Back to insights
Checking Compliance Practices

What are the three elements of valid consent?

Learn the three elements of valid consent under CASL: specific, informed, and unambiguous. Avoid fines up to $10M and keep your email outreach compliant.

What are the three elements of valid consent?

What are the three elements of valid consent?

Key Facts

Introduction

If you send a single marketing email to a Canadian recipient without valid consent, you could be on the hook for up to $10 million per violation. That is not a typo — it is the penalty ceiling the CRTC's official FAQ cites for corporations, with individuals facing up to $1 million per violation, according to CASL guidance.

Canada's Anti-Spam Legislation, or CASL, is widely considered the toughest of the major anti-spam frameworks — stricter than CAN-SPAM in the U.S. and even GDPR in one key respect: it generally requires consent before you hit send, not just an easy opt-out afterward. And the regulator is not bluffing. In 2023, a Canadian firm was fined $1.3 million for unsolicited bulk email with deceptive subject lines and hidden sender information, per enforcement records.

Here is where it gets confusing. When people ask about the "three elements of valid consent," they usually mean one of two things:

  • The three mandatory components every commercial electronic message must contain: sender identification, contact information, and a working unsubscribe mechanism
  • The three qualities consent itself must have: specific, informed, and unambiguous
  • The burden of proof — which sits entirely with the sender, not the recipient

Both framings matter, and this article covers both. Canada's official CASL guidance states that consent must be specific, informed, and unambiguous, while every compliant message must also carry the three structural elements — identification, contact details, and an unsubscribe that stays functional for 60 days and is processed within 10 business days, per the CRTC's guidance.

The stakes are real for anyone running outreach or lead generation. A contact sitting in your CRM does not prove consent — compliance experts are blunt about this. And implied consent expires: two years after a purchase or contract, six months after a mere inquiry.

This matters to us at Worqd because our own B2B outreach is built on permission-aware, personalized contact — the opposite of a template blast. Getting consent right is not just legal hygiene; as deliverability research notes, it directly improves inbox placement. Compliant outreach simply performs better.

In the sections ahead, we break down each element in plain language, so you can audit your own outreach — or your provider's — with confidence.

Key Concepts

Valid consent under CASL isn't a single checkbox — it's a set of requirements that regulators, courts, and your email deliverability all depend on. Get one element wrong, and your entire outreach program sits on shaky legal ground.

When people ask about the three elements, they usually mean one of two things. The first framing comes from the message side: CASL guidance states that every commercial electronic message (CEM) must contain sender identification information, contact information, and a functional unsubscribe mechanism. Miss any one of these and the message itself is non-compliant, regardless of how the contact got onto your list.

The second framing describes the quality of consent itself. According to Canada's official CASL guidance, consent must be specific, informed, and unambiguous. That means the person knew who was asking, what they were agreeing to receive, and gave a clear, voluntary answer.

Sender identification means naming your business or yourself, plus the entity on whose behalf the message is sent. Contact information requires a valid physical address, phone number, email, or website. The unsubscribe mechanism must be clear, prominent, easy to use, functional for 60 days, and processed within 10 business days per CRTC requirements.

For the consent itself, the bar is an affirmative action — never silence, pre-ticked boxes, or assumed permission. As consent experts note, the request wording must identify the sender, describe the message types, stand separate from other actions, and explain how to withdraw.

The stakes are real. CRTC penalties reach up to $10 million per violation for corporations and $1 million for individuals, according to the CRTC's official FAQ. Canadian firms have already been fined $1.3 million and $1.1 million in recent enforcement cases, and a U.S. lead generator paid $340,000 for scraping Canadian emails without consent.

Critically, the onus of proving consent falls on the sender. A contact sitting in your CRM proves nothing. That's why disciplined outreach programs — like Worqd's own booking funnel, which requires an explicit "I agree to be contacted about my request" opt-in — treat consent capture as a documented process, not an afterthought.

To stay on solid ground, every outreach program should:

  • Capture consent with a dedicated, unchecked opt-in — never bundled into a purchase or terms acceptance
  • Record the consent basis, date, method, and exact opt-in wording for every contact, and retain records for at least 3 years after the last message
  • Treat implied consent as dated: it expires 2 years after a purchase or contract, and just 6 months after an inquiry
  • Verify both B2B conditions before sending — a conspicuously published address without a refusal statement, and a message relevant to the recipient's role

As one practical rule puts it: if you're unsure, assume you don't have consent. Compliance isn't just legal hygiene — it directly improves inbox placement, turning a regulatory obligation into a competitive advantage.

