Technology Compliance

HubSpot CASL & PIPEDA Compliance for Canadian Businesses

Using HubSpot in Canada? You need CASL-compliant email consent, PIPEDA-compliant data handling, and proper HubSpot configuration.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
12 min read
HubSpot CASL
HubSpot Canada Compliance
HubSpot PIPEDA
CRM Privacy Canada
HubSpot Email Marketing Canada

HubSpot is one of the most widely used CRM and marketing automation platforms for Canadian SMBs and mid-market businesses. But its default settings are not optimised for CASL compliance — and its data handling raises PIPEDA considerations that many Canadian users overlook. Here's how to configure HubSpot for Canadian privacy compliance.

Last updated: April 2026

Why HubSpot + Canada Requires Special Attention

HubSpot was built primarily for the US market. Its default email consent architecture assumes CAN-SPAM (US law), not CASL (Canada). The differences are significant:

FeatureCAN-SPAM (US)CASL (Canada)
Default for email marketingOpt-outOpt-in required
Consent record requiredNoYes — must document consent basis
Unsubscribe windowVaries10 business days
Implied consent windowN/A as concept24 months from last transaction

If you use HubSpot's default marketing email settings with a Canadian contact list, you're likely sending emails to contacts without valid CASL consent.

HubSpot's GDPR/Privacy Features for Canadian Use

HubSpot offers "GDPR features" in Settings → Privacy & Consent that — while built for GDPR — can be configured for CASL compliance:

Enable Consent Tracking

  1. Go to HubSpot Settings → Privacy & Consent
  2. Enable "GDPR-compliant consent" features
  3. This activates consent tracking on forms, chat, meetings, and emails

When enabled, HubSpot adds consent checkboxes to your forms and records consent in the contact's timeline.

Configure Lawful Basis Options

In HubSpot's privacy settings, you can configure "lawful basis" labels. For Canadian use, adapt these:

  • Express consent → For contacts who explicitly opt in to marketing
  • Existing business relationship → For contacts with implied consent (existing customers)
  • Legitimate interest → Use cautiously (this is a GDPR concept not directly applicable under CASL — but may cover transactional communications)

Contact Property: "Marketing Email Opt-In" vs Consent Record

HubSpot has a "Marketing email opt-in/out" field that controls whether a contact receives marketing emails. Under CASL, this field alone isn't sufficient — you need to document the basis for consent (when, how, what they agreed to).

Set up a custom property for each contact:

  • casl_consent_type — express, implied-transaction, implied-published
  • casl_consent_date — the date consent was established
  • casl_consent_source — form name, event, or business transaction reference
  • casl_implied_expires — for implied consent: date 24 months from last transaction

Form Configuration for CASL

Adding CASL Consent Checkboxes

For any HubSpot form used to collect marketing consent:

  1. Go to Marketing → Forms → Create/Edit Form

  2. Under Privacy & Consent, add a checkbox for "Marketing communications consent"

  3. Configure the checkbox:

    • Required: No (should be optional — pre-ticking for CASL consent is not valid)
    • Label: "I agree to receive marketing emails from [Your Company Name]" or "Subscribe to our newsletter"
    • Unchecked by default
  4. Enable the consent data tracking to record when and which form was submitted

Forms That Are Not Marketing Consent

For non-marketing forms (contact requests, demo requests, quote requests):

  • These are covered by CASL's "response to inquiry" exemption — no marketing consent needed to respond
  • But if you want to add these people to a marketing list, you need a separate consent checkbox

Email Subscription Settings

Creating Subscription Types

Set up distinct HubSpot subscription types corresponding to your email programmes:

  1. Marketing emails — require CASL opt-in
  2. Product updates — may be transactional (check your product type)
  3. Transactional emails — order confirmations, receipts (CASL exempt if purely transactional)

Go to Settings → Marketing → Email → Subscription Types and configure each type.

Applying Subscription Types

Assign each marketing email to the appropriate subscription type. Contacts who aren't subscribed to that type won't receive the email — providing an automatic CASL safeguard.

