What are the three elements of valid consent?
Learn the three elements of valid consent under CASL: specific, informed, and unambiguous. Avoid fines up to $10M and keep your email outreach compliant.

What are the three elements of valid consent?
Key Facts
- Every commercial email must include sender identification, contact details, and a working unsubscribe link that stays functional for 60 days according to CASL guidance.
- Canada's Anti-Spam Legislation imposes fines up to $10 million per violation for corporations as stated in the CRTC's official FAQ.
- Consent must be specific, informed, and unambiguous to comply with CASL regulations as per Canada's official CASL guidance.
- A Canadian company was fined $1.3 million for unsolicited bulk emails with deceptive subject lines as recorded in recent enforcement cases.
- Implied consent expires 2 years after a purchase or 6 months after an inquiry according to consent experts.
- Unsubscribe requests must be processed within 10 business days to meet CASL compliance per CRTC requirements.
Introduction
If you send a single marketing email to a Canadian recipient without valid consent, you could be on the hook for up to $10 million per violation. That is not a typo — it is the penalty ceiling the CRTC's official FAQ cites for corporations, with individuals facing up to $1 million per violation, according to CASL guidance.
Canada's Anti-Spam Legislation, or CASL, is widely considered the toughest of the major anti-spam frameworks — stricter than CAN-SPAM in the U.S. and even GDPR in one key respect: it generally requires consent before you hit send, not just an easy opt-out afterward. And the regulator is not bluffing. In 2023, a Canadian firm was fined $1.3 million for unsolicited bulk email with deceptive subject lines and hidden sender information, per enforcement records.
Here is where it gets confusing. When people ask about the "three elements of valid consent," they usually mean one of two things:
- The three mandatory components every commercial electronic message must contain: sender identification, contact information, and a working unsubscribe mechanism
- The three qualities consent itself must have: specific, informed, and unambiguous
- The burden of proof — which sits entirely with the sender, not the recipient
Both framings matter, and this article covers both. Canada's official CASL guidance states that consent must be specific, informed, and unambiguous, while every compliant message must also carry the three structural elements — identification, contact details, and an unsubscribe that stays functional for 60 days and is processed within 10 business days, per the CRTC's guidance.
The stakes are real for anyone running outreach or lead generation. A contact sitting in your CRM does not prove consent — compliance experts are blunt about this. And implied consent expires: two years after a purchase or contract, six months after a mere inquiry.
This matters to us at Worqd because our own B2B outreach is built on permission-aware, personalized contact — the opposite of a template blast. Getting consent right is not just legal hygiene; as deliverability research notes, it directly improves inbox placement. Compliant outreach simply performs better.
In the sections ahead, we break down each element in plain language, so you can audit your own outreach — or your provider's — with confidence.
Key Concepts
Valid consent under CASL isn't a single checkbox — it's a set of requirements that regulators, courts, and your email deliverability all depend on. Get one element wrong, and your entire outreach program sits on shaky legal ground.
When people ask about the three elements, they usually mean one of two things. The first framing comes from the message side: CASL guidance states that every commercial electronic message (CEM) must contain sender identification information, contact information, and a functional unsubscribe mechanism. Miss any one of these and the message itself is non-compliant, regardless of how the contact got onto your list.
The second framing describes the quality of consent itself. According to Canada's official CASL guidance, consent must be specific, informed, and unambiguous. That means the person knew who was asking, what they were agreeing to receive, and gave a clear, voluntary answer.
Sender identification means naming your business or yourself, plus the entity on whose behalf the message is sent. Contact information requires a valid physical address, phone number, email, or website. The unsubscribe mechanism must be clear, prominent, easy to use, functional for 60 days, and processed within 10 business days per CRTC requirements.
For the consent itself, the bar is an affirmative action — never silence, pre-ticked boxes, or assumed permission. As consent experts note, the request wording must identify the sender, describe the message types, stand separate from other actions, and explain how to withdraw.
