Back to insights
Checking Compliance Practices

What does it mean to be CASL compliant?

Learn what CASL compliance means for email and outreach: consent rules, penalties up to $10M, and how to send commercial messages legally in Canada.

What does it mean to be CASL compliant?

What does it mean to be CASL compliant?

Key Facts

Why CASL Compliance Matters Before You Send Anything

Most senders discover CASL the hard way: after the send, not before. Canada's Anti-Spam Legislation is an opt-in law, which means you need consent before your message reaches a Canadian inbox — not an opt-out link after the fact. As compliance practitioners point out, a cold email that is perfectly legal in the US becomes a violation the moment it lands in a Canadian inbox.

The law's reach surprises people. CASL covers commercial electronic messages across email, SMS, instant messages, and social media messages, according to the CRTC's own guidance. And jurisdiction follows the recipient: emailing even one Canadian contact pulls a foreign sender inside CASL's scope.

The stakes are severe. Businesses face penalties of up to $10 million per violation, individuals up to $1 million, and directors and officers carry personal liability for violations that happen on their watch (Tomba's compliance guide; SMTPedia). Canadian regulators have issued more than $20 million in penalties since CASL took effect in July 2014, with typical small-business settlements ranging from $5,000 to $250,000 (SMTPedia's enforcement overview).

Here is the trap that catches growing companies: one wrong send to a purchased list is the violation. There is no warning shot, no grace period, no "first strike" exemption.

  • A message asking for consent is itself a commercial electronic message — so you cannot email a purchased list to "request permission" (CRTC guide).
  • Selling an email list does not transfer consent, even if recipients once interacted with your organization (Higgerty Law).
  • The burden of proof sits entirely with the sender: if you cannot document consent, you do not have it (CRTC).
  • Agencies, contractors, and affiliates can make their clients vicariously liable for what they send on the client's behalf (Tomba).

That last point matters if you outsource outreach or lead reactivation. When Worqd runs B2B cold outreach or revives old CRM contacts, every contact is treated as a dated record with a documented consent basis — never as a permanent subscriber list to blast. That is not caution for its own sake; it is the difference between a defensible program and a $10 million exposure.

This is why compliance belongs at the start of your sending process, not in a policy document nobody reads. Build consent, identification, and unsubscribe mechanics into how contacts enter your system, and you never have to wonder whether the next send is the one that costs you.

Every legal commercial electronic message in Canada stands on three pillars — and if even one is missing, the message breaks the law. According to the CRTC's own guidance, senders must obtain consent, provide identification information, and provide an unsubscribe mechanism on every single send.

The first pillar is consent before sending — and this is what makes CASL the strictest anti-spam regime in North America. Unlike the U.S. CAN-SPAM Act, which lets you email first and opt out later, CASL is an opt-in law: permission must exist before your message ever leaves the server.

Consent comes in two forms. Express consent — a clear, affirmative "yes, contact me" — never expires until the recipient withdraws it. Implied consent is time-limited: the CRTC's compliance guide sets it at two years from a purchase or contract, and just six months from an inquiry or application. That six-month clock matters enormously for lead follow-up — an old inquiry is not a standing invitation.

The second pillar is identification. Every message — including a first cold email — must clearly state who is sending it, with a mailing address and a contact method that stays valid for at least 60 days after sending, per practitioner compliance guidance.

The third pillar is a working unsubscribe mechanism, honored within 10 business days. A broken or slow unsubscribe link is itself a violation, not a technicality.

The piece most senders underestimate is the burden of proof. The CRTC states plainly that "the onus of proving consent, be it express or implied, is on the person who claims they have consent." In practice, that means your records are your defense:

  • The email address and its consent basis (express or implied)
  • The date and method consent was captured
  • The exact wording the person agreed to
  • Retention of these records for at least three years

This is why compliance discipline matters when choosing a growth partner. At Worqd, every outreach and lead reactivation program treats contacts as dated records with a documented consent basis — because documentation is not optional paperwork, it is your legal defense. Companies are also vicariously liable for what their agencies send on their behalf, as compliance analysts note, so a provider's record-keeping practices are your risk, not just theirs.

