CASL Compliance: The Comprehensive Guide

Reviewed By Lawyer: Harrison Jordan, J.D. ||
Last Updated: August 2026.

Understanding Canada’s Anti-Spam Legislation

Get Your Complimentary Quote Now
Conversational Form (#3)

Canada’s Anti-Spam Legislation, commonly known as CASL, regulates commercial electronic messages, certain installations of computer programs, alterations of electronic transmission data, electronic address harvesting, and misleading digital representations.

CASL is not limited to fraudulent or high-volume “spam.” It can apply to ordinary emails, text messages, newsletters, direct messages, promotional notifications, referral campaigns, and other electronic communications sent by legitimate businesses.

For most commercial electronic messages, the three central requirements are:

  • valid consent;
  • prescribed sender identification and contact information; and
  • a functioning unsubscribe mechanism. (CRTC)

Substance Law assists businesses throughout Canada with CASL compliance reviews, electronic marketing policies, consent systems, website forms, email and SMS campaigns, unsubscribe procedures, lead-generation practices, software-installation rules, vendor agreements, and responses to regulatory investigations.

What Is CASL?

CASL is the informal name commonly used for the federal statute titled An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities.

CASL prohibits sending, causing or permitting the sending of a commercial electronic message to an electronic address unless the statutory requirements are satisfied. It also regulates certain software installations and prohibits unauthorized alterations of transmission data. (Laws and Regulations of Canada)

CASL works alongside other Canadian laws, including:

  • the Competition Act;
  • the Personal Information Protection and Electronic Documents Act;
  • provincial privacy legislation;
  • consumer-protection laws;
  • telemarketing rules; and
  • contractual and platform-specific requirements.

What Is a Commercial Electronic Message?

A commercial electronic message, or CEM, is generally an electronic message that, having regard to its content, hyperlinks or contact information, encourages participation in a commercial activity.

A CEM may promote or encourage:

  • the purchase of goods;
  • the purchase of services;
  • an investment;
  • a business opportunity;
  • a paid event;
  • a subscription;
  • a membership;
  • a contest or promotion;
  • a commercial website;
  • a consultation;
  • a referral; or
  • another commercial transaction.

The message does not need to complete a sale. An invitation, promotion, offer, request for business, or message intended to generate commercial interest may be enough.

A request asking a recipient to consent to future commercial messages is itself treated as a commercial electronic message. A business therefore generally cannot send an unsolicited marketing email merely to ask whether the recipient would like to receive marketing emails. (Laws and Regulations of Canada)

What Is an Electronic Address?

CASL applies to messages sent to an electronic address.

Examples may include:

  • email addresses;
  • mobile telephone accounts used for text messaging;
  • instant-messaging accounts;
  • social-media messaging accounts; and
  • other similar accounts.

The relevant question is not simply whether the communication was called an “email.” SMS messages, app messages and some direct messages may also be covered.

The Three Main CASL Requirements

Most CEMs require the sender to satisfy three basic requirements.

Consent

The sender must have either express consent or a legally recognized form of implied consent, unless an exemption applies.

Identification

The message must identify the sender and, where applicable, the person on whose behalf the message is sent.

Unsubscribe Mechanism

The message must include a clear and functioning method by which the recipient can withdraw consent.

These requirements should be built into the organization’s systems before a campaign is launched, rather than addressed only after complaints are received.

Express Consent Under CASL

Express consent occurs where the recipient affirmatively agrees to receive commercial electronic messages after receiving the required information.

A compliant request for express consent should generally state:

  • the purpose for which consent is sought;
  • the name of the person seeking consent;
  • the identity of any other person on whose behalf consent is sought;
  • prescribed contact information; and
  • that consent may later be withdrawn. (CRTC)

Express consent may be obtained through:

  • an unchecked website checkbox;
  • a newsletter registration form;
  • an account-creation process;
  • an event registration;
  • a signed agreement;
  • a recorded verbal consent process; or
  • another affirmative opt-in mechanism.

The sender bears the burden of proving consent. Businesses should therefore maintain records of when, how and on what terms consent was obtained. The CRTC expressly advises senders to retain proof of express consent. (CRTC)

Pre-Checked Boxes and Bundled Consent

Pre-checked boxes create significant compliance risk because they may not demonstrate an affirmative act by the individual.

Similarly, consent should not be hidden inside unrelated contractual language or bundled so broadly that a person cannot understand what they are agreeing to receive.

