Back to insights
Checking Compliance Practices

What does "consent" mean under CASL?

Learn what 'consent' means under CASL. Avoid multimillion-dollar fines with compliant email practices. Optimize your outreach today.

What does "consent" mean under CASL?

What does "consent" mean under CASL?

Key Facts

A single email sent without provable consent can cost your business up to $10 million. That's the maximum penalty under Canada's Anti-Spam Legislation for businesses — and $1 million for individuals, with directors and officers personally on the hook. Consent isn't paperwork. It's the legal foundation of every email, text, and LinkedIn message you send.

The enforcement record shows that no company is too big or too careful to get this wrong. Compu-Finder was fined $1.1 million for sending emails without proper consent. Porter Airlines paid $150,000 — not for spamming anyone, but for keeping inadequate records of the consent it claimed to have.

That second case is the one most businesses should lose sleep over. Under CASL, the CRTC puts the burden of proof squarely on the sender: you must be able to demonstrate you obtained consent, whether express or implied. Having no verifiable record of how and when someone opted in is often the weakest point in an audit.

In other words, the most common failure isn't malicious spamming. It's consent you actually had — but can't prove. As Global Relay puts it, CASL is less a warning and more a magnifying glass held over your consent records.

The stakes get higher once you understand what counts as a commercial electronic message. "Electronic address" covers email, phone accounts, instant messaging, and similar channels — including Facebook Messenger and LinkedIn messaging. And CASL applies to most B2B communication too. The belief that business emails are exempt is often mistakenly over-applied and still requires an existing relationship.

So what does defensible consent capture look like? Strong programs record:

  • Who consented, and which address or account they consented from
  • When it happened — exact date and time, plus IP address where possible
  • How they opted in — the form, the checkbox (unchecked by default), the campaign
  • The exact consent text the person saw and agreed to

This is why we treat consent tracking as a first-class part of outreach at Worqd, not an afterthought. Personalized, permission-aware outreach to relevant accounts only works if the permission itself is documented. For anyone running lead generation, database reactivation, or multi-channel follow-up — especially with implied consent's 2-year limit on business relationships and 6-month limit on inquiries — the expiry dates and the evidence trail matter as much as the message itself.

Get consent right, and CASL is a non-issue. Get it wrong, or fail to prove you got it right, and the fine could outsize your entire marketing budget many times over.

Consent under CASL isn't a vague handshake — it's a legal requirement with a hard burden of proof on you, the sender. The CRTC is blunt about this: the onus of proving consent, whether express or implied, falls on the person claiming it. That's why understanding the two consent types matters before you send a single commercial message.

Express consent is a positive, explicit opt-in — someone verbally or in writing agrees to receive your messages, typically by subscribing through a form. If you use a checkbox to request consent, it must be unchecked by default. The big advantage: express consent does not expire unless the recipient withdraws it, which they can do at any time.

Implied consent works differently. Under subsection 10(9) of CASL, it only exists in specific circumstances — and it always comes with a clock:

  • Existing business relationship (a purchase, lease, or written contract): implied consent lasts up to 2 years.
  • Inquiry or application about your product or service: implied consent lasts just 6 months.
  • Conspicuously published email addresses: consent is implied only if the address was published without a statement declining messages, and your message must relate to the recipient's business role, functions, or duties.

A valid consent request also has required elements. You must explain why you're obtaining consent, describe the types of messages you'll send, identify yourself with a valid mailing address and contact details, and state that the recipient can withdraw at any time. Missing any of these weakens your position if the CRTC comes asking.

One nuance trips up many marketers: consent is channel-specific. Someone who opted into email hasn't opted into SMS — texting always requires explicit consent, while email permits implied consent in certain conditions. If your outreach spans email, phone, and social channels, you need consent captured for each.

This is why we treat consent as a design decision, not an afterthought. When Worqd builds a lead-handling path — from ads to instant follow-up to reactivating old contacts in your CRM — the consent type and its expiry date shape what we can send, when, and on which channel. Any partner you work with should be able to tell you exactly how consent is captured and recorded for every message they send on your behalf.

Under CASL, saying "they opted in" isn't enough — you have to prove it. The CRTC is explicit: "The onus of proving consent, be it express or implied, is on the person who claims they have consent." If you can't produce the record, the consent effectively doesn't exist in the regulator's eyes.

That makes record-keeping the practical backbone of compliance. Compliance analysts note that having no verifiable record of how and when a customer consented is "often the weakest point in an audit." Porter Airlines learned this the hard way — a $150,000 CAD fine was levied for inadequate consent records, not for the absence of consent itself.

So what should a complete consent record capture? The details matter more than most senders realize:

  • Who consented — the specific email address or phone number, matched to the exact recipient.
  • When it happened — a full timestamp, including the date.
  • How it was obtained — form submission, checkbox, verbal, or written.
  • What text was shown — the exact wording of the consent request, since it must have explained the purpose, message types, and withdrawal rights.
  • Where it came from — the IP address, which compliance experts recommend recording alongside the date and consent text.

