emailmarketing.net

Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail

Digest of CRTC CASL enforcement — penalties, undertakings, the section 9 intermediary-liability bulletin, compliance-program guidance, and program statistics — plus the CAN-SPAM statute itself (15 U.S.C. 7704 prohibitions, aggravated violations incl. harvesting, and 7705 promoted-business liability), each with the lesson for an ESP.

Reference13 min read

Who it is for Compliance teams, Senders

Applies to senders on any platform

To judge your real exposure under Canada's Anti-Spam Legislation (CASL) or the US CAN-SPAM Act, you need to know how the rules are enforced as well as what they say. CASL and CAN-SPAM set out the rules themselves.

This page covers what happens in enforcement: the tools of the Canadian Radio-television and Telecommunications Commission (CRTC), decided cases with names and amounts, and the guidance the CRTC issued on the liability of intermediaries such as ESPs. It also covers the statutory text of CAN-SPAM's prohibitions, which goes further than the Federal Trade Commission's (FTC) business guide.

CASL enforcement: who does what

Three agencies share responsibility for CASL (according to the ISED Performance Measurement Report 2024-25):

  • The CRTC enforces sections 6–9 (spam, altered transmission data, malware, aiding) as a civil administrative regime with administrative monetary penalties (AMPs), and runs the Spam Reporting Centre.
  • The Competition Bureau pursues false or misleading electronic representations (about the sender, subject, message, or locator such as a URL) under the Competition Act.
  • The Office of the Privacy Commissioner (OPC) handles address harvesting and unlawful collection under PIPEDA. It has no power to impose AMPs, and relies on voluntary commitments or Federal Court orders.

The National Coordinating Body at Innovation, Science and Economic Development Canada (ISED) runs policy, and fightspam.gc.ca is the outreach site. The CRTC has memoranda of understanding (MOUs) with the FTC, FCC, ICO, ACMA (Australia), Japan's MIC and New Zealand's DIA, and works with the FBI, the RCMP and the AFP.

The CRTC's enforcement instruments

Instrument What it is Key mechanics
Notice of Violation (NOV) A formal finding by investigation staff of violations of s.6–9, with an AMP sized by severity and number of violations 30 days to pay, or to file written representations for review by the CRTC. No response means the violation is deemed committed. Payment is suspended during review. Decided on the balance of probabilities, and published
Undertaking A voluntary settlement, negotiated Usually admits the acts, and includes a payment and a compliance program. It ends the case and cancels any NOV for those violations. Refusing one usually leads to an NOV. A summary is published
Warning letter or citation An alternative for less serious violations No formal duty to respond, and not published. Failing to apply corrective measures invites escalation
Notice to Produce A demand for records relevant to an investigation 30 days to respond. Suspended while the CRTC reviews an objection (that the demand is unreasonable, or covers privileged material)
Preservation Demand An order, usually to telecom or Internet providers, to preserve transmission data Up to 21 days, with one 21-day extension. Telecommunications service providers (TSPs) get 5 business days to seek review, but must preserve the data in the meantime

Practical tips from the CRTC's own guidance: put everything into your first written representations, because reviews normally allow no later submissions, and take warning letters seriously, because they are the cheap way out.

Bulletin 2014-326: corporate compliance programs (the due-diligence defence)

Compliance and Enforcement Information Bulletin CRTC 2014-326 (June 19, 2014) tells businesses how to build a program that can support a due-diligence defence, and persuade the Commission that a violation was isolated rather than systemic.

The required elements are:

  • ownership by senior management (a designated compliance officer or point person);
  • an assessment of the activities at risk of violations;
  • a written policy covering procedures, training (with written acknowledgments by employees, and refresher training), auditing and monitoring, compliance by third parties, record-keeping, and feedback from employees;
  • CASL record-keeping, specifically of unsubscribe requests and the actions taken, evidence of consent, logs of recipients' consent, and message scripts;
  • regular audits, with documented follow-up;
  • a system for handling complaints, with defined times for resolution;
  • a disciplinary code, with documented corrective actions.

A program in place beforehand is not a complete defence, but it shows that reasonable precautions were taken. A well-run ESP should be able to produce this checklist for itself, and demand it of its customers.