A consent request should be clear, specific and separate enough to demonstrate an informed choice.

Does Express Consent Expire?

Express consent generally does not expire merely because time passes.

It continues until the recipient withdraws it, unless the consent was limited by its own terms.

However, the organization must still be able to prove that valid consent was obtained and must honour any later unsubscribe request.

Implied Consent Under CASL

Implied consent may arise in specific circumstances recognized by CASL.

Common examples include:

  • an existing business relationship;
  • an existing non-business relationship;
  • conspicuous publication of an electronic address without a statement that unsolicited messages are not wanted; or
  • disclosure of an electronic address to the sender without an indication that commercial messages are unwanted, where the message is relevant to the recipient’s role or business.

Implied consent should not be treated as a general substitute for express consent. Its scope may be narrow, fact-specific and time-limited. (CRTC)

Existing Business Relationships

An existing business relationship may arise from certain transactions, contracts, inquiries or applications.

Depending on the basis for the relationship, implied consent may continue for a prescribed period after:

  • a purchase;
  • a lease;
  • a written contract;
  • an investment;
  • an inquiry; or
  • an application.

Businesses should record the event that created the relationship and the date on which the implied-consent period begins and ends.

A customer’s purchase years ago does not necessarily authorize indefinite marketing.

Existing Non-Business Relationships

An existing non-business relationship may arise in connection with certain charities, political organizations, clubs, associations and voluntary relationships.

These rules are technical and depend on the recipient’s relationship with the organization. A not-for-profit status alone does not automatically exempt all electronic messages.

Conspicuously Published Email Addresses

A business may sometimes rely on implied consent where a recipient has conspicuously published an electronic address without indicating that unsolicited messages are not wanted.

This is not a blanket authorization to scrape addresses from the internet.

The message must generally be relevant to the recipient’s business role, functions or duties. A publicly available email address does not authorize unrelated mass marketing.

Organizations should document:

  • where the address was found;
  • when it was found;
  • whether a no-solicitation statement appeared;
  • the recipient’s apparent business role; and
  • why the message was relevant to that role.

Voluntarily Disclosed Addresses

Implied consent may sometimes arise where a person gives the sender their electronic address without indicating that they do not wish to receive unsolicited CEMs.

The proposed message must still be relevant to the person’s business, role, functions or duties.

Receiving a business card does not necessarily authorize every type of future marketing campaign.

Business-to-Business Messages

CASL applies to many B2B communications.

A message is not automatically exempt simply because it is sent:

  • to a corporate email address;
  • by one business to another;
  • to a director or employee;
  • through LinkedIn; or
  • for professional purposes.

There are exclusions for certain messages sent within an organization or between organizations where the organizations have an established relationship and the message concerns the recipient organization’s activities. The precise conditions should be reviewed before relying on the exclusion. (Laws and Regulations of Canada)

Referrals

CASL contains a limited referral provision.

The first CEM following a referral may be sent without the ordinary consent requirement where the prescribed relationships exist among the sender, recipient and referring individual. The message must disclose the full name of the person who made the referral and state that it was sent because of that referral. (Laws and Regulations of Canada)

This exception should not be interpreted as permission to send an ongoing marketing sequence. It generally concerns the first message.

Identification Requirements

A CEM must generally identify:

  • the person sending the message; and
  • any different person on whose behalf the message is sent.

The message must also include prescribed contact information, such as a valid mailing address and another means of contact.

The Electronic Commerce Protection Regulations prescribe the identification information required in commercial messages. (Laws and Regulations of Canada)

Marketing agencies, affiliates and lead generators should make clear whose business is being promoted and on whose behalf the message is sent.

Unsubscribe Requirements

A compliant CEM must generally include an unsubscribe mechanism that is:

  • clearly and prominently displayed;
  • readily performed;
  • available without charge;
  • capable of being used through the same electronic means where practicable; and
  • functional for the required period.

Businesses must process unsubscribe requests within the statutory timeframe. Their systems should suppress future marketing across all relevant platforms rather than merely removing the individual from a single campaign.

A preference centre can be useful, but it should not make complete withdrawal confusing or difficult.

Transactional and Factual Messages

Some messages are sent primarily to complete, confirm or facilitate a transaction rather than market a product.

Examples may include:

  • receipts;
  • delivery notices;
  • warranty information;
  • safety notices;
  • recall notices;
  • account statements;
  • subscription-expiry notices;
  • factual information about an existing purchase; and
  • security alerts.

