Canadian Privacy
Featured
Part of the CASL guide

CASL Compliance for Email Marketing: Consent, Unsubscribe and Penalty Rules for Canadian Businesses

How CASL is enforced and what it can cost: the consent, identification and unsubscribe rules, the common failures, and how to audit your email.

Canada Compliance AI• Compliance Team
January 6, 2026
Updated September 12, 2026
14 min read
CASL
Email Marketing
CRTC
Anti-Spam
Marketing Compliance

Canada's Anti-Spam Legislation (CASL) is enforced by the Canadian Radio-television and Telecommunications Commission (CRTC), and administrative monetary penalties can reach $10 million per violation for organizations.

If you're using email marketing, SMS campaigns, or any commercial electronic messaging in Canada, you need to understand what the law requires and where businesses most often fall short.


Common CASL Compliance Failures

Inability to Prove Consent

The Problem:

  • Business sends emails
  • Recipient complains or CRTC audits
  • Business cannot produce consent record
  • CASL places the onus of proving consent on the person alleging it (s. 13)

How to Avoid:

  • ✅ Implement consent management system
  • ✅ Capture: who, what, when, where, how for every consent
  • ✅ Store consent with timestamp and IP address
  • ✅ Never rely on verbal consent without documentation

Expired Implied Consent

The Problem:

  • Business relationship ends
  • Implied consent expires (2 years from purchase, 6 months from inquiry)
  • Business continues sending marketing emails

How to Avoid:

  • ✅ Track consent expiry dates in CRM
  • ✅ Automated alerts 30 days before expiry
  • ✅ Re-consent campaigns before expiry
  • ✅ Convert implied to express consent proactively

Unsubscribe Mechanism Failures

CASL Requirements:

  • Must include unsubscribe mechanism in every CEM
  • Must be able to be readily performed
  • Must process within 10 business days
  • Must let the recipient unsubscribe at no cost to them
  • Must work for minimum 60 days after sending

How to Avoid:

  • ✅ One-click unsubscribe (no login required)
  • ✅ Automated processing (instant when possible)
  • ✅ Test unsubscribe links monthly
  • ✅ Unsubscribe from ALL lists (not just specific campaign)

Affiliate Marketing Violations

The Problem:

  • Company hires affiliates to promote products
  • Affiliates send spam on company's behalf
  • Section 9 of CASL prohibits aiding, inducing or procuring a contravention of sections 6 to 8

How to Avoid:

  • ✅ Written agreements with all affiliates
  • ✅ Require affiliates to warrant CASL compliance
  • ✅ Periodic audits of affiliate practices
  • ✅ Immediate termination for violations

Insufficient Identification Information

CASL Requirements:

  • Must identify sender clearly
  • Must provide valid mailing address
  • Must include a telephone number, email address or web address
  • Must remain valid for 60 days after sending

How to Avoid:

  • ✅ Include full identification in every email
  • ✅ Company name, physical address, contact info in footer
  • ✅ Use real "from" names, not generic
  • ✅ Keep contact information current

Understanding the $10M Maximum Penalty

CASL's maximum penalties are severe:

  • Individuals: $1,000,000 per violation
  • Businesses: $10,000,000 per violation

How Penalty Amounts Are Determined

Under section 20(3) of CASL, the purpose of a penalty is to promote compliance, not to punish, and the factors that must be taken into account include:

  • The nature and scope of the violation
  • The person's history of previous violations and undertakings
  • Any financial benefit obtained from the violation
  • The person's ability to pay
  • Whether the person has voluntarily paid compensation to anyone affected
  • Any other relevant factor

Express vs. Implied Consent

Express Consent (Best Protection)

Valid Express Consent Mechanisms:

✅ Unchecked checkbox that person checks:

☐ Yes, I want to receive marketing emails from [Company]

✅ Typed confirmation

✅ Verbal consent (documented with date, time, witness)

✅ Written signature

Invalid Express Consent:

❌ Pre-checked box ❌ Negative option ("Check here if you DON'T want emails") ❌ Bundled consent hidden in terms ❌ Opt-out instead of opt-in

Advantage: Never expires (until withdrawn)


Implied Consent (Time-Limited)

Existing Business Relationship (2 years from):

  • Purchase or lease of product/service
  • Written contract (during contract + 2 years after end)

Recent Inquiry (6 months from):

  • Application or inquiry about product/service

Common Traps:

❌ Attended free webinar (not a business relationship) ❌ Downloaded free whitepaper (inquiry = 6 months only) ❌ Entered contest (not a business relationship) ❌ Met at networking event (no relationship)


Consent Expiry Scenarios

Scenario 1: The One-Time Customer

  • January 2023: Customer purchases product
  • January 2023 - January 2025: Implied consent valid (2 years)
  • February 2025: Implied consent expired
  • March 2025: Marketing email sent → VIOLATION

Scenario 2: The Inquiry That Never Converted

  • March 2025: Prospect requests product demo
  • March-September 2025: Implied consent valid (6 months)
  • October 2025: Implied consent expired
  • November 2025: Still receiving weekly emails → VIOLATION

Scenario 3: The Reactivation Campaign

  • 2019: Customer made purchase
  • 2021: Implied consent expired
  • 2025: "Win-back" campaign sent → VIOLATION

Note: Expired consent cannot be "reactivated" by email. Under CASL s. 1(3), an electronic message that requests consent is itself a commercial electronic message, so new express consent must be obtained through other channels (direct mail, phone, in-person).


