What is Canada's Anti-Spam Legislation (CASL)?
Learn what CASL requires for email and SMS marketing: consent rules, unsubscribe laws, penalties up to $10M, and a checklist for compliant B2B outreach.
?.jpg)
What is Canada's Anti-Spam Legislation (CASL)?
Key Facts
- CASL penalties reach $10 million per violation for organizations — compared to just $53,088 under U.S. law.
- Canada's Spam Reporting Centre received over 208,000 complaints in just six months ending March 2025.
- Hudson's Bay Company paid $120,000 for sending emails without a readily performable unsubscribe mechanism.
- Consent violations were the largest complaint category — 3,879 of 8,128 online-form complaints in six months.
- Under CASL, the sender bears the full burden of proving consent was ever obtained.
- Implied consent expires two years after a purchase and just six months after an inquiry.
- Within a year of CASL, Canadian-based spam dropped 37% and Canadians received 29% less email in their inboxes.
Why CASL Catches Marketers Off Guard
Most marketers assume anti-spam enforcement is a paper tiger — until they look at the numbers. Canada's Anti-Spam Legislation has a reputation as one of the strictest anti-spam laws in the world, and the enforcement data shows regulators take it seriously.
In just six months — October 2024 through March 2025 — the Spam Reporting Centre received over 208,000 complaints. That same period saw 16 warning letters, 105 notices to produce, and a $120,000 undertaking from Hudson's Bay Company, penalized for sending commercial messages without a readily performable unsubscribe mechanism.
The financial exposure goes far beyond one retailer. Under section 20(4) of CASL, maximum penalties reach $10 million per violation for organizations and $1 million for individuals — and officers and directors can be held personally liable. Compare that to the U.S. CAN-SPAM Act, an opt-out law with penalties capped at $53,088 per violating email, and the gap becomes obvious.
Here's what surprises most businesses: under CASL, the onus is on the sender to prove consent was obtained. It doesn't matter that someone filled out a form two years ago — if you can't produce a clear, verifiable record of how and when they opted in, that consent may as well not exist. According to compliance analysts, these proof gaps are "often the weakest point in an audit."
Consent violations are also the most common complaint. Of the 8,128 online-form complaints filed in that six-month enforcement window, 3,879 — the largest single category — concerned consent for messages. The traps marketers fall into most often include:
- Assuming implied consent lasts forever (it expires 2 years after a purchase and just 6 months after an inquiry)
- Using pre-checked boxes or default toggles instead of a proactive opt-in action
- Reactivating old CRM lists without verifying consent windows
- Buying standalone email lists, which do not transfer consent and may not be CASL-compliant at all
- Over-applying B2B exemptions that are narrower than most senders assume
The second blind spot is third-party liability. The primary organization remains liable even when vendors or agencies send messages on its behalf. If a growth partner runs outreach, reactivation, or follow-up campaigns for you and cuts corners on consent, the penalty lands on your business — not theirs.
This is why checking a provider's compliance practices matters as much as checking their case studies. Any partner touching your email, SMS, or direct messages should be able to explain exactly how they capture express consent, how they store proof of it, and how they honor unsubscribes within the required 10 business days. At Worqd, for example, the booking funnel requires explicit consent before any contact, and outreach is built as permission-aware communication to relevant accounts rather than template blasts — because a compliant list isn't just a legal shield, it's a better-performing one.
What CASL Actually Covers (and What It Doesn't)
Most marketers assume CASL only governs email. It doesn't. The law defines a commercial electronic message as any electronic message that encourages participation in a commercial activity — whether or not profit is expected — and that definition sweeps in SMS, Bluetooth messages, and direct messages on platforms like Facebook Messenger and LinkedIn. A Facebook wall post or public tweet falls outside CASL; a private DM does not. Live voice calls and automated telemarketing are regulated separately under the Unsolicited Telecommunications Rules, not CASL.
The law's reach is also extraterritorial. CASL applies to CEMs sent from Canada and to CEMs received in Canada from abroad, so a U.S.-based sender messaging Canadian contacts is on the hook. The CRTC's best practice is to ensure every CEM complies with section 6 regardless of origin. This opt-in model stands in sharp contrast to the U.S. CAN-SPAM Act, which permits messages until the recipient opts out and caps penalties at roughly $53,000 per email. CASL's maximum penalties run to $10 million for organizations and $1 million for individuals per violation — a difference that reflects fundamentally different regulatory philosophies.
