Your Outbound Playbook Was Written Under U.S. Law
The six months I spent fixing the wrong thing
I ran cold outbound on my own firm for six months. LinkedIn sequences, Apollo-sourced lists, the whole apparatus. It produced zero paid customers. In the same period, the same offer — introduced through a government-backed advisor who pre-qualified the buyer and vouched for me — converted repeatedly.
For most of those six months I treated the result as a copy problem. Weaker hooks, wrong list, bad send times. I rewrote sequences. I re-segmented. I tested subject lines against each other like a man tuning a radio that was not plugged in.
That is one seller, one offer, one market. It is not evidence of anything, and I want to be precise about that before I build a single argument on top of it. It is the question, not the answer. The answer turned out to be sitting in plain text on a regulator's website, and it has nothing to do with how well anyone writes.
The spine: In Canada, the regulated act is the send, not the pitch. Consent comes first, the regulator names LinkedIn messaging as an "electronic address," and an address pulled from a contact database fails the exemption most sequenced playbooks quietly lean on. A U.S.-built outbound motion does not port across the border — not because it converts worse, but because its legal foundation is inverted.
What the law actually says — and what it does not
Start with the correction, because it is the first thing the regulator itself says and the thing most commentary gets wrong in both directions.
Canada's anti-spam legislation does not ban marketing email. Asked directly whether the legislation prohibits sending marketing messages, the Canadian Radio-television and Telecommunications Commission answers: "No." What it does instead is set out three requirements for sending a commercial electronic message: obtain consent, provide identification information, and provide an unsubscribe mechanism (Canadian Radio-television and Telecommunications Commission, 2026a).
That is a meaningful distinction. Anyone telling you cold email is simply illegal in Canada is wrong, and you should discount the rest of their analysis accordingly. The regime is not prohibition. It is consent-first — and for an outbound motion built on lists of people who have never heard of you, consent-first is the harder constraint of the two, because it binds before the first message rather than after the first complaint.
The second structural fact is the one that breaks the portability assumption. CASL reaches messages sent into Canada from anywhere: "Commercial electronic messages (CEM) sent to recipients in Canada from another country must comply with CASL" (Canadian Radio-television and Telecommunications Commission, 2026a). A sequence designed in Denver and pointed at Toronto is governed by Canadian law on arrival. Nothing about the sender's location changes that.
Three bases for sending, and why a cold list fails all three
If consent is required, the practical question is which basis you are relying on. There are three that matter for outbound, and it is worth walking each one, because the failure mode is different in each case.
Express consent. You asked, they agreed, you can show it. A purchased or scraped list has none of this by construction. The regulator is explicit that the onus sits with the sender: "the onus is on the sender to prove they received consent" (Canadian Radio-television and Telecommunications Commission, 2026a). Not on the recipient to prove they refused.
Conspicuous publication. This is the exemption most outbound programs believe they are operating under — the address was on a website, therefore it is fair game. The actual test has three conditions, and they are conjunctive. Consent is implied only if the person conspicuously published the address; the publication is not accompanied by a statement that they do not want unsolicited commercial messages; and the message is relevant to that person's business role, functions or duties (Canadian Radio-television and Telecommunications Commission, 2026a).
Then comes the sentence that should stop a modern outbound stack cold. The regulator glosses what "conspicuous" means online: "A 'conspicuous publication' online entails that the electronic address is directly available to the public because it is typically indexed by a search engine. Therefore, an electronic address that requires specific queries in a corporate database to be found is not conspicuously published" (Canadian Radio-television and Telecommunications Commission, 2026a).
Read that against how contact data is actually acquired in 2026. An address surfaced by running a filtered query against a commercial contact database is, on the regulator's own description, the paradigm case of an address that is not conspicuously published. The exemption is not merely narrow. It is close to the precise inverse of the enrichment workflow that most sequenced outbound depends on.
The business-to-business exemption. This one is real, and it is narrower than its name suggests. It applies where the message passes between employees, representatives, consultants or franchisees of two organizations, the organizations have a relationship, and the message concerns the activities of the recipient organization (Canadian Radio-television and Telecommunications Commission, 2026a). The regulator adds a clarification that closes the obvious workaround: "The mere fact that an employee of an organization has a relationship with an employee of another organization does not necessarily result in a relationship between the organizations" (Canadian Radio-television and Telecommunications Commission, 2026a).
A relationship between the organizations is precisely what cold outbound lacks — that is what makes it cold. The exemption describes account expansion and partner motion. It does not describe prospecting into strangers.