Certain messages may be exempt from some CASL requirements or treated differently under the legislation.

However, inserting promotional content into an otherwise factual message may cause the communication to become a CEM. Businesses should separate operational notices from marketing wherever possible.

Messages Responding to Requests

A direct response to a request, inquiry, complaint or solicitation may be exempt in appropriate circumstances.

The response should remain connected to the recipient’s request. Using a customer-service inquiry as an opportunity to add unrelated marketing may create additional risk.

Family and Personal Relationships

CASL excludes certain messages sent within qualifying family or personal relationships.

These terms have specific legal meanings. Merely knowing someone socially or connecting through social media may not be enough to establish the required relationship.

Charities and Political Organizations

Certain messages sent by or on behalf of registered charities or political organizations may be exempt where the message’s primary purpose falls within the prescribed fundraising or political categories.

The exemption does not necessarily cover every message sent by a charity, political party, candidate or third-party organization.

The content and primary purpose of the message remain important.

CASL and Email Marketing

Email campaigns should be reviewed for:

  • the legal basis for consent;
  • the date consent was obtained;
  • proper sender identification;
  • accurate subject lines;
  • working unsubscribe links;
  • suppression-list controls;
  • proof of consent;
  • third-party vendor practices; and
  • compliance across automated sequences.

Common high-risk practices include purchasing email lists, using scraped addresses, importing undocumented contacts into a CRM, and assuming that all former customers may be marketed to indefinitely.

CASL and SMS Marketing

CASL applies to commercial text messages sent to mobile accounts.

Businesses using SMS campaigns should review:

  • the opt-in language;
  • the telephone number used;
  • proof of consent;
  • message frequency disclosures;
  • sender identification;
  • “STOP” functionality;
  • suppression lists; and
  • the practices of the messaging platform.

A telephone number collected for order fulfilment is not necessarily consent to receive promotional text messages.

CASL and Social-Media Direct Messages

Commercial direct messages sent through LinkedIn, Instagram, Facebook or another platform may engage CASL where they are sent to an electronic address and encourage commercial activity.

A connection request, follow, or acceptance of platform terms should not automatically be treated as express consent to off-platform or direct-message marketing.

The message’s content, destination and surrounding relationship should be assessed.

CASL and Purchased Lead Lists

Purchased lists create substantial risk.

Before using a vendor’s contacts, a business should determine:

  • how the addresses were collected;
  • what consent language was shown;
  • which organizations were identified;
  • whether consent covers the purchasing business;
  • whether the consent remains valid;
  • whether unsubscribes were removed;
  • whether addresses were harvested; and
  • whether auditable records are available.

Organizations remain responsible for ensuring that electronic addresses collected by them or by third parties acting on their behalf were obtained lawfully. (Office of the Privacy Commissioner)

A contractual promise that a list is “CASL compliant” is not an adequate substitute for due diligence.

Electronic Address Harvesting

CASL-related amendments to Canadian privacy law restrict electronic address harvesting and certain uses of addresses obtained through harvesting.

Address harvesting generally involves collecting electronic addresses through automated or indiscriminate methods, often from websites or online directories.

The Office of the Privacy Commissioner has investigated large-scale address harvesting and has advised organizations that they remain responsible for addresses collected by third parties. (Office of the Privacy Commissioner)

False or Misleading Electronic Messages

CASL also interacts with the Competition Act.

False or misleading representations may create liability where they appear in:

  • sender information;
  • subject lines;
  • message content;
  • URLs;
  • domain names; or
  • other electronic locators.

The Competition Bureau states that it is illegal to promote a product or business interest through false or misleading electronic representations. (Competition Bureau)

Businesses should avoid:

  • false urgency;
  • deceptive sender names;
  • misleading “RE:” or “FW:” subject lines;
  • disguised advertisements;
  • inaccurate discount claims;
  • fake endorsements;
  • misleading prize notices; and
  • URLs that misrepresent their destination.

A business can have valid CASL consent and still violate the Competition Act through deceptive content.

CASL and Computer Programs

CASL also regulates the installation of computer programs on another person’s computer system in the course of commercial activity.

Express consent may be required unless an exception applies. The consent request may also require enhanced disclosure where the program performs specified functions that users would not reasonably expect.

These provisions may affect:

  • mobile applications;
  • browser extensions;
  • plugins;
  • downloadable software;
  • automatic updates;
  • adware;
  • device-management software;
  • tracking technologies; and
  • bundled installations.

