Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail
Digest of CRTC CASL enforcement — penalties, undertakings, the section 9 intermediary-liability bulletin, compliance-program guidance, and program statistics — plus the CAN-SPAM statute itself (15 U.S.C. 7704 prohibitions, aggravated violations incl. harvesting, and 7705 promoted-business liability), each with the lesson for an ESP.
The substantive rules are in CASL and CAN-SPAM. This article covers what actually happens when they are enforced — the CRTC's toolkit, decided cases with names and amounts, the guidance the CRTC issued about intermediary (ESP) liability — and the statutory text of CAN-SPAM's prohibitions, which goes further than the FTC's business guide.
CASL enforcement — who does what
Three agencies share CASL (per the ISED Performance Measurement Report 2024-25): the CRTC enforces sections 6–9 (spam, altered transmission data, malware, aiding) as a civil administrative regime with administrative monetary penalties (AMPs) and hosts the Spam Reporting Centre; the Competition Bureau pursues false/misleading electronic representations (sender, subject, message, locator/URL information) under the Competition Act; the OPC handles address harvesting and unlawful collection under PIPEDA (no AMP power — voluntary commitments or Federal Court orders). ISED's National Coordinating Body runs policy; fightspam.gc.ca is the outreach hub. The CRTC has MOUs with the FTC, FCC, ICO, ACMA (Australia), Japan's MIC, and New Zealand's DIA, and works with the FBI, RCMP, and AFP.
The CRTC's enforcement instruments
| Instrument | What it is | Key mechanics |
|---|---|---|
| Notice of Violation (NOV) | Formal finding by investigation staff of s.6–9 violations, with an AMP sized by severity and count | 30 days to pay or file written representations for CRTC review; no response = deemed violation; payment suspended during review; decided on balance of probabilities and published |
| Undertaking | Negotiated voluntary settlement | Usually admits the acts, includes a monetary payment and a compliance program; ends the case and terminates any NOV on those violations; refusal typically triggers an NOV; summary published |
| Warning letter / citation | Alternative for less severe violations | No formal response duty, not published — but non-implementation of corrective measures invites escalation |
| Notice to Produce | Demand for records relevant to an investigation | 30 days to respond; suspended while the CRTC reviews an objection (unreasonableness/privilege) |
| Preservation Demand | Order (typically to telecom/Internet providers) to preserve transmission data | Up to 21 days, one 21-day extension; TSPs get 5 business days to seek review but must preserve meanwhile |
Practical tips from the CRTC's own guidance: put everything into the first written representations (reviews normally allow no later submissions), and treat warning letters as real — they are the cheap exit.
Bulletin 2014-326 — corporate compliance programs (the due-diligence defence)
Compliance and Enforcement Information Bulletin CRTC 2014-326 (June 19, 2014) tells businesses how to build a program that can ground a due-diligence defence and persuade the Commission a violation was isolated rather than systemic. Required ingredients: senior-management ownership (a designated compliance officer or point person); a risk assessment of violation-prone activities; a written policy covering procedures, training (with written employee acknowledgments and refreshers), auditing/monitoring, third-party compliance, record-keeping, and employee feedback; CASL record-keeping specifically of unsubscribe requests and the actions taken, consent evidence, recipient-consent logs, and message scripts; regular audits with documented follow-up; a complaint-handling system with defined resolution timeframes; and a disciplinary code with documented corrective actions. A pre-existing program is not a complete defence but demonstrates reasonable precautions. This is the checklist a well-run ESP should be able to produce for itself and demand of customers.
Bulletin 2018-415 — section 9 liability for intermediaries (the ESP bulletin)
Compliance and Enforcement Information Bulletin CRTC 2018-415 (November 5, 2018) interprets section 9 — it is a violation to aid, induce, procure, or cause to be procured a violation of sections 6–8. The at-risk categories the CRTC names: advertising brokers, electronic marketers, software/app developers and distributors, telecommunications and Internet service providers, and payment processors — i.e., the whole delivery chain, ESPs squarely included.
