# The Jurisdiction Reference for Lawful Sourcing and First Contact

*For any candidate or prospect's country, you can state whether you may source and send a first message, on what basis, with which required elements and the penalty for getting it wrong.*

- Canonical URL: https://www.refolk.ai/guides/jurisdiction-reference-lawful-sourcing
- Pillar: Process, data, and compliance
- Format: Reference
- Published: 2026-10-05
- Last reviewed: 2026-10-05
- Reading time: 16 min

Before you source a person and send them a first message, you need to answer two separate legal questions keyed to one fact: the country that person is in. This reference is for recruiting operations, revenue operations, and anyone who has to defend how the data was gathered. It gives you one scannable position per jurisdiction: whether you may process public data, whether you may send a first message, under which basis, with which mandatory elements and penalties.

Most cold-email guidance online is marketing-centric, B2B-only, and keyed to the sender's country. All three assumptions are wrong for sourcing work. Recruiting legitimate-interest outreach is not the same as commercial advertising. "The EU" is not one sending regime. And the law that governs a first message follows the recipient, not you. This guide separates those threads so you can jump to a jurisdiction, read the row, and act.

## The two questions you must never merge

There are two distinct legal gates, and merging them is the most common mistake in sourcing. GDPR Article 6 answers whether you may process a person's data for your purpose. The ePrivacy regime, as each country implemented it, answers whether you may send the message. One can pass while the other fails.

Sourcing a public profile into your pipeline is processing. Sending the first email is an electronic communication. In Germany the distinction is sharp: GDPR may let you hold the data under legitimate interest, while UWG Section 7 still bars the email without prior consent. Clearing one gate tells you nothing about the other.

> **Rule:** Split processing from sending, always
>
> GDPR answers whether you can process the data for the purpose. UWG, CASL, the Spam Act and PECR answer whether you can send. Clear both gates separately before any first contact.

Keep the questions labelled throughout your workflow. "May I source" is the processing question. "May I send" is the sending question. When someone asks "is this compliant," make them say which gate they mean.

## Why the recipient's country is the only safe default

Applicable sending law keys to the recipient's location, not yours. If your company is in the US but you email a prospect in Germany, German law applies. This is the single fact that most listicles get backwards, and it is the fact that drives the entire procedure below.

The extraterritorial reach runs deeper on the processing side. GDPR Article 3(2) applies to processing the data of people who are in the EU, by a controller outside the EU, through its targeting criterion. Applicability is tied to the physical presence of a data subject in the EU, irrespective of nationality, residence or intention to stay. Where it applies, the controller, even though located in the US, must appoint a representative under Article 27, based in an EU member state where the data subjects are.

That is why a US sourcer's domicile offers no shelter. Your office being in Austin does not make a German recipient a CAN-SPAM matter. It makes them a UWG and GDPR matter, with an Article 27 representative obligation attached.

#### Routing a first contact by recipient location

1. **Read the profile** - Determine the recipient's country of residence
2. **Select regime** - Recipient country picks CAN-SPAM, CASL, UWG, Spam Act or PECR
3. **Set basis** - Establish processing basis and consent model for that country
4. **Attach obligations** - Add Article 27 representative if non-EU sourcer targeting EU

*The recipient's country, not the sender's, selects the sending regime and the processing obligations.*

## The sending regime by jurisdiction

Here is the core lookup. Each row answers the sending question: what statute governs, whether it is opt-in or opt-out, the maximum penalty, and how fast you must honor an opt-out. Read the row for the recipient's country and nothing else.

