Unlike the US (CAN-SPAM) or the EU (GDPR + ePrivacy), India has no statute dedicated to commercial email. B2B cold email to business addresses is broadly lawful — but three legal frameworks still constrain it.
1. The DPDP Act 2023
A work email like priya.sharma@company.com identifies an individual, making it personal data. Emailing it for marketing is processing. The safest posture: business-context outreach with a clear identity, a genuine reason for relevance, and a working unsubscribe that you honour instantly.
2. The IT Act 2000
Section 66 penalises sending grossly offensive or menacing messages and misleading origin information. Practical translation: never spoof sender identities, never use deceptive subject lines.
3. Contract & platform rules
Your email provider’s anti-spam policies bind you contractually — violating them gets domains blacklisted faster than any regulator would act.
The compliant cold-email checklist
- Real sender name, real company, real address in the footer
- Relevant, honest subject line
- One-click unsubscribe, honoured immediately
- Verified, current data — bounces are the loudest spam signal
- Suppress anyone who opted out, forever
This article is general information, not legal advice.