The workaround that is not a workaround
When email gets hard, sequenced outbound migrates to LinkedIn direct messages. In Canada this is not the escape hatch it is assumed to be.
CASL defines an electronic address as an email account, a telephone account, an instant messaging account, "and any other similar accounts." Whether a given social platform qualifies is decided case by case — but the regulator supplies its own worked example: "messages sent to other users using a social media messaging system (e.g., Facebook Messenger and LinkedIn messaging), would qualify as sending messages to 'electronic addresses'" (Canadian Radio-television and Telecommunications Commission, 2026a).
The boundary is drawn at broadcast versus message. A public post is treated differently — the regulator notes that a Facebook wall post would not be captured, and that websites, blogs and micro-blogging would typically not be considered electronic addresses (Canadian Radio-television and Telecommunications Commission, 2026a). Publishing to an audience is one thing. Sending to an inbox is another, and the platform the inbox lives on does not change the analysis.
So the common sequence design — email until it stalls, then move to DMs — does not reduce exposure. It relocates it.
The enforcement is real, published, and personal
It would be fair to ask whether any of this is enforced. The CRTC publishes its enforcement register, and the answer is visible in it.
Under CASL specifically, the register records undertakings with monetary payments from Gap Inc. — CA$200,000 in 2021, Hudson's Bay Company CA$120,000 in 2024, and DavidsTea Inc. CA$40,000 in 2023 — each paired with the implementation of a compliance program (Canadian Radio-television and Telecommunications Commission, 2026b). It also records notices of violation issued to named individuals — CA$50,000 against Marc-Anthony Younes for violations of paragraph 6(1)(a), and CA$40,000 against Sami Medouni under section 6 (Canadian Radio-television and Telecommunications Commission, 2026b). Section 6 is the consent provision.
One caution on reading that register, because it is easy to misread and I nearly did. Most of the recent high-value penalties on it — including a CA$1.5 million settlement with a well-known data vendor in July 2026 — are Unsolicited Telecommunications Rules matters, not CASL. Those are the telemarketing and Do Not Call regime, a separate instrument; CASL does not apply to live voice or automated calls (Canadian Radio-television and Telecommunications Commission, 2026a). Citing a UTR penalty as a CASL penalty would overstate the case, and the case does not need overstating.
All Canadian figures in this piece are Canadian dollars; the U.S. penalty below is U.S. dollars. The ceiling is worth knowing precisely. The maximum administrative monetary penalty per violation is CA$1 million for an individual and CA$10 million for a business, and directors, officers, agents and mandataries can be personally liable where they directed, authorized, assented to, acquiesced in, or participated in the violation — "whether or not the corporation is proceeded against" (Canadian Radio-television and Telecommunications Commission, 2026a).
Three countries, three different kinds of rule
Here is why a playbook does not travel. The three regimes I was able to verify at primary sources do not differ by degree. They differ in kind.
| Canada (CASL) | United States (CAN-SPAM) | United Kingdom (PECR) | |
|---|---|---|---|
| Structure | Consent required before sending | No prior consent required; opt-out | Depends on subscriber type |
| Applies to B2B? | Yes, with a narrow relationship-based exemption | Yes — "The law makes no exception for business-to-business email" | The electronic-mail rule does not apply to corporate subscribers |
| The trap | Database-sourced addresses fail conspicuous publication; LinkedIn messaging counts as an electronic address | Compliance is about disclosure and opt-out, not permission | Sole traders and most partnerships are individual subscribers and get full protection |
| Maximum penalty | CA$1M individual / CA$10M business per violation | Up to US$53,088 per offending email | — |
The United States runs on opt-out. The Federal Trade Commission states plainly that CAN-SPAM "covers all commercial messages," that "the law makes no exception for business-to-business email," and that "each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088" (Federal Trade Commission, n.d.). Note what that regime regulates: header accuracy, subject-line honesty, identification and a working unsubscribe. It regulates the conduct of the message. It does not require permission to send it.
The United Kingdom splits the question by who is being contacted. Businesses with separate legal status are "corporate subscribers," and the Information Commissioner's Office is direct that "the rule on marketing by electronic mail (eg email or text message) doesn't apply to corporate subscribers" (Information Commissioner's Office, n.d.). But sole traders and most partnerships "are classed as 'individual subscribers' and PECR treats them the same as individuals" (Information Commissioner's Office, n.d.) — so the same list can be lawful for half its rows and not the other half, sorted by a legal-status field almost nobody stores. UK GDPR continues to apply to the personal data either way.
