transparency, security and any direct-marketing requirements applicable to the specific campaign, including sector or free-zone requirements where relevant.
India
India’s Digital Personal Data Protection Act, 2023 establishes requirements concerning notice, consent, processing and withdrawal of consent, subject to its scope, commencement and applicable rules. Filesie should assess the applicable Indian data-protection and communications requirements for each campaign.
- Use business-relevant information only.
- Do not infer or use sensitive personal information merely to make an email more persuasive.
- Record data provenance where reasonably possible.
- Correct or suppress inaccurate records.
- Do not use personal information beyond the stated or otherwise lawful purpose.
Every campaign must provide an appropriate way for the recipient to stop future marketing communications. Opt-outs should be actioned without unnecessary delay and reflected across relevant lists, sequences and sending systems.
Filesie may pause a campaign where consent evidence is inadequate, the data source is questionable, a client instruction conflicts with applicable requirements, complaint rates are abnormal, or the campaign presents material legal, ethical or security risk.
This policy describes Filesie’s operating standards and compliance approach. It is not legal advice or a jurisdiction-specific legal opinion. Electronic marketing, privacy, data protection and communications laws may apply differently depending on the recipient, sender, message, data source and jurisdiction. Appropriate local legal advice should be obtained where required.
This policy is effective as of September 24, 2026.