The stakes are real. CRTC penalties reach up to $10 million per violation for corporations and $1 million for individuals, according to the CRTC's official FAQ. Canadian firms have already been fined $1.3 million and $1.1 million in recent enforcement cases, and a U.S. lead generator paid $340,000 for scraping Canadian emails without consent.
Critically, the onus of proving consent falls on the sender. A contact sitting in your CRM proves nothing. That's why disciplined outreach programs — like Worqd's own booking funnel, which requires an explicit "I agree to be contacted about my request" opt-in — treat consent capture as a documented process, not an afterthought.
To stay on solid ground, every outreach program should:
- Capture consent with a dedicated, unchecked opt-in — never bundled into a purchase or terms acceptance
- Record the consent basis, date, method, and exact opt-in wording for every contact, and retain records for at least 3 years after the last message
- Treat implied consent as dated: it expires 2 years after a purchase or contract, and just 6 months after an inquiry
- Verify both B2B conditions before sending — a conspicuously published address without a refusal statement, and a message relevant to the recipient's role
As one practical rule puts it: if you're unsure, assume you don't have consent. Compliance isn't just legal hygiene — it directly improves inbox placement, turning a regulatory obligation into a competitive advantage.
Best Practices
Knowing the rules is one thing; running your outreach so you can prove compliance is another. These practices turn the three elements of valid consent into habits your team can actually follow every day.
Start by treating every consent record as evidence. Under CASL, the sender bears the burden of proving consent, whether express or implied — a contact sitting in your CRM proves nothing on its own, per CRTC guidance. For each contact, capture the email address, the consent basis, the date, the method, and the exact opt-in wording, as compliance practitioners recommend. Retain those records for at least 3 years after the last message sent under that consent.
Next, structure every message around the three mandatory elements. Each commercial electronic message must identify the sender, include valid contact information, and carry a working unsubscribe mechanism that stays functional for 60 days and is processed within 10 business days, according to CASL guidance citing the CRTC. Build these into your templates so no message goes out without them.
For collecting express consent, keep it clean and unbundled:
- Use a dedicated, unchecked opt-in — no pre-ticked boxes, silence, or assumed permission.
- State who you are, what type of messages you send, and how the recipient can withdraw.
- Keep consent voluntary and separate from purchases or terms — never bundle it.
This mirrors how Worqd's own booking funnel works: every inquiry requires an explicit "I agree to be contacted about my request" action, and the details are used only to prepare for the call. That same permission-first mindset shapes our B2B outreach — personalized, relevant messages to the right people rather than template blasts.
For B2B outreach specifically, verify both implied-consent conditions before sending: the recipient's email must be conspicuously published without a refusal statement, and your message must be relevant to their role, as cold email compliance guides make clear. A published email address is a narrow signal of relevance, not an evergreen subscription.
Finally, adopt a simple default: if you can't verify consent, assume you don't have it. The stakes are real — penalties reach up to $10 million per violation for corporations and $1 million for individuals, and enforcement cases include fines of $1.3 million and $1.1 million for missing opt-in consent, unsubscribe mechanisms, or sender identification, per CASL enforcement case reviews. When in doubt, don't send — and treat every implied-consent contact as a dated record with an expiry, not a permanent subscriber.
Implementation
Knowing the three elements is one thing — putting them into daily practice is where most businesses stumble. Here is how to build consent into your outreach process so it holds up under scrutiny.
Start with how you collect permission. Express consent requires a dedicated, unchecked opt-in — no pre-ticked boxes, no bundling consent into a purchase or terms acceptance. The wording must identify who is sending, describe the type of messages, and explain how to withdraw. This is why our own booking funnel at Worqd requires an explicit "I agree to be contacted about my request" checkbox rather than assuming interest implies permission.
