Definition
Canada's Anti-Spam Legislation (CASL), which came into full force on 1 July 2014, is widely regarded as the strictest anti-spam law in the world. It regulates the sending of commercial electronic messages (CEMs) to electronic addresses, including email, SMS, and social media messages. CASL applies to any message whose primary purpose is to encourage participation in a commercial activity, regardless of whether the sender or recipient is located in Canada, as long as a computer system in Canada is used to access or send the message. This extraterritorial reach means that email marketers worldwide must consider CASL compliance when targeting Canadian subscribers.
CASL requires express consent before sending most commercial messages, with only limited exceptions for implied consent. Express consent must be obtained through a clear affirmative action — pre-checked boxes are explicitly prohibited and do not constitute valid consent under CASL. The consent request must identify the person seeking consent, specify the email address or other electronic address that will receive the messages, and clearly state that consent can be withdrawn at any time. Implied consent arises from an existing business relationship (purchase within the past two years) or an existing non-business relationship (donation, membership, volunteer activity within the past two years), and expires after two years.
Penalties under CASL are severe: administrative monetary penalties of up to $10 million per violation for organisations, plus personal liability for directors and officers who authorise or permit the violation. The legislation also creates a private right of action, although the relevant provisions were suspended in 2022 pending parliamentary review. According to the Canadian Radio-television and Telecommunications Commission (CRTC), which enforces CASL alongside the Competition Bureau and the Office of the Privacy Commissioner, over $15 million in penalties have been issued since enactment. Key compliance requirements include maintaining auditable consent records, providing functional unsubscribe mechanisms that process within 10 business days, and including accurate sender identification in every message.
Best Practices
Implement a consent capture process that records the date, time, and source of express consent for every Canadian subscriber. Store the exact wording of your consent request, the IP address of the subscriber at the time of consent, and the specific URL or location where consent was given. The CRTC recommends retaining these records for at least three years after consent is withdrawn or expires.
Design your email collection forms to include separate unchecked checkboxes for each type of commercial communication you intend to send, such as promotional offers, newsletters, and event invitations. CASL does not recognise blanket consent to "all communications" — each purpose must be clearly identified at the point of consent, and subscribers must be able to grant consent for some purposes while withholding it for others.
Build automated consent management workflows that track the two-year expiration window for implied consent relationships. When a Canadian subscriber's implied consent is approaching expiry, trigger a re-consent campaign that requests express consent before the implied consent period lapses. If express consent is not obtained, you must cease sending commercial messages once the two-year period ends.
Ensure your unsubscribe processing system can honour CASL's 10-business-day fulfilment window, which is shorter than CAN-SPAM's 10-business-day requirement. CASL also requires that unsubscribe requests apply to all commercial messages from your organisation, not just the specific mailing list from which the subscriber unsubscribed, unless you obtained separate consent for each type of communication.
Review your referral, forward-to-friend, and social sharing features for CASL compliance. If your email template includes a "forward to a friend" link that triggers an automated message, you may be sending an unsolicited CEM unless the recipient has given prior express consent. Third-party referrals require the referrer to obtain the recipient's consent before providing the address to your organisation.
Related Glossary Terms
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email CCPA
California Consumer Privacy Act requirements for email marketing, including consumer rights to access, delete, and opt out of data collection and sale.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Data Portability
Data portability under GDPR Article 20 gives subscribers the right to receive their email marketing data in a machine-readable format and transfer it to another provider. Common export formats are CSV and JSON.
Email Data Retention
Email data retention policies govern how long subscriber data, activity logs, consent records, and campaign data are kept. GDPR requires data not be kept longer than necessary for the processing purpose.
Email Encryption
Email encryption uses TLS for transit security and end-to-end methods like PGP, with compliance requirements for HIPAA, GDPR, and impacts on marketing email tracking.
Frequently Asked Questions
Yes, CASL applies to any commercial electronic message sent to or from a computer system in Canada. If your email is accessed on a device in Canada, CASL applies regardless of where the sender is based. Many US email marketers choose to comply with CASL for all Canadian-targeted campaigns.
Express consent requires an affirmative action such as checking a box or clicking a button after seeing a clear disclosure. Implied consent arises automatically from an existing business or non-business relationship, such as a purchase within the past two years, and expires after two years of inactivity.
Organisations face administrative monetary penalties of up to $10 million per violation. Directors and officers can be held personally liable for up to $1.5 million if they directed or authorised the violation. The CRTC also has the power to enter into compliance agreements and issue cease-and-desist orders.
The CRTC recommends retaining consent records for at least three years after consent is withdrawn or expires. In practice, many organisations retain records for the duration of the subscriber relationship plus three years to ensure they can demonstrate compliance during an investigation.
No. Pre-checked boxes do not constitute valid express consent under CASL. The subscriber must take an active, affirmative step to indicate their consent, such as manually checking an unchecked box or clicking a consent button.