When did CASL come into effect?
CASL came into effect July 1, 2014. Learn the full CASL timeline, consent rules, penalties up to $10 million, and how to keep your Canadian outreach com...

When did CASL come into effect?
Key Facts
- CASL came into force on July 1, 2014 — over three years after receiving Royal Assent on December 15, 2010, according to Gowling WLG's legal guide.
- CASL's transitional implied-consent window closed permanently on July 1, 2017, so pre-2014 contacts now need fresh permission, per CRTC regulatory guidance.
- Businesses face penalties of up to $10 million per CASL violation, making it one of the world's most punitive anti-spam laws.
- In just six months of 2025, the CRTC issued 153 Notices to Produce, 123 Warning Letters, and fielded over 152,000 spam complaints, according to the regulator's enforcement report.
- Implied consent expires after 2 years for existing business relationships and just 6 months after an inquiry, under federal consent rules.
- Recent CASL enforcement includes a $500,000 undertaking from Pizza Hut and $200,000 from Indeed Canada, per the CRTC's enforcement actions.
- Unsubscribe requests must be honored within 10 business days, and sender contact info must stay valid for at least 60 days, according to CRTC rules.
Why the CASL Start Date Still Matters for Your Outreach
Canada's Anti-Spam Legislation took effect on July 1, 2014 — a date that anchors every compliance decision for outreach targeting Canadian contacts. The law received Royal Assent in December 2010 but did not come into force for over three years, giving organizations a long runway that has long since closed. The CRTC's own guidance uses July 1, 2014 as the baseline for its consent regime, and the 36-month transitional window for pre-existing implied consent expired on July 1, 2017, leaving no grandfathering for old databases.
Penalties reach $10 million per violation for businesses, and enforcement is active across three federal agencies: the CRTC, the Competition Bureau, and the Office of the Privacy Commissioner of Canada. In the first half of the 2025 enforcement year alone, the CRTC issued 153 Notices to Produce, 123 Warning Letters, and 5 Preservation Demands, while fielding more than 152,000 spam complaints — roughly 98% of them email-related. Recent undertakings include Pizza Hut at $500,000 and Indeed Canada at $200,000, illustrating that the regulator pursues both consumer brands and B2B platforms.
For anyone running cold email, lead generation, or database reactivation aimed at Canadian prospects, the risk profile is concrete:
- Consent must be express or implied — and the sender bears the burden of proof
- Implied consent expires after 2 years for existing business relationships and 6 months for inquiries
- Unsubscribe requests must be honored within 10 business days
- Contact information in every message must remain valid for at least 60 days
These requirements apply whether the message originates in Canada, targets a Canadian recipient, or routes through Canadian infrastructure. At Worqd, our AI SDR and Pipeline Recovery workflows are built around explicit, timestamped consent capture — the same standard the CRTC expects — so reactivation campaigns convert old contacts into booked calls without creating compliance exposure.
The Full CASL Timeline: From Royal Assent to Today
A three-year gap between a law being passed and actually taking effect is uncommon in Canadian legislation. CASL's timeline is a deliberate example of that — and understanding each phase matters if you're planning outreach to Canadian contacts today.
The Act received Royal Assent on December 15, 2010, but Parliament built in a long runway before enforcement began. That gap gave businesses time to build consent infrastructure, update their messaging, and align their practices with the new regulatory framework.
The main provisions — consent requirements, identification rules, and unsubscribe obligations — came into force on July 1, 2014. From that date forward, anyone sending commercial electronic messages to Canadian electronic addresses needed valid consent.
A second wave followed months later. The computer program installation provisions took effect on January 15, 2015, extending CASL's reach to software and code installed on Canadian devices without proper authorization.
Here's the full phased timeline at a glance:
- December 15, 2010 — Royal Assent; the Act is passed but not yet enforceable
- July 1, 2014 — Core consent, identification, and unsubscribe provisions take effect
- January 15, 2015 — Computer program installation rules begin
- July 1, 2017 — The 36-month transitional implied-consent window closes permanently
That last date is the one most businesses miss. Section 66 of CASL granted a 36-month transitional period during which implied consent could be inferred from existing business relationships created before July 1, 2014, as outlined in CRTC regulatory guidance. That window closed on July 1, 2017. No extension was granted. No grace period followed.
Today, every Canadian contact in your database needs valid, current consent — either express or implied within the standard windows of two years for existing business relationships and six months following an inquiry. The sender bears the burden of proving that consent exists, per CRTC guidance.
This isn't theoretical risk. The CRTC has issued more than 2,000 Notices to Produce to date, and recent enforcement actions include a $500,000 undertaking from Pizza Hut and a $200,000 undertaking from Indeed Canada. Penalties reach up to $10 million per violation for businesses.
If you're evaluating a partner for outreach or lead reactivation, ask how they handle consent verification and timestamping. At Worqd, our B2B outreach is built on personalized, permission-aware contact — the opposite of a template blast — and our booking funnel captures explicit consent before any follow-up begins.
What CASL Requires Now That It's in Force
Since July 1, 2014, every commercial electronic message sent to, from, or through Canada has had to clear three non-negotiable hurdles — and there is no grace period left to lean on. The transitional implied-consent window that softened CASL's launch closed on July 1, 2017, meaning the full rules apply to every message you send today.
