Educational Resource

What Is CASL Compliance? (Canada, $10 Million, and Personal Liability)

If you build your list practice to satisfy Canada, you are almost certainly compliant everywhere else. CASL demands consent before the first message, proof on request, and it expires implied consent on a clock most senders do not track.

Hamit Kaya
Hamit Kaya
Founder & CTO, aicente
8 min read

Key Takeaways

  • Consent is required BEFORE the first commercial message. There is no equivalent of the US position where a stranger may be emailed lawfully.
  • The burden of proof is on the sender. If you cannot evidence consent, you do not have it.
  • Implied consent EXPIRES: two years from a purchase or contract, six months from an enquiry. Most senders never track this, and it is where otherwise careful lists go wrong.
  • Penalties reach $10 million per violation for a business and $1 million for an individual.
  • Directors and officers can be personally liable, and employers are liable for what employees do in the course of employment.
  • Unsubscribe requests must be honoured within 10 business days with no further action required by the recipient.

What CASL Covers

Canada’s Anti-Spam Legislation governs commercial electronic messages sent to or accessed from a computer in Canada. The territorial hook is worth reading twice: it is not about where your business is, and it is not only about Canadian residents. A message opened in Canada is in scope.

It is enforced by the Canadian Radio-television and Telecommunications Commission, which has brought real actions with real numbers attached rather than leaving the law theoretical.

Express Consent

Someone actively agreed to receive commercial messages from you. To be valid, the request must have stated the purpose, identified who is seeking consent (and on whose behalf, if different), and given contact information.

Express consent does not expire. That is the prize, and it is why building a list on express consent is worth the lower signup rate.

Implied Consent, and the Clock Nobody Tracks

Implied consent arises from an existing business relationship, and it has a hard expiry.

Two years from a purchase, a contract, a lease or a written contract that has expired.

Six months from an enquiry or an application, which is a much shorter window than people expect and covers most inbound lead activity.

Implied consent also arises from a conspicuously published business address where the message is relevant to that person’s role, and from an address disclosed to you without a statement that they do not want unsolicited mail. Both are narrower than they sound, and neither survives a “no unsolicited email” note on the page.

The expiry is where careful senders fail. A list that was lawful when imported quietly becomes unlawful at the two-year mark, and nothing in a typical email platform tells you it happened. If you rely on implied consent you need the acquisition date stored per contact and a rule that stops mailing when it lapses.

The Burden of Proof Is Yours

Under CASL you must be able to prove you had consent. This is stronger than it looks: absence of evidence is treated as absence of consent, so an address with no provenance is an address you may not mail.

Practically that means recording, per contact, what they agreed to, when, through which form, and what the form said at the time. Form wording changes; the record has to reflect what that person actually saw.

What Every Message Must Contain

Identification of who sent it, and on whose behalf if those differ. A mailing address, and either a phone number, an email address or a web address, all of which must stay valid for at least 60 days after the message. And an unsubscribe mechanism that works, is clearly set out, and can be used at no cost.

The 60-day validity requirement on your own contact details is a CASL-specific detail that trips senders who rotate addresses between campaigns.

Ten Business Days

An unsubscribe must be given effect within 10 business days, and the recipient must not have to do anything else to make it take effect. No confirmation email they have to click, no login, no preference centre they must navigate.

Who Pays

Up to $10 million per violation for a business, up to $1 million for an individual.

Directors and officers can be held personally liable where they directed, authorised, assented to or participated in the violation. Employers are liable for what employees do in the course of employment. There is a due diligence defence, which is a practical reason to be able to show a documented consent process rather than a verbal policy.

Why Building for CASL Is the Efficient Choice

A list practice that satisfies CASL (consent before the first message, evidence per contact, expiry tracked, unsubscribe honoured promptly, identity and address in every message) satisfies GDPR on most points and CAN-SPAM comfortably. Building to the US baseline and then trying to retrofit the other two means auditing a list you can no longer evidence.

The engineering version of that is simple: record a consent event at every point where consent changes, keep the method and the timestamp, and never let an import create a contact without one. Action BeeMail does this by default, and an import that cannot attest to a source is refused rather than accepted quietly.

This is a description of the rules, not legal advice. If a decision turns on your specific circumstances, ask a lawyer.

Ready to Try Aicente?

Join 10,000+ businesses using aicente's 60+ AI tools to manage operations, win recognition, and grow. Platform Access starts at $19.99/month. Action Award entry is always free.