I looked at the European Union as a fourth column and could not verify it. The primary legislative source returned an empty response to two fetch attempts. That is an unproven column, not an empty one, and I have left it out rather than fill it from commentary.
The second wall, which is not legal at all
Suppose you clear the legal question completely — you have express consent, documented, for every row. There is a second constraint, and it is structural rather than statutory.
B2B purchases are not made by the person who receives your message. They are made by a buying centre, and a systematic review of more than fifty years of that literature sets out the roles: user, buyer, influencer, decider, gatekeeper, and initiator (Cabanelas, Mora Cortez, & Charterina, 2023). Each holds a different kind of power. The one that determines whether a seller gets a hearing at all is not the decider. It is the gatekeeper: gatekeepers "control the information flow and largely determine which vendors have the chance to sell" (Cabanelas et al., 2023).
The same review notes that the buying centre has a non-static nature — who is involved, and who carries decision responsibility, shifts by buying stage and by organizational factors (Cabanelas et al., 2023). A single message into a single inbox is a bet that one named individual is, at that moment, the role that matters. Most of the time the bet is simply wrong, and it is wrong for reasons no amount of message quality repairs.
Two independent walls. Different mechanisms. Same conclusion.
Admissibility comes before persuasion
The reframe I eventually arrived at, and the thing I wish I had understood six months earlier, is an ordering.
A perfectly persuaded buyer with no lawful instrument to transact is not a slow deal. It is not a deal. Before asking whether a message is compelling, ask whether it is admissible — whether the buying system on the other side is permitted to receive it and equipped to act on it. That property is observable from outside, before a single conversation, and it does not depend on anything about your product.
I am a go-to-market advisor, not legal counsel, and nothing here is legal advice. The primary sources are linked below and I would encourage you to read them yourself; where your own exposure is genuinely at issue, that is a conversation for a lawyer who practises in this area, not for a strategy consultant and certainly not for a blog post.
Where Sagentix fits
This analysis came out of building an access-motion assessment into my own delivery pipeline — the question of which acquisition motion a given industry's buying system can actually receive, resolved before the go-to-market plan is written rather than discovered in month nine. It sits inside a 6–8 week engagement, priced CA$4K–$50K, drawing on 727+ curated artifacts and run through a 16-point quality gate, with a Phase 1 money-back guarantee (subject to terms) Sagentix GTM Methodology, 2026.
The reason I am publishing the failure rather than the framework is that the failure is the more useful half. I paid for that finding with six months of the wrong work.
Three things you can do with this
One — run the admissibility question yourself, this week, for free. For each target geography, write down the lawful basis on which your first message is sent. If the answer is "the address was public," check it against the three conjunctive conditions and the search-engine test above. If the answer is "we use LinkedIn instead," check it against the electronic-address definition. This costs an afternoon and it is the highest-value afternoon in the sequence.
Two — get a legal read before you scale, not after. If outbound is material to your plan and Canada is material to your market, a scoped opinion from counsel who practises in this area is cheaper than a compliance program imposed as part of an undertaking. The register shows what that path looks like.
Three — if the question is broader than one channel, bring in help. If you are trying to work out which motion an entire industry can receive — not just whether an email is lawful, but who holds the initiating right and what gates admissibility — that is the assessment I run.
Only the third of those involves hiring me, and it is the one that matters least if the first one gives you a clean answer.
I will end on the thing I am genuinely curious about, because I do not think the answer is settled. For those of you running outbound into Canada right now: what is the lawful basis you are relying on, and could you produce the evidence for it if someone asked you to?
References
-
Cabanelas, P., Mora Cortez, R., & Charterina, J. (2023). The buying center concept as a milestone in industrial marketing: Review and research agenda. Industrial Marketing Management, 108, 65–78. Open-access author copy, University of Southern Denmark Research Portal (CC BY). Version of record: https://doi.org/10.1016/j.indmarman.2022.10.026
-
Canadian Radio-television and Telecommunications Commission. (2026a). Frequently asked questions about Canada's anti-spam legislation. https://crtc.gc.ca/eng/com500/faq500.htm
-
Canadian Radio-television and Telecommunications Commission. (2026b). Enforcement actions. https://crtc.gc.ca/eng/ce/actions.htm
-
Federal Trade Commission. (n.d.). CAN-SPAM Act: A compliance guide for business. https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business
-
Information Commissioner's Office. (n.d.). Business to business marketing. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/business-to-business-marketing/
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,000–CA$5,000 with a money-back guarantee.