Bulletin 2018-415: section 9 liability for intermediaries (the ESP bulletin)

Compliance and Enforcement Information Bulletin CRTC 2018-415 (November 5, 2018) interprets section 9, which makes it a violation to aid, induce, procure, or cause to be procured a violation of sections 6–8. The categories at risk that the CRTC names are advertising brokers, electronic marketers, software and app developers and distributors, telecommunications and Internet service providers, and payment processors. That is the whole delivery chain, and ESPs are clearly included.

The assessment factors are: (1) level of control, meaning the ability to prevent or stop the activity; (2) degree of connection between the acts that helped and the underlying violation; and (3) reasonable steps, meaning the precautions and safeguards actually put in place.

The bulletin's first example applies directly to ESPs. A marketing company that supplies email templates without sender identification or unsubscribe mechanisms, together with contact lists without verification of consent, aids its client's s.6 violation by "providing the tools." Other examples are a web host that ignores a reported phishing campaign, and an app store that distributes software with hidden functions behind a pre-checked consent box.

The expected due diligence includes:

  • regular assessments of threats and risks;
  • validation of client identity (incorporation records, government ID, tax documents);
  • flagging discrepancies in location, and clients who seek anonymity (aliases, P.O. boxes, payment in cryptocurrency);
  • researching the client's reputation and the legality of its products;
  • written contracts that bind clients to CASL;
  • auditing how existing clients use the service;
  • monitoring for suspected violations and reporting them;
  • resources for prompt takedown and remediation;
  • documenting all of it.

The bulletin warns that "simply following industry standards may be insufficient". Static policies without active oversight do not meet the s.9 obligation.

CASL case digest

The formal CRTC actions below come from the CRTC's list of enforcement actions as fetched in July 2026, supplemented by the CRTC's CASL enforcement report for October 2020–March 2021. The public list is split across pages, so earlier cases that predate it, such as the 2015–2018 undertakings, are not reproduced here.

Notices of Violation (AMPs)

Date Party AMP Violation ESP lesson
2025-08-13 Jimmy Genesse $50,000 s.7(1)(a) (altering transmission data) Redirecting or altering routing data is a separate type of violation, distinct from consent
2023-07-11 Sami Medouni $40,000 s.6 (CEMs without consent) Individuals, not only companies, are named and fined personally
2022-01-17 Marc-Anthony Younes $50,000 s.6(1)(a) (no consent) Same
2021-03 Scott William Brewer $75,000 s.6: 670,000+ affiliate-marketing emails using a "hailstorm" technique (bursts sent quickly to evade anti-spam detection) Sending in bursts to outrun filtering is treated as an aggravating tactic. The list of actions also records a 2022-01-04 undertaking by Brewer ($7,500 and a compliance program)
2019-12-12 John Paul Revesz & Vincent Leo Griebel / Orcus Technologies $115,000 s.9 (aiding) Section 9 is enforced, with real money, against those who supply the means of a violation
2019-04-23 Brian Conley $100,000 s.6(1) and 6(2) The requirements for consent and for content and identification were enforced together

Undertakings (negotiated settlements)

Date Party Payment Notes and ESP lesson
2024-06-10 Hudson's Bay Company $120,000 A major mainstream retailer, plus a compliance program. CASL enforcement is not only about spammers: marketing programs of household brands settle too
2023-02-10 NortonLifeLock Inc. None (compliance program) A commitment to a program alone can be the price of settlement
2021-12-06 Gap Inc. $200,000 Plus a compliance program. Brands headquartered abroad that mail Canadians can be reached
2020-09-21 Notesolution Inc. / OneClass $100,000 Plus a compliance program
2022-08-24 Christos Tyrone Dracos $40,000 An individual, with conditions
2022-05-10 Souhail Amaarak / Moustapha Sabir $10,000 / $17,000 Individuals in the same investigation, each separately liable
2022-01-04 Scott William Brewer $7,500 Plus a compliance program (see the NOV above)

Confirmation by the courts. According to the CRTC's 2020-21 enforcement report, in March 2021 the Supreme Court of Canada declined to hear CompuFinder's appeal. That left in place the Federal Court of Appeal ruling that upheld CASL's constitutionality and clarified the consent provisions on existing business relationships and conspicuous publication. The report also used CompuFinder as its example of a violation involving an unsubscribe mechanism that did not work. Challenging CASL on constitutional grounds leads nowhere, and the categories of implied consent in CASL are read as written.