Suppressing Non-Consented Contacts

Create an active list in HubSpot:

  • Filter: Marketing email opt-in = true AND casl_consent_type = [is known]
  • Use this list as the default send list for all marketing campaigns
  • This ensures only consented contacts receive marketing emails

HubSpot Workflows for CASL Implied Consent

24-Month Implied Consent Tracking

Set up a HubSpot workflow to manage the implied consent window:

  1. Trigger: Contact makes a purchase or becomes a customer
  2. Set property: casl_implied_expires = [24 months from today]
  3. Create a workflow that fires 30 days before expiry: enroll in a "re-consent" campaign
  4. Post-expiry: If no express consent established, set marketing email opt-in = false

This automated process ensures implied consent is tracked without manual effort.

PIPEDA Compliance in HubSpot

Data Residency

HubSpot stores customer data on AWS infrastructure, primarily in the United States. For PIPEDA compliance:

  • Disclose in your privacy policy that contact data is processed and stored in the United States
  • HubSpot Enterprise offers data residency options (EU, US) — Canadian data residency is not currently available as of 2026
  • This is particularly relevant for Quebec businesses subject to Law 25, who must conduct a PIA before transferring data outside Quebec

Data Retention in HubSpot

HubSpot retains contact data indefinitely by default. For PIPEDA limiting retention principle:

  • Set up a periodic review to identify and delete contacts who have:
    • Unsubscribed and have no other business relationship
    • Not engaged in any transaction in over 3-5 years
    • Requested deletion

Use HubSpot's GDPR Delete feature (available in Privacy & Consent settings) to delete individual contact records on request.

Access Requests

When a contact makes an access request:

  1. Search HubSpot for the contact record
  2. Export all properties and activity history for that contact
  3. Review and provide to the requester within 30 days

HubSpot's contact export feature provides a CSV of contact properties. Activity history may need to be documented separately.

CRM Data Management

Data Minimisation

Review your HubSpot contact properties and remove fields you don't actually use. Collecting data in HubSpot that serves no operational purpose violates PIPEDA's limiting collection principle.

Third-Party App Integrations

HubSpot integrates with hundreds of apps. Each integration that shares contact data with a third party is a PIPEDA disclosure. Review your connected apps:

  • Settings → Integrations → Connected Apps
  • Identify all apps that receive contact data
  • Ensure each is covered in your privacy policy
  • Review their data handling practices

Compliance Checklist for HubSpot Users in Canada

  • Enable GDPR/Privacy features in HubSpot settings
  • Add CASL consent checkboxes (unchecked) to all marketing forms
  • Create custom contact properties for CASL consent tracking
  • Set up subscription types for each email programme category
  • Configure active list of consented contacts for campaign sends
  • Set up workflow for 24-month implied consent monitoring
  • Disclose HubSpot data residency (US) in your privacy policy
  • Configure a periodic contact data review/deletion process
  • Review all connected apps for data sharing
  • Set up GDPR-compliant deletion process for access/deletion requests

Frequently Asked Questions

Q: We imported 5,000 contacts from our old CRM. Are they CASL compliant in HubSpot? A: It depends on how they were originally collected. Trace each segment back to its collection source. Map CASL consent status in your import and suppress non-consented contacts from marketing.

Q: HubSpot shows a "subscribed" status for contacts. Is that CASL consent? A: "Subscribed" in HubSpot typically means the contact has not opted out — it does NOT confirm CASL consent was given. You need to track actual consent records separately.

Q: Can we use HubSpot's Sequences feature for B2B outreach to Canadian companies? A: B2B outreach to published business email addresses may qualify for CASL's implied consent provision (conspicuously published addresses). Still include your identification and an unsubscribe option in each sequence email.


CASL Compliance Beyond HubSpot

Canada Compliance AI helps Canadian businesses build their complete CASL and PIPEDA compliance programme — working alongside your HubSpot setup.

Get your free compliance check — about two minutes, no account needed.

Related reading: CASL Email Compliance | CASL Express vs Implied Consent | CASL Email List Audit

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.