
The stakes are real. Businesses face fines up to $10 million CAD per violation. Beyond the financial risk, spam complaints damage sender reputation and can tank deliverability across your entire email program.
This guide breaks down CASL's consent rules, the mandatory elements every commercial email needs, what penalties actually look like in practice, and how to build a compliant email program without losing your mind over compliance paperwork.
Key Takeaways
- CASL applies to any commercial email reaching a Canadian recipient, regardless of where you're sending from
- Express consent never expires; implied consent has strict time limits (6-24 months)
- Every message needs consent, sender identification, and a working unsubscribe link
- Violations can cost businesses up to $10 million CAD, with directors personally liable
- Buying an email list does not satisfy CASL's consent requirements
What Is CASL and Who Does It Apply To?
CASL (Canada's Anti-Spam Legislation) has regulated commercial electronic messages since July 1, 2014. Its purpose: cut down on spam and protect Canadians from unwanted, deceptive, or malicious electronic communications.
A Commercial Electronic Message (CEM) is any electronic message that encourages participation in commercial activity, having regard to its content, hyperlinks, or contact information. That covers marketing emails, promotional offers, and sales outreach.
Not a CEM:
- Transactional receipts and order confirmations
- Shipping and delivery notifications
- Warranty, recall, or safety information
- Personal or family communications
The Recipient Rule Changes Everything for US Businesses
Here's the part that surprises a lot of American marketers: CASL applies based on where the recipient is, not where you're sending from. If your computer system sends a message to someone in Canada, CASL applies, regardless of where your business operates.
This makes CASL directly relevant to US and international businesses with any Canadian contacts on their list, even a handful. The scope extends beyond email, too: SMS, instant messaging, and some social media direct messaging systems all count as "electronic addresses" under the law. Managing this correctly across every channel is exactly why many businesses hand email broadcasting and compliance tracking off to a service that builds unsubscribe management and regulatory checks into the campaign itself.
Key exemptions to know:
- B2B messages between organizations with an existing relationship (message must relate to the recipient's role)
- Registered charities raising funds
- One-time referral messages meeting specific conditions
Consent Under CASL: Express vs. Implied Consent
Consent is the foundation of everything under CASL. You need it before sending most CEMs, and the burden of proof always falls on you, the sender. If the CRTC asks you to prove consent, "I assumed it was fine" won't cut it.
Express Consent: The Gold Standard
Express consent requires a clear, unambiguous opt-in action. Think an unchecked checkbox that a visitor actively checks, not one pre-checked for them.
To be valid, your consent request must:
- Clearly state the purpose for seeking consent
- Identify your business (and anyone you're sending on behalf of)
- Provide required contact information
- Confirm that consent can be withdrawn anytime
The upside: Express consent never expires. It stays valid until the recipient withdraws it.

Here's a simple example of compliant opt-in language:
"By checking this box, you consent to receive marketing emails from [Business Name] about our products and services. You can unsubscribe at any time by clicking the link in any email we send."
Implied Consent: Useful, But It Expires
Implied consent arises from an existing relationship, but it comes with a countdown clock:
| Relationship Type | Implied Consent Window |
|---|---|
| Purchase, lease, or contract | 24 months after the transaction |
| Inquiry or application | 6 months after the inquiry |
| Written contract | Duration of contract + 2 years after |
There's also a narrow conspicuous publication exception: if someone publicly lists their business email without stating they don't want unsolicited messages, and your message relates to their role, you may have implied consent. This exception is assessed case by case and is risky to lean on as your primary strategy.
One rule with zero exceptions: purchased or rented email lists never satisfy CASL consent requirements. The CRTC has confirmed that simply acquiring a list, even one built from "publicly available" addresses, doesn't create implied consent on its own.
Smart move: Track your implied consent expiry dates and run re-consent campaigns to convert those contacts to express consent before the clock runs out. Managing this manually across a large contact list gets complicated fast, which is why many businesses fold expiry tracking and re-consent workflows into their broader email broadcasting operations rather than handling it as a separate task.
Mandatory Elements of Every Compliant Marketing Email
Every CEM needs three things: consent, sender identification, and a working unsubscribe mechanism. Miss any one of these, and you're exposed. Here's what each requirement looks like in practice.
Sender Identification & Contact Info
Your message must clearly identify:
- Your business name
- The name of anyone else you're sending on behalf of
You also need valid contact information included in the message itself:
- A mailing address
- A phone number, email address, or website (at least one)
This contact information must remain valid for at least 60 days after you hit send.
Unsubscribe Mechanism Rules
The unsubscribe process has to be genuinely easy:
- Free for the recipient to use
- No login required
- Doesn't take more than one page to complete
- Processed within 10 business days
- The unsubscribe link itself must stay valid for 60 days

