Back to insights
Checking Compliance Practices

What does "express consent" mean?

Learn what express consent means under CASL, which shortcuts don't count, and how to prove consent. Avoid penalties up to $10M with compliant opt-ins.

What does "express consent" mean?

What does "express consent" mean?

Key Facts

Most outreach programs don't fail because marketers are careless. They fail because the shortcuts look like consent — until a regulator, or a recipient hitting "spam," decides otherwise. The gap between real consent and compliance theater is where programs quietly accumulate risk, one send at a time.

The CRTC is blunt about what counts: express consent requires that "the recipient must take a proactive action to indicate their express consent," obtained through an opt-in mechanism such as signing up at your website. That definition disqualifies most of what passes for consent in the wild:

  • Pre-checked boxes — the recipient took no action, so no consent exists (https://www.smarte.pro/blog/casl-compliance)
  • Buried terms — opt-ins "cannot be buried in the terms and conditions of another service or contract" (https://gowlingwlg.com/en/insights-resources/guides/2023/doing-business-in-canada-casl)
  • Purchased lists — "I bought a list" is not a defense, because purchased lists almost never carry valid CASL consent (https://tomba.io/blog/casl-email-compliance)
  • Bundled consent — "By creating an account, you agree to receive marketing emails" is a documented non-compliant pattern (https://www.sender.net/blog/casl-compliance/)

Then there's implied consent — the shortcut that fails silently. It expires 2 years after a purchase and just 6 months after an inquiry, per CRTC guidance. As one compliance analysis puts it, implied consent "expires silently — and on the day it expires, every email you send becomes a violation" (https://www.sender.net/blog/casl-compliance/). Many teams never see the expiry coming.

The stakes make the shortcuts expensive. CASL carries penalties up to $10 million per violation for organizations (https://gowlingwlg.com/en/insights-resources/guides/2023/doing-business-in-canada-casl), and enforcement is real: Compu-Finder received a $1.1M notice of violation, later reduced to $200,000 (https://www.smarte.pro/blog/casl-compliance). Remember, too, that CASL follows the recipient, not the sender — there's no "we're not based in Canada" exemption.

And the burden of proof always sits with you. "The onus of proving consent, be it express or implied, is on the person who claims they have consent" (https://crtc.gc.ca/eng/com500/guide.htm). If you can't produce the timestamp, the method, and the scope of agreement, you don't have consent — you have a claim.

This is why, when we at Worqd run targeted outreach, we treat permission as the starting point, not an afterthought. Our booking funnel requires an explicit opt-in — "I agree to be contacted about my request" — and our B2B outreach is personalized to relevant accounts, the opposite of a template blast. It's also the right question to ask any provider you're evaluating: show me exactly how consent is captured, and prove you can document it. If the answer is a shrug, you're looking at compliance theater — and carrying the risk yourself.

Express consent sounds simple — someone said yes — but under Canada's Anti-Spam Legislation, "yes" has a precise legal shape, and getting it wrong carries penalties of up to $10 million per violation for organizations, according to legal guidance from Gowling WLG.

The CRTC, the federal regulator that enforces CASL, defines it directly: a person has clearly agreed to receive a commercial electronic message, either in writing or orally, and must take a proactive action to show it. In other words, express consent only exists through an opt-in mechanism — ticking an unchecked box, submitting a form, or saying yes to a specific request — per the CRTC's official guidance.

That word "proactive" eliminates most of the shortcuts marketers once relied on. Pre-checked boxes don't count. Consent buried in terms and conditions doesn't count. Bundled language like "by creating an account, you agree to receive marketing emails" doesn't count either, as compliance experts at Sender document. Silence is never consent.

A valid opt-in request must also disclose specific information:

  • The name of the organization requesting consent
  • The types and purposes of the messages you'll send
  • A mailing address plus one additional contact method
  • A statement that consent can be withdrawn at any time

This is why Worqd's booking funnel captures explicit agreement — "I agree to be contacted about my request" — rather than assuming interest from a form fill. It's a textbook opt-in, and it's what separates permission-aware outreach from a template blast.

