
How many messages are considered harassment?
Key Facts
- No Canadian rule or CRTC enforcement case defines harassment by message count — compliance hinges on consent, disclosure, and conduct, per the CRTC's consultation record.
- The CRTC has conducted over 3,500 investigations and levied more than $17.6 million in penalties since Canada's telemarketing rules took effect, according to its enforcement record.
- Canadians have filed over 944,000 complaints about telemarketing violations since 2008 — roughly 1,029 per week, per CRTC data.
- Canada's National Do Not Call List has grown to more than 15.2 million numbers since launching in September 2008, according to the CRTC.
- Telemarketing violations can cost corporations up to $15,000 per violation, with individuals facing $1,500 per violation, per compliance analysis.
- Do-not-call requests must be processed within 14 days, and internal DNC records must be retained for three years and 14 days, under CRTC rules.
- Voice calls fall under the Unsolicited Telecommunications Rules while marketing texts fall under CASL — two separate regimes, as the CRTC's FAQ states.
The Myth of a Magic Number: Why Teams Count Messages (and Why It Fails)
If you are planning an outbound campaign in Canada, you have probably searched for a specific number: how many calls or messages before you cross the line into harassment? It is a reasonable question. You want to scale outreach without legal risk, and a clear threshold would make that easy.
The uncomfortable truth is that the number does not exist. No Canadian rule, no CRTC document, and no enforcement case defines harassment by message count. Across eight sources reviewed — including the CRTC's own consultation materials — not one sets a numeric limit on how many messages a business can send.
Instead, Canadian telemarketing regulation is built around consent, disclosure, and conduct standards. The CRTC's authority under sections 41–41.7 of the Telecommunications Act lets it regulate unsolicited telecommunications to prevent "undue inconvenience or nuisance" — a judgment about the nature of the contact, not its frequency. Calling a number registered on the National Do Not Call List is prohibited unless an exemption applies, such as an existing business relationship or prior express consent, according to compliance guidance from Blacklist Alliance.
Why does the counting instinct persist? Because it feels manageable. A team can set an internal cap — three touches, five touches — and believe the legal box is checked. But message counts create false confidence while the real risks go unmanaged:
- Calling numbers with no valid consent record or expired exemption window
- Dialing outside permitted hours (9:00 a.m.–9:30 p.m. weekdays, 10:00 a.m.–6:00 p.m. weekends for automated calls, per CallHub's CRTC overview)
- Failing to honor do-not-call requests, which must be processed within 14 days under CRTC enforcement rules
- Conflating voice calls with texts — calls fall under the Unsolicited Telecommunications Rules, while marketing texts fall under CASL, as the CRTC's FAQ makes clear
The enforcement stakes are real. The CRTC has conducted over 3,500 investigations and levied more than $17.6 million in penalties since the rules were introduced. With over 944,000 complaints received since 2008 — roughly 1,029 per week — regulators are clearly watching conduct, not tallying messages.
This is why list discipline matters more than volume math. Before any campaign launches at My AI Call Center, list source and consent records are reviewed — and bought lists without clear permission records are flagged or declined. The goal is to satisfy the actual legal standard, not to stay under an arbitrary number that offers no protection at all.
A shift toward volume-based standards may eventually arrive. Industry body M3AAWG has recommended the CRTC replace its dialing-mechanism rules with standards based on call volume and consent in its UTR modernization consultation. But no numbers have been set — and until they are, counting calls tells you nothing about whether your campaign is compliant.
What Actually Defines Harassment Under Canadian Telemarketing Rules
If you're looking for a magic number — three calls a week, five texts a month — you won't find one. Canadian telemarketing law does not define harassment by message count at all. Instead, the CRTC's Unsolicited Telecommunications Rules (UTRs) judge conduct on four pillars: consent, disclosure, calling hours, and opt-out handling.
The CRTC's authority comes from sections 41–41.7 of the Telecommunications Act, which let it regulate unsolicited telecommunications to prevent "undue inconvenience or nuisance." According to the CRTC's Notice of Consultation 2026-132, the framework centers on whether valid consent exists — not how often you call. Calling a number registered on the National Do Not Call List is prohibited unless an exemption applies, such as an Existing Business Relationship or prior express consent.
That DNCL is no small registry. Since launching in September 2008, it has grown to more than 15.2 million numbers, per the CRTC's consultation record. Exemption windows are also time-limited: a purchase creates an 18-month EBR, while an inquiry or application creates only a 6-month window, as outlined in this Canadian telemarketing compliance primer.
Where the rules do get numeric, they focus on timing rather than volume. Key limits include:
- Permitted calling hours of 9:00 a.m.–9:30 p.m. on weekdays and 10:00 a.m.–6:00 p.m. on weekends, with stricter provincial rules taking precedence
- A 14-day deadline to add a contact to your internal do-not-call list after a request (reduced from 31 days in 2014)
- A retention period of three years and 14 days for internal DNC records
- A prohibition on sequential dialing
These requirements come from the CRTC and CASL outreach guidance and the Contact Center Pipeline's compliance analysis. Notably, even organizations exempt from the DNCL must maintain an internal do-not-call list and stop calling anyone who asks not to be contacted.
