
Does CASL apply to text messages?
Key Facts
- Yes — CASL applies to texts: the CRTC states commercial SMS and Bluetooth messages are subject to the law per its official FAQ.
- The CRTC fined one Quebec individual $40,000 for sending over 30,000 texts without consent per its enforcement report.
- Maximum CASL penalties reach $1 million for individuals and $10 million CAD for businesses per legal analysis.
- 75% of CRTC investigations begin with a single consumer report to the Spam Reporting Centre according to the CRTC.
- Implied consent lasts only 2 years after a customer's last purchase, and just 6 months for prospects per compliance guidance.
- CASL does not cover voice calls — telemarketing calls fall under separate Unsolicited Telecommunications Rules according to the CRTC.
- A pre-checked consent box does not qualify as valid express consent under CASL per legal practitioners.
The Compliance Gap: Texts and Calls Follow Different Rules
Yes — and the answer comes straight from the regulator. The CRTC states plainly that commercial messages "sent over a text messaging service or Bluetooth messaging are subject to CASL, as these messages are transmitted to an electronic address" (per the CRTC's official FAQ). Under CASL's technology-neutral definition, an "electronic address" includes telephone accounts and SMS messaging to mobile devices, putting texts in the same regulatory bucket as email.
Here is where campaign planners get tripped up: texts and voice calls follow entirely different rules. CASL does not apply to unsolicited telecommunications — including live voice and automated telemarketing calls — which fall under the separate Unsolicited Telecommunications Rules (according to the CRTC). So a business running a multi-touch campaign faces a heavier consent regime on the text side than on the call side.
That channel-by-channel split creates a real exposure gap. A combined calling-and-texting blitz — say, a database reactivation campaign running calls, texts, and emails over a few weeks — can be fully compliant on the voice side while every text touch carries CASL risk. Each SMS must satisfy three requirements before it goes out:
- Valid consent — express or implied, with the burden of proof on the sender
- Clear sender identification
- A functioning unsubscribe mechanism, with requests processed within 10 business days (per compliance guidance)
The stakes are not theoretical. The CRTC issued a $40,000 penalty to a Quebec individual who sent more than 30,000 text messages without consent (per the CRTC's enforcement report), and maximum penalties reach $10 million CAD for businesses (per legal analysis). Even the $40,000 case involved phishing rather than legitimate marketing, but the consent principle applied identically.
Consent records are where most campaigns fail. Proof gaps — the inability to produce verifiable records of how and when consent was obtained — are "often the weakest point in an audit" (compliance experts note). And critically, hiring a vendor does not transfer the risk: the primary organization remains liable for CASL compliance even when an agency sends messages on its behalf.
This is why any service running outbound campaigns — including managed calling operations like My AI Call Center — reviews list source and consent records before launch, and why texts in a multi-touch sequence deserve the same scrutiny as the calls themselves. Compliance is applied channel by channel, and a clean call list tells you nothing about whether the same contacts can legally receive a text.
What CASL Actually Requires of Your Text Campaigns
Sending a promotional text in Canada without consent can cost you — the CRTC fined one individual $40,000 for sending more than 30,000 texts without permission. If you're running text campaigns, here's exactly what the law expects of you.
According to the CRTC's own guidance, every commercial text must satisfy three requirements: valid consent, clear sender identification, and a functioning unsubscribe mechanism. Miss any one of the three and the message violates CASL.
Consent is where most campaigns break down. Express consent means a positive opt-in — and as legal practitioners point out, a pre-checked box at checkout does not qualify. Implied consent exists, but it comes with strict time limits: two years after a customer's most recent purchase or formal agreement, and only six months after a prospect provides their contact information. A new purchase resets the customer clock.
Here's the part that catches teams off guard: the burden of proof sits entirely with the sender. The CRTC states plainly that the onus is on you to prove consent — in writing or orally — for every recipient. Compliance analysts note that proof gaps, meaning no verifiable record of how and when consent was obtained, are often the weakest point in an audit. Best practice is capturing the IP address, timestamp, and exact consent language for each contact.
Not every text requires consent, though. CASL exempts messages that:
- Facilitate, complete, or confirm a transaction (e.g., a purchase confirmation)
- Occur within a genuine two-way conversation with a customer
- Directly respond to a customer's question or inquiry
- Deliver warranty, safety recall, or legally required information
For everything outside those exemptions, your opt-out mechanics matter. Texts must recognize the keywords STOP, END, QUIT, and UNSUBSCRIBE, and unsubscribe requests must be processed within 10 business days. Logging and honoring opt-outs immediately is the safer standard.
This is why a pre-launch list and consent review is worth more than any post-campaign fix. At My AI Call Center, list source and consent records are checked before any campaign launches — bought lists without clear permission records are flagged, and in most cases declined. If your list can't support the campaign, you're told plainly, before you spend anything.
The Cost of Getting It Wrong — Real Enforcement Numbers
CASL enforcement is not theoretical. Since the law came into force in 2014, the CRTC has issued over $3.2 million in administrative monetary penalties, and text messages have produced real cases with real dollar figures attached.