The payoff for doing this properly is durability. Express consent does not expire — it lasts until the recipient withdraws it, per the CRTC's FAQ. Implied consent, by contrast, expires silently: 24 months after a purchase or contract ends, and just 6 months after an inquiry or application. One compliance guide puts the risk bluntly — on the day implied consent expires, every email you send becomes a violation, per Sender's CASL analysis.

Here's the part most businesses underestimate: the burden of proof sits entirely on the sender. The CRTC states plainly that the onus of proving consent — express or implied — is on the person claiming they have it. That makes documentation your legal defense, not an administrative afterthought.

The practical standard is the 5W model — Who consented, When, How, What they agreed to, and Where it happened — with records kept for at least three years, as compliance practitioners recommend. Timestamp, form URL, and the exact checkbox language all matter. It's also why purchased lists fail so completely: they almost never carry valid, provable consent, and "I bought a list" is not a defense, per Tomba's compliance breakdown.

When you're evaluating any growth partner, this is the question worth asking: not just whether they claim consent, but whether they can prove it — for every contact, on demand.

The Shortcuts That Don't Count

Not every "yes" counts as consent. Regulators and legal experts have spent years documenting the shortcuts businesses take to build email lists fast — and every one of them fails the express consent test under Canada's Anti-Spam Legislation.

The most common failure is the pre-checked box. Express consent requires a proactive opt-in action from the recipient, and compliance analysts are blunt: a box someone never touched is not an action. The same logic kills consent buried in fine print — opt-ins "cannot be buried in the terms and conditions of another service or contract," according to a legal practice guide from Gowling WLG.

Then there is the bundled opt-in, the pattern behind countless signup flows: "By creating an account, you agree to receive marketing emails." CASL compliance guides flag this exact phrasing as non-compliant, because consent to marketing must be a separate, positive action — not a rider on an account agreement. Silence doesn't count either. A person who ignores your email has not consented to anything.

The documented non-compliant patterns worth auditing your own forms against:

  • Pre-checked boxes that "consent" on the user's behalf
  • Marketing consent buried inside terms of service or contracts
  • Bundled opt-ins tying account creation to email agreement
  • Treating silence or inaction as a yes
  • Purchased or rented email lists

Purchased lists deserve special attention because they feel like a legitimate business transaction. They are not. The CRTC's guidance states directly that selling a list of email addresses for which consent was obtained does not transfer those consents to the new owner — consent attaches to the organization that collected it, not to the address itself. As one compliance resource puts it, purchased lists "almost never carry valid CASL consent," and "I bought a list" is not a defense.

The stakes make these shortcuts expensive gambles. CASL penalties reach $10 million per violation for organizations, and enforcement is real — Compu-Finder received a $1.1 million notice of violation in 2015, while Porter Airlines paid $150,000, according to documented enforcement cases.

Every one of these failed patterns shares a root cause: the template blast mindset, where volume substitutes for permission. That is precisely the approach Worqd rejects. Its B2B outreach is built as personalized, permission-aware outreach to relevant accounts — the opposite of a template blast — and its own booking funnel captures consent the way the regulator intends, with an explicit, active opt-in: "I agree to be contacted about my request."

When you evaluate any growth partner, ask how they capture consent and whether they can prove it. The burden of proof always sits with the sender — which means a partner who can't show you their consent records is handing you their risk.

How Permission-Aware Outreach Works in Practice

A growth partner's compliance practices become your legal exposure the moment they send a message on your behalf. Before you sign anything, turn CASL's requirements into interview questions — the answers will tell you more than any sales deck.

How is consent captured, and can you show me the records? This is the single most important question, because the CRTC places the burden of proof entirely on the sender. A credible partner should produce documentation on demand. Ask whether they follow the 5W record-keeping model — Who consented, When, How, What they agreed to, and Where — and whether records are kept for at least three years after the relationship ends. If the answer is vague, walk away.

What happens when implied consent expires? Implied consent lapses 2 years after a purchase and just 6 months after an inquiry, per CRTC guidance. As one compliance analysis warns, it "expires silently — and on the day it expires, every email you send becomes a violation." Ask how the partner tracks these windows and, better yet, whether they default to express consent, which never expires until withdrawn.