#### Consent model vs enforcement intensity

Horizontal axis runs from Opt-out model to Opt-in model. Vertical axis runs from Lighter exposure to Heavier exposure.

| Quadrant | What it means |
| --- | --- |
| US, UK/IE B2B, France B2B | Send on opt-out with full disclosure and a working unsubscribe |
| Canada, Australia | Get documented consent first, keep records, honor fast opt-outs |
| Netherlands B2B | Opt-out works only for professionally provided contact info |
| Germany, Austria | Consent-first with no reliable B2B carve-out, private enforcement risk |

*Where a jurisdiction sits tells you whether to get consent first and how hard the penalty bites.*

| Jurisdiction | Statute | Model | Max penalty | Opt-out SLA |
|---|---|---|---|---|
| US | CAN-SPAM | Opt-out | $53,088/email | 10 business days |
| Canada | CASL | Opt-in | CAD $10M/violation (org) | 10 business days |
| Germany | UWG s7 | Opt-in (incl B2B) | 300,000 EUR (s20, mainly calls) | n/a, consent-first |
| France | L.34-5 CPCE | B2B opt-out | 20M EUR / 4% (GDPR) | immediate/undue delay |
| Australia | Spam Act 2003 | Opt-in | ~A$3.64M (s25) | 5 business days |

A few rows need their limits stated. The US figure of $53,088 is per violating email as of 2026, with no aggregate cap, which is why volume senders face eye-watering exposure. The German 300,000 EUR figure under UWG Section 20 understates real risk: that administrative-fine provision is aimed mainly at telephone advertising, so email exposure runs instead through competitor Abmahnung and injunctions under private enforcement. The France row carries the GDPR penalty because the headline enforcement against unlawful prospecting there comes through the data-protection regulator, not the commercial-email statute.

**$53,088 - CAN-SPAM maximum civil penalty per violating email**

There is no aggregate cap, so each non-compliant email stacks the exposure.

## The EU is not one regime

The ePrivacy Directive leaves implementation to each member state, so the consent model varies country by country. A template cleared for France will fail in Germany or Austria. Never reason from "GDPR" to a sending decision; reason from the recipient's national statute.

The overrides that matter most break the B2B assumption. Section 7 of the UWG treats advertising email sent without the recipient's prior express consent as an unreasonable nuisance, with no general carve-out for business recipients. Austria's TKG applies opt-in to both natural and legal persons, so B2B communication must be opt-in. Poland added an electronic communications law alongside its UWG-equivalent, also opt-in. Meanwhile France permits B2B email prospecting on opt-out under L.34-5 CPCE if the message relates to the recipient's role, and the Netherlands keys its B2B exemption to contact information intended and provided by the professional.

| Country | B2B first contact | Basis to send |
|---|---|---|
| Germany | Blocked without consent | Prior express consent (no B2B carve-out) |
| Austria | Blocked without consent | Opt-in for natural and legal persons |
| France | Allowed | Opt-out, if message relates to the role |
| Netherlands | Allowed, conditionally | Opt-out, only for professionally provided contact info |

Austria quietly breaks the B2B assumption more than Germany does. Teams that learn "Germany is the exception" still treat a generic company inbox in Vienna as fair game. It is not. Austria extends opt-in to legal persons explicitly, so even a role-based address needs consent.

> **Watch out:** A cleared template is not portable across the EU
>
> A message approved for France is not approved for Germany or Austria. The consent model is national. Re-check the recipient's state statute every time, not the fact that both countries are in the EU.

## Public does not mean lawful

A public profile does not grant you a basis to process it. Public availability does not by itself create a lawful basis; you need a documented basis, which for sourcing is usually legitimate interest supported by a Legitimate Interest Assessment. Without a recorded LIA, you have nothing to show a regulator.

The LIA is a three-part test: the purpose you are pursuing, whether the processing is necessary for it, and a balancing exercise weighing it against the subject's rights and expectations. The balancing test is where sourcing lives or dies, and it turns on the subject's reasonable expectation. The ICO's worked example treats a CV uploaded to a job board, or an "open to recruiters" flag, as creating a reasonable expectation of recruiter contact. That expectation is the whole ballgame for EU sourcing. Absent it, legitimate interest weakens fast.

The flip side is a hard line. The ICO advises avoiding searching for candidates on their personal social media profiles, even when made public, because it is intrusive and high risk. A public post is not an invitation. The job-board signal supports a legitimate interest; a personal Instagram account does not.

