What is CASL? Canada's Anti-Spam Law, Explained
What CASL is and when it applies: which messages count as commercial electronic messages, what consent you need, and what every message must contain.
Canada's Anti-Spam Legislation — universally known as CASL — is one of the strictest anti-spam laws in the world. Since it came into full force in 2014, the Canadian Radio-television and Telecommunications Commission (CRTC) has levied fines totalling tens of millions of dollars against companies large and small. Yet many Canadian businesses still don't fully understand their obligations.
This plain-language guide covers everything a Canadian small business owner needs to know about CASL.
Last updated: April 2026
What is CASL?
CASL (Canada's Anti-Spam Legislation, formally S.C. 2010, c. 23) regulates commercial electronic messages (CEMs) sent to Canadian electronic addresses. It came into force on July 1, 2014, and introduced some of the world's strongest consent requirements for business communications.
CASL is enforced primarily by the CRTC (Canadian Radio-television and Telecommunications Commission), with additional enforcement powers shared with the Competition Bureau and the Office of the Privacy Commissioner.
What Does CASL Cover?
CASL applies to commercial electronic messages (CEMs) — any electronic message sent to an electronic address (email, text/SMS, social media direct messages, some app notifications) that has as one of its purposes to encourage participation in a commercial activity.
This includes:
- Promotional emails about products or services
- Newsletters containing commercial content
- Transactional emails that include upsell or promotional content
- SMS campaigns
- Direct messages on social media platforms
- Push notifications with commercial content
What is NOT a CEM under CASL:
- Pure transactional messages (order confirmations, receipts, password resets) with no promotional content
- Messages between individuals with a personal relationship
- Messages to people who have given their business contact information and the message relates to their role
- Messages to government organisations
- B2B messages meeting specific criteria (see CASL Exemptions)
The Three Core CASL Requirements
Every CEM you send to a Canadian must meet three requirements:
1. Consent
You must have express or implied consent from the recipient before sending a CEM.
Express consent: The recipient has explicitly opted in — by ticking a checkbox, filling out a form, or signing up specifically for your messages. Express consent never expires unless withdrawn, but best practice is to refresh it periodically.
Implied consent exists in limited circumstances:
- Existing business relationship (EBR): If someone purchased from you, enquired about your products, or entered into a contract within the past 2 years, you may have implied consent
- Conspicuously published electronic address: If a business publishes an email address on a website without a statement that they don't wish to receive CEMs, you may send messages relevant to their role or function
- Referrals: If an existing customer refers someone to you (and includes their own information in the referral), you may contact the referred person once — disclosing who gave the referral
Implied consent is temporary. EBR-based implied consent lasts 2 years from the last transaction. After that, you need express consent or must stop sending.
2. Identification
Every CEM must clearly identify who sent the message. This means:
- Your legal business name (or the brand name if clearly associated with a legal entity)
- Your full mailing address
- Either a phone number, email address, or web address where you can be reached
This information must be accurate and the contact must remain reachable for 60 days after the message is sent.
3. Unsubscribe Mechanism
Every CEM must include a working unsubscribe mechanism that is:
- Clearly and prominently displayed
- Easy to use (one click is the standard)
- Effective within 10 business days of receiving the unsubscribe request
- Free of charge to use
You cannot charge for unsubscribing, require the recipient to log in to unsubscribe, or make the process difficult.
CASL Penalties: The Real Risk
CASL has serious teeth:
| Violator | Maximum Penalty Per Violation |
|---|---|
| Individuals | $1,000,000 |
| Organisations | $10,000,000 |
Enforcement in practice: the CRTC publishes its CASL enforcement actions — notices of violation, undertakings and decisions — on its anti-spam enforcement page. Check the published record for the organization, the amount and the outcome before relying on any case you see quoted elsewhere; several early penalties were reduced on review.
CASL also contains a private right of action (sections 47–51) that would allow individuals and organisations to sue for statutory damages. It has never come into force: the federal government suspended it by Order in Council in June 2017, weeks before its scheduled start date, and it remains suspended indefinitely. No one can bring a CASL private action today — enforcement is the CRTC's, through the administrative penalties above.
Common CASL Mistakes Canadian Businesses Make
1. Assuming a pre-CASL list is compliant If you have email addresses collected before July 2014 without explicit consent records, you need fresh consent.
2. Treating newsletter signups as consent for everything Someone subscribing to your newsletter consented to your newsletter. They didn't consent to be added to a separate promotional list or to receive third-party partner offers.
3. Not processing unsubscribes fast enough The 10-business-day window is strict. Many businesses process unsubscribes weekly — acceptable as long as no more than 10 business days pass.
4. Using consent obtained by others If you buy, rent, or inherit an email list, you inherit the consent records (or lack thereof). "We bought this list from a reputable vendor" is not a CASL defence.
5. CEMs from US-based platforms CASL applies based on the recipient's location, not the sender's. If you're a Canadian company sending from a US ESP to Canadian addresses, CASL applies.
How CASL Interacts with PIPEDA
CASL and PIPEDA overlap but serve different functions:
- PIPEDA governs the collection, use, and protection of personal information broadly
- CASL specifically regulates commercial electronic messages
Obtaining an email address (PIPEDA) and obtaining consent to send marketing emails (CASL) are separate actions requiring separate consent. Your sign-up form must address both.
See our full guide to PIPEDA compliance for the broader framework.
Building a CASL-Compliant Email Programme
Consent audit:
- Review your current subscriber lists — do you have documented consent records?
- Identify any lists where consent documentation is missing or expired
- Launch a re-permission campaign for uncertain contacts before the implied consent period ends
Consent capture:
- All new sign-ups get an explicit opt-in checkbox (not pre-ticked)
- Consent record includes: date, IP address, method of consent, version of consent language shown
- Double opt-in adds a layer of verification (though not required by CASL)
Ongoing compliance:
- Process unsubscribes within 10 business days — set up automatic processing
- Include sender identification in every message
- Review mailing lists quarterly to remove expired implied consent contacts
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Frequently Asked Questions
Q: Does CASL apply to B2B emails? A: Yes, but with important exceptions for messages sent to a business email address related to the recipient's role or function in a business context. See our dedicated CASL B2B guide for details.
Q: Do transactional emails (receipts, shipping notifications) need CASL consent? A: Pure transactional messages without any promotional content are not CEMs and don't require CASL consent. However, the moment you add promotional content — a "you might also like" section, a discount code — the entire message becomes a CEM and requires consent.
Q: Can I ask for consent in the same email where I'm sending a promotional offer? A: No. You need consent before sending the CEM. You can send a standalone consent request (which is not itself a CEM if it contains no commercial content).
Q: Does CASL apply to social media marketing? A: CASL applies to direct messages (DMs) on social platforms if they are CEMs. It does not apply to public posts, paid ads, or algorithmic content delivery.
Q: Is a footer unsubscribe link sufficient? A: Yes, as long as it is functional, clearly visible, works with a single click, and is honoured within 10 business days.
Take the Complexity Out of CASL Compliance
Managing CASL compliance across your CRM, email platform, and website can be complex — especially as your contact list grows and implied consent windows start expiring.
Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.
Related reading: CASL Compliance Guide | CRTC CASL Information
Found this article helpful?
Share it with your team or save it for later reference.
Related compliance guides
Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.
Continue Reading
Double Opt-In and CASL: Is It Required for Canadian Email Marketing?
Is double opt-in required under CASL? Not legally — but it provides the strongest CASL consent evide...
How to Audit Your Email List for CASL Compliance in 2026
Audit your email list against CASL step by step: find contacts without valid consent, document what ...