Best Practices

Knowing the rules is one thing; running your outreach so you can prove compliance is another. These practices turn the three elements of valid consent into habits your team can actually follow every day.

Start by treating every consent record as evidence. Under CASL, the sender bears the burden of proving consent, whether express or implied — a contact sitting in your CRM proves nothing on its own, per CRTC guidance. For each contact, capture the email address, the consent basis, the date, the method, and the exact opt-in wording, as compliance practitioners recommend. Retain those records for at least 3 years after the last message sent under that consent.

Next, structure every message around the three mandatory elements. Each commercial electronic message must identify the sender, include valid contact information, and carry a working unsubscribe mechanism that stays functional for 60 days and is processed within 10 business days, according to CASL guidance citing the CRTC. Build these into your templates so no message goes out without them.

For collecting express consent, keep it clean and unbundled:

  • Use a dedicated, unchecked opt-in — no pre-ticked boxes, silence, or assumed permission.
  • State who you are, what type of messages you send, and how the recipient can withdraw.
  • Keep consent voluntary and separate from purchases or terms — never bundle it.

This mirrors how Worqd's own booking funnel works: every inquiry requires an explicit "I agree to be contacted about my request" action, and the details are used only to prepare for the call. That same permission-first mindset shapes our B2B outreach — personalized, relevant messages to the right people rather than template blasts.

For B2B outreach specifically, verify both implied-consent conditions before sending: the recipient's email must be conspicuously published without a refusal statement, and your message must be relevant to their role, as cold email compliance guides make clear. A published email address is a narrow signal of relevance, not an evergreen subscription.

Finally, adopt a simple default: if you can't verify consent, assume you don't have it. The stakes are real — penalties reach up to $10 million per violation for corporations and $1 million for individuals, and enforcement cases include fines of $1.3 million and $1.1 million for missing opt-in consent, unsubscribe mechanisms, or sender identification, per CASL enforcement case reviews. When in doubt, don't send — and treat every implied-consent contact as a dated record with an expiry, not a permanent subscriber.

Implementation

Knowing the three elements is one thing — putting them into daily practice is where most businesses stumble. Here is how to build consent into your outreach process so it holds up under scrutiny.

Start with how you collect permission. Express consent requires a dedicated, unchecked opt-in — no pre-ticked boxes, no bundling consent into a purchase or terms acceptance. The wording must identify who is sending, describe the type of messages, and explain how to withdraw. This is why our own booking funnel at Worqd requires an explicit "I agree to be contacted about my request" checkbox rather than assuming interest implies permission.

Next, document everything. Under CASL, the burden of proving consent falls on the sender — and as compliance guidance points out, a contact sitting in your CRM does not count as proof. Your records should capture:

  • The email address and consent basis (express or implied)
  • The date, method, and exact opt-in wording
  • For implied consent, the qualifying transaction or inquiry — treated as a dated record with an expiry, not a permanent subscriber
  • Every withdrawal, logged in a suppression record

Watch the clock on implied consent. You have two years from a purchase or written contract, and six months from an inquiry that doesn't lead to a transaction, according to CRTC guidance. Once the window closes, you need express consent to keep sending.

For B2B cold outreach, verify both conditions before hitting send: the recipient's address must be conspicuously published without a refusal statement, and your message must be relevant to their business role. A published email is a narrow signal of relevance, not an evergreen subscription. That is why personalized, permission-aware outreach to relevant accounts beats a template blast every time — it is both the compliant approach and the more effective one.

Finally, build your message template around the three mandatory elements: sender identification, valid contact information, and an unsubscribe mechanism that stays functional for 60 days and gets processed within 10 business days, per CRTC-cited requirements.

When in doubt, don't send. With penalties reaching up to $10 million per violation for corporations, enforcement guidance is blunt: if you can't verify consent, assume you don't have it.