The CRTC identifies express consent as a central requirement when installing a computer program on another person’s system in the course of commercial activity. (CRTC)

Altering Transmission Data

CASL prohibits altering transmission data in an electronic message so that the message is delivered to a destination other than, or in addition to, the destination specified by the sender, unless consent or another statutory basis exists.

This provision can apply to unauthorized redirection practices and certain forms of digital interception. (Laws and Regulations of Canada)

CASL and Privacy Law

CASL compliance and privacy compliance overlap but are not identical.

A business may need to consider:

  • whether it lawfully collected the address;
  • whether it may use the address for marketing;
  • whether CASL consent exists;
  • what its privacy policy says;
  • how long the information is retained;
  • whether it is disclosed to vendors; and
  • how unsubscribe and suppression records are maintained.

An unsubscribe request may require the organization to stop marketing while still retaining limited information needed to ensure that the person is not added back to future campaigns.

Third-Party Agencies and Affiliates

A company may remain exposed where an agency, affiliate, contractor or lead generator sends non-compliant messages on its behalf.

Vendor agreements should address:

  • consent requirements;
  • approved data sources;
  • message approval;
  • identification obligations;
  • unsubscribe processing;
  • suppression-list sharing;
  • record retention;
  • audit rights;
  • indemnification;
  • privacy and security; and
  • cooperation during investigations.

The business should monitor actual practices rather than relying solely on contractual language.

Director and Officer Liability

CASL provides for extended liability in certain circumstances.

Directors, officers, agents and mandataries may be exposed where they directed, authorized, assented to, acquiesced in or participated in a violation. Employers and principals may also face liability for acts of employees or agents.

The CRTC has previously held an individual corporate officer liable for violations committed by a corporation, including messages sent without consent and without a properly functioning unsubscribe mechanism. (CRTC)

Senior management should therefore treat CASL compliance as a governance issue rather than a responsibility delegated entirely to marketing staff.

CASL Penalties

CASL permits significant administrative monetary penalties.

The maximum AMP per violation is:

  • $1 million for an individual; and
  • $10 million for a business or other organization. (CRTC)

The maximum is not automatically imposed. The regulator considers statutory factors, including the nature and scope of the violation, the person’s history, ability to pay, financial benefit and other relevant circumstances.

Enforcement may also involve:

  • warning letters;
  • preservation demands;
  • notices to produce;
  • search warrants;
  • undertakings;
  • notices of violation;
  • public decisions; and
  • reputational damage.

The CRTC continues to actively enforce CASL and publish enforcement information. (CRTC)

Is There a Private Right of Action?

The planned CASL private right of action was suspended by the federal government before it came into force.

Accordingly, CASL enforcement currently remains primarily regulatory rather than permitting the originally proposed statutory lawsuits by private parties under those suspended provisions. (Canada)

This does not prevent claims under other legal theories where the facts support them.

Due-Diligence Defence

CASL provides a due-diligence defence.

A person may avoid liability where they can establish that they exercised due diligence to prevent the violation.

A credible due-diligence position generally requires more than a written policy that nobody follows. Businesses should be able to demonstrate:

  • management oversight;
  • clear policies;
  • staff training;
  • approved consent language;
  • functioning technical controls;
  • record keeping;
  • campaign review;
  • vendor supervision;
  • unsubscribe testing;
  • periodic audits; and
  • corrective action when problems are identified.

Building a CASL Compliance Program

A practical CASL compliance program should include:

  • an inventory of all marketing channels;
  • identification of the legal basis for each contact;
  • approved express-consent language;
  • implied-consent expiry tracking;
  • standard message templates;
  • sender-identification rules;
  • unsubscribe testing;
  • centralized suppression lists;
  • lead-vendor due diligence;
  • written policies;
  • employee training;
  • complaint handling;
  • record-retention procedures; and
  • periodic legal and technical reviews.

The program should reflect the organization’s actual size, risk profile and marketing practices.

Records Businesses Should Keep

Businesses should maintain records showing:

  • the recipient’s electronic address;
  • the date consent was obtained;
  • whether consent was express or implied;
  • the exact consent language;
  • the method used to obtain consent;
  • the source of the address;
  • the relationship supporting implied consent;
  • the expiry date of implied consent;
  • copies of messages sent;
  • unsubscribe requests;
  • suppression-list activity;
  • vendor contracts; and
  • compliance training.

Screenshots and version-controlled copies of web forms are particularly useful when consent language changes over time.

