Back to insights
Checking Compliance Practices

Is cold email legal in Canada?

Cold email is legal in Canada — but CASL demands consent, clear ID, and a working unsubscribe. Skip one, and fines hit $10M per violation. Here's how to...

Is cold email legal in Canada?

Is cold email legal in Canada?

Key Facts

The Compliance Fear Stopping Canadian Outreach

You've built a clean prospect list of Canadian businesses, your offer is sharp, and your sequences are ready — but a voice in the back of your head keeps asking: "Isn't cold email basically illegal in Canada?" You're not alone. Canada's Anti-Spam Legislation (CASL) has a reputation for being lawsuit-bait, and the fear stops a lot of good outreach before it starts.

Here's the honest framing: CASL doesn't ban cold email — it conditions it. As the CRTC's own guidance puts it, the law doesn't prohibit marketing messages; it sets requirements for sending them, starting with consent. Canada runs an opt-in regime, not the opt-out model US senders are used to under CAN-SPAM. And no, B2B doesn't get a pass — work emails require consent just like consumer ones.

The stakes are real, and the numbers back that up:

  • Up to $10 million per violation for organizations — and $1 million per violation for individuals, according to legal analysis from BLG.
  • A $75,000 penalty against one individual who sent more than 670,000 emails without consent — at the time, the largest penalty ever issued to an individual.
  • 152,603 spam complaints filed with the Spam Reporting Centre in just six months of 2025 (April through September).
  • 75% of CRTC investigations begin with reports from everyday Canadians — your recipients are the ones who trigger scrutiny.

What surprises most senders is who enforcement actually targets. More than 76% of reported messages came from affiliate marketing or legitimate businesses promoting real products — not fraudsters. In 2024–25, the CRTC analyzed roughly 25 high-complaint companies and sent warning letters stating that continued non-compliance may result in further enforcement action. Regulators aren't hunting cold outreach itself — they're hunting sloppy, consent-blind sending.

There's also a border effect worth knowing. Spam sent into Canada falls under CASL regardless of where it originates, so a US or UK sender emailing Canadian prospects is fully exposed to these rules.

The good news: compliance done right is also better outreach. ISED notes that permission-based senders enjoy stronger open and click-through rates and deeper recipient trust. That's why at Worqd we treat B2B outreach as personalized, permission-aware contact with relevant accounts — the opposite of a template blast — and why, when you evaluate any outreach partner, checking their compliance practices should sit near the top of your question list. CASL isn't a wall. It's a filter, and the senders who respect it are the ones who last.

The CRTC puts it plainly: cold email isn't banned in Canada — it's conditional. Under CASL, every commercial electronic message needs three things: consent, sender identification, and a working unsubscribe mechanism. That's it. No consent, no send. The regulator's own FAQ confirms the legislation "sets out some requirements for sending commercial electronic messages" rather than prohibiting them outright.

This makes Canada an opt-in regime, fundamentally different from the U.S. CAN-SPAM opt-out model. You can't email first and ask forgiveness later. The burden of proof sits entirely with the sender — the CRTC states explicitly that the onus is on you to prove consent was obtained. B2B emails get no special exemption; work addresses require consent just like consumer inboxes, and corporations cannot claim a "personal relationship" exemption. Even senders outside Canada fall under CASL if the recipient is in Canada, a point the CRTC reinforces as best practice for all outbound messages.

  • Consent complaints dominate enforcement: 3,950 of 7,654 complaints in one reporting period were consent-related
  • Penalties reach $10 million per violation for organizations and $1 million for individuals
  • The Spam Reporting Centre fielded 152,603 complaints in just six months of 2025
  • 75% of CRTC investigations begin with reports from Canadians

Narrow implied-consent pathways exist — conspicuously published business addresses or a business card received in person — but vendors describe these as "narrow and risky." Purchased lists are prohibited outright. For teams running B2B outreach, the compliant path is personalized, permission-aware outreach to relevant accounts — the opposite of a template blast. That's the approach Worqd builds into every cold email program: consent-first, identification-clear, unsubscribe-functional. It's not just legal protection; ISED notes compliant businesses enjoy better open and click-through rates because permission builds trust.

ctaText: Book a Growth Call to see how permission-aware outreach fits your pipeline. socialProofText: One partner runs the whole path from first click to booked call — no vanity metrics.

