Casl Compliance
Part of the CASL guide

How to Audit Your Email List for CASL Compliance in 2026

Audit your email list against CASL step by step: find contacts without valid consent, document what you have, and clean the list before you send.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
10 min read
CASL Email Audit
Email List Compliance
CASL List Cleaning
Email Marketing Canada
CASL Compliance Audit

If your email list was built before 2017, acquired from a third party, or has never been audited for CASL compliance, you're likely sitting on a compliance problem. Every marketing email you send to a non-consented Canadian recipient is a potential CASL violation. Here's how to audit your list and fix it.

Last updated: April 2026

Why You Need a CASL Email List Audit

CASL has been in force since 2014. The transitional period ended in 2017. Yet many Canadian businesses still have lists that include:

  • Contacts from purchased or rented lists (no CASL consent)
  • Contacts who opted in before 2014 under the old rules
  • Contacts from expired implied consent windows (24 months from last purchase)
  • Contacts who unsubscribed but weren't properly removed
  • Business cards collected at trade shows without clear consent

A single CASL complaint can trigger a CRTC investigation. Documented violations carry penalties up to $1 million for individuals and $10 million per violation for organisations.

The Three Consent Categories in Your List

Before auditing, understand the three categories your contacts fall into:

Category 1: Express Consent — Active The contact explicitly opted in to receive marketing from you, and consent is still valid (no time limit on express consent, unless withdrawn).

Category 2: Implied Consent — Active The contact made a purchase or inquiry within the last 24 months, giving implied consent for relevant marketing, OR their business email address was conspicuously published and they haven't unsubscribed.

Category 3: No Valid Consent Purchased lists, trade show cards without opt-in, contacts from before CASL, expired implied consent (24+ months since last transaction), or contacts who unsubscribed.

Only Categories 1 and 2 can receive marketing emails legally.

Step-by-Step CASL Email Audit

Step 1: Export Your Full Contact List

Export all contacts from your email platform (Klaviyo, Mailchimp, HubSpot, Constant Contact) including:

  • Email address
  • Name
  • Date added to list
  • Source/how they were collected
  • Consent field (if captured)
  • Last transaction date
  • Subscription status (subscribed/unsubscribed)
  • Any consent timestamp recorded

Step 2: Remove All Unsubscribed Contacts

Filter and permanently suppress all contacts marked as:

  • Unsubscribed
  • Bounced (hard bounces)
  • Marked as spam
  • Manually opted out

Verify these are fully suppressed from all campaigns and automation flows, not just paused.

Step 3: Flag Contacts by Consent Source

For each contact (or segment), document the consent source:

Consent SourceCASL StatusNotes
Checked marketing opt-in at checkoutExpress — likely validVerify timestamp
Newsletter signup form with unchecked checkboxExpress — likely validVerify language
Pre-checked checkbox at checkoutInvalid — no valid consentRequires re-permission
Purchased from a third partyInvalid — no CASL consentDo not email
Trade show card collectedInvalid unless explicit opt-inSuppress unless you have records of verbal/written consent
Customer (purchase within 24 months)Implied — validTrack purchase date
Customer (purchase >24 months ago)Expired — no longer validRequires express consent
Legacy opt-in before 2014 (pre-CASL)Depends on termsAudit original consent language

Step 4: Check Your Implied Consent Window

For all contacts you're relying on implied consent (i.e., customers who haven't expressly opted in to marketing):

  1. Pull the most recent transaction date for each contact
  2. Calculate whether 24 months have passed since that date
  3. Contacts beyond 24 months: implied consent has lapsed — suppress from marketing

Set up a regular process (quarterly) to identify contacts whose 24-month window is expiring and decide whether to:

  • Run a re-consent campaign before the window closes
  • Suppress them from marketing automatically

Step 5: Investigate Your High-Risk Segments

Segment A: Contacts added before 2017 These predate the end of CASL's transitional period. Do you have records of:

  • How they were originally collected?
  • What consent language they saw?
  • Whether they were given express consent or relied on the old transitional rule?

If you can't document valid consent, these contacts should be treated as Category 3 (no valid consent).

Segment B: Contacts from non-Canadian sources CASL applies to messages sent to Canadians. If you have a mixed Canadian/US/international list:

  • For non-Canadian contacts, CASL doesn't technically apply (but CAN-SPAM and other laws may)
  • Segment your Canadian contacts separately so you can apply CASL rules appropriately

Segment C: Contacts from list acquisitions or co-registration If you've ever purchased, rented, or received a list from a third party, those contacts have no direct CASL consent relationship with you. Even if the original collector had consent, that consent does not transfer to your organisation. Suppress all purchased/rented list contacts from marketing.

Step 6: Create Your Compliant Core List

After the audit, you should have:

  • Compliant segment: Contacts with documented express consent or active implied consent
  • Suppressed segment: All others — kept in your system (for suppression purposes) but not emailed

Your compliant segment is your new baseline. All future marketing emails go only to this list.

Step 7: Consider a Re-Permission Campaign

If you have a large number of valuable contacts in the non-compliant category, you may want to run a re-permission campaign before the audit eliminates them entirely.

Re-permission campaign best practices:

  • Send ONE email explaining that you're updating your list and asking recipients to confirm their subscription
  • Make it clear that if they don't opt in, you won't email them again
  • Include a clear, easy opt-in button
  • Use neutral, informative language — not high-pressure sales copy

CASL risk of re-permission campaigns: Sending a re-permission email to non-consented contacts is itself potentially a CASL violation. This is a judgment call: one targeted, transparent re-permission email carries lower risk than continued regular marketing. Many businesses and their counsel conclude the re-permission email is worth the low risk. Consult your legal advisor.

Documentation Requirements

After the audit, document:

  • Date the audit was conducted
  • Methodology used to assess consent
  • What categories of contacts were suppressed and why
  • The consent timestamp format you now capture
  • Your process for ongoing 24-month implied consent monitoring

This documentation is your evidence of CASL compliance due diligence.

Ongoing CASL List Hygiene

The audit is a one-time fix — but list hygiene is ongoing:

  • Quarterly: Review and suppress contacts with expired 24-month implied consent
  • Monthly: Process any manual unsubscribes within 10 business days
  • Annually: Re-audit consent documentation for the full list
  • Always: Capture express consent at all new collection points with timestamp

Frequently Asked Questions

Q: We imported 20,000 contacts from Salesforce. How do we know if they're CASL compliant? A: Trace each import back to its source. If you can't document when and how they opted in, treat them as non-compliant and suppress until you can obtain new consent.

Q: We've been sending newsletters to a list of 5,000 for years and nobody has complained. Are we still at risk? A: CASL violations don't require a complaint to exist — you're liable for non-compliant sends regardless of whether anyone has complained. The absence of a complaint is luck, not compliance.

Q: How long do we need to keep consent records? A: Keep records for at least three years after the last marketing send to each contact. CASL allows complaints to be filed up to three years after the alleged violation.


Fix Your List. Protect Your Business.

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — because CASL compliance starts with knowing your list.

Related reading: CASL Express vs Implied Consent | CASL Unsubscribe Requirements | What is CASL

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.