- Email, SMS/text, and Bluetooth messages
- Facebook Messenger and LinkedIn direct messages
- Any electronic message encouraging commercial activity
- Messages received in Canada even when sent from abroad
The practical impact shows in the data. Between October 2024 and March 2025, the Spam Reporting Centre logged over 208,000 complaints, with consent violations leading the pack at 3,879 of 8,128 online-form complaints. Hudson's Bay Company paid $120,000 after sending CEMs without a readily performable unsubscribe mechanism — a reminder that the "readily performed" standard and the 10-business-day honor window apply regardless of consent type. For teams running pipeline recovery or old-lead reactivation, the implied consent windows are critical: two years post-purchase or contract expiry, six months post-inquiry. Anything older requires fresh express consent.
Worqd builds consent capture into every lead funnel because the burden of proof rests entirely on the sender, and proof gaps are consistently the weakest point in audits. The same discipline applies when evaluating any growth partner: if they're sending on your behalf, you remain liable.
The Three Requirements Every Message Must Meet
Every commercial electronic message sent to a Canadian recipient must clear three non-negotiable hurdles: valid consent, clear sender identification, and a working unsubscribe mechanism. Miss one, and the message is illegal — regardless of how relevant or well-intentioned it is.
Consent is where most organizations stumble. Express consent requires a proactive opt-in — an unchecked-by-default checkbox, not a pre-ticked box or buried terms — and it lasts until the recipient withdraws it. Implied consent, by contrast, runs on a strict clock: 2 years after a purchase, contract, or accepted opportunity, and only 6 months after an inquiry or application. The CRTC makes the burden explicit: the sender must be able to prove consent was obtained, and proof gaps are "often the weakest point in an audit." In the six months ending March 2025, consent violations accounted for 3,879 of 8,128 online-form complaints — the single largest category by far.
- Express consent: active opt-in, no expiry unless withdrawn
- Implied consent (purchase/contract): 24 months
- Implied consent (inquiry/application): 6 months
- Conspicuous publication: only if no opt-out statement and message is role-relevant
Identification and unsubscribe rules are equally precise. Every CEM must include the sender's identity and contact information, plus an unsubscribe mechanism that is "readily performed" — no login walls, no multi-step forms, no "reply with STOP" as the only option. Unsubscribe requests must be honored within 10 business days, regardless of whether the original consent was express or implied. Hudson's Bay Company paid $120,000 for getting this wrong.
Three traps catch even careful marketers. First, an email asking for express consent is itself a CEM — you can't send it unless implied consent already exists. Second, purchased or standalone email lists "may not be compliant with CASL" because consent does not transfer with a list sale. Third, B2B exemptions are "often mistakenly over-applied"; CASL covers business-to-business messages, and the narrow exemptions require specific conditions that many outreach programs don't meet.
For teams running pipeline recovery or old lead reactivation — campaigns that pull contacts from CRM archives — the implied consent windows are the first filter. If a contact hasn't purchased in two years or inquired in six months, there's no implied consent to rely on. Worqd builds consent capture into every lead funnel and verifies compliance before any outreach launches, because the primary organization remains liable even when an agency sends on its behalf.
How to Run Compliant Outreach: A Practical Checklist
Running compliant outreach under CASL isn't about checking boxes — it's about building systems that protect your pipeline and your reputation. The CRTC received over 208,000 complaints in a recent six-month period, and consent violations topped the list at 3,879 of 8,128 online-form complaints. Hudson's Bay Company paid $120,000 for an unsubscribe mechanism that wasn't "readily performed" — a reminder that technical details carry real costs.
- Build explicit opt-in consent into every lead funnel — unchecked-by-default checkboxes, verifiable timestamped records, and clear language about what the contact agrees to receive.
- Honor every unsubscribe within 10 business days regardless of consent type, and make the mechanism frictionless (one click, no login required).
- Audit legacy and third-party lists before any reactivation campaign — implied consent expires at 2 years post-purchase or 6 months post-inquiry, and standalone purchased lists may not transfer consent at all.