The enforcement record shows this is not theoretical. The Irish DPC fined LinkedIn 310 million EUR for invalid consent and unlawful legitimate-interest reliance. The Dutch DPA fined Clearview AI 30.5 million EUR for scraping. France's CNIL fined Hubside.Store 525,000 EUR for prospecting with broker-bought data without valid consent. The failure in each case was a basis that did not hold, not an absence of data.

> A public profile is evidence a person exists, not permission to process them.

## Sourcing supply sits behind the strictest wall

The structural tension in European sourcing is that the biggest talent pools are in the hardest sending regimes. In Refolk's index, Germany holds 4,647 recruiter and sourcer-titled professionals against 617 in France, roughly 7.5 times as many. Germany is also the strictest country to send into. The largest pool sits behind the highest compliance wall.

| Country | Recruiter/sourcer-titled profiles | Share of the pair (derived) |
|---|---|---|
| Germany | 4,647 | 88% |
| France | 617 | 12% |

That is not a reason to avoid Germany. It is a reason to build the consent and documentation workflow before you start, because the volume is there and so is the enforcement.

Capacity to document a basis also varies, and it tracks enforcement rather than population. In Refolk's index, the United Kingdom carries 814 Data Protection Officer-titled professionals against Germany's 227, roughly 3.6 times as many despite comparable economy size. That tells you where documented-basis capacity already exists, and where you may need to build the LIA habit yourself.

| Country | Data Protection Officer-titled profiles | Derived |
|---|---|---|
| Germany | 227 | 1.0x base |
| United Kingdom | 814 | ~3.6x Germany |

When you need to find the people who can sign off on a basis, or the sourcers already working a strict market, describing the shape of who you want is faster than filtering a database by hand.

I ran this search: `Data protection officers at German enterprises who have written about GDPR legitimate interest` - [see the full result list](https://www.refolk.ai/s/bgs14p6wck).

*Returns named DPO-titled profiles in Germany with public evidence they have engaged with the legitimate-interest question, so you can find a reviewer who already speaks the language.*

Refolk also helps on the sourcing side of this exact job. If you need in-house recruiters in the Netherlands whose corporate email is publicly listed by their employer, the kind of contact the Dutch B2B exemption actually covers, you can ask for that directly rather than inferring it from a scrape. [Refolk](/) keys on the signals that matter to the basis, not just the name.

## The procedure, start to first send

This is the sequence to run for every person before first contact. It takes under two hours even for an EU subject who needs a fresh LIA, and most of that is reusable across a sourcing context rather than per person.

#### From profile to a defensible first message

1. **Locate the person, not yourself** - Determine the recipient's country of residence from the profile. Applicable sending law follows recipient location, not the sender's. Done when a jurisdiction is assigned.
2. **Split the two questions** - Separate "may I process this data" (GDPR Article 6) from "may I send this message" (ePrivacy, UWG, CASL, Spam Act). Done when both halves are mapped.
3. **Establish the processing basis** - For EU and UK subjects, run and document a Legitimate Interest Assessment covering purpose, necessity and balancing. Done when the LIA is recorded.
4. **Classify recruiting vs commercial** - Tag the message as recruiting legitimate-interest outreach or commercial advertising, since regimes treat them differently. Done when the type is tagged.
5. **Check the sending regime** - Look up opt-in (Germany, Austria, Canada, Australia, B2C everywhere) vs opt-out (US, France B2B, NL B2B, UK/IE B2B). Done when a go or no-go is set.
6. **Assemble mandatory elements** - Add sender identity, valid postal address, working opt-out, and the Article 14 notice where EU applies. Done when the template passes the checklist.
7. **Set opt-out SLA and suppression** - Wire the window to the regime: 10 business days (US, Canada), 5 (Australia), immediate (EU). Done when suppression is connected to the send tool.
8. **Appoint an Article 27 representative** - If non-EU and targeting EU residents, name a representative in a member state where subjects are. Done before the first EU send.

