CASL Compliance for Email Marketing: Consent, Unsubscribe and Penalty Rules for Canadian Businesses
How CASL is enforced and what it can cost: the consent, identification and unsubscribe rules, the common failures, and how to audit your email.
Canada's Anti-Spam Legislation (CASL) is enforced by the Canadian Radio-television and Telecommunications Commission (CRTC), and administrative monetary penalties can reach $10 million per violation for organizations.
If you're using email marketing, SMS campaigns, or any commercial electronic messaging in Canada, you need to understand what the law requires and where businesses most often fall short.
Common CASL Compliance Failures
Inability to Prove Consent
The Problem:
- Business sends emails
- Recipient complains or CRTC audits
- Business cannot produce consent record
- CASL places the onus of proving consent on the person alleging it (s. 13)
How to Avoid:
- ✅ Implement consent management system
- ✅ Capture: who, what, when, where, how for every consent
- ✅ Store consent with timestamp and IP address
- ✅ Never rely on verbal consent without documentation
Expired Implied Consent
The Problem:
- Business relationship ends
- Implied consent expires (2 years from purchase, 6 months from inquiry)
- Business continues sending marketing emails
How to Avoid:
- ✅ Track consent expiry dates in CRM
- ✅ Automated alerts 30 days before expiry
- ✅ Re-consent campaigns before expiry
- ✅ Convert implied to express consent proactively
Unsubscribe Mechanism Failures
CASL Requirements:
- Must include unsubscribe mechanism in every CEM
- Must be able to be readily performed
- Must process within 10 business days
- Must let the recipient unsubscribe at no cost to them
- Must work for minimum 60 days after sending
How to Avoid:
- ✅ One-click unsubscribe (no login required)
- ✅ Automated processing (instant when possible)
- ✅ Test unsubscribe links monthly
- ✅ Unsubscribe from ALL lists (not just specific campaign)
Affiliate Marketing Violations
The Problem:
- Company hires affiliates to promote products
- Affiliates send spam on company's behalf
- Section 9 of CASL prohibits aiding, inducing or procuring a contravention of sections 6 to 8
How to Avoid:
- ✅ Written agreements with all affiliates
- ✅ Require affiliates to warrant CASL compliance
- ✅ Periodic audits of affiliate practices
- ✅ Immediate termination for violations
Insufficient Identification Information
CASL Requirements:
- Must identify sender clearly
- Must provide valid mailing address
- Must include a telephone number, email address or web address
- Must remain valid for 60 days after sending
How to Avoid:
- ✅ Include full identification in every email
- ✅ Company name, physical address, contact info in footer
- ✅ Use real "from" names, not generic
- ✅ Keep contact information current
Understanding the $10M Maximum Penalty
CASL's maximum penalties are severe:
- Individuals: $1,000,000 per violation
- Businesses: $10,000,000 per violation
How Penalty Amounts Are Determined
Under section 20(3) of CASL, the purpose of a penalty is to promote compliance, not to punish, and the factors that must be taken into account include:
- The nature and scope of the violation
- The person's history of previous violations and undertakings
- Any financial benefit obtained from the violation
- The person's ability to pay
- Whether the person has voluntarily paid compensation to anyone affected
- Any other relevant factor
Express vs. Implied Consent
Express Consent (Best Protection)
Valid Express Consent Mechanisms:
✅ Unchecked checkbox that person checks:
☐ Yes, I want to receive marketing emails from [Company]
✅ Typed confirmation
✅ Verbal consent (documented with date, time, witness)
✅ Written signature
Invalid Express Consent:
❌ Pre-checked box ❌ Negative option ("Check here if you DON'T want emails") ❌ Bundled consent hidden in terms ❌ Opt-out instead of opt-in
Advantage: Never expires (until withdrawn)
Implied Consent (Time-Limited)
Existing Business Relationship (2 years from):
- Purchase or lease of product/service
- Written contract (during contract + 2 years after end)
Recent Inquiry (6 months from):
- Application or inquiry about product/service
Common Traps:
❌ Attended free webinar (not a business relationship) ❌ Downloaded free whitepaper (inquiry = 6 months only) ❌ Entered contest (not a business relationship) ❌ Met at networking event (no relationship)
Consent Expiry Scenarios
Scenario 1: The One-Time Customer
- January 2023: Customer purchases product
- January 2023 - January 2025: Implied consent valid (2 years)
- February 2025: Implied consent expired
- March 2025: Marketing email sent → VIOLATION
Scenario 2: The Inquiry That Never Converted
- March 2025: Prospect requests product demo
- March-September 2025: Implied consent valid (6 months)
- October 2025: Implied consent expired
- November 2025: Still receiving weekly emails → VIOLATION
Scenario 3: The Reactivation Campaign
- 2019: Customer made purchase
- 2021: Implied consent expired
- 2025: "Win-back" campaign sent → VIOLATION
Note: Expired consent cannot be "reactivated" by email. Under CASL s. 1(3), an electronic message that requests consent is itself a commercial electronic message, so new express consent must be obtained through other channels (direct mail, phone, in-person).
