Technology Compliance

Mailchimp CASL Compliance: Setup Guide for Canadian Businesses

Mailchimp's defaults are not built for CASL. How to set up audiences, record consent, segment lists and configure unsubscribes for Canada.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
10 min read
Mailchimp CASL
Mailchimp Canada Compliance
Email Marketing Canada
Mailchimp Privacy
CASL Email Setup

Mailchimp is a popular email marketing platform, and its default configuration can create CASL compliance risks. This guide walks you through every Mailchimp setting a Canadian business needs to configure for CASL compliance.

Last updated: April 2026

The Core CASL Challenge with Mailchimp

Mailchimp was designed for the US market where CAN-SPAM governs commercial emails. CAN-SPAM is an opt-out law — you can email people until they unsubscribe. CASL is an opt-in law — you cannot email people until they consent.

This means:

  • Mailchimp's default "clean" subscriber status doesn't equal CASL consent
  • Importing any CSV of emails into Mailchimp and sending a campaign may violate CASL
  • Mailchimp's built-in double opt-in is optional — and many Canadian businesses have it disabled

Audience Configuration for CASL

Set Your Audience to CASL Mode

Mailchimp doesn't have a "CASL mode" per se, but you can configure your audience to track the information CASL requires:

Step 1: Use tags and merge fields to track consent

Create custom merge fields in your audience:

  • CONSENTTYPE — values: express-form, express-pos, implied-purchase, implied-inquiry
  • CONSENTDATE — date of consent
  • CONSENTEXP — for implied consent: expiry date (24 months from last transaction)
  • CONSENTSRC — where consent was collected (form name, checkout, event)

To add these:

  1. Go to Audience → Audience fields and |MERGE| tags
  2. Create the fields as "Text" type
  3. Mark them as hidden (they don't need to show on signup forms)

Enable Double Opt-In (Recommended)

Mailchimp's double opt-in sends a confirmation email to new subscribers before adding them to your active list. This provides stronger consent documentation for CASL:

  1. Go to Audience → Manage Audience → Settings → Audience name and campaign defaults
  2. Enable "Enable double opt-in"

When enabled:

  • New signups receive a confirmation email
  • Only contacts who click "Confirm subscription" are added to your active list
  • Mailchimp records the confirmation timestamp — this is strong CASL consent evidence

Signup Forms for CASL

Embedded and Popup Forms

For any form that collects email addresses for marketing:

Step 1: Add explicit consent language Above or near the email field, add:

"By subscribing, you agree to receive marketing emails from [Your Business Name]. You can unsubscribe at any time."

Step 2: Do NOT pre-check any marketing consent boxes

Step 3: Include your business name — CASL requires identification of who the individual is consenting to hear from.

Mailchimp Form Builder:

  • Go to Audience → Signup forms → Form builder
  • Add a text block with your consent disclosure
  • Ensure the email field label is clear about the purpose

Landing Page Forms

If using Mailchimp landing pages:

  • Same rules apply — explicit consent language, no pre-checked boxes
  • Link to your privacy policy in the footer of every landing page

Segmenting Your Audience for CASL

Create segments to ensure you only send marketing to properly consented contacts:

Active Consent Segment

Create a saved segment:

  • Filter 1: Status = Subscribed
  • Filter 2: CONSENTTYPE = express-form OR express-pos OR implied-purchase
  • Filter 3 (for implied-purchase): CONSENTEXP is after [today's date]

Use this segment as your default send list for all marketing campaigns.

Implied Consent Management

For customers who gave implied consent (purchased in the last 24 months):

  • Set CONSENTEXP to 24 months from their last purchase date
  • Create an automated journey (Customer Journey Builder) that fires 30 days before expiry:
    • Send a "Stay Connected" email asking for express consent
    • If they click the consent link, update their consent type to express
    • If no action, suppress from marketing after expiry

Transactional Emails in Mailchimp

Messages that solely facilitate, complete or confirm a transaction, or provide factual account information, do not require consent under CASL (s. 6(6)), but they must still meet CASL's sender-identification and unsubscribe requirements (s. 6(2)). If you send transactional emails through Mailchimp:

  • Use Mailchimp Transactional (Mandrill) for transactional emails, not your marketing campaigns
  • Keep transactional and marketing audiences separate
  • Don't add promotional content to transactional emails (which would convert them to CEMs)