Practitioners split on sequencing. Some run the jurisdiction lookup first and the LIA second; others document the basis first because it is reusable across jurisdictions. Either works. What does not work is skipping the LIA because the jurisdiction "allows" sending, since the LIA answers the processing question and the jurisdiction answers the sending one.

## Mandatory message elements by regime

Every regime requires some elements in the message itself. Get these into the template once per jurisdiction and the per-send check becomes fast.

| Regime | Required in the message |
|---|---|
| CAN-SPAM (US) | Accurate header, non-deceptive subject, ad identification, valid physical postal address, working opt-out |
| CASL (Canada) | Proof of consent, sender identification with mailing address, functional unsubscribe |
| Spam Act (Australia) | Sender identification, functional unsubscribe, contact details valid at least 30 days |
| GDPR (EU, processing) | Article 14 privacy notice, including where the data came from (required in France) |

Note that GDPR Article 14 applies specifically because you did not collect the data from the subject. That is the normal case in sourcing. The notice must tell the person what you hold and where you got it, and France requires you to state the source explicitly.

**First-contact message skeleton (EU recruiting, legitimate interest)**

```
Subject: [Specific role] at [Company] - a note from [Your name]

Hi [First name],

I came across your profile [state the public source, e.g. your job-board CV / your open-to-work flag] and I am reaching out about a [role] at [Company].

[Two sentences on why this role fits what the signal showed.]

How I found you and your rights: I am processing your public professional data under legitimate interest to contact you about relevant roles. You can ask what I hold, correct it, or object at any time. Reply "stop" and I will remove you and not contact you again.

[Your full name]
[Company legal name and physical postal address]
[EU representative, if you are a non-EU sourcer targeting EU residents]
```

*Swap the bracketed context before sending. Keep the source line and the opt-out; they are what make this defensible.*

## How this goes wrong

Most failures here are confident misreadings, not missing knowledge. Each one below is a false positive: a reason to believe you are clear when you are not. Check the stated signal before you send.

- **"The EU is one regime."** A template cleared for France fails in Germany or Austria. The tell is a workflow that branches on "EU vs non-EU" instead of on the member state. Check the recipient's national statute, not "GDPR."
- **Treating public as lawful.** A public LinkedIn profile does not grant a basis; without a documented LIA you have nothing to show. The tell is a pipeline full of sourced records and no LIA on file for any sourcing context. Check for a recorded LIA per context.
- **Keying law to the sender.** A US sender assumes CAN-SPAM covers a German recipient. The tell is a single compliance policy written around the company's own country. Check recipient location first; German UWG governs that message.
- **Confusing recruiting with commercial.** The ICO's job-board expectation does not extend to personal social media. The tell is sourcing from Instagram or a personal account and calling it legitimate interest. The ICO advises against searching personal social media even when public, so check the source context.
- **Soft opt-in overreach.** Using the existing-customer exemption for contacts who are not existing customers, or for unrelated products, is a violation. The tell is a "we have a relationship" justification that does not survive a specific question about what that relationship is. Check that a prior relationship actually exists.
- **Assuming legitimate interest overrides ePrivacy.** Where national law demands consent to send, an LIA cannot replace it. The tell is a German or Austrian send justified by "we did the balancing test." The balancing test is the processing gate, not the sending gate. Check whether the state requires consent to send.
- **Missing the Article 27 representative.** A non-EU sourcer targets EU residents without appointing a representative. The tell is an EU-wide campaign from a company with no EU entity and no named representative. Check the appointment is in place before the first EU send.

> **Note:** Germany's real risk is civil, not the headline fine
>
> The 300,000 EUR UWG figure is aimed mostly at telephone advertising. Email exposure in Germany runs through competitor Abmahnung and injunctions under private enforcement, which "max fine" framing understates.

## Before you call the job done

Run this checklist against the specific person and message, not against your general policy. Each item is something to verify, not a topic to have thought about.