Assessment factors: (1) level of control — the ability to prevent or stop the activity; (2) degree of connection between the facilitating acts and the underlying violation; (3) reasonable steps — precautions and safeguards actually implemented. The bulletin's first example is on point for ESPs: a marketing company that supplies email templates lacking sender identification and unsubscribe mechanisms, plus contact lists without consent verification, aids its client's s.6 violation by "providing the tools." Other examples: a web host that ignores a reported phishing campaign; an app store distributing software with undisclosed functionality behind a pre-checked consent box.
Expected due diligence: regular threat/risk assessments; client identity validation (incorporation records, government ID, tax documents); flagging location discrepancies and clients seeking anonymity (aliases, P.O. boxes, cryptocurrency payment); researching client reputation and product legality; written contracts binding clients to CASL; auditing existing clients' usage; monitoring and reporting suspected violations; resourcing prompt takedown and remediation; and documenting all of it. The bulletin warns that "simply following industry standards may be insufficient" — static policies without active oversight do not discharge s.9.
CASL case digest
Formal CRTC actions (from the CRTC enforcement-actions list as fetched July 2026, supplemented by the CRTC's October 2020–March 2021 CASL enforcement report; the public list paginates, so early-era cases such as the 2015–2018 undertakings predating it are not reproduced here):
Notices of Violation (AMPs)
| Date | Party | AMP | Violation | ESP lesson |
|---|---|---|---|---|
| 2025-08-13 | Jimmy Genesse | $50,000 | s.7(1)(a) (altering transmission data) | Redirecting/altering routing data is its own violation class, separate from consent |
| 2023-07-11 | Sami Medouni | $40,000 | s.6 (CEMs without consent) | Individuals, not just companies, get personally named and fined |
| 2022-01-17 | Marc-Anthony Younes | $50,000 | s.6(1)(a) (no consent) | Same |
| 2021-03 | Scott William Brewer | $75,000 | s.6 — 670,000+ affiliate-marketing emails using a "hailstorm" technique (bursts sent fast to evade anti-spam detection) | Burst-sending to outrun filtering is treated as an aggravating tactic; the actions list also records a 2022-01-04 undertaking by Brewer ($7,500 + compliance program) |
| 2019-12-12 | John Paul Revesz & Vincent Leo Griebel / Orcus Technologies | $115,000 | s.9 (aiding) | Section 9 is enforced with real money against those who supply the means of violation |
| 2019-04-23 | Brian Conley | $100,000 | s.6(1) and 6(2) | Consent and content/identification requirements enforced together |
Undertakings (negotiated settlements)
| Date | Party | Payment | Notes / ESP lesson |
|---|---|---|---|
| 2024-06-10 | Hudson's Bay Company | $120,000 | Major mainstream retailer + compliance program — CASL enforcement is not only about spammers; household-brand marketing programs settle too |
| 2023-02-10 | NortonLifeLock Inc. | — (compliance program) | A program commitment alone can be the settlement price |
| 2021-12-06 | Gap Inc. | $200,000 | + compliance program — foreign-headquartered brands mailing Canadians are reachable |
| 2020-09-21 | Notesolution Inc. / OneClass | $100,000 | + compliance program |
| 2022-08-24 | Christos Tyrone Dracos | $40,000 | Individual, with conditions |
| 2022-05-10 | Souhail Amaarak / Moustapha Sabir | $10,000 / $17,000 | Individuals in the same investigation, separate liability |
| 2022-01-04 | Scott William Brewer | $7,500 | + compliance program (see NOV above) |
Judicial confirmation. Per the CRTC's 2020-21 enforcement report: in March 2021 the Supreme Court of Canada declined to hear CompuFinder's appeal, leaving standing the Federal Court of Appeal ruling that upheld CASL's constitutionality and clarified the existing-business-relationship and conspicuous-publication consent provisions. CompuFinder was also the report's example of a working-unsubscribe violation. Constitutional attack on CASL is a dead end; the implied-consent categories in CASL are construed as written.