According to CRTC guidance, a compliant commercial electronic message must meet three core requirements:
- Consent — either express (a clear opt-in) or implied (an existing relationship), obtained before the message is sent.
- Identification — the sender must clearly state who they are, including valid contact information.
- A working unsubscribe mechanism — and opt-out requests must be honored within 10 business days.
Implied consent is where most compliance plans quietly fall apart. Under CRTC rules, an existing business relationship — a purchase or contract — gives you up to two years of implied consent. An inquiry or application gives you only six months. After those windows close, you need express consent or you stop sending.
That clock matters enormously for database reactivation. Old leads sitting in your CRM may feel like warm opportunities, but if the relationship predates the implied-consent window, contacting them without fresh consent is a violation. It is one reason Worqd's booking funnel captures explicit opt-in — "I agree to be contacted about my request" — at the point of inquiry, creating a timestamped consent record from day one.
That record-keeping instinct is not optional. The sender bears the burden of proving consent if a complaint or investigation arises. If you cannot produce evidence of when and how consent was given, regulators treat it as if you never had it.
Two smaller rules round out the picture. Your identification and contact details must remain valid for at least 60 days after a message is sent, so recipients can actually reach you. And the 10-business-day unsubscribe deadline is a hard limit, not a target.
The stakes justify the rigor. Penalties reach up to $10 million per violation for businesses, and enforcement is active — the CRTC issued 153 Notices to Produce and 123 Warning Letters in just six months of 2025, with recent undertakings from major brands running into the hundreds of thousands of dollars.
For teams evaluating an outreach or growth partner, these rules make a useful litmus test. Ask how they capture consent, how they track implied-consent expiry, and how fast they process opt-outs. A provider that treats permission-aware outreach as a design principle — not an afterthought — is the one keeping your growth engine on the right side of a law that has been fully in force for over a decade.
How to Build a CASL-Compliant Outreach Program
Knowing CASL took effect on July 1, 2014 is only the starting point — the real work is building an outreach program that can prove consent for every contact you message. Since CRTC guidance places the burden of proving consent squarely on the sender, your systems need to capture evidence, not just intentions.
Timestamp express consent at the point of inquiry. Every form, booking page, and landing page should record when someone opted in and what they agreed to. Implied consent from an inquiry expires after just six months under federal consent rules, so a dated express opt-in is your strongest protection. This is why Worqd's own booking funnel requires explicit consent — "I agree to be contacted about my request" — before any follow-up begins.
Keep consent records attached to every lead in your CRM, not in a separate spreadsheet. When a contact moves from inquiry to nurture sequence to sales call, the consent trail should move with them.
Treat old-lead reactivation with extra care. The transitional implied-consent window under section 66 closed on July 1, 2017, and it only ever applied to relationships created before CASL took effect, according to CRTC's implied consent guidance. That means pre-2014 contacts in your database likely have no valid consent at all — they need fresh permission before you reach out.
Build unsubscribe handling directly into your follow-up workflow:
- Honor every unsubscribe request within 10 business days, as required by CRTC rules
- Include clear sender identification in every commercial electronic message
- Keep contact information in your messages valid for at least 60 days after sending
- Suppress opted-out contacts across all sequences immediately, not just in one tool
The stakes justify the effort. Penalties reach up to $10 million for businesses, and enforcement is active — the CRTC has issued more than 2,000 Notices to Produce, with recent undertakings including $500,000 from Pizza Hut and $200,000 from Indeed Canada, per the regulator's enforcement reporting.
Permission-aware outreach isn't a constraint on growth — it's what makes personalized, relevant follow-up possible at scale. When consent is captured instantly and every inquiry gets a response in under 60 seconds, compliance and conversion stop competing and start reinforcing each other.
Frequently Asked Questions
When did CASL actually take effect, and why does the 2010 Royal Assent date matter?
Is the 36-month transitional period for implied consent still active?
What are the real penalties if we get CASL wrong?
How long does implied consent last for inquiries versus existing customers?
Does CASL apply if we're emailing Canadian prospects from outside Canada?
What's the fastest way to prove consent if a complaint or investigation happens?
The Date Is Settled — Now Make Your Outreach Prove It
July 1, 2014 is more than trivia — it is the anchor for every compliance decision you make when messaging Canadian contacts. The transitional implied-consent window closed for good on July 1, 2017, which means there is no grandfathering left to hide behind: every contact in your database needs valid, provable consent today. With implied consent expiring after two years for business relationships and six months for inquiries, and the sender carrying the burden of proof, old-lead reactivation is where risk quietly concentrates. The enforcement record makes that risk concrete — the CRTC issued 153 Notices to Produce and 123 Warning Letters in just six months of 2025, per the regulator's own enforcement reporting. Your next step: audit your CRM for consent timestamps, expiry dates, and opt-out handling before your next campaign. If you would rather have a partner handle it, Worqd builds permission-aware outreach and timestamped consent capture into every reactivation workflow — book a free growth call to see how.
Want help putting this into action?
Book a Growth Call