Three pitfalls trip up even careful senders. First, legacy list errors: contacts collected before July 1, 2014 that were never re-confirmed can leave you with no provable consent at all. Second, the B2B commercial-activity exemption is often mistakenly over-applied — it still requires an existing relationship, not just a business email address. Third, third-party sender liability: your organization remains liable even when a vendor sends messages on your behalf, so any outreach partner — Worqd included when running B2B outreach for clients — needs to document consent to the same standard you would.

How long must you keep these records? The answer is genuinely unresolved. One vendor source claims records must be retained for 3 years after the business relationship ends, while other compliance guidance notes that no prescribed retention period exists anywhere in the legislation. With penalties reaching $10 million per violation for businesses, the safe path is simple: keep your consent records indefinitely.

How to Run CASL-Compliant Outreach: A Practical Checklist

Complying with Canada’s Anti-Spam Legislation (CASL) isn’t just about avoiding penalties—it’s about building trust and ensuring your outreach resonates with real audiences. For businesses running lead generation or database reactivation programs, a structured approach to consent is critical. By aligning with CASL requirements, you not only mitigate risk but also create more engaged, high-quality lists.

A CASL-compliant outreach strategy starts with defaulting to express consent. Unlike implied consent, which expires after 2 years for existing business relationships or 6 months for inquiries, express consent requires a positive opt-in action and remains valid indefinitely unless withdrawn. This approach reduces compliance risks and ensures you’re messaging people who genuinely want to hear from you. Research shows that explicit consent is the safest and most transparent method, especially given the burden of proof placed on senders.

To maintain compliance, implement these key practices:

  • Run re-permission campaigns 90 days before implied consent expires, ensuring contacts reaffirm their interest.
  • Suppress lapsed contacts immediately once consent lapses, as sending to inactive lists violates CASL’s core principles.
  • Never purchase email lists—purchased lists are a violation waiting to happen and transfer no valid consent.
  • Capture consent per channel, as email and SMS require distinct opt-ins under CASL.
  • Process unsubscribe requests within 10 business days, a requirement mandated by CASL.

Worqd’s approach emphasizes permission-aware, personalized outreach, ensuring explicit consent is captured in every form. By prioritizing genuine engagement over volume, businesses like Worqd build lists that convert better—because they’re populated with people who actively choose to participate. This alignment with CASL isn’t just compliance; it’s a competitive advantage.

Frequently Asked Questions

What's the difference between express and implied consent under CASL?
Express consent is an explicit opt-in — verbal, written, or a form subscription — and it does not expire unless the recipient withdraws it. Implied consent only exists in specific situations under subsection 10(9) of CASL, like an existing business relationship (valid up to 2 years) or a recent inquiry (6 months), per ISED Canada.
Who has to prove consent if the CRTC comes asking — me or the recipient?
You do. The CRTC is explicit that the onus of proving consent, express or implied, falls on the person claiming it — which is why Porter Airlines paid $150,000 not for spamming, but for keeping inadequate consent records. If you can't produce the record, the consent effectively doesn't exist.
Does CASL apply to B2B emails, or just consumer marketing?
CASL applies to most B2B communication too. The exemption for messages relevant to a recipient's commercial activity is often mistakenly over-applied — it still requires an existing relationship, not just a business email address. And "electronic address" covers LinkedIn and Facebook Messenger, not just email, per the CRTC.
If someone opted into my emails, can I also text them?
No — consent is channel-specific. Email permits implied consent in certain conditions, but texting always requires explicit consent. If your outreach spans email, phone, and social channels, you need consent captured for each one.
What should I actually record when someone consents?
Capture who consented (the exact address or account), when (full timestamp), how (form, checkbox unchecked by default, campaign), the exact consent text they saw, and the IP address where possible — compliance experts say missing records are often the weakest point in an audit. Since no prescribed retention period exists in the legislation, the safe path is to keep records indefinitely.
Can I buy an email list and message it if the seller says it's CASL-compliant?
No. Purchased email lists are a violation waiting to happen — selling lists without the business transfers no valid consent, per the CRTC. With penalties up to $10 million per violation for businesses, build your list on genuine opt-ins instead — it's what Worqd's permission-aware outreach is built on.

Consent You Can Prove Is Worth More Than Consent You Have

Under CASL, consent comes in exactly two forms: express consent, which never expires unless withdrawn, and implied consent, which carries hard deadlines — 2 years for existing business relationships, 6 months for inquiries. The burden of proof sits entirely with you, the sender. As the Porter Airlines case showed, a $150,000 fine for inadequate consent records can land even when consent existed. Your next steps are practical: audit your lists for pre-2014 contacts, capture consent per channel with unchecked-by-default checkboxes, record who, when, how, and what text was shown for every opt-in, and run re-permission campaigns before implied consent lapses. If a vendor sends outreach on your behalf, you remain liable — so ask them exactly how consent is documented for every message. At Worqd, we treat permission-aware outreach as a design decision, not an afterthought, because compliant lists convert better. Want a growth partner who builds consent into every step from first click to booked call? Book a growth call and see how the whole path can work together.

Want help putting this into action?

Book a Growth Call
TopicsCASL consent definitionAvoid CASL penaltiesCASL email complianceCanadian anti-spam lawEmail consent best practicesB2B marketing complianceCASL consent tracking

Stay in the Loop