Common CASL Compliance Mistakes

Frequent problems include:

  • using pre-checked boxes;
  • purchasing undocumented lists;
  • scraping publicly available addresses;
  • failing to track implied-consent expiry;
  • sending a CEM to request express consent;
  • using inaccurate sender information;
  • omitting a mailing address;
  • using broken unsubscribe links;
  • failing to process unsubscribes across all systems;
  • adding promotional content to transactional messages;
  • assuming B2B messages are automatically exempt;
  • relying on a platform’s default settings; and
  • failing to supervise marketing vendors.

Responding to a CASL Complaint or Investigation

Businesses receiving a regulatory inquiry, preservation demand, notice to produce or complaint should act promptly.

Relevant steps may include:

  • preserving emails, CRM data and consent records;
  • suspending questionable campaigns;
  • identifying the affected recipients;
  • testing unsubscribe systems;
  • reviewing third-party vendors;
  • avoiding destruction or alteration of records;
  • assessing the legal basis for each message; and
  • obtaining legal advice before making substantive admissions.

A poorly coordinated response can make an otherwise manageable compliance issue more serious.

Our CASL Compliance Services

Substance Law assists businesses with:

  • CASL compliance audits;
  • express-consent language;
  • implied-consent analysis;
  • email and SMS campaign reviews;
  • website and checkout forms;
  • B2B outreach;
  • social-media messaging;
  • lead-generation programs;
  • vendor agreements;
  • unsubscribe procedures;
  • suppression-list systems;
  • internal CASL policies;
  • employee training materials;
  • software-installation issues;
  • privacy-law alignment;
  • regulator correspondence;
  • notices to produce;
  • undertakings; and
  • enforcement defence.

Work With a CASL Compliance Lawyer in Canada

Businesses should not wait for a complaint before reviewing their marketing practices.

A properly designed CASL compliance program can support lawful customer engagement while reducing regulatory, reputational and operational risk.

Substance Law advises businesses throughout Canada on commercial electronic messages, consent systems, electronic marketing, software installations, privacy compliance and CASL enforcement matters.

Frequently Asked Questions About CASL Compliance

What does CASL stand for?

CASL stands for Canada’s Anti-Spam Legislation, the commonly used name for the federal law regulating commercial electronic messages and certain other digital activities.

What are the three main CASL requirements?

Most commercial electronic messages require valid consent, prescribed sender-identification information and a functioning unsubscribe mechanism.

Does CASL apply only to spam?

No. CASL can apply to ordinary commercial emails, text messages, newsletters and direct messages sent by legitimate businesses.

Does CASL apply to B2B emails?

Yes. B2B messages are not automatically exempt. A specific exclusion, exemption or valid form of consent must apply.

Can I send an email asking someone to consent?

Generally, a message requesting consent to receive commercial electronic messages is itself a CEM. The sender therefore needs an existing legal basis to send that request electronically.

Does express consent expire?

Express consent generally continues until it is withdrawn, unless it was limited by its own terms.

How long does implied consent last?

The duration depends on the relationship or event creating it. Businesses should identify the applicable statutory period and track expiry dates.

Can I email an address found on a company website?

Possibly, but only where the statutory conditions for conspicuous publication are satisfied, including relevance to the recipient’s business role and the absence of a statement prohibiting unsolicited messages.

Are purchased email lists legal?

They are high risk. The sender must be able to establish that the addresses were lawfully collected and that valid consent covers the sender and proposed messages.

Do text messages fall under CASL?

Yes. Commercial SMS messages can be CEMs and generally require consent, identification and an unsubscribe mechanism.

Does CASL apply to LinkedIn messages?

It may. Commercial direct messages sent to an electronic account may engage CASL depending on the nature of the account, message and surrounding circumstances.

How quickly must an unsubscribe request be processed?

CASL requires unsubscribe requests to be given effect within the statutory period. Businesses should process them promptly and ensure suppression across all relevant systems.

What are the maximum CASL penalties?

The maximum administrative monetary penalty per violation is $1 million for an individual and $10 million for an organization. (CRTC)

Can directors be personally liable?

Potentially. Directors and officers may face liability where they directed, authorized, assented to, acquiesced in or participated in the violation.

Can Substance Law assist with CASL compliance?

Yes. Substance Law assists businesses with CASL audits, consent language, electronic marketing reviews, policies, staff training, vendor arrangements and responses to regulatory investigations.

Lawyer Harrison Jordan
Sidebar