skills/prospecting/references/compliance.md
The legal and platform-ToS constraints that apply to prospect list building. Read first, every engagement.
Operational guidance, not legal advice. For high-volume programs or programs touching EU/UK residents, run your setup past a privacy attorney.
CAN-SPAM regulates the cold email send, not the list build. But the list build matters because:
For prospecting specifically: capture and retain the source URL + date for every contact you add to a list. CAN-SPAM doesn't require it explicitly, but defending your sender practices does.
The strictest applicable framework. Triggers when:
You have three credible options:
Legitimate interest (most common for B2B). Requires:
Consent — typically not feasible for cold outreach (you don't have consent before first contact)
Existing customer relationship — only applies to current customers, not prospects
Stricter than CAN-SPAM. Cold B2B outreach requires:
Practical implication for Canadian prospects: relying on the publicly-published-address exception is the most defensible cold prospecting basis in Canada. You must include sender identification, mailing address, and an unsubscribe mechanism in every message.
Before shipping a list to the user (or downstream to cold-email):