Next, document everything. Under CASL, the burden of proving consent falls on the sender — and as compliance guidance points out, a contact sitting in your CRM does not count as proof. Your records should capture:
- The email address and consent basis (express or implied)
- The date, method, and exact opt-in wording
- For implied consent, the qualifying transaction or inquiry — treated as a dated record with an expiry, not a permanent subscriber
- Every withdrawal, logged in a suppression record
Watch the clock on implied consent. You have two years from a purchase or written contract, and six months from an inquiry that doesn't lead to a transaction, according to CRTC guidance. Once the window closes, you need express consent to keep sending.
For B2B cold outreach, verify both conditions before hitting send: the recipient's address must be conspicuously published without a refusal statement, and your message must be relevant to their business role. A published email is a narrow signal of relevance, not an evergreen subscription. That is why personalized, permission-aware outreach to relevant accounts beats a template blast every time — it is both the compliant approach and the more effective one.
Finally, build your message template around the three mandatory elements: sender identification, valid contact information, and an unsubscribe mechanism that stays functional for 60 days and gets processed within 10 business days, per CRTC-cited requirements.
When in doubt, don't send. With penalties reaching up to $10 million per violation for corporations, enforcement guidance is blunt: if you can't verify consent, assume you don't have it.
Conclusion
The importance of adhering to Canada’s Anti-Spam Legislation (CASL) cannot be overstated, as noncompliance risks severe financial penalties and reputational damage. Understanding the dual frameworks of valid consent—three mandatory message elements and specific, informed, and unambiguous consent—is critical for businesses navigating digital communication. These requirements ensure transparency, respect for user autonomy, and legal protection.
Every commercial electronic message (CEM) must include sender identification, contact details, and a functional unsubscribe mechanism, while consent itself demands clarity, voluntariness, and precision. For instance, a 2023 case saw a Canadian firm fined $1.3 million for violating these principles, underscoring the stakes involved.
Businesses must prioritize proactive compliance by verifying consent types, documenting processes, and aligning practices with CASL’s strict standards. This includes distinguishing between express and implied consent, understanding time limits (e.g., 2 years for purchases, 6 months for inquiries), and ensuring unsubscribe requests are resolved within 10 business days.
- Audit existing contact lists to confirm consent validity
- Implement clear opt-in mechanisms, such as dedicated checkboxes with explicit language
- Leverage tools like Worqd’s booking funnel, which requires explicit consent before initiating outreach
For B2B outreach, personalized, permission-aware strategies are essential, avoiding generic blasts in favor of targeted, relevant communication. As one expert notes, compliance is not just legal hygiene—it directly impacts inbox placement and trust.
By embedding these practices into workflows, businesses mitigate risks and build long-term credibility. The path to compliance is clear, but it demands diligence, documentation, and a commitment to ethical engagement.
Frequently Asked Questions
What are the three elements of valid consent under CASL?
How much can I actually be fined for sending one non-compliant email to a Canadian recipient?
If a contact is in my CRM, does that count as proof of consent?
How long does implied consent last before it expires?
Can I cold email someone if their email address is publicly listed on their company website?
What does a CASL-compliant unsubscribe mechanism look like?
Consent First, Send Second
The three elements of valid consent come down to two checklists: every message must carry sender identification, contact information, and a working unsubscribe, and the consent behind it must be specific, informed, and unambiguous. Get either wrong and the risk is real — penalties reach up to $10 million per violation for corporations, per the CRTC's official FAQ. But the bigger takeaway is simpler: if you can't prove consent, assume you don't have it. Audit your lists, document the basis, date, and wording for every contact, and treat implied consent as a dated record with an expiry. The payoff goes beyond avoiding fines — permission-aware outreach lands in more inboxes and builds more trust than a template blast ever will. That's exactly how we approach B2B outreach at Worqd: personalized, relevant messages to the right people, with explicit consent captured up front. If you'd rather grow your pipeline without gambling on compliance, book a growth call and let's talk about what a permission-first plan could do for your lead flow.
Want help putting this into action?
Book a Growth Call