Consider the case of one Quebec individual who sent more than 30,000 phishing text messages without consent over a span of just a few weeks. The CRTC responded with a $40,000 penalty against that single sender — proof that enforcement reaches down to individuals, not just large corporations.
The ceiling is far higher for organizations. Under section 20(4) of the legislation, maximum penalties reach $1 million CAD for individuals and $10 million CAD for businesses. The very first CASL enforcement action set the tone: a $1.1 million penalty against Compu-Finder, a company whose messages generated more than 25% of all spam complaints at the time.
The complaint pipeline is what makes this dangerous for legitimate businesses. According to the CRTC, 75% of its investigations begin with a single consumer report to the Spam Reporting Centre. The SRC received over 152,000 complaints in just six months during 2025, and consent issues consistently rank as the largest complaint category. One annoyed recipient on your list can start the file that ends in an audit.
This creates a specific trap for win-back and reactivation campaigns. Implied consent for existing customers lasts up to two years after the most recent purchase, and only six months for prospects who handed over contact information. Dormant lists targeting contacts at the 12–24 month mark sit exactly where that implied consent has quietly expired.
Those lists need fresh express consent before any text goes out. Before launching a text touch against an older list, verify the following:
- The date of each contact's last purchase or agreement, measured against the two-year implied consent window
- Whether prospect records fall within the six-month window from when contact information was provided
- Documented proof of consent for every recipient — the onus of proving consent rests on the sender
- A functioning unsubscribe mechanism supporting required keywords like STOP
- Whether contacts outside all consent windows need a fresh express opt-in first
One more point catches businesses off guard: outsourcing does not outsource the risk. When a vendor or agency sends messages on your behalf, the primary organization remains liable for CASL compliance. This is why My AI Call Center reviews list source and consent records before any campaign launches — and flags or declines bought lists without clear permission records. Proof gaps are often the weakest point in an audit, and the cheapest time to close them is before the first message sends, not after the complaint lands.
Running Compliant Campaigns: Consent Verification in Practice
Knowing CASL applies to your texts is one thing; proving consent for every contact on your list is where campaigns actually succeed or fail. The CRTC puts it plainly: the onus is on the sender to prove consent was obtained — in writing or orally — for every message sent.
That burden shapes everything that should happen before launch. Global Relay's compliance analysis notes that consent proof gaps are often the weakest point in an audit, so your pre-launch checklist matters more than your creative. A workable verification process looks like this:
- Verify the list source and consent records for every contact before a single text goes out — bought lists without clear permission records won't survive scrutiny.
- Capture the IP address, date, and exact consent wording for each contact; a checkout checkbox alone is not sufficient under CASL.
- Apply consent standards channel by channel — texts carry the 2-year implied consent window for customers and 6 months for prospects, while voice calls fall under different rules.
- Honor STOP, END, QUIT, and UNSUBSCRIBE keywords immediately, and process all unsubscribe requests within 10 business days across every campaign.
Here is the part many businesses miss: hiring a vendor does not transfer your liability. When an agency or service sends messages on your behalf, the primary organization — you — remains liable under CASL. The enforcement stakes are real, with penalties reaching $10 million CAD for businesses, and 75% of CRTC investigations begin with a consumer report.
This is why My AI Call Center treats list discipline as a pre-launch requirement, not an afterthought. List source and consent records are reviewed before any campaign runs, and lists that won't support the campaign are flagged plainly — before money is spent. Clients are also responsible for obtaining their own legal guidance, because campaign requirements vary by location, industry, and consent status.
The working process, then, is straightforward: review the goal, check the list and consent records, approve the script, launch inside approved windows, and log every opt-out. Nothing launches until the consent foundation is verified — because a campaign built on an unprovable list isn't a campaign at all.
Frequently Asked Questions
Does CASL actually apply to text messages, or just email?
Do voice calls and texts follow the same CASL rules?
What are the penalties for sending marketing texts without consent in Canada?
How long does implied consent last before I need fresh opt-in for a text campaign?
If an agency sends texts for me, are they on the hook for CASL compliance?
Is a pre-checked box at checkout enough to count as consent for texting?
The Consent Checklist That Protects Your Campaign Before It Starts
CASL applies to every commercial text sent to a Canadian number — no exceptions for channel, no loopholes for automation. The CRTC's three requirements (consent, identification, unsubscribe) are non-negotiable, and the burden of proof sits entirely with the sender. That means every contact on your list needs a verifiable record of how and when permission was obtained, measured against the correct window: two years for customers, six months for prospects. Voice calls follow different rules entirely, so a clean calling list does not cover your text touches. The $40,000 penalty against a single sender and the $10 million ceiling for businesses show the regulator is willing to enforce, and 75% of investigations start with one consumer report. My AI Call Center runs a mandatory list and consent review before any campaign launches — bought lists without clear permission records are flagged and typically declined. If your list can't support the campaign, you'll know before you spend a dollar. Ready to see if your contacts are campaign-ready? Plan your campaign and we'll review the consent foundation together.