Consent is where CASL lives or dies for your outreach program. The law doesn't ban commercial email — it makes consent the price of admission, and the burden of proving that consent sits entirely on you, the sender, according to the CRTC's own guidance.

Express consent is the gold standard. Someone actively opts in — checks a box, replies affirmatively, fills out your form. The CRTC notes that express consent does not expire, but it can be withdrawn at any time, and once it's withdrawn, you must stop. Because the onus is on you to prove consent existed, you need records — and best practice suggests keeping those records for three years after the relationship ends.

Implied consent is where most cold outreach goes wrong. It exists, but the windows are narrow and they tick down:

  • 24 months after a purchase, lease, contract, or accepted quote — an existing business relationship buys you time, not forever.
  • 6 months after an inquiry, application, or a business card handed over in person.
  • A "conspicuously published" business email address can support implied consent — but only if the message is relevant to the person's role and no "do not contact" statement exists. Legal commentators call this pathway narrow and risky.

That last pathway is the one cold emailers reach for most, and it's the one that deserves the most caution. The "their email is on their website, so it's fair game" logic has landed real businesses in trouble: CRTC enforcement data shows consent violations were the single largest complaint category in a recent reporting period, and more than 76% of reported messages came from legitimate businesses, not fraudsters.

Then there's the hard line. Purchased and scraped lists are prohibited outright. You cannot prove consent you never collected, and address harvesting is explicitly banned under CASL. As one compliance guide bluntly puts it, purchased lists are "a CASL violation waiting to happen" — and with penalties reaching $10 million per violation for organizations, that's not a risk worth pricing into your pipeline.

This is why we treat permission-aware outreach as a design constraint, not an afterthought. When Worqd runs B2B cold outreach for clients, every campaign is built around consent you can actually document — personalized, relevant, and sent to accounts where a defensible consent basis exists. It's the opposite of a template blast, and it's the only approach that survives contact with a regulator.

Your CASL-Safe Outreach Checklist

Before you hit send on your next cold email, run it through a simple test: could you prove consent, show who you are, and give the recipient a working way out? If any answer is no, CASL penalties of up to $10 million per violation for organizations are waiting on the other side.

Here's a practical checklist to run every campaign through before launch.

  • Verify your consent basis for every contact. CASL is an opt-in regime, so the onus is on you to prove consent was obtained. Express consent is safest; implied consent through a conspicuously published business email address is described as narrow and risky, and purchased lists are prohibited outright.
  • Keep consent records for 3 years after the relationship ends. If the CRTC comes asking, documentation is your only defence.
  • Include your real name and valid contact information in every message. Identification complaints accounted for 1,460 of 7,654 complaints in one six-month reporting period.
  • Add a working unsubscribe mechanism and process requests within 10 business days. Your contact details must stay valid for at least 60 days after sending.
  • Remember CASL covers more than email. LinkedIn messages and SMS texts count as commercial electronic messages too, so the same consent rules apply.

That last point catches a lot of teams off guard. Many businesses treat LinkedIn outreach and text messaging as informal channels outside the rules, but regulators have been clear that CASL applies to all SMS messages sent and to social media messaging on platforms like LinkedIn.

The stakes are higher than most senders realize. More than 76% of messages reported to the Spam Reporting Centre came from legitimate businesses selling real products and services, not obvious scams. Missing unsubscribe links are a top trigger for enforcement against otherwise honest companies. In 2024–25, the CRTC analyzed roughly 25 high-complaint companies and issued warning letters cautioning that continued non-compliance may result in further enforcement action.

The good news: compliance pays. ISED notes that businesses that ask permission enjoy better open and click-through rates and stronger consumer trust. Permission-aware outreach also tends to be better outreach — relevant, personalized messages to the right accounts convert far better than template blasts.

That's the standard we hold ourselves to at Worqd. Our B2B cold email and outreach work is built as personalized, permission-aware outreach to relevant accounts, and we apply the same consent-first discipline to every channel we run for clients, from paid ads to fast follow-up.

Run this checklist before every send. It takes minutes, and it's the difference between a growing pipeline and an enforcement letter.

