Playbooks

Is Cold DM Outreach Legal? The 2026 Compliance Map for Instagram Operators

Regulators treat an Instagram DM as electronic mail, same as email. The UK penalty ceiling just jumped to 17.5 million pounds. Here is the jurisdiction map, the enforcement record, and the compliance layer to build.

Cold DM outreach sits on top of two separate rulebooks, and most operators only ever read one of them.

The first is the platform rulebook. Meta decides whether your account keeps existing. Break it and you lose accounts, not money. Every operator running Instagram outreach at volume already treats this one seriously, because the pain is immediate.

The second is the law. Data protection regulators decide whether your outreach is a lawful use of someone's personal data. Break that one and nothing happens for a long time, then a monetary penalty notice arrives. Almost nobody in this niche reads that rulebook, mostly because the guides that exist are written for cold email and stop there.

Here is the problem with that. In the UK, the regulator has explicitly said the direct message is not a special case. It is electronic mail, same as an email, same as an SMS. And on 5 February 2026 the maximum penalty for breaking those rules went from £500,000 to £17.5 million.

This is the compliance map for people who send cold DMs for a living. Not legal advice, and jurisdiction detail changes fast, so run your final setup past a lawyer who knows your market. But you should not be doing outreach without knowing where the tripwires are.

£17.5M
New UK PECR penalty ceiling, live 5 Feb 2026
49
ICO penalty notices for unsolicited marketing since Mar 2022
£4.63M
Total issued in those notices
~10M
Profiles Meta removed for impersonation in H1 2025

The DM is legally an email

The UK regulator, the ICO, defines electronic mail as any text, voice, sound or image message sent over a public network and stored until the recipient collects it. In its guidance the ICO states that this includes in-app messages and direct messaging on social media.

That single line does most of the work. It means the PECR rules written for email marketing apply to your Instagram DMs. It also means the carve-out you might be hoping for does not exist: the ICO separately says feed ads are not electronic mail, because they are displayed openly rather than stored for one named recipient. A DM is stored for one named recipient. It is in scope.

The EU position runs on the same logic through the ePrivacy Directive, which covers electronic communications generally rather than email specifically. Member states implement it differently, which is why a setup that is fine in Paris can be unlawful in Berlin.

The rule that decides everything: individual or corporate subscriber

For electronic mail marketing, UK PECR splits the world in two.

Send to an individual subscriber, which includes sole traders and most unincorporated partnerships, and you need consent or the soft opt-in, and soft opt-in only applies to your own existing customers. Cold DMs to that group do not clear the bar.

Send to a corporate subscriber, meaning a limited company, LLP or public body, and the PECR consent rule does not apply. You still owe them the GDPR side: a lawful basis, which for B2B prospecting is legitimate interests, plus transparency and an immediate honour of any opt-out.

So the practical question for every account on your list is not "is this a business account on Instagram". Instagram's own business-account toggle is a marketing label, not a legal status. The question is whether the human behind the profile is a corporate subscriber or a sole trader with a logo.

That distinction is brutal for this channel, because a large share of Instagram outreach targets exactly the people who sit on the wrong side of it: coaches, creators, personal trainers, freelance designers, solo med spa owners. Many of them are individual subscribers.

What the regulators actually punish

Enforcement in this space is not theoretical, it just moves slowly and lands on volume senders. Three recent UK cases show the shape of it.

Recent UK PECR fines for unsolicited marketing Fine size does not track message volume ZMLUK Ltd 67m emails £105,000 Allay Claims Ltd 4m texts £120,000 B. S. Chand 1m texts £200,000 £0 £200k

The sender who pushed 67 million emails paid less than the sender who pushed 1 million texts. Penalties are set on culpability, the state of the consent evidence and the complaint trail, not on a per-message rate card. Sending less is not a defence, and sending more is not automatically the bigger fine.

France runs the same play through the CNIL, which fined CALOGA €80,000 in May 2025 over prospecting without a valid basis and data sharing with partners, and SOLOCAL €900,000 in 2025 over non-compliant prospecting. The recurring findings there are the boring ones: no working opt-out, no transparency about where the data came from, prospecting outside the recipient's professional field, and holding prospect data for more than three years.