Program statistics: what the regulator actually does

CRTC CASL enforcement report, 1 Oct 2020 – 31 Mar 2021 (six months). The CRTC issued 143 Notices to Produce, 17 Preservation Demands, 10 warning letters and 1 NOV, with $75,000 in penalties. The cumulative total since 2014 was then over $1.4M payable ($805K in AMPs and $668K in undertakings).

The Spam Reporting Centre received 144,560+ complaints (~5,560/week). Only 3% came through the web form, and the rest were sent to spam@fightspam.gc.ca. 93% of complaints alleged lack of consent, 34% problems with identification, 30% deceptive marketing, and 3% software or malware. 76% of the mail complained about was affiliate marketing or legitimate business email, not criminal spam.

The top affiliate categories were food, drugs and health; surveys and sweepstakes; casinos; online shopping; and technology. The top commercial categories were marketing services, technology, online shopping, updates and notifications, and newsletters. In November 2020, the CRTC, the OPC and the Competition Bureau jointly warned 36 mobile-app companies about keeping apps compliant with CASL (no false claims, no keylogging without consent, no hidden functions, no spamming of users' contacts).

ISED CASL Performance Measurement Report 2024-25. The Spam Reporting Centre (SRC) received 414,630 complaints, only ~2.1% of them through the online form. The CRTC's totals for the year were 260 Notices to Produce, 33 warning letters, 14 Preservation Demands, 2 undertakings, and over $137,000 in AMPs. Cumulative CRTC AMPs since 2014 reached over $3.6 million.

In November 2024, the CRTC analyzed ~25 companies with noticeably high complaint volumes, checked their consent and unsubscribe practices, and sent warning letters where potential violations appeared. In other words, the volume of complaints at the Spam Reporting Centre directly selects the targets of enforcement. This is the regulatory counterpart of the loop between complaint rates and reputation described in Foundations.

The Competition Bureau's CASL-related actions that year included a settlement with SiriusXM Canada over subscription offers with drip pricing, promoted "on its website, as well as in promotional emails and direct mail"; proceedings at the Competition Tribunal against Rogers Communications over claims of "unlimited" data; and a second court order in an ongoing investigation of Amazon for misleading marketing. The OPC received 14 CASL-related complaints (unsolicited CEMs, missing unsubscribe options, and unsubscribes not honored). It reported that >90% of phishing begins with email, and cited OECD findings that more than half of spam and malicious email is now generated by AI.

Overall lessons for ESPs from the CASL record: (1) most enforcement starts with recipients' complaints about gaps in consent at legitimate marketers, not about criminals; (2) individuals and officers are named personally; (3) an unsubscribe that does not work, or is not honored, is a recurring violation that is easy to prove; (4) an ESP's own exposure is under s.9, and its only defence is documented client vetting and active monitoring; (5) a documented compliance program is both what settlements are paid in and the basis of the due-diligence defence.

CAN-SPAM statutory detail: 15 U.S.C. § 7704 and § 7705

The FTC compliance guide paraphrases the Act. The statute adds structure that matters when you assign blame along a chain of advertiser, ESP and list supplier.

