CASL is Canada's Anti-Spam Legislation, in force since July 2014. It requires that you have consent before sending a commercial electronic message to a Canadian recipient, clearly identify yourself, and provide a working unsubscribe mechanism. It applies based on where the message is received, not where you are.
This article is general information, not legal advice. CASL has real nuance and meaningful penalties. Have counsel review your specific program before you rely on any interpretation here.
Who CASL applies to
The trigger is geography of receipt. If a commercial electronic message is sent to or accessed on a computer system located in Canada, CASL is in play — regardless of whether your business has any Canadian presence. A US company emailing a subscriber who happens to open in Toronto is within scope.
A "commercial electronic message" (CEM) is broadly defined: any message that, in part, encourages participation in commercial activity. Newsletters with product links, promotional campaigns, event invitations, and most sales outreach all qualify. Purely transactional messages — order confirmations, receipts, warranty information, delivery updates — are largely excluded from the consent requirement, though they still must not be misleading.
CASL is enforced primarily by the CRTC, with roles for the Competition Bureau and the Office of the Privacy Commissioner. Administrative monetary penalties run up to CAD $1 million for individuals and CAD $10 million for organizations per violation, and officers and directors can face personal liability. The private right of action written into the statute was suspended before it took effect and remains suspended, but that suspension is a policy decision, not a repeal.
Express versus implied consent
This distinction is the core of CASL, and it is stricter than CAN-SPAM in the United States, which permits sending until someone opts out.
| Consent type | How you get it | How long it lasts |
|---|---|---|
| Express | Recipient actively opts in — checks an unchecked box, submits a signup form, confirms a double opt-in | No expiry until withdrawn |
| Implied — existing business relationship | Purchase, contract, or lease within the prior period | 2 years from the transaction date |
| Implied — inquiry | Recipient made an inquiry or application about your business | 6 months from the inquiry |
| Implied — conspicuous publication | Business address published publicly without a statement refusing CEMs | While published; message must be relevant to their role |
| Implied — disclosed address | Recipient gave you the address directly without refusing CEMs | Message must be relevant to their role or function |
| Non-consent | Purchased lists, scraped addresses, appended data | Never valid under CASL |
Two consequences follow. Implied consent is a clock, not a status — a customer who bought 25 months ago is no longer reachable on that basis, so you need automation that ages contacts out or converts them to express consent before the deadline. And pre-checked boxes do not create express consent; the recipient must take a positive action.
What every message must contain
Consent is only half the obligation. Each CEM must also include:
- Identification. The name of the sender, and if you're sending on behalf of another party, both names and the relationship between them.
- Contact information. A mailing address plus either a phone number, email address, or web address — and that contact information must stay valid for at least 60 days after the message is sent.
- An unsubscribe mechanism. Clearly and prominently set out, and able to be readily performed at no cost.
- Honest content. Subject lines, sender names, and links must not be false or misleading — this applies to transactional messages too.
The unsubscribe must be honored within 10 business days, with no additional steps required of the recipient. That means no login wall, no "tell us why" gate, and no confirmation email that must be clicked before the removal takes effect. Most reputable platforms process this instantly, which is the safer default.
Proving consent is your job
Under CASL, the burden of proof sits with the sender. If a complaint is investigated, you must be able to show that consent existed and how it was obtained. That makes record-keeping a compliance control, not an admin task.
For every contact, store and retain:
- Date and time of consent, with time zone.
- Source — the exact form, page URL, or offline event.
- The precise wording shown at the point of consent, versioned so you can reproduce what they actually agreed to.
- Consent type — express or implied, and if implied, the qualifying event and its date.
- IP address for online signups, or a signed record for offline capture.
- Full unsubscribe history with timestamps.
Retain these for a meaningful period after the relationship ends; three years is a common conservative practice. If you also mail EU recipients, the documentation overlaps heavily with GDPR requirements — our guide to GDPR-compliant email marketing in the EU covers that side, and building one consent-record schema that satisfies both is far easier than maintaining two.
Consent request wording that holds up
When you ask for express consent, CASL expects the request itself to be clear about what's being agreed to. A defensible request states:
- The purposes for which consent is sought, in plain language.
- Who is seeking consent, by name.
- If consent is sought on behalf of someone else, that party's identity too.
- Your mailing address and one other contact method.
- A statement that consent can be withdrawn at any time.
A workable example: "Yes, send me monthly product updates and offers from Northwind Supply Co., 220 Bay Street, Toronto ON M5J 2W4, support@example.com. You can unsubscribe at any time." Keep that checkbox unchecked, keep it separate from your terms-of-service agreement, and store the wording with the record.
A practical compliance checklist
| Area | Action | Frequency |
|---|---|---|
| Signup forms | Unchecked consent box, full identification, plain-language purpose | Audit quarterly |
| Consent records | Timestamp, source, wording version, IP stored per contact | Continuous |
| Implied consent aging | Automation flags contacts at 22 months and 5 months | Monthly review |
| Footer | Sender name, mailing address, second contact method, unsubscribe link | Every send |
| Unsubscribe processing | Immediate suppression; verify no re-add via imports | Every send |
| List imports | Block any list without a documented consent source | Every import |
| Segmentation | Canadian recipients identifiable so rules can be applied | Continuous |
| Staff training | Sales and support know that scraped addresses are not consent | Annually |
Common ways good senders get this wrong
- Treating CAN-SPAM practice as sufficient. Opt-out is enough in the US; it is not in Canada.
- Letting implied consent run indefinitely because no system tracks the two-year and six-month clocks.
- Bundling consent into terms acceptance, which undermines the argument that consent was freely and specifically given.
- Adding conference badge scans to the main list without checking whether the attendee actually agreed to marketing.
- Re-importing an old CRM export that resurrects previously unsubscribed contacts.
- Assuming a Canadian-hosted transactional email is exempt from everything — the misleading-content rules still apply.
Frequently asked questions
Does CASL apply to US companies?
Yes, if the message is sent to or accessed on a computer system in Canada. Your own location doesn't determine coverage; the recipient's does.
How long does implied consent last under CASL?
Two years from a purchase, contract, or similar transaction, and six months from an inquiry or application. Express consent has no expiry until the recipient withdraws it.
Are transactional emails covered by CASL?
Messages that are purely transactional — receipts, order status, warranty and account information — are largely excluded from the consent requirement. They must still be truthful and not misleading, and adding promotional content can pull them into scope.
How fast must I honor a CASL unsubscribe?
Within 10 business days, with no cost or extra steps for the recipient. Processing removals immediately is the safer standard and is what most modern platforms do by default.
What are the penalties for a CASL violation?
Administrative monetary penalties reach up to CAD $1 million for individuals and CAD $10 million for organizations per violation, and directors and officers can be held personally liable. Consult counsel about exposure specific to your program.
Send compliant email without the spreadsheet gymnastics. Start free with IGSendMail — consent tracking, one-click unsubscribe handling, and GDPR, CAN-SPAM and CASL-ready infrastructure from $19/mo.

