Mailchimp CASL Compliance: Setup Guide for Canadian Businesses
Mailchimp's defaults are not built for CASL. How to set up audiences, record consent, segment lists and configure unsubscribes for Canada.
Mailchimp is a popular email marketing platform, and its default configuration can create CASL compliance risks. This guide walks you through every Mailchimp setting a Canadian business needs to configure for CASL compliance.
Last updated: April 2026
The Core CASL Challenge with Mailchimp
Mailchimp was designed for the US market where CAN-SPAM governs commercial emails. CAN-SPAM is an opt-out law — you can email people until they unsubscribe. CASL is an opt-in law — you cannot email people until they consent.
This means:
- Mailchimp's default "clean" subscriber status doesn't equal CASL consent
- Importing any CSV of emails into Mailchimp and sending a campaign may violate CASL
- Mailchimp's built-in double opt-in is optional — and many Canadian businesses have it disabled
Audience Configuration for CASL
Set Your Audience to CASL Mode
Mailchimp doesn't have a "CASL mode" per se, but you can configure your audience to track the information CASL requires:
Step 1: Use tags and merge fields to track consent
Create custom merge fields in your audience:
- CONSENTTYPE — values: express-form, express-pos, implied-purchase, implied-inquiry
- CONSENTDATE — date of consent
- CONSENTEXP — for implied consent: expiry date (24 months from last transaction)
- CONSENTSRC — where consent was collected (form name, checkout, event)
To add these:
- Go to Audience → Audience fields and |MERGE| tags
- Create the fields as "Text" type
- Mark them as hidden (they don't need to show on signup forms)
Enable Double Opt-In (Recommended)
Mailchimp's double opt-in sends a confirmation email to new subscribers before adding them to your active list. This provides stronger consent documentation for CASL:
- Go to Audience → Manage Audience → Settings → Audience name and campaign defaults
- Enable "Enable double opt-in"
When enabled:
- New signups receive a confirmation email
- Only contacts who click "Confirm subscription" are added to your active list
- Mailchimp records the confirmation timestamp — this is strong CASL consent evidence
Signup Forms for CASL
Embedded and Popup Forms
For any form that collects email addresses for marketing:
Step 1: Add explicit consent language Above or near the email field, add:
"By subscribing, you agree to receive marketing emails from [Your Business Name]. You can unsubscribe at any time."
Step 2: Do NOT pre-check any marketing consent boxes
Step 3: Include your business name — CASL requires identification of who the individual is consenting to hear from.
Mailchimp Form Builder:
- Go to Audience → Signup forms → Form builder
- Add a text block with your consent disclosure
- Ensure the email field label is clear about the purpose
Landing Page Forms
If using Mailchimp landing pages:
- Same rules apply — explicit consent language, no pre-checked boxes
- Link to your privacy policy in the footer of every landing page
Segmenting Your Audience for CASL
Create segments to ensure you only send marketing to properly consented contacts:
Active Consent Segment
Create a saved segment:
- Filter 1: Status = Subscribed
- Filter 2: CONSENTTYPE = express-form OR express-pos OR implied-purchase
- Filter 3 (for implied-purchase): CONSENTEXP is after [today's date]
Use this segment as your default send list for all marketing campaigns.