Do you use purchased lists? The only acceptable answer is no. According to compliance researchers, purchased lists "almost never carry valid CASL consent," and "I bought a list" is not a defense. The CRTC also confirms that consent does not transfer when a list is sold. A partner who buys contact data is building your funnel on a violation waiting to happen.

Use this quick checklist when evaluating any provider:

  • Can you show a real opt-in record with timestamp, method, and scope?
  • Do your forms use unchecked boxes and standalone consent language, not bundled terms?
  • How do you track and stop outreach when implied consent windows close?
  • How are unsubscribe requests processed, and within what timeframe?
  • What disclosures appear in your consent requests — organization name, mailing address, and withdrawal statement?

On unsubscribes, the rule is firm: requests must be honored within 10 business days. Ask whether their systems process opt-outs automatically or manually — manual queues are where deadlines get missed. Also confirm their consent requests include the full disclosures legal guidance requires: message types and purposes, the requesting organization's name, a mailing address plus another contact method, and a statement that consent can be withdrawn.

The stakes justify the interrogation. CASL penalties reach $10 million per violation for organizations, and enforcement is real — Porter Airlines paid $150,000 and Kellogg Canada paid $60,000, according to documented enforcement cases.

This is why Worqd builds outreach around explicit consent from the first touch — its booking funnel captures a clear "I agree to be contacted about my request" opt-in, and its B2B outreach is permission-aware by design. Any partner you consider should be able to answer every question above just as concretely.

Frequently Asked Questions

What counts as express consent under CASL?
Express consent means a person has clearly agreed to receive commercial electronic messages, in writing or orally, by taking a proactive action like ticking an unchecked box or submitting a form. According to CRTC guidance, it must be obtained through an opt-in mechanism such as signing up at your website — silence or inaction never counts.
Does express consent ever expire?
No — express consent does not expire and lasts until the recipient withdraws it, per the CRTC's FAQ. That's why it's considered the gold standard compared to implied consent, which lapses 2 years after a purchase and just 6 months after an inquiry.
Are pre-checked boxes valid consent?
No. Express consent requires a proactive action from the recipient, and a box they never touched isn't an action. Consent buried in terms and conditions or bundled with account creation ("by creating an account, you agree to receive marketing emails") also fails, as compliance guides document.
Can I email people from a purchased list if I bought it legitimately?
No — purchased lists almost never carry valid CASL consent, and "I bought a list" is not a defense. The CRTC confirms that selling a list of email addresses does not transfer consent to the new owner; consent attaches to the organization that collected it.
What do I have to include when asking for consent?
A valid opt-in request must disclose the types and purposes of your messages, your organization's name, a mailing address plus one additional contact method, and a statement that consent can be withdrawn. Legal guidance from Gowling WLG confirms these disclosures are required.
What happens if I can't prove I had consent?
The burden of proof is entirely on the sender — the CRTC states the onus of proving consent is on the person claiming to have it. Without a timestamp, method, and scope of agreement on record, you don't have consent, and with penalties up to $10 million per violation for organizations, undocumented outreach is a serious risk.

Consent You Can Prove Is the Only Consent That Counts

Express consent comes down to one idea: a real person took a clear, proactive action to say yes — no pre-checked boxes, no buried terms, no bundled fine print, and definitely no purchased lists. Done right, it never expires until the recipient withdraws it, which makes it the sturdiest foundation any outreach program can have. But the rule that should shape every decision you make is the burden of proof: if you can't produce the timestamp, the method, and the scope of agreement for every contact, you don't have consent — you have a claim. With penalties reaching $10 million per violation for organizations, that distinction is expensive to get wrong. So audit your own forms against the shortcuts above, and put any growth partner through the same checklist. At Worqd, permission is the starting point — an explicit opt-in in the booking funnel and personalized, permission-aware outreach, never a template blast. If you want a partner who can answer every consent question concretely, book a free growth call and ask us anything.

Want help putting this into action?

Book a Growth Call
Topicsexpress consent meaningCASL express consentCASL compliance requirementsimplied vs express consentemail opt-in rules CanadaCASL penalties for businessespermission-based email outreach

Stay in the Loop