Quick compliance checklist before you send:
- ✅ Consent obtained and documented (express or implied)
- ✅ Sender clearly identified in the message
- ✅ Valid mailing address and contact info included
- ✅ Unsubscribe link tested and functional
Managing this checklist manually for every campaign is where most in-house teams lose time. Pipeline Media's email broadcasting service builds unsubscribe processing and contact compliance directly into every managed send, so nothing falls through the cracks.
Penalties and Enforcement: What's at Stake
CASL penalties aren't theoretical. The maximum administrative monetary penalty is $1 million CAD per violation for individuals and $10 million CAD per violation for businesses.
A Real Case: Porter Airlines
In 2015, Porter Airlines agreed to pay $150,000 CAD under an undertaking with the CRTC. The alleged issues:
- Unclear or missing unsubscribe mechanisms
- Incomplete sender contact information
- Unsubscribe links that didn't stay valid for 60 days
- Opt-out requests not processed within 10 business days
- Inability to prove consent for certain email addresses
Nobody's too big to get flagged. If a national airline can slip up on unsubscribe timing, smaller businesses running campaigns without dedicated compliance support face the same risk, especially since three separate federal agencies actively watch for violations.

Three agencies enforce CASL jointly:
- CRTC — unsolicited CEMs, unsubscribe violations, sender ID
- Competition Bureau — false or misleading electronic representations
- Office of the Privacy Commissioner — address harvesting, unauthorized data use
Directors and officers aren't shielded either. Anyone who authorized, assented to, or participated in a violation can be held personally liable, separate from the corporation, which is why many businesses hand off unsubscribe tracking and consent record-keeping to a dedicated campaign management service rather than risk gaps in an in-house process.
CASL vs. CAN-SPAM: What Cross-Border Marketers Need to Know
If you're marketing to both US and Canadian audiences, this distinction matters a lot.
| Requirement | CASL (Canada) | CAN-SPAM (US) |
|---|---|---|
| Consent model | Opt-in — consent required before sending | Opt-out — no prior consent required |
| Unsubscribe | Must be honored within 10 business days | Must be honored within 10 business days |
| Sender identification | Required in every message | Required in every message |
| Penalties | Up to $10 million CAD per violation | Up to $53,088 USD per violation |
That gap in consent models creates a trap for marketers running one unified list. Compliance with CAN-SPAM does nothing to satisfy CASL for your Canadian contacts, since the FTC's rules never required consent in the first place. Apply CASL standards to any Canadian recipient, regardless of how your US list operates.
Add EU contacts to the mix, and GDPR's consent and documentation requirements stack on top of both. At that point, a spreadsheet tracking consent status, expiry dates, and unsubscribe rules across three regimes stops being a workaround and starts being a compliance risk. Pipeline Media's email broadcasting service builds unsubscribe and compliance management directly into every campaign, so cross-border lists don't rely on manual tracking to stay compliant.
Best Practices for Stress-Free CASL Compliance
Prioritize Express Consent Whenever Possible
Double opt-in forms create a clear, defensible record and never expire. Relying on implied consent means constantly tracking expiry dates, which adds risk with no compensating benefit.
Keep Detailed Consent Records
For every contact, document:
- Who gave consent
- When it was obtained
- How it was collected (form, purchase, business card)
- What they consented to receive
Maintain these records for at least as long as the relationship lasts.
Consider Outsourcing the Operational Burden
Tracking consent expiry across thousands of contacts, processing unsubscribes within 10 business days, and keeping sender identification consistent across every campaign takes real time. Many businesses hand this off to full-service providers instead of managing it internally.
Pipeline Media's Email Broadcasting service addresses exactly this burden. Rather than building unsubscribe tracking and compliance monitoring from scratch, clients hand off the operational side of email compliance:
- Pipeline manages the unsubscribe system on the client's behalf
- Campaigns run at millions of emails per hour, with most jobs live within 60-90 minutes
- Every job is tested before deployment, with detailed tracking reports flagging undeliverable addresses

Pipeline Media has operated out of Toronto since 2003, working with regulated industries including Financial Services, Healthcare, and Government, sectors where getting compliance wrong carries outsized consequences.
The result: businesses can focus on messaging strategy and campaign performance, while the regulatory upkeep runs quietly in the background.
Frequently Asked Questions
What law applies to send a promotional email to Canadian customers?
CASL applies to any commercial electronic message sent to a recipient located in Canada, regardless of where you're sending from. You'll need consent, clear sender identification, and a working unsubscribe mechanism.
What are the legal requirements for email marketing in Canada?
Three pillars: obtain express or implied consent, identify your business with valid contact information, and include a functional, free unsubscribe option processed within 10 business days.
Does CASL apply to B2B emails?
Generally, yes. However, an exemption exists when two organizations have an existing relationship and the message relates to the recipient's business role or responsibilities.
Can I email someone after receiving their business card?
Yes, direct disclosure like a business card exchange can support implied consent, provided your message relates to their business role and they haven't indicated they don't want unsolicited messages.
Can I use a purchased email list for Canadian recipients?
No. Purchased lists don't satisfy CASL consent requirements because there's no documented express or implied consent from those individuals, regardless of how the list was compiled.
What happens if I don't comply with CASL?
Penalties can reach $10 million CAD per violation for businesses and $1 million CAD for individuals. The CRTC, Competition Bureau, and Privacy Commissioner all actively enforce these rules.