Unsubscribe Mechanism Requirements
Common Failures
Failure #1: Broken Links
- Link stops working after campaign sent
- 60-day validity requirement violated
Failure #2: Requires Login
- Creates friction, undermines the requirement that unsubscribing be "readily performed"
Failure #3: Multiple Lists Without Master Unsubscribe
- User unsubscribes from one list, still receives others
Failure #4: Slow Processing (>10 Business Days)
- Manual processing, user receives emails after unsubscribing
Best Practice Implementation
- User clicks "Unsubscribe" link in email
- Lands on simple page: "Are you sure?"
- Large button: "Yes, Unsubscribe"
- Click triggers immediate suppression
- Confirmation: "You have been unsubscribed"
- Processed in system immediately
Affiliate Marketing CASL Traps
Section 9 of CASL prohibits aiding, inducing or procuring a contravention of sections 6 to 8, so an advertiser can be held responsible alongside the affiliate that sends non-compliant messages.
Due Diligence Requirements
1. Written Agreements
- Contract with every affiliate
- Explicit CASL compliance requirements
- Right to audit affiliate practices
- Immediate termination for violations
2. Verification Procedures
- Review affiliate's email list sources
- Verify consent exists for recipients
- Approve campaign content before sending
3. Monitoring and Audits
- Regular review of affiliate campaigns
- Monitor spam complaints
- Investigate suspicious activity
Red Flags
⚠️ High spam complaint rates (>0.1%) ⚠️ Very large lists for small affiliate ⚠️ No consent verification provided ⚠️ Resistance to audits ⚠️ Offshore operations with no Canadian presence
AI Tools and New CASL Risks
Risk #1: AI-Generated Contact Lists
The Problem: AI tools scrape web for email addresses, claimed as "publicly available"
CASL Issue: Scraped emails do NOT constitute consent
Risk #2: AI-Written Subject Lines (Misleading)
Problematic Examples:
- ❌ "Your account needs immediate attention" (when nothing wrong)
- ❌ "You've been selected" (no actual selection)
- ❌ "RE: Your order" (when no prior order)
Solution: Human review of all AI-generated subject lines
Risk #3: Shadow AI Usage
The Problem: Employees paste customer emails into ChatGPT
Privacy Issue: Potential disclosure of personal information to a third party without consent (a privacy-law concern rather than a CASL one)
Solution: Approved AI tool policy, train staff on data handling
How to Audit Your CASL Compliance
Self-Audit Checklist
Part 1: Consent Documentation
- ✅ Select 50 random contacts from email list
- ✅ Locate consent record for each
- ✅ Verify: Who, what, when, where, how documented
- ✅ Pass rate: 100% required
Part 2: Email Content Review
- ✅ Review last 10 campaign emails
- ✅ Verify sender identification present
- ✅ Test unsubscribe links work
- ✅ Check subject line accuracy
Part 3: System Configuration
- ✅ Review all email capture forms
- ✅ Verify no pre-checked boxes
- ✅ Check automated campaign suppression
- ✅ Confirm consent expiry automation
Part 4: Third-Party Compliance
- ✅ List all vendors sending emails on your behalf
- ✅ Verify contracts include CASL compliance
- ✅ Review affiliate complaint rates
Compliance Automation Strategies
Essential Automation Tools
1. Consent Management Platform
- Captures consent with full metadata
- Automatically calculates expiry dates
- Sends pre-expiry re-consent campaigns
2. Email Platform with CASL Features
- Double opt-in workflow
- Consent metadata storage
- Automatic suppression lists
- One-click unsubscribe
3. Consent Expiry Automation
- Transaction recorded → expiry date calculated
- Alert triggered 60 days before expiry
- Automated re-consent campaign
- If no response, contact suppressed
Frequently Asked Questions
Q: Does CASL apply to B2B emails? Yes, with limited exemptions. Most B2B marketing still requires consent.
Q: Can I email someone who gave me their business card? Risky. Better to ask for express consent explicitly.
Q: What if I bought an email list? Stop immediately. Purchased lists have no consent. Delete and build your own through proper opt-ins.
Q: Does CASL apply to text messages (SMS)? Yes. CASL's definition of "electronic address" includes a telephone account, so commercial text messages are subject to the same consent, identification and unsubscribe rules as email.
Q: Can I be fined personally as an employee? Yes. Individuals face personal liability up to $1M per violation.
Protect Your Business from CASL Penalties
With penalties of up to $10 million per violation for organizations, CASL compliance isn't optional—it's existential.
Start with Your Free CASL Compliance Assessment
The free compliance check asks eight plain-language questions, takes about two minutes, and needs no account. You get a readiness score and the CASL and PIPEDA gaps your answers point to. Get your free compliance check.
The good news: compliance is achievable and affordable with the right tools.
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Quebec Law 25 Penalties: Maximum Fines and How Penalties Are Set
Law 25 penalties explained: the monetary administrative penalties and penal fines in the Act, who ca...
PIPEDA Compliance Checklist 2026: 10 Requirements Every Canadian SMB Must Meet
PIPEDA compliance checklist for Canadian small businesses: the 10 requirements explained, plus a 30-...