Conclusion

The importance of adhering to Canada’s Anti-Spam Legislation (CASL) cannot be overstated, as noncompliance risks severe financial penalties and reputational damage. Understanding the dual frameworks of valid consent—three mandatory message elements and specific, informed, and unambiguous consent—is critical for businesses navigating digital communication. These requirements ensure transparency, respect for user autonomy, and legal protection.

Every commercial electronic message (CEM) must include sender identification, contact details, and a functional unsubscribe mechanism, while consent itself demands clarity, voluntariness, and precision. For instance, a 2023 case saw a Canadian firm fined $1.3 million for violating these principles, underscoring the stakes involved.

Businesses must prioritize proactive compliance by verifying consent types, documenting processes, and aligning practices with CASL’s strict standards. This includes distinguishing between express and implied consent, understanding time limits (e.g., 2 years for purchases, 6 months for inquiries), and ensuring unsubscribe requests are resolved within 10 business days.

  • Audit existing contact lists to confirm consent validity
  • Implement clear opt-in mechanisms, such as dedicated checkboxes with explicit language
  • Leverage tools like Worqd’s booking funnel, which requires explicit consent before initiating outreach

For B2B outreach, personalized, permission-aware strategies are essential, avoiding generic blasts in favor of targeted, relevant communication. As one expert notes, compliance is not just legal hygiene—it directly impacts inbox placement and trust.

By embedding these practices into workflows, businesses mitigate risks and build long-term credibility. The path to compliance is clear, but it demands diligence, documentation, and a commitment to ethical engagement.

Frequently Asked Questions

What are the three elements of valid consent under CASL?
There are two ways to read this. Every commercial electronic message must contain three mandatory elements — sender identification, contact information, and a functional unsubscribe mechanism — per CASL guidance. Separately, the consent itself must be specific, informed, and unambiguous, meaning the person knew who was asking, what they'd receive, and gave a clear, voluntary answer.
How much can I actually be fined for sending one non-compliant email to a Canadian recipient?
Penalties reach up to $10 million per violation for corporations and $1 million for individuals, according to the CRTC's official FAQ. Enforcement is real: a Canadian firm was fined $1.3 million in 2023, and a U.S. lead generator paid $340,000 for scraping Canadian emails without consent.
If a contact is in my CRM, does that count as proof of consent?
No — under CASL, the burden of proving consent falls entirely on the sender, and a contact sitting in your CRM proves nothing, per CRTC guidance. You need records showing the consent basis, date, method, and exact opt-in wording for every contact.
How long does implied consent last before it expires?
Implied consent lasts two years from a purchase or written contract, and just six months from an inquiry that doesn't lead to a transaction, per compliance guidance. Treat every implied-consent contact as a dated record with an expiry, not a permanent subscriber.
Can I cold email someone if their email address is publicly listed on their company website?
Only if two conditions are both true: the address is conspicuously published without a refusal statement, and your message is relevant to the person's business role, per cold email compliance guidance. A published email is a narrow signal of relevance, not an evergreen subscription — so personalized, role-relevant outreach beats a template blast.
What does a CASL-compliant unsubscribe mechanism look like?
It must be clear, prominent, and easy to use, stay functional for 60 days after the message is sent, and be processed within 10 business days, per CRTC-cited requirements. Log every withdrawal in a suppression record so you can prove compliance later.

Consent First, Send Second

The three elements of valid consent come down to two checklists: every message must carry sender identification, contact information, and a working unsubscribe, and the consent behind it must be specific, informed, and unambiguous. Get either wrong and the risk is real — penalties reach up to $10 million per violation for corporations, per the CRTC's official FAQ. But the bigger takeaway is simpler: if you can't prove consent, assume you don't have it. Audit your lists, document the basis, date, and wording for every contact, and treat implied consent as a dated record with an expiry. The payoff goes beyond avoiding fines — permission-aware outreach lands in more inboxes and builds more trust than a template blast ever will. That's exactly how we approach B2B outreach at Worqd: personalized, relevant messages to the right people, with explicit consent captured up front. If you'd rather grow your pipeline without gambling on compliance, book a growth call and let's talk about what a permission-first plan could do for your lead flow.

Want help putting this into action?

Book a Growth Call
TopicsCASL valid consent requirementsCASL compliance for email marketingCanada anti-spam legislation consentexpress consent CASL rulesCASL unsubscribe requirementsB2B cold email compliance Canada

Stay in the Loop