How do you approach data management, compliance, and security like GDPR or the EU AI Act in your business?
GDPR and similar rules are low risk for small‑scale cold email because you’re not sending tens of millions of emails like spammers; you’re delivering value. Treat compliance like a stop sign—follow it when practical, but don’t let it block you. You can also incorporate in the US or sell to non‑EU clients to avoid the issue.
You have to work within the regulations. If you follow GDPR and telecom rules exactly, you won’t be able to send cold emails, so you need to use alternative, lawful channels. Some people set up shell companies to route communications, but that’s a gray area and I wouldn’t recommend it. In practice, just be reasonable, stick to the letter of the law, and look for other outreach methods that comply with EU rules.
Yes, targeting U.S. companies is a solid tactical move if you want to avoid German restrictions. The idea that cold email is 'not allowed' in Europe is often overstated; it’s really a risk‑reward imbalance, not a hard ban—similar to jaywalking being illegal but still safe when no cars are around. You can also set up a U.S. entity and operate from there to minimize risk. All these tactics avoid the underlying risk‑reward misbalance, but they aren’t legal advice.
Nick explains that most cold emails require an unsubscribe opt‑out and a PO box address for CAN‑SPAM compliance in the USA. He notes the legality isn’t mainly about regulation but about enforceability and downside risk. He points out that millions send cold emails, but the vast majority do so poorly—blasting massive spam campaigns fishing for email addresses or banking details. Enforcement will target those bad actors, not the few sending high‑quality, customized emails with strong offers. He emphasizes he’s not a lawyer and his video isn’t legal advice, adding the disclaimer that someone might misinterpret it as encouragement for illegal activity. He observes that people send cold emails at scale worldwide, and laws like CAN‑SPAM are deliberately vague to push self‑compliance for risk reasons. He concludes by saying to do with that information what you will. He then acknowledges a comment from Tech to Jazz about replacing scrolling with daily updates being the best thing for their media diet, and thanks them.
Even though they don’t want to buy burner domains or warm‑up accounts, you can still achieve volume by purchasing pre‑warmed email addresses. At roughly $15 per address you could buy about 60 accounts for $1,000 a month, which lets you send around 2,000 emails per day. With a modest 2 % reply rate that’s about 40 replies daily, yielding roughly 20 qualified leads and maybe 10 calls. The funnel looks boring and hacky—buying dozens of email accounts and blasting at low conversion—but if you position and sell it correctly it can generate a lot of money. The main issue is the moral or legal concerns some companies have about mass‑emailing, especially in the Netherlands where GDPR worries arise. If you target US clients or operate through your own company the risk is lower, but it’s not legal advice.