Unsubscribe Compliance

CASL requires:

  • A functioning unsubscribe mechanism in every marketing email
  • Processing unsubscribes within 10 business days

Mailchimp handles this automatically:

  • Every Mailchimp campaign includes an unsubscribe link by default
  • Unsubscribes are processed immediately in Mailchimp
  • Mailchimp updates the contact status to "Unsubscribed" and suppresses them from future campaigns

What you need to verify:

  • Your Mailchimp campaigns are using the standard footer (not a custom template that removed the unsubscribe link)
  • Unsubscribed contacts are not being re-imported from your CRM or POS system
  • If you have other contact databases (Shopify, Salesforce), unsubscribes in Mailchimp are synced back

Managing List Imports

When importing contacts from CSV or other systems:

Before importing, document for each contact:

  • How and when consent was obtained
  • The form of consent (express vs. implied)
  • For implied: the date of last transaction

In Mailchimp's import process:

  • Map your consent data to your custom merge fields
  • Tag imported contacts by source (e.g., "2024-Q1-POS-import")
  • Import directly to "Subscribed" only if all contacts have valid CASL consent
  • Import non-consented contacts as "Unsubscribed" (so they're in your system for suppression, not marketing)

Never import a purchased email list. Purchased lists have no CASL consent for your organisation and cannot legally receive your marketing emails.

Mailchimp Data and PIPEDA

Where Mailchimp Stores Your Data

Mailchimp stores customer data in the United States. For PIPEDA compliance:

  • Disclose in your privacy policy that email marketing is managed through Mailchimp and that subscriber data is stored in the US
  • This is particularly important for Quebec businesses subject to Law 25's cross-border transfer requirements

Accessing and Deleting Subscriber Data

For access requests under PIPEDA:

  1. Search your Mailchimp audience for the subscriber's email
  2. View and export their contact data (email, custom fields, activity history)
  3. Provide to the requestor within 30 days

For deletion requests:

  1. Find the contact in Mailchimp
  2. Permanently delete them (archive is not sufficient — the data remains; permanent delete removes it)
  3. Note: Permanently deleted contacts cannot be re-added, which provides useful evidence that you've honoured a deletion request

CASL-Compliant Email Requirements

Every marketing email sent to Canadian subscribers must include:

  • Your business name (the sender name)
  • Your mailing address, plus a telephone number, email address or web address (required by the Electronic Commerce Protection Regulations (CRTC), s. 2 — set out in the message, or on a web page reached by a clear and prominent link only if including it in the message is not practicable)
  • A functioning unsubscribe link

In Mailchimp's Campaign footer / Default footer settings:

  • Add your physical mailing address
  • Ensure your business name appears as the "From" name
  • Verify the unsubscribe link is present in your template

Compliance Checklist for Mailchimp in Canada

  • Enable double opt-in for new subscribers
  • Create custom merge fields for CASL consent tracking
  • Update all signup forms with explicit consent language (no pre-ticked boxes)
  • Create active consent segment for all marketing campaigns
  • Set up implied consent expiry workflow (24-month re-consent campaign)
  • Ensure physical mailing address appears in all campaign footers
  • Verify unsubscribe link is in all email templates
  • Document and suppress all imported contacts who lack CASL consent
  • Disclose Mailchimp US data storage in your privacy policy

Frequently Asked Questions

Q: We have 2,000 subscribers from an old list. How do we know if they're CASL compliant? A: Audit the source of each subscriber. If you can document valid consent (express opt-in or prior purchase within 24 months), they're compliant. If not, they need to be suppressed or given the opportunity to re-consent.

Q: Does Mailchimp's "cleaned" status mean we're CASL compliant? A: "Cleaned" in Mailchimp means the email bounced — it says nothing about consent status. Don't confuse Mailchimp email health metrics with CASL compliance.

Q: Can we send a re-permission campaign to our non-compliant contacts? A: Sending a re-permission email to non-consented contacts carries some CASL risk. One targeted, transparent re-permission email is a common approach. Consult your legal advisor on whether the risk is appropriate given your list size.


Canadian Email Marketing That's Actually Compliant

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — email compliance without the compliance headache.

Related reading: CASL Email Compliance | CASL Email List Audit | HubSpot CASL Compliance

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.