Why Permission-Aware Outreach Wins More Booked Calls

Spam complaints don't just create legal risk — they quietly kill your reply rates. Canada's own regulator has documented the payoff of doing this right: ISED notes that businesses asking permission see good open and click-through rates, because asking first shows recipients you respect their inbox — and their trust.

That finding flips the usual framing. Compliance isn't a tax on cold outreach; it's a quality signal. When you email only people whose consent you can actually prove, you're emailing people who are more likely to open, read, and respond. The CRTC puts the burden of proving consent on the sender, which means every compliant list is, by definition, a list of people who welcomed the conversation.

Contrast that with the blast approach. Purchased lists are, as one compliance guide bluntly puts it, "a CASL violation waiting to happen" — and even when they don't draw a penalty, they flood inboxes with irrelevant messages. The numbers show how badly recipients punish that: the Spam Reporting Centre received 152,603 complaints in just six months of 2025, and 75% of CRTC investigations start with a report from an ordinary Canadian.

The compliant path to booked calls looks different:

  • Target relevant accounts, not scraped volumes — relevance is what makes implied-consent pathways defensible.
  • Personalize each message to the recipient's actual role and situation, rather than sending one template to thousands.
  • Document consent carefully, since the sender — not the recipient — has to prove it.
  • Include clear identification and a working unsubscribe in every message, processed promptly.

This is exactly how Worqd runs Canadian B2B outreach: personalized, permission-aware outreach to relevant accounts — the opposite of a template blast. It's not a workaround for CASL; it's outreach designed around the reality that a smaller list of consenting, relevant contacts books more calls than a massive list of annoyed strangers.

If you want your pipeline built that way — full of conversations with people who actually agreed to hear from you — book a growth call. We'll look at where your lead flow is stuck and show you what compliant, high-response outreach could do for your calendar.

Frequently Asked Questions

Is cold email actually illegal in Canada, or is that just a myth?
Cold email isn't illegal in Canada — it's conditional. CASL doesn't prohibit marketing messages; it sets requirements for sending them, starting with consent, plus sender identification and a working unsubscribe mechanism.
Does CASL apply to B2B cold email, or is there an exemption for business-to-business outreach?
There's no B2B exemption — work emails require consent just like consumer emails, and corporations can't claim a personal relationship exemption. CASL applies to any commercial electronic message sent to an electronic address in Canada.
What are the real penalties if I get CASL compliance wrong?
Organizations face up to $10 million per violation and individuals up to $1 million per violation. One individual was fined $75,000 for sending over 670,000 emails without consent, and a company received a $1.1 million penalty for similar violations.
If I'm based in the US or UK, does CASL still apply when I email Canadian prospects?
Yes — spam sent into Canada falls under CASL regardless of where it originates. The CRTC recommends ensuring all commercial electronic messages comply with CASL even when sent from abroad.
Can I use purchased or scraped email lists for Canadian outreach if I include an unsubscribe link?
No — purchased and scraped lists are prohibited outright because you can't prove consent you never collected, and address harvesting is explicitly banned under CASL. An unsubscribe link doesn't fix missing consent.
Does CASL only cover email, or do LinkedIn messages and SMS count too?
CASL covers SMS, Bluetooth messaging, and social media messaging like LinkedIn messages — they all qualify as electronic addresses. The CRTC has explicitly advised businesses that CASL applies to all SMS messages sent.

The Consent Advantage: Why Compliant Outreach Wins

Cold email isn't illegal in Canada — it's conditional. CASL demands consent, clear identification, and a working unsubscribe, and the numbers show regulators are watching: 152,603 spam complaints in just six months of 2025, with 75% of investigations triggered by recipient reports. The businesses getting penalized aren't fraudsters — they're legitimate companies sending without permission. But here's the upside: ISED confirms that permission-aware senders earn better open rates, stronger trust, and more replies. Compliance isn't a tax on outreach; it's a quality filter that leaves you talking to people who actually want to hear from you. At Worqd, we build B2B outreach around that reality — personalized, permission-aware contact with relevant accounts, not template blasts. If your pipeline is stuck on volume that doesn't convert, book a growth call. We'll show you what consent-first outreach can do for your calendar.

Want help putting this into action?

Book a Growth Call

Stay in the Loop