Implied Consent Management
For customers who gave implied consent (purchased in the last 24 months):
- Set CONSENTEXP to 24 months from their last purchase date
- Create an automated journey (Customer Journey Builder) that fires 30 days before expiry:
- Send a "Stay Connected" email asking for express consent
- If they click the consent link, update their consent type to express
- If no action, suppress from marketing after expiry
Transactional Emails in Mailchimp
Messages that solely facilitate, complete or confirm a transaction, or provide factual account information, do not require consent under CASL (s. 6(6)), but they must still meet CASL's sender-identification and unsubscribe requirements (s. 6(2)). If you send transactional emails through Mailchimp:
- Use Mailchimp Transactional (Mandrill) for transactional emails, not your marketing campaigns
- Keep transactional and marketing audiences separate
- Don't add promotional content to transactional emails (which would convert them to CEMs)
Unsubscribe Compliance
CASL requires:
- A functioning unsubscribe mechanism in every marketing email
- Processing unsubscribes within 10 business days
Mailchimp handles this automatically:
- Every Mailchimp campaign includes an unsubscribe link by default
- Unsubscribes are processed immediately in Mailchimp
- Mailchimp updates the contact status to "Unsubscribed" and suppresses them from future campaigns
What you need to verify:
- Your Mailchimp campaigns are using the standard footer (not a custom template that removed the unsubscribe link)
- Unsubscribed contacts are not being re-imported from your CRM or POS system
- If you have other contact databases (Shopify, Salesforce), unsubscribes in Mailchimp are synced back
Managing List Imports
When importing contacts from CSV or other systems:
Before importing, document for each contact:
- How and when consent was obtained
- The form of consent (express vs. implied)
- For implied: the date of last transaction
In Mailchimp's import process:
- Map your consent data to your custom merge fields
- Tag imported contacts by source (e.g., "2024-Q1-POS-import")
- Import directly to "Subscribed" only if all contacts have valid CASL consent
- Import non-consented contacts as "Unsubscribed" (so they're in your system for suppression, not marketing)
Never import a purchased email list. Purchased lists have no CASL consent for your organisation and cannot legally receive your marketing emails.
Mailchimp Data and PIPEDA
Where Mailchimp Stores Your Data
Mailchimp stores customer data in the United States. For PIPEDA compliance:
- Disclose in your privacy policy that email marketing is managed through Mailchimp and that subscriber data is stored in the US
- This is particularly important for Quebec businesses subject to Law 25's cross-border transfer requirements
Accessing and Deleting Subscriber Data
For access requests under PIPEDA:
- Search your Mailchimp audience for the subscriber's email
- View and export their contact data (email, custom fields, activity history)
- Provide to the requestor within 30 days
For deletion requests:
- Find the contact in Mailchimp
- Permanently delete them (archive is not sufficient — the data remains; permanent delete removes it)
- Note: Permanently deleted contacts cannot be re-added, which provides useful evidence that you've honoured a deletion request
CASL-Compliant Email Requirements
Every marketing email sent to Canadian subscribers must include:
- Your business name (the sender name)
- Your mailing address, plus a telephone number, email address or web address (required by the Electronic Commerce Protection Regulations (CRTC), s. 2 — set out in the message, or on a web page reached by a clear and prominent link only if including it in the message is not practicable)
- A functioning unsubscribe link
In Mailchimp's Campaign footer / Default footer settings:
- Add your physical mailing address
- Ensure your business name appears as the "From" name
- Verify the unsubscribe link is present in your template
Compliance Checklist for Mailchimp in Canada
- Enable double opt-in for new subscribers
- Create custom merge fields for CASL consent tracking
- Update all signup forms with explicit consent language (no pre-ticked boxes)
- Create active consent segment for all marketing campaigns
- Set up implied consent expiry workflow (24-month re-consent campaign)
- Ensure physical mailing address appears in all campaign footers
- Verify unsubscribe link is in all email templates
- Document and suppress all imported contacts who lack CASL consent
- Disclose Mailchimp US data storage in your privacy policy
Frequently Asked Questions
Q: We have 2,000 subscribers from an old list. How do we know if they're CASL compliant? A: Audit the source of each subscriber. If you can document valid consent (express opt-in or prior purchase within 24 months), they're compliant. If not, they need to be suppressed or given the opportunity to re-consent.
Q: Does Mailchimp's "cleaned" status mean we're CASL compliant? A: "Cleaned" in Mailchimp means the email bounced — it says nothing about consent status. Don't confuse Mailchimp email health metrics with CASL compliance.
Q: Can we send a re-permission campaign to our non-compliant contacts? A: Sending a re-permission email to non-consented contacts carries some CASL risk. One targeted, transparent re-permission email is a common approach. Consult your legal advisor on whether the risk is appropriate given your list size.
Canadian Email Marketing That's Actually Compliant
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Start your free trial today — email compliance without the compliance headache.
Related reading: CASL Email Compliance | CASL Email List Audit | HubSpot CASL Compliance
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
HubSpot CASL & PIPEDA Compliance for Canadian Businesses
Using HubSpot in Canada? You need CASL-compliant email consent, PIPEDA-compliant data handling, and ...
WordPress PIPEDA Compliance: Privacy Settings for Canadian Websites
Running a WordPress site in Canada? PIPEDA requires proper cookie consent, privacy policies, contact...