Program statistics — what the regulator actually does
CRTC CASL enforcement report, 1 Oct 2020 – 31 Mar 2021 (six months): 143 Notices to Produce, 17 Preservation Demands, 10 warning letters, 1 NOV, $75,000 in penalties; cumulative since 2014 at that point: over $1.4M payable ($805K AMPs + $668K undertakings). Complaints: 144,560+ to the Spam Reporting Centre (~5,560/week; only 3% via the web form, the rest to spam@fightspam.gc.ca). 93% of complaints alleged lack of consent, 34% identification problems, 30% deceptive marketing, 3% software/malware. 76% of complained-about mail was affiliate marketing or legitimate business email — not criminal spam. Top affiliate categories: food/drug/health, surveys/sweepstakes, casino, online shopping, technology; top commercial categories: marketing services, technology, online shopping, updates/notifications, newsletters. In November 2020 the CRTC, OPC, and Competition Bureau jointly warned 36 mobile-app companies about CASL-compliant apps (no false claims, no keylogging without consent, no obscured functions, no spamming users' contacts).
ISED CASL Performance Measurement Report 2024-25: 414,630 SRC complaints (only ~2.1% via the online form); CRTC year totals — 260 Notices to Produce, 33 warning letters, 14 Preservation Demands, 2 undertakings, over $137,000 in AMPs; cumulative CRTC AMPs since 2014: over $3.6 million. In November 2024 the CRTC analyzed ~25 companies with noticeably high complaint volumes, checked their consent and unsubscribe practice, and sent warning letters where potential violations appeared — i.e., complaint volume at the Spam Reporting Centre directly selects enforcement targets, the regulatory mirror of the complaint-rate reputation loop in Foundations. Competition Bureau CASL-related actions that year: a settlement with SiriusXM Canada over drip-priced subscription offers promoted "on its website, as well as in promotional emails and direct mail"; Competition Tribunal proceedings against Rogers Communications over "unlimited" data claims; a second court order in an ongoing Amazon misleading-marketing investigation. The OPC received 14 CASL-related complaints (unsolicited CEMs, missing unsubscribe options, and unsubscribes not honored) and reported >90% of phishing beginning with email and OECD findings that more than half of spam/malicious email is now AI-generated.
Aggregate ESP lessons from the CASL record: (1) most enforcement starts with recipient complaints about legitimate marketers' consent gaps, not criminals; (2) individuals and officers are named personally; (3) the unsubscribe that doesn't work or isn't honored is a recurring, provable violation; (4) an ESP's own exposure is s.9, defended only by documented client vetting and active monitoring; (5) a documented compliance program is both the settlement currency and the due-diligence defence.
CAN-SPAM statutory detail — 15 U.S.C. § 7704 and § 7705
The FTC compliance guide paraphrases the Act; the statute adds structure that matters when assigning blame across an advertiser/ESP/list-supplier chain.
§ 7704(a) — the core prohibitions
- (a)(1) Materially false or misleading header information — applies to commercial and transactional/relationship mail. Three deeming rules: technically accurate headers still count as misleading if the originating address, domain, or IP was obtained by false or fraudulent pretenses; a "from" line that accurately identifies any actual initiator is compliant; headers are materially misleading when they fail to identify the injecting machine because the sender knowingly relayed through another protected computer to disguise origin. "Materially" (defined in (a)(6)) means alteration or concealment that would impair the ability of a receiving service, law enforcement, or the recipient to identify, locate, or respond to the initiator or to investigate.
- (a)(2) Deceptive subject headings — unlawful with actual knowledge, or knowledge fairly implied from objective circumstances, that the subject would likely mislead a reasonable recipient about a material fact regarding the contents or subject matter.
- (a)(3) Functioning return address or Internet-based opt-out, clearly and conspicuously displayed, able to receive opt-out requests for at least 30 days after transmission. A preference menu is allowed only if it includes an option to decline all commercial messages from the sender. A temporary outage beyond the sender's control is excused if corrected within a reasonable time.