§ 7704(a): the core prohibitions

  • (a)(1) Materially false or misleading header information. This applies to commercial mail and to transactional or relationship mail. Three rules decide what counts. Headers that are technically accurate still count as misleading if the originating address, domain or IP address was obtained by false or fraudulent pretenses. A "from" line that accurately identifies any actual initiator is compliant. Headers are materially misleading when they fail to identify the machine that injected the message because the sender knowingly relayed it through another protected computer to disguise its origin. "Materially" (defined in (a)(6)) means alteration or concealment that would impair the ability of a receiving service, law enforcement or the recipient to identify, locate, or respond to the initiator, or to investigate.
  • (a)(2) Deceptive subject headings. These are unlawful when the sender actually knows, or when objective circumstances fairly imply that the sender knows, that the subject would likely mislead a reasonable recipient about a material fact regarding the contents or subject matter.
  • (a)(3) A working return address or Internet-based opt-out, displayed clearly and conspicuously, and able to receive opt-out requests for at least 30 days after transmission. A preference menu is allowed only if it includes an option to decline all commercial messages from the sender. A temporary outage beyond the sender's control is excused if it is corrected within a reasonable time.
  • (a)(4) Prohibitions after an opt-out. After 10 business days, it is unlawful for the sender to mail within the scope of the request; for anyone acting on the sender's behalf to do so with actual or fairly implied knowledge; for anyone to assist by providing or selecting addresses knowing the transmission would violate the law; and for any person who knows of the request to sell, lease, exchange, or otherwise transfer or release the address (except to a contractor for compliance purposes). Only the recipient's later affirmative consent allows mailing again. The clause on providing addresses is the one that reaches list brokers and ESP data teams directly.
  • (a)(5) Required content. Clear and conspicuous identification as an advertisement (waived only if the recipient gave affirmative consent beforehand), clear and conspicuous notice of the opt-out, and a valid physical postal address of the sender.

§ 7704(b): aggravated violations

These are added on top of violations of (a), and lead to higher penalties:

  1. Address harvesting: sending unlawful mail (or assisting by providing or selecting addresses) to addresses obtained by automated means from a website or online service whose operator posted a notice that it will not give, sell, or transfer addresses for mailing purposes. Also dictionary attacks: addresses generated by automatically combining names, letters or numbers. The knowledge required is actual or fairly implied. (The provision expressly creates no property right in email addresses.)
  2. Automated account creation: using scripts or other automated means to register several email or user accounts to send unlawful commercial mail, or enabling others to do so.
  3. Unauthorized relay: knowingly relaying or retransmitting a message that violates (a) from a protected computer or network accessed without authorization.

Under (c), the FTC has rulemaking authority to shorten or lengthen the 10-business-day window, and to designate additional aggravated practices. Subsection (d) is the regime of warnings for sexually oriented material: marks in the subject line, or a "wrapper" that shows only the marks, the (a)(5) disclosures and instructions for access. It is waived by prior affirmative consent, and knowing violations carry fines and up to 5 years' imprisonment.

§ 7705: liability of the business being promoted

This section removes the "we just hired them" defence. Under (a), it is unlawful for a person to promote its trade or business, or allow it to be promoted, in a commercial message whose transmission violates § 7704(a)(1) (false or misleading headers) if that person: (1) knows, or should have known in the ordinary course of business, that its goods or services were being promoted in such a message; (2) received or expected to receive an economic benefit from the promotion; and (3) took no reasonable action (A) to prevent the transmission, or (B) to detect it and report it to the Commission.

Under (b), a third party whose goods appear in someone else's promotion is generally not liable, unless it owns or holds >50% of the violating trade or business, or has actual knowledge of the unlawful promotion and receives or expects an economic benefit. Under (c), §§ 7706(f) and (g) do not apply to this section. State attorneys general cannot sue, and Internet access services cannot bring private actions, under § 7705. Only the FTC (and federal regulators) enforce it.

Lessons for ESPs from the statute: (1) the obligation to keep headers truthful applies even to transactional mail, so accurate HELO, From and Return-Path chains are a legal requirement, not only good authentication practice (see SPF and DKIM); (2) the 30-day window during which the opt-out must work, and the 10-business-day window for honoring it, are legal minimums that an ESP's suppression infrastructure must beat (compare CASL's pair of 60-day and 10-business-day windows in CASL); (3) accepting or supplying a harvested list, or one generated by combining names, turns ordinary violations into aggravated ones, and "assisting through the provision or selection of addresses" is a separate ground of liability for the ESP itself, which gives legal backing for refusing purchased lists (see Consent Methods and Spam Traps); (4) advertisers cannot outsource liability, so an ESP's compliance practice is part of what its customers rely on legally, which mirrors CASL s.9 from the other direction.

These summaries are drawn from the cited regulator publications and the text of the statute, and are not legal advice. Penalty figures and case lists change, so check the CRTC's enforcement-actions page and the U.S. Code for the current state.