Get these three pillars right, and every message you send has a solid legal foundation. Miss one, and penalties can reach $10 million per violation for businesses, according to enforcement tracking.

Many B2B teams assume CASL gives them a free pass. It doesn't. The legislation contains no B2B exemption — a point the CRTC and enforcement records make unambiguously clear. That misconception has fueled expensive mistakes, including the $1.1 million Compu-Finder penalty that rested squarely on treating purchased lists as consent. A review of enforcement actions shows that buying a list and sending a "consent request" email is itself a violation, because that request is a commercial electronic message sent without prior consent.

The only legal route for cold outreach is narrow and conditional. Implied consent may exist when a business address is conspicuously published without a statement refusing unsolicited messages, and your message is relevant to the recipient's business role. The CRTC confirms all three conditions must be met. This is a dated signal of relevance, not an evergreen subscription — one practitioner describes it as a "narrow signal of relevance, not an evergreen subscription" that expires the moment context shifts.

  • The address must be published by the recipient or their organization, not scraped from a third-party directory
  • No statement — explicit or implied — may refuse commercial messages
  • Your outreach must relate directly to the recipient's professional function
  • Every message still requires full sender identification and a working unsubscribe honored within 10 business days

For a growth agency like Worqd running B2B cold email and outreach on behalf of clients, this distinction shapes every campaign. Vicarious liability means the client shares responsibility for what an agency sends, so consent documentation isn't optional paperwork — it's the legal defense. The CRTC places the burden of proof on the sender, and practitioners recommend retaining consent records for at least three years. Treating implied consent as a bridge toward express consent — not a permanent subscriber status — keeps outreach on the right side of the law.

Compliance as an Operating System, Not a Checkbox

Most companies treat CASL compliance as a pre-send checklist. The regulator sees it differently: the CRTC frames compliance as a standing operating system for how you collect, verify, document, and retire contacts (source). That shift changes everything — from how you store a lead's origin to how you evaluate any outreach partner's documentation practices.

The burden of proof sits entirely with the sender (source). A consent audit trail isn't optional paperwork; it's your legal defense. Every record should capture the email address, consent basis (express or implied), date obtained, method of collection, and the exact wording presented to the recipient — retained for at least three years (source). Implied-consent contacts demand even stricter discipline: treat each one as a dated record with a known expiry, not a permanent subscriber. Express consent never expires; implied consent lapses at 24 months from a purchase or contract, and at 6 months from an inquiry (source). The practical play is to convert implied contacts to express consent 2–3 months before those windows close (source).

  • Log every consent event with basis, date, method, and exact wording
  • Flag implied-consent records with hard expiry dates
  • Run re-consent campaigns before the 6-month or 24-month cutoffs
  • Verify unsubscribe mechanics on every send — 10 business days to honor, contact info valid 60+ days (source)
  • Require the same documentation from any agency or contractor sending on your behalf

Vicarious liability makes this a shared risk: a company can be held responsible for what its agency or contractor sends (source), and directors face personal liability up to $1 million per violation (source). When we run B2B outreach or pipeline recovery for clients, the consent trail is a non-negotiable deliverable — not because it checks a box, but because it's the only way to operate sustainably in Canadian inboxes.

Compliance isn't a phase. It's the operating system.

Ready to build outreach that converts — and stays compliant? Book a Growth Call and we'll map the whole path from first click to booked call.

One partner runs the full funnel: paid ads, creative, outreach, AI SDR follow-up, and pipeline recovery — integrated, not fragmented.

What to Ask Before You Hand Outreach to Anyone

Handing outreach to a provider without verifying their compliance practices is like lending your car to someone who refuses to show you their license. Under CASL, your company remains vicariously liable for every message an agency sends on your behalf — directors and officers face personal liability too, with penalties reaching $10 million per violation for businesses according to enforcement analysis. The CRTC makes this explicit: a company can be held responsible for what its contractors send, and the $1.1 million Compu-Finder penalty was built on exactly this kind of purchased-list violation documented by regulatory records.