#### Pre-send verification

- [ ] The recipient's country of residence is assigned from the profile, and the sending regime is selected from that country.
- [ ] A Legitimate Interest Assessment is recorded for this sourcing context, covering purpose, necessity and balancing.
- [ ] The basis for sourcing rests on a job-board or open-to-recruiters signal, not a personal social media profile.
- [ ] The message is tagged recruiting or commercial, and the consent model matches that type for this jurisdiction.
- [ ] For Germany, Austria or any B2C recipient, prior consent exists; do not rely on a B2B carve-out there.
- [ ] The message carries sender identity, a valid physical postal address and a working opt-out.
- [ ] Where EU law applies, an Article 14 notice states what is held and where it came from.
- [ ] The opt-out SLA is wired to the regime: 10 business days US and Canada, 5 Australia, immediate EU.
- [ ] If you are a non-EU sourcer targeting EU residents, an Article 27 representative is named before the first send.

## Keeping this current

Three things in this reference move, and each has a mechanism you can re-check rather than a value to memorise. The CAN-SPAM per-email penalty is adjusted for inflation, so confirm the current figure against the FTC's published penalty tables before relying on the number in a policy. Member-state implementations change: Poland added its electronic communications law alongside the UWG-equivalent, and other states can shift their B2B carve-outs, so re-check the national statute for any country you send into regularly. And enforcement signals the regulators' actual priorities, so track the decisions coming out of the CNIL, the Dutch DPA, the Irish DPC and the FTC, because a fine against a named company tells you which failure mode is live.

The structural facts are stable. Law follows the recipient. Public does not mean lawful. Germany and Austria are opt-in with no reliable B2B carve-out. Build the workflow around those, and the moving values become a quarterly lookup rather than a risk.

## Frequently asked questions

### Can I email candidates in Germany without consent?

No. Germany's UWG Section 7 treats advertising email sent without the recipient's prior express consent as an unreasonable nuisance, with no general carve-out for business recipients. That means Germany is opt-in even for B2B. The practical risk runs mostly through private enforcement, competitor Abmahnung and injunctions, rather than the Section 20 administrative fine, which is aimed chiefly at telephone advertising. Treat a first cold email to a German recipient as needing consent.

### Does CASL require consent before a cold email in Canada?

Yes. CASL is consent-first and operates on a reverse onus, meaning the sender must prove it had express or implied consent before sending a commercial electronic message. It applies to any commercial message accessed by a computer in Canada regardless of where the sender sits. Penalties reach CAD 1 million per violation for individuals and CAD 10 million per violation for organizations, so the cost of getting consent wrong is high.

### Does a public LinkedIn profile give me a lawful basis to source someone?

No. Public availability does not by itself create a lawful basis. For EU and UK subjects you need a documented basis, usually legitimate interest supported by a recorded Legitimate Interest Assessment. The ICO treats a CV on a job board or an "open to recruiters" flag as creating a reasonable expectation of recruiter contact, but advises against searching personal social media even when public, because it is intrusive and high risk.

### Which country's law applies if my company is in the US but the recipient is in the EU?

The recipient's country determines which marketing law applies. A US company emailing a prospect in Germany is governed by German law. Separately, GDPR Article 3(2) attaches to the physical presence of a data subject in the EU, so a non-EU sourcer processing that data falls under GDPR and must appoint an Article 27 representative in a member state where the subjects are. Your domicile offers no shelter.

### Is B2B cold email always allowed in the EU?

No. The B2B carve-out varies by member state because the ePrivacy Directive leaves implementation to each country. France and the Netherlands permit B2B prospecting on opt-out where the message relates to the recipient's professional role. Germany requires opt-in with no B2B carve-out, and Austria extends opt-in explicitly to legal persons, so even a generic company address needs consent there.

### How fast must I honor an unsubscribe request?

It depends on the regime. CAN-SPAM in the US and CASL in Canada both require opt-outs honored within 10 business days. Australia's Spam Act requires 5 business days, and also requires your contact details to stay valid for at least 30 days. Under EU law you should act immediately or without undue delay. Wire the suppression window to the recipient's jurisdiction rather than applying one blanket rule.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/jurisdiction-reference-lawful-sourcing*