- Keep consent evidence organized for due diligence defence — the burden of proof rests entirely on the sender.
- Vet any agency or vendor running outreach on your behalf; primary liability stays with you even when a partner sends the message.
Clean, consent-based lists also perform better — higher open rates, stronger inbox placement, and fewer deliverability surprises. Worqd builds consent capture into every lead funnel by default, and our pipeline recovery work starts with a compliance audit so reactivation campaigns reach only contacts with valid, verifiable permission. When you're evaluating a growth partner, ask how they handle consent records, unsubscribe processing, and third-party sender liability — those answers tell you more than any pitch deck.
ctaText: Book a free growth call to see where your funnel leaks — and get a plan to fix it. socialProofText: One partner runs the whole path from first click to booked call — no vanity metrics, no fragmented vendors.
What This Means When You Choose a Growth Partner
Hiring an agency to run your outreach doesn't transfer your legal risk — it concentrates it. Under CASL, the hiring organization remains liable for commercial electronic messages even when a vendor or agency sends them on its behalf.
That makes compliance a due-diligence question, not a legal footnote. With penalties reaching $10 million per violation for organizations, the way your growth partner handles consent directly affects your exposure.
The stakes are easy to underestimate. Consent problems dominate enforcement: of 8,128 online-form complaints filed with the Spam Reporting Centre between October 2024 and March 2025, consent for messages was the largest category at 3,879 complaints. And because the burden of proving consent rests entirely on the sender, a partner who can't produce records leaves you exposed in an audit.
Before you sign with any provider, ask three questions:
- How do you capture consent? The CRTC expects a proactive opt-in action — default toggles don't suffice, and an email asking for consent is itself a CEM.
- How do you store proof? Records of consent evidence, unsubscribe requests, and actions taken support a due diligence defence under CRTC guidance.
- How do you handle old lists? Implied consent expires — two years after a purchase and six months after an inquiry — so reactivating stale CRM contacts requires checking each contact's window first.
That last question matters most for database reactivation campaigns, where the temptation is to blast every contact in the CRM. A partner doing this properly verifies implied-consent windows before sending, and treats purchased standalone lists as off-limits entirely.
At Worqd, our B2B outreach is built as permission-aware, personalized contact with relevant accounts — the opposite of a template blast — and our booking funnel requires explicit consent ("I agree to be contacted about my request") with a clear statement that details are used only to prepare for your call. That's what CASL-aligned practice looks like in daily operations: consent captured deliberately, purpose stated plainly, and outreach sent only where a defensible basis exists.
Compliance questions belong in your first conversation with any provider, alongside pricing and performance. If a partner can't explain their consent practices in plain language, that gap will eventually show up in your risk profile, not theirs.
Want to see how a growth partner handles both compliance and results? Book a growth call — we'll find where your growth is stuck and show you the whole path from first click to booked call.
Frequently Asked Questions
Does CASL apply to my business if I'm based outside of Canada?
How long does consent last under CASL before I need to get it again?
Can I just buy an email list and start marketing to it?
How is CASL different from the U.S. CAN-SPAM Act?
Am I liable if my agency sends non-compliant messages on my behalf?
Is CASL actually enforced, or is it just a paper tiger?
Compliance Isn't a Constraint — It's Your Competitive Edge
CASL isn't going away, and neither is the risk of getting it wrong. With penalties up to $10 million per violation, the burden of proving consent resting entirely on the sender, and over 208,000 complaints filed in just six months, the numbers make one thing clear: regulators are watching, and consent violations are where most senders stumble. The good news is that compliance and performance point in the same direction. Explicit opt-ins, verifiable consent records, frictionless unsubscribes, and audited legacy lists don't just shield you from penalties — they build cleaner lists that open, engage, and convert better. And because you stay liable even when an agency sends on your behalf, how a growth partner handles consent matters as much as how they handle results. Start with an audit of your own funnel: check your consent capture, your unsubscribe flow, and any stale lists before your next campaign. Then ask any provider the same three questions. If you want a partner who treats permission-aware outreach as the default — not an afterthought — book a free growth call and see where your funnel leaks, and how to fix it.
Want help putting this into action?
Book a Growth Call