  • How do you document consent for every contact — express, implied, date, method, and exact wording?
  • Do you ever send to purchased, rented, or scraped lists?
  • How fast are unsubscribes processed — and can you prove the 10-business-day deadline from the CRTC guide is met?
  • Who carries liability in your service agreement, and do you maintain a documented compliance program?

Permission-aware, personalized outreach to relevant accounts is the compliant growth path — the opposite of a template blast. Worqd runs B2B cold email and outreach as personalized, permission-aware outreach to relevant accounts, with explicit consent captured at every booking step and records retained for audit. If your current provider can't answer these questions with evidence, the risk sits on your books. Book a growth call and we'll show you how the whole path from first click to booked call stays inside the rules.

Frequently Asked Questions

What are the three things every email I send to Canadians needs to be CASL compliant?
Every commercial electronic message needs three things: consent obtained before sending, clear sender identification (with a mailing address and a contact method valid for at least 60 days), and a working unsubscribe mechanism honored within 10 business days. Miss any one and the message breaks the law, according to the CRTC's own guidance.
Can I buy an email list and just ask people for permission before marketing to them?
No — this is one of the most expensive mistakes in CASL enforcement. A message asking for consent is itself a commercial electronic message, so sending a consent request to a purchased list is already a violation; the $1.1 million Compu-Finder penalty rested on exactly this, per enforcement records. Selling a list also does not transfer consent even if recipients once interacted with your organization.
Does CASL apply to my company if we're not based in Canada?
Yes — jurisdiction follows the recipient, so emailing even one Canadian contact pulls you inside CASL's scope. A cold email that is perfectly legal under US CAN-SPAM becomes a violation the moment it lands in a Canadian inbox, as compliance analysts point out. CASL also covers SMS, instant messages, and social media messages, not just email.
How long does consent actually last under CASL?
Express consent — a clear, affirmative yes — never expires until the recipient withdraws it. Implied consent is time-limited: two years from a purchase or contract, and only six months from an inquiry or application, per the CRTC's compliance guide — so an old inquiry is not a standing invitation to keep emailing.
Is there a B2B exemption that lets me cold-email Canadian businesses?
No, CASL has no B2B exemption. The only narrow legal path is implied consent when the recipient's business address is conspicuously published by them or their organization, there's no statement refusing unsolicited messages, and your message relates directly to their professional role — all three conditions must be met per the CRTC. Every message still needs full identification and a working unsubscribe.
What proof do I need to keep in case a regulator asks about consent?
The burden of proof sits entirely with the sender — if you can't document consent, you legally don't have it. Records should capture the email address, consent basis (express or implied), the date and method it was captured, and the exact wording the person agreed to, retained for at least three years as practitioners recommend. Businesses face penalties of up to $10 million per violation, and directors and officers carry personal liability.

Compliance Is the Foundation, Not the Fine Print

CASL compliance comes down to three pillars on every send: consent obtained before the message leaves your server, clear sender identification, and a working unsubscribe honored within 10 business days. Because the CRTC places the burden of proof on the sender, your records are your defense — every contact needs a documented consent basis, capture date, and the exact wording agreed to, retained for at least three years. And since businesses can be held liable for what their agencies send, any outreach partner you choose should treat that documentation as a deliverable, not an afterthought. That's exactly how Worqd runs B2B outreach and lead reactivation: every contact is a dated record with a consent basis, never a list to blast. Your next step is simple — audit your current contact records and ask your provider the four questions above. If the answers come with evidence, you're on solid ground. If they don't, book a growth call and we'll show you what a defensible, compliant outreach program looks like from first click to booked call.

Want help putting this into action?

Book a Growth Call
TopicsCASL compliance requirementsCASL email rules CanadaCanada anti-spam legislationCASL consent rulesCASL penalties for businessesCASL compliant cold emailcommercial electronic messages Canada

Stay in the Loop