Those four findings map one to one onto how most DM operations run.

Penalty ceilings changed in 2026

Maximum penalty by regime £0.5m PECR, old until Feb 2026 £17.5m PECR, new from 5 Feb 2026 €20m GDPR or 4% of turnover

The UK's Data (Use and Access) Act 2025 lifted the PECR ceiling from £500,000 to £17.5 million with effect from 5 February 2026. Two things follow. Ceilings are not typical outcomes, and the actual notices above are five figures. But the ICO now has room to price mass unsolicited messaging and ignored opt-outs at GDPR scale, and that is the stated direction.

Jurisdiction map

Market Cold DM to a limited company Cold DM to a sole trader or individual The thing that gets you
UK Allowed. PECR consent rule does not apply to corporate subscribers. GDPR duties still apply Needs consent, or soft opt-in for your own existing customers Treating every business-looking profile as a corporate subscriber
France Allowed on legitimate interest if the message relates to the person's professional role Consent required No opt-out in the message, and no record of where the data came from
Germany Consent-heavy in practice, routinely enforced as opt-in even in B2B Consent required Assuming an EU-wide legitimate interest position covers you
Rest of EU ePrivacy is implemented locally, so check per country before you send Usually consent One EU playbook applied to 27 different implementations
United States Opt-out regime. No B2B exemption under CAN-SPAM Same opt-out regime Fake identifiers, no opt-out path, no postal address
Canada CASL is consent-first, with narrow implied-consent routes Consent-first Sending on assumed implied consent that expired

On the US side, do not assume CAN-SPAM only covers inbox email. Courts have applied it to social platform messaging, and the FTC's framing is that the primary purpose of the message matters more than the pipe it travels down. The law has no B2B exemption. It is an opt-out regime, which is why US-targeted outreach is the easy mode of this channel, but you still owe honest identifiers, a physical postal address and a working opt-out.

Scraping your list is a separate question

Where the list came from is its own exposure, and the picture there improved for operators. In Meta v Bright Data, Judge Edward Chen held that Meta's Facebook and Instagram terms do not bar logged-off scraping of public data, because those terms bind a user who is logged into an account. Meta dropped the remaining claims in February 2024.

Read that precisely. It is a contract ruling about logged-off collection of public data in one US court. It does not make the data non-personal, so GDPR still governs what you do with an EU or UK prospect's details once you have them. And it says nothing about scraping while logged into an account, which is exactly how most Instagram lead scrapers operate.

The platform layer, which moves faster than any regulator

None of this replaces the platform risk. Meta reported removing roughly 10 million profiles for impersonating large content producers across the first half of 2025, plus around 500,000 accounts demoted for spammy or inauthentic behaviour. Enforcement there needs no notice period, no assessment and no appeal you can rely on.

The operator-consensus behaviours that draw platform action are unchanged: identical message bodies at scale, links in first-touch DMs, bursts instead of spread, and fresh accounts sending before they have any history. Those are covered in our pieces on DM and action limits and action block recovery.

The compliance layer you can actually build this week

None of this requires a legal department. It requires five things wired into your ops.

  1. Segment your list by legal status, not by profile type. Tag limited company versus sole trader before the send, and route EU and UK sole traders out of cold sequences.
  2. Log provenance per lead. Source, date, method. CNIL findings repeatedly cite failure to explain where the data came from, and you cannot reconstruct it later.
  3. Put an opt-out in the first message and honour it in minutes. One line is enough. "If this is not relevant, tell me and I will not message again." Then enforce it as a hard suppression across every account you own.
  4. Set a retention clock. Delete cold prospect data that never engaged after a fixed window. Three years is the reference point regulators keep using.
  5. Write the legitimate interest assessment once. Purpose, necessity, balancing. Two pages. It is the document you produce if a complaint ever lands, and having it beats having a better argument.

The uncomfortable summary: the platform can end your operation this month, and the regulator can end it in two years. Operators obsess over the first risk and carry the second one uninsured. The five steps above cost you a day and remove most of the second one.

compliancegdprcold-dmdeliverabilityinstagram-outreach
Start free trial →