How to Audit Your Email List for CASL Compliance in 2026
Audit your email list against CASL step by step: find contacts without valid consent, document what you have, and clean the list before you send.
If your email list was built before 2017, acquired from a third party, or has never been audited for CASL compliance, you're likely sitting on a compliance problem. Every marketing email you send to a non-consented Canadian recipient is a potential CASL violation. Here's how to audit your list and fix it.
Last updated: April 2026
Why You Need a CASL Email List Audit
CASL has been in force since 2014. The transitional period ended in 2017. Yet many Canadian businesses still have lists that include:
- Contacts from purchased or rented lists (no CASL consent)
- Contacts who opted in before 2014 under the old rules
- Contacts from expired implied consent windows (24 months from last purchase)
- Contacts who unsubscribed but weren't properly removed
- Business cards collected at trade shows without clear consent
A single CASL complaint can trigger a CRTC investigation. Documented violations carry penalties up to $1 million for individuals and $10 million per violation for organisations.
The Three Consent Categories in Your List
Before auditing, understand the three categories your contacts fall into:
Category 1: Express Consent — Active The contact explicitly opted in to receive marketing from you, and consent is still valid (no time limit on express consent, unless withdrawn).
Category 2: Implied Consent — Active The contact made a purchase or inquiry within the last 24 months, giving implied consent for relevant marketing, OR their business email address was conspicuously published and they haven't unsubscribed.
Category 3: No Valid Consent Purchased lists, trade show cards without opt-in, contacts from before CASL, expired implied consent (24+ months since last transaction), or contacts who unsubscribed.
Only Categories 1 and 2 can receive marketing emails legally.
Step-by-Step CASL Email Audit
Step 1: Export Your Full Contact List
Export all contacts from your email platform (Klaviyo, Mailchimp, HubSpot, Constant Contact) including:
- Email address
- Name
- Date added to list
- Source/how they were collected
- Consent field (if captured)
- Last transaction date
- Subscription status (subscribed/unsubscribed)
- Any consent timestamp recorded
Step 2: Remove All Unsubscribed Contacts
Filter and permanently suppress all contacts marked as:
- Unsubscribed
- Bounced (hard bounces)
- Marked as spam
- Manually opted out
Verify these are fully suppressed from all campaigns and automation flows, not just paused.
Step 3: Flag Contacts by Consent Source
For each contact (or segment), document the consent source:
| Consent Source | CASL Status | Notes |
|---|---|---|
| Checked marketing opt-in at checkout | Express — likely valid | Verify timestamp |
| Newsletter signup form with unchecked checkbox | Express — likely valid | Verify language |
| Pre-checked checkbox at checkout | Invalid — no valid consent | Requires re-permission |
| Purchased from a third party | Invalid — no CASL consent | Do not email |
| Trade show card collected | Invalid unless explicit opt-in | Suppress unless you have records of verbal/written consent |
| Customer (purchase within 24 months) | Implied — valid | Track purchase date |
| Customer (purchase >24 months ago) | Expired — no longer valid | Requires express consent |
| Legacy opt-in before 2014 (pre-CASL) | Depends on terms | Audit original consent language |
Step 4: Check Your Implied Consent Window
For all contacts you're relying on implied consent (i.e., customers who haven't expressly opted in to marketing):
- Pull the most recent transaction date for each contact
- Calculate whether 24 months have passed since that date
- Contacts beyond 24 months: implied consent has lapsed — suppress from marketing
Set up a regular process (quarterly) to identify contacts whose 24-month window is expiring and decide whether to:
- Run a re-consent campaign before the window closes
- Suppress them from marketing automatically
Step 5: Investigate Your High-Risk Segments
Segment A: Contacts added before 2017 These predate the end of CASL's transitional period. Do you have records of:
- How they were originally collected?
- What consent language they saw?
- Whether they were given express consent or relied on the old transitional rule?
If you can't document valid consent, these contacts should be treated as Category 3 (no valid consent).
Segment B: Contacts from non-Canadian sources CASL applies to messages sent to Canadians. If you have a mixed Canadian/US/international list:
- For non-Canadian contacts, CASL doesn't technically apply (but CAN-SPAM and other laws may)
- Segment your Canadian contacts separately so you can apply CASL rules appropriately
Segment C: Contacts from list acquisitions or co-registration If you've ever purchased, rented, or received a list from a third party, those contacts have no direct CASL consent relationship with you. Even if the original collector had consent, that consent does not transfer to your organisation. Suppress all purchased/rented list contacts from marketing.
Step 6: Create Your Compliant Core List
After the audit, you should have:
- Compliant segment: Contacts with documented express consent or active implied consent
- Suppressed segment: All others — kept in your system (for suppression purposes) but not emailed
Your compliant segment is your new baseline. All future marketing emails go only to this list.
Step 7: Consider a Re-Permission Campaign
If you have a large number of valuable contacts in the non-compliant category, you may want to run a re-permission campaign before the audit eliminates them entirely.
Re-permission campaign best practices:
- Send ONE email explaining that you're updating your list and asking recipients to confirm their subscription
- Make it clear that if they don't opt in, you won't email them again
- Include a clear, easy opt-in button
- Use neutral, informative language — not high-pressure sales copy
CASL risk of re-permission campaigns: Sending a re-permission email to non-consented contacts is itself potentially a CASL violation. This is a judgment call: one targeted, transparent re-permission email carries lower risk than continued regular marketing. Many businesses and their counsel conclude the re-permission email is worth the low risk. Consult your legal advisor.
Documentation Requirements
After the audit, document:
- Date the audit was conducted
- Methodology used to assess consent
- What categories of contacts were suppressed and why
- The consent timestamp format you now capture
- Your process for ongoing 24-month implied consent monitoring
This documentation is your evidence of CASL compliance due diligence.
Ongoing CASL List Hygiene
The audit is a one-time fix — but list hygiene is ongoing:
- Quarterly: Review and suppress contacts with expired 24-month implied consent
- Monthly: Process any manual unsubscribes within 10 business days
- Annually: Re-audit consent documentation for the full list
- Always: Capture express consent at all new collection points with timestamp
Frequently Asked Questions
Q: We imported 20,000 contacts from Salesforce. How do we know if they're CASL compliant? A: Trace each import back to its source. If you can't document when and how they opted in, treat them as non-compliant and suppress until you can obtain new consent.
Q: We've been sending newsletters to a list of 5,000 for years and nobody has complained. Are we still at risk? A: CASL violations don't require a complaint to exist — you're liable for non-compliant sends regardless of whether anyone has complained. The absence of a complaint is luck, not compliance.
Q: How long do we need to keep consent records? A: Keep records for at least three years after the last marketing send to each contact. CASL allows complaints to be filed up to three years after the alleged violation.
Fix Your List. Protect Your Business.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — because CASL compliance starts with knowing your list.
Related reading: CASL Express vs Implied Consent | CASL Unsubscribe Requirements | What is CASL
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
CASL Exemptions: When You Don't Need Consent to Email in Canada
Not every commercial electronic message needs CASL consent. The full exemption list: transactional m...
CASL for Shopify Stores: Canadian Email Marketing Compliance Guide
Does CASL apply to your Shopify store? The problem with default settings, a consent framework, setup...