- (a)(4) Post-opt-out prohibitions — after 10 business days it is unlawful for: the sender to mail within the scope of the request; anyone acting on the sender's behalf to do so with actual or fairly-implied knowledge; anyone to assist by providing or selecting addresses knowing the transmission would violate; and any person with knowledge of the request to sell, lease, exchange, or otherwise transfer or release the address (except to a compliance contractor). Only the recipient's subsequent affirmative consent revives mailing. The address-provision clause is the one that reaches list brokers and ESP data teams directly.
- (a)(5) Required content — clear and conspicuous ad identification (waived only by the recipient's prior affirmative consent), clear and conspicuous opt-out notice, and a valid physical postal address of the sender.
§ 7704(b) — aggravated violations
These stack on top of (a) violations and drive enhanced penalties:
- Address harvesting — initiating (or assisting via address provision/selection) unlawful mail to addresses obtained by automated means from a website or online service whose operator posted a notice that it will not give, sell, or transfer addresses for mailing purposes; and dictionary attacks — addresses generated by automated permutation of names, letters, or numbers. Knowledge standard: actual or fairly implied. (The provision expressly creates no property right in email addresses.)
- Automated account creation — using scripts or automated means to register multiple email or user accounts to send unlawful commercial mail, or enabling others to.
- Unauthorized relay — knowingly relaying/retransmitting an (a)-violating message from a protected computer or network accessed without authorization.
The FTC has rulemaking authority under (c) to shorten/lengthen the 10-business-day window and to designate additional aggravated practices. Subsection (d) is the sexually-oriented-material warning regime (marks in the subject line or a "wrapper" showing only the marks, (a)(5) disclosures, and access instructions; waived by prior affirmative consent; knowing violations carry fines and up to 5 years' imprisonment).
§ 7705 — liability of the business being promoted
The anti-"we just hired them" section. Under (a) it is unlawful for a person to promote (or allow promotion of) its trade or business in a commercial message whose transmission violates § 7704(a)(1) (false/misleading headers) if that person: (1) knows, or should have known in the ordinary course of business, that its goods/services were being promoted in such a message; (2) received or expected to receive an economic benefit from the promotion; and (3) took no reasonable action (A) to prevent the transmission, or (B) to detect it and report it to the Commission. Under (b), a third party whose goods appear in someone else's promotion is generally not liable — unless it owns or holds >50% of the violating trade or business, or has actual knowledge of the unlawful promotion and receives or expects economic benefit. Under (c), §§ 7706(f) and (g) do not apply to this section — no state-AG suits and no Internet-access-service private actions for § 7705; only the FTC (and federal regulators) enforce it.
ESP lessons from the statute: (1) header truthfulness obligations attach even to transactional mail — accurate HELO/From/Return-Path chains are a legal requirement, not just an authentication nicety (see SPF/DKIM); (2) the 30-day opt-out availability and 10-business-day honoring windows are statutory minimums an ESP's suppression infrastructure must beat (compare CASL's 60-day/10-business-day pair in CASL); (3) accepting or supplying a harvested or permutation-generated list converts ordinary violations into aggravated ones, and "assisting through the provision or selection of addresses" is an independent hook on the ESP itself — statutory backing for refusing purchased lists (see Consent Methods and Spam Traps); (4) advertisers cannot outsource liability, so an ESP's compliance posture is part of what its customers are legally relying on — mirroring CASL s.9 from the other direction.
These summaries are drawn from the cited regulator publications and statute text and are not legal advice; penalty figures and case lists change — check the CRTC enforcement-actions page and the U.S. Code for current state.
Sources
- https://crtc.gc.ca/eng/archive/2014/2014-326.htm
- https://crtc.gc.ca/eng/archive/2018/2018-415.htm
- https://www.crtc.gc.ca/eng/ce/actions.htm
- https://web.crtc.gc.ca/eng/ce/caslpro.htm
- https://crtc.gc.ca/eng/internet/pub/20210331.htm
- https://ised-isde.canada.ca/site/canada-anti-spam-legislation/sites/default/files/documents/2024-25-casl-en.pdf
- https://www.law.cornell.edu/uscode/text/15/7704
- https://www.law.cornell.edu/uscode/text/15/7705