emailmarketing.net

CASL — Canada's Anti-Spam Legislation

CRTC rules for commercial electronic messages sent to Canada: express vs. implied consent (with time limits), CEM identification and unsubscribe requirements, exemptions, and penalties up to $10M.

Referencecompliancesender

CASL is Canada's law governing commercial electronic messages (CEMs). Unlike the US CAN-SPAM Act (opt-out), CASL is an opt-in regime: consent — express or implied — is required before sending, and the sender bears the burden of proving it.

Not legal advice — verify penalties and thresholds against the primary source (below) and counsel before relying on them. See compliance/README.md.

What CASL regulates

CASL establishes four core prohibitions/obligations:

  1. Commercial electronic messages — a sender must: obtain prior consent from the recipient (express or implied); provide identification and contact information; and include a working unsubscribe mechanism.
  2. Computer program installation — installing software on someone's system requires express consent from the owner or authorized user, plus a clear and simple description of the program's function and purpose.
  3. Message transmission data — routing information must not be altered so a message is delivered to a destination other than (or in addition to) the one specified, without appropriate consent.
  4. Aiding violations — organizations must not assist others in breaching these requirements (liability for "aiding" under section 9).

What is a CEM?

A commercial electronic message is one where any one of its purposes is to encourage the recipient to participate in a commercial activity — e.g., offers to purchase/sell/lease products or services, business or investment opportunities, or promoting a person's commercial activities. Note this is broader than CAN-SPAM's "primary purpose" test: a single commercial purpose among several is enough.

Covered and excluded messages

Covered Excluded / exempt
Email Live voice and automated telemarketing calls (regulated separately)
SMS / text messages One-way social media broadcasts (tweets, wall posts)
Instant messaging Political messages primarily soliciting contributions
Social media direct messages B2B: messages between employees of organizations with an existing relationship
Push notifications (if commercial) Membership communications to club/association members
Messages within limited-access secure accounts (e.g., banking portals)
Registered charity fundraising (where that is the primary purpose)

Consent

Express consent

  • The person has clearly agreed to receive CEMs, in writing or orally, through a proactive opt-in action.
  • Pre-checked boxes, silence, or inactivity are not valid — a positive action is required.
  • Express consent does not expire; it remains valid until the recipient withdraws it.
  • The onus is on the sender to prove consent was obtained.

Implied consent categories and time limits

Category Basis Valid for
Existing business relationship (EBR) Purchase or lease of goods, services, or land 2 years from the transaction
EBR Accepted business, investment, or gaming opportunity 2 years
EBR Written contract (in existence or expired) 2 years from expiry
EBR Inquiry or application regarding products/services 6 months
Existing non-business relationship (charities, political parties/candidates, clubs/associations) Donation or gift 2 years
Existing non-business relationship Volunteer work or meeting attendance 2 years
Existing non-business relationship Membership Duration of membership (no fixed time limit while current)
Conspicuous publication Address published publicly (e.g., on a website) with no statement discouraging CEMs, and the message relates to the recipient's business role, functions, or official duties While published
Business card / disclosed address Recipient gave their address (e.g., business card) and the message relates to their business role
Referral One person refers another One CEM only, and it must identify the referrer
Transitional (historical) EBR or non-business relationship existing before July 1, 2014, with prior CEM history 3 years — July 1, 2014 to July 1, 2017 (now lapsed)

Records and burden of proof

The sender must be able to demonstrate consent. Keep records of: the electronic address; the date consent was obtained; the method (form, verbal, purchase, etc.); and the context (purchase history, volunteer work, business card exchange). The CRTC has issued an enforcement advisory specifically on record-keeping of consent.

CEM content requirements

Every CEM must:

  1. Identify the sender — and any person on whose behalf the message is sent. If impractical to include in the message body, the information may be provided via a hyperlink to a web page that is clearly and prominently set out and accessible at no cost.
  2. Provide contact information — including a valid mailing address (a P.O. box is acceptable). The contact information must remain valid for a minimum of 60 days after the message is sent.
  3. Include an unsubscribe mechanism that can be "readily performed" — simple, quick, and easy (e.g., an unsubscribe link, or replying "STOP"/"Unsubscribe" by SMS). The mechanism must:
    • remain functional for at least 60 days after the message is sent;
    • be processed without delay, and no later than 10 business days after the request.

Penalties and liability

Exposure Detail
Administrative monetary penalty — individual Up to $1,000,000 per violation
Administrative monetary penalty — organization Up to $10,000,000 per violation
Directors and officers Personally liable if they directed, authorized, assented to, acquiesced in, or participated in the violation
Aiding Liability under section 9 for assisting violations
Third-party marketers/affiliates Shared liability — both the brand and the party sending on its behalf are responsible for compliance

A documented corporate compliance program (due diligence) mitigates risk. Enforcement is handled by the CRTC (compliance and enforcement processes and published enforcement actions are on its site); spam can be reported to the Spam Reporting Centre (fightspam.gc.ca).

Deliverability relevance

CASL's opt-in-with-expiry model effectively mandates the list-hygiene practices that also protect sender reputation: mail only addresses with a recent, provable relationship, and age lists out (6-month inquiry / 2-year purchase windows). Senders who honor those windows naturally avoid the stale, unengaged addresses that drive complaints and spam-trap hits — see Foundations of Email Deliverability.

#compliance#legal#casl#canada#consent#opt-in