# CASL — Canada's Anti-Spam Legislation

> CRTC rules for commercial electronic messages sent to Canada: express vs. implied consent (with time limits), CEM identification and unsubscribe requirements, exemptions, and penalties up to $10M.

Source: emailmarketing.net — https://emailmarketing.net/learn/compliance/casl

If you send commercial email, text messages or other electronic messages to people in Canada, you need their consent before you send. Canada's Anti-Spam Legislation (CASL) governs these commercial electronic messages (CEMs).

Unlike the US [CAN-SPAM Act](https://emailmarketing.net/learn/compliance/can-spam), which is an opt-out law, CASL is an **opt-in** regime. Consent, express or implied, is required **before** sending, and the sender bears the burden of proving it.

This is not legal advice. Check penalties and thresholds against the primary source (below) and with counsel before relying on them. See [Compliance](https://emailmarketing.net/learn/compliance).

## What CASL regulates

CASL sets out four core prohibitions and obligations:

1. **Commercial electronic messages**: a sender must obtain prior consent from the recipient (express or implied), provide identification and contact information, and include a working unsubscribe mechanism.
2. **Installing computer programs**: installing software on someone's system requires express consent from the owner or an authorized user, and a clear and simple description of what the program does and why.
3. **Message transmission data**: routing information must not be altered so that a message is delivered to a destination other than the one specified (or in addition to it) without appropriate consent.
4. **Aiding violations**: organizations must not help others breach these requirements (liability for "aiding" under section 9).

## What is a CEM?

A commercial electronic message is one where **any one of its purposes** is to encourage the recipient to take part in a commercial activity. Examples include offers to purchase, sell or lease products or services, business or investment opportunities, and promotion of a person's commercial activities. This is broader than the "primary purpose" test in CAN-SPAM: one commercial purpose among several is enough.

### Covered and excluded messages

| Covered | Excluded or exempt |
|---|---|
| Email | Live voice and automated telemarketing calls (regulated separately) |
| SMS and text messages | One-way social media broadcasts (tweets, wall posts) |
| Instant messaging | Political messages whose main purpose is to ask for contributions |
| Social media direct messages | Business-to-business (B2B): messages between employees of organizations that have an existing relationship |
| Push notifications (if commercial) | Membership communications to members of clubs or associations |
| | Messages within secure accounts with limited access (for example, banking portals) |
| | Fundraising by registered charities (where that is the main purpose) |

## Consent

### Express consent

- The person has **clearly agreed** to receive CEMs, in writing or orally, by taking an active step to opt in.
- **Pre-checked boxes, silence or inactivity are not valid.** A positive action is required.
- Express consent **does not expire**. It remains valid until the recipient withdraws it.
- The **burden is on the sender** to prove that consent was obtained.

### Implied consent categories and time limits

| Category | Basis | Valid for |
|---|---|---|
| Existing business relationship (EBR) | Purchase or lease of goods, services, or land | **2 years** from the transaction |
| EBR | Accepted business, investment, or gaming opportunity | **2 years** |
| EBR | Written contract (in existence or expired) | **2 years** from expiry |
| EBR | Inquiry or application about products or services | **6 months** |
| Existing non-business relationship (charities, political parties and candidates, clubs and associations) | Donation or gift | **2 years** |
| Existing non-business relationship | Volunteer work or meeting attendance | **2 years** |
| Existing non-business relationship | Membership | Duration of membership (no fixed time limit while current) |
| Conspicuous publication | The address is published publicly (for example, on a website) with **no statement** discouraging CEMs, and the message relates to the recipient's business role, functions or official duties | While published |
| Business card or disclosed address | The recipient gave their address (for example, on a business card) and the message relates to their business role | No time limit stated |
| Referral | One person refers another | **One CEM only**, and it must identify the person who made the referral |
| Transitional (historical) | An EBR or non-business relationship that existed before July 1, 2014, with a history of CEMs | 3 years, from July 1, 2014 to July 1, 2017 (now lapsed) |

### Records and burden of proof

The sender must be able to demonstrate consent. Keep records of the electronic address, the date consent was obtained, the method (a form, verbally, a purchase and so on), and the context (purchase history, volunteer work, an exchange of business cards). The CRTC has issued an enforcement advisory specifically on keeping records of consent.

## CEM content requirements

Every CEM must:

1. **Identify the sender**, and any person on whose behalf the message is sent. If it is impractical to include this in the body of the message, the information may be provided through a link to a web page that is **clearly and prominently set out** and free to access.
2. **Provide contact information**, including a valid mailing address (a P.O. box is acceptable). The contact information must remain **valid for a minimum of 60 days** after the message is sent.
3. **Include an unsubscribe mechanism** that can be "readily performed", meaning simple, quick and easy (for example, an unsubscribe link, or replying "STOP" or "Unsubscribe" by SMS). The mechanism must:
   - keep working for **at least 60 days** after the message is sent;
   - be processed **without delay, and no later than 10 business days** after the request.

## Penalties and liability

| Exposure | Detail |
|---|---|
| Administrative monetary penalty (individual) | Up to **$1,000,000 per violation** |
| Administrative monetary penalty (organization) | Up to **$10,000,000 per violation** |
| Directors and officers | Personally liable if they **directed, authorized, assented to, acquiesced in, or participated in** the violation |
| Aiding | Liability under section 9 for helping others commit violations |
| Third-party marketers and affiliates | Shared liability: both the brand and the party sending on its behalf are responsible for compliance |

A documented corporate compliance program (due diligence) reduces the risk. The Canadian Radio-television and Telecommunications Commission (CRTC) handles enforcement, and its site describes its compliance and enforcement processes and publishes its enforcement actions. Spam can be reported to the Spam Reporting Centre (fightspam.gc.ca).

## Deliverability relevance

Because CASL's consent expires, it effectively requires the list-hygiene practices that also protect sender reputation. Mail only addresses with a recent relationship you can prove, and remove addresses as they age out (after 6 months for an inquiry, and 2 years for a purchase). Senders who respect those windows naturally avoid the stale, unengaged addresses that cause complaints and spam-trap hits. See [Foundations of Email Deliverability](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability).