Unsubscribe Mechanism Requirements

Common Failures

Failure #1: Broken Links

  • Link stops working after campaign sent
  • 60-day validity requirement violated

Failure #2: Requires Login

  • Creates friction, undermines the requirement that unsubscribing be "readily performed"

Failure #3: Multiple Lists Without Master Unsubscribe

  • User unsubscribes from one list, still receives others

Failure #4: Slow Processing (>10 Business Days)

  • Manual processing, user receives emails after unsubscribing

Best Practice Implementation

  1. User clicks "Unsubscribe" link in email
  2. Lands on simple page: "Are you sure?"
  3. Large button: "Yes, Unsubscribe"
  4. Click triggers immediate suppression
  5. Confirmation: "You have been unsubscribed"
  6. Processed in system immediately

Affiliate Marketing CASL Traps

Section 9 of CASL prohibits aiding, inducing or procuring a contravention of sections 6 to 8, so an advertiser can be held responsible alongside the affiliate that sends non-compliant messages.

Due Diligence Requirements

1. Written Agreements

  • Contract with every affiliate
  • Explicit CASL compliance requirements
  • Right to audit affiliate practices
  • Immediate termination for violations

2. Verification Procedures

  • Review affiliate's email list sources
  • Verify consent exists for recipients
  • Approve campaign content before sending

3. Monitoring and Audits

  • Regular review of affiliate campaigns
  • Monitor spam complaints
  • Investigate suspicious activity

Red Flags

⚠️ High spam complaint rates (>0.1%) ⚠️ Very large lists for small affiliate ⚠️ No consent verification provided ⚠️ Resistance to audits ⚠️ Offshore operations with no Canadian presence


AI Tools and New CASL Risks

Risk #1: AI-Generated Contact Lists

The Problem: AI tools scrape web for email addresses, claimed as "publicly available"

CASL Issue: Scraped emails do NOT constitute consent

Risk #2: AI-Written Subject Lines (Misleading)

Problematic Examples:

  • ❌ "Your account needs immediate attention" (when nothing wrong)
  • ❌ "You've been selected" (no actual selection)
  • ❌ "RE: Your order" (when no prior order)

Solution: Human review of all AI-generated subject lines

Risk #3: Shadow AI Usage

The Problem: Employees paste customer emails into ChatGPT

Privacy Issue: Potential disclosure of personal information to a third party without consent (a privacy-law concern rather than a CASL one)

Solution: Approved AI tool policy, train staff on data handling


How to Audit Your CASL Compliance

Self-Audit Checklist

Part 1: Consent Documentation

  • ✅ Select 50 random contacts from email list
  • ✅ Locate consent record for each
  • ✅ Verify: Who, what, when, where, how documented
  • ✅ Pass rate: 100% required

Part 2: Email Content Review

  • ✅ Review last 10 campaign emails
  • ✅ Verify sender identification present
  • ✅ Test unsubscribe links work
  • ✅ Check subject line accuracy

Part 3: System Configuration

  • ✅ Review all email capture forms
  • ✅ Verify no pre-checked boxes
  • ✅ Check automated campaign suppression
  • ✅ Confirm consent expiry automation

Part 4: Third-Party Compliance

  • ✅ List all vendors sending emails on your behalf
  • ✅ Verify contracts include CASL compliance
  • ✅ Review affiliate complaint rates

Compliance Automation Strategies

Essential Automation Tools

1. Consent Management Platform

  • Captures consent with full metadata
  • Automatically calculates expiry dates
  • Sends pre-expiry re-consent campaigns

2. Email Platform with CASL Features

  • Double opt-in workflow
  • Consent metadata storage
  • Automatic suppression lists
  • One-click unsubscribe

3. Consent Expiry Automation

  • Transaction recorded → expiry date calculated
  • Alert triggered 60 days before expiry
  • Automated re-consent campaign
  • If no response, contact suppressed

Frequently Asked Questions

Q: Does CASL apply to B2B emails? Yes, with limited exemptions. Most B2B marketing still requires consent.

Q: Can I email someone who gave me their business card? Risky. Better to ask for express consent explicitly.

Q: What if I bought an email list? Stop immediately. Purchased lists have no consent. Delete and build your own through proper opt-ins.

Q: Does CASL apply to text messages (SMS)? Yes. CASL's definition of "electronic address" includes a telephone account, so commercial text messages are subject to the same consent, identification and unsubscribe rules as email.

Q: Can I be fined personally as an employee? Yes. Individuals face personal liability up to $1M per violation.


Protect Your Business from CASL Penalties

With penalties of up to $10 million per violation for organizations, CASL compliance isn't optional—it's existential.

Start with Your Free CASL Compliance Assessment

The free compliance check asks eight plain-language questions, takes about two minutes, and needs no account. You get a readiness score and the CASL and PIPEDA gaps your answers point to. Get your free compliance check.

The good news: compliance is achievable and affordable with the right tools.

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.