CASL — Canada's Anti-Spam Legislation
CRTC rules for commercial electronic messages sent to Canada: express vs. implied consent (with time limits), CEM identification and unsubscribe requirements, exemptions, and penalties up to $10M.
CASL is Canada's law governing commercial electronic messages (CEMs). Unlike the US CAN-SPAM Act (opt-out), CASL is an opt-in regime: consent — express or implied — is required before sending, and the sender bears the burden of proving it.
Not legal advice — verify penalties and thresholds against the primary source (below) and counsel before relying on them. See compliance/README.md.
What CASL regulates
CASL establishes four core prohibitions/obligations:
- Commercial electronic messages — a sender must: obtain prior consent from the recipient (express or implied); provide identification and contact information; and include a working unsubscribe mechanism.
- Computer program installation — installing software on someone's system requires express consent from the owner or authorized user, plus a clear and simple description of the program's function and purpose.
- Message transmission data — routing information must not be altered so a message is delivered to a destination other than (or in addition to) the one specified, without appropriate consent.
- Aiding violations — organizations must not assist others in breaching these requirements (liability for "aiding" under section 9).
What is a CEM?
A commercial electronic message is one where any one of its purposes is to encourage the recipient to participate in a commercial activity — e.g., offers to purchase/sell/lease products or services, business or investment opportunities, or promoting a person's commercial activities. Note this is broader than CAN-SPAM's "primary purpose" test: a single commercial purpose among several is enough.
Covered and excluded messages
| Covered | Excluded / exempt |
|---|---|
| Live voice and automated telemarketing calls (regulated separately) | |
| SMS / text messages | One-way social media broadcasts (tweets, wall posts) |
| Instant messaging | Political messages primarily soliciting contributions |
| Social media direct messages | B2B: messages between employees of organizations with an existing relationship |
| Push notifications (if commercial) | Membership communications to club/association members |
| Messages within limited-access secure accounts (e.g., banking portals) | |
| Registered charity fundraising (where that is the primary purpose) |
Consent
Express consent
- The person has clearly agreed to receive CEMs, in writing or orally, through a proactive opt-in action.
- Pre-checked boxes, silence, or inactivity are not valid — a positive action is required.
- Express consent does not expire; it remains valid until the recipient withdraws it.
- The onus is on the sender to prove consent was obtained.
Implied consent categories and time limits
| Category | Basis | Valid for |
|---|---|---|
| Existing business relationship (EBR) | Purchase or lease of goods, services, or land | 2 years from the transaction |
| EBR | Accepted business, investment, or gaming opportunity | 2 years |
| EBR | Written contract (in existence or expired) | 2 years from expiry |
| EBR | Inquiry or application regarding products/services | 6 months |
| Existing non-business relationship (charities, political parties/candidates, clubs/associations) | Donation or gift | 2 years |
| Existing non-business relationship | Volunteer work or meeting attendance | 2 years |
| Existing non-business relationship | Membership | Duration of membership (no fixed time limit while current) |
| Conspicuous publication | Address published publicly (e.g., on a website) with no statement discouraging CEMs, and the message relates to the recipient's business role, functions, or official duties | While published |
| Business card / disclosed address | Recipient gave their address (e.g., business card) and the message relates to their business role | — |
| Referral | One person refers another | One CEM only, and it must identify the referrer |
| Transitional (historical) | EBR or non-business relationship existing before July 1, 2014, with prior CEM history | 3 years — July 1, 2014 to July 1, 2017 (now lapsed) |
Records and burden of proof
The sender must be able to demonstrate consent. Keep records of: the electronic address; the date consent was obtained; the method (form, verbal, purchase, etc.); and the context (purchase history, volunteer work, business card exchange). The CRTC has issued an enforcement advisory specifically on record-keeping of consent.
CEM content requirements
Every CEM must:
- Identify the sender — and any person on whose behalf the message is sent. If impractical to include in the message body, the information may be provided via a hyperlink to a web page that is clearly and prominently set out and accessible at no cost.
- Provide contact information — including a valid mailing address (a P.O. box is acceptable). The contact information must remain valid for a minimum of 60 days after the message is sent.
- Include an unsubscribe mechanism that can be "readily performed" — simple, quick, and easy (e.g., an unsubscribe link, or replying "STOP"/"Unsubscribe" by SMS). The mechanism must:
- remain functional for at least 60 days after the message is sent;
- be processed without delay, and no later than 10 business days after the request.
Penalties and liability
| Exposure | Detail |
|---|---|
| Administrative monetary penalty — individual | Up to $1,000,000 per violation |
| Administrative monetary penalty — organization | Up to $10,000,000 per violation |
| Directors and officers | Personally liable if they directed, authorized, assented to, acquiesced in, or participated in the violation |
| Aiding | Liability under section 9 for assisting violations |
| Third-party marketers/affiliates | Shared liability — both the brand and the party sending on its behalf are responsible for compliance |
A documented corporate compliance program (due diligence) mitigates risk. Enforcement is handled by the CRTC (compliance and enforcement processes and published enforcement actions are on its site); spam can be reported to the Spam Reporting Centre (fightspam.gc.ca).
Deliverability relevance
CASL's opt-in-with-expiry model effectively mandates the list-hygiene practices that also protect sender reputation: mail only addresses with a recent, provable relationship, and age lists out (6-month inquiry / 2-year purchase windows). Senders who honor those windows naturally avoid the stale, unengaged addresses that drive complaints and spam-trap hits — see Foundations of Email Deliverability.