One distinction trips up many businesses. The CRTC states plainly in its official FAQ that "CASL does not apply to unsolicited telecommunications, including live voice and automated telemarketing calls, to telephone numbers, which are regulated under the Unsolicited Telecommunications Rules." Marketing text messages and emails fall under Canada's Anti-Spam Legislation (CASL) instead, which requires express or implied consent.
So a single call to a DNCL-registered number without consent can violate the rules, while ten calls to a consenting customer within permitted hours may not. The violation lives in the missing consent, not the count.
With over 944,000 complaints and $17.6 million in penalties since 2008, per the CRTC's enforcement record, the consent-first standard has real teeth. This is why My AI Call Center reviews list source and consent records before any campaign launches — and honors opt-outs immediately rather than waiting out the 14-day window. In Canada, list discipline is the compliance strategy.
The Cost of Getting It Wrong: CRTC Enforcement in Real Numbers
The numbers behind Canada's telemarketing rules tell a blunt story: getting this wrong is expensive, and the regulator is watching. Since the Unsolicited Telecommunications Rules came into force, the CRTC has opened more than 3,500 investigations into telemarketer compliance.
The complaint volume is just as striking. The CRTC has received over 944,000 complaints about alleged violations since 2008 — an average of 1,029 per week. Canadians are not shy about reporting unwanted calls, and the National Do Not Call List now holds more than 15.2 million numbers.
Enforcement has teeth. CRTC actions have produced over $17.6 million in administrative monetary penalties and other payments. And penalties stack quickly: violations can run up to $15,000 per violation for corporations, with a $1,500 per-violation rate for individuals.
The legal standard driving all of this comes from sections 41–41.7 of the Telecommunications Act, which lets the CRTC regulate unsolicited telecommunications to prevent "undue inconvenience or nuisance." That phrase is deliberately broad. It means the regulator judges conduct — consent, disclosure, calling hours, opt-out handling — rather than counting how many messages you sent.
One enforcement action makes the accountability question especially clear. In 2013, an MP and a telemarketing service provider paid penalties totaling $17,000 for robocall identification violations. At the time, Andrea Rosen, the CRTC's Chief Compliance and Enforcement Officer, stated: "We expect candidates who are running political campaigns, and telemarketing service providers to put appropriate safeguards in place to ensure compliance with the Unsolicited Telecommunications Rules."
That expectation matters for any organization outsourcing outbound calls. If you hand calling work to a third party, you still carry the compliance risk. Before launching any campaign, it is worth confirming that your provider:
- Reviews list source and consent records before a single call is placed
- Honors do-not-call requests immediately, not at the 14-day regulatory deadline
- Limits calling to permitted hours, including stricter provincial rules
- Discloses AI or automated voice use on every call
This is the approach My AI Call Center takes with every campaign — approved, permissioned, or reviewed lists only, with consent records checked before launch and opt-outs logged and honored on the spot. The CRTC's enforcement record shows that safeguards are not optional paperwork. They are what stands between a useful calling program and a costly complaint.
How to Stay Compliant Without Counting: A Consent-First Campaign Checklist
Since Canadian rules define violations by consent status, DNCL registration, calling hours, and opt-out handling — not message counts — the only reliable compliance path is a consent-first campaign model. The CRTC has conducted over 3,500 investigations and levied more than $17.6 million in penalties since 2008, making list discipline the practical standard that matters.
- Verify list source and consent records before launch. Express consent or a valid Existing Business Relationship — purchase within 18 months, inquiry within 6 months — is the legal gate for every call.
- Honor opt-outs immediately. The rules allow up to 14 days to process internal DNC requests; logging and suppressing them on the spot eliminates the risk window entirely.
- Keep internal DNC records for three years and 14 days, as the CRTC requires.
- Call only within permitted windows: 9:00 a.m.–9:30 p.m. weekdays, 10:00 a.m.–6:00 p.m. weekends, with stricter provincial limits taking precedence.
- Disclose AI voices on every call so recipients can ask for a human or opt out.
My AI Call Center bakes each of these steps into the pre-launch review: list source and consent records are checked before any campaign runs, bought lists without clear permission records are flagged and typically declined, opt-outs are logged and honored immediately, and AI disclosure is built into every script. The result is a managed, list-disciplined campaign model that addresses the actual legal standard — consent, disclosure, and conduct — rather than chasing a numeric threshold that does not exist.
Plan a compliant campaign with approved, permissioned lists — from 9¢ per connected minute.
Plan My CampaignWhat's Coming Next: AI Voices and the CRTC's Rule Modernization
Canadian telemarketing rules were written before AI voices existed — and the CRTC knows it. That gap is exactly what the regulator is now working to close.
The CRTC has opened Notice of Consultation 2026-132, a formal review of the Unsolicited Telecommunications Rules. Two proposed changes matter most for anyone running outbound campaigns: modernizing the ADAD (Automatic Dialing-Announcing Device) definition to explicitly capture AI and synthesized voices, and potentially introducing volume-based standards for the first time.
The timing is significant. Since the rules were introduced, the CRTC has conducted over 3,500 investigations, fielded more than 944,000 complaints — an average of 1,029 per week — and levied over $17.6 million in penalties, according to the consultation record. Modernized rules will meet an enforcement apparatus that is already active and well-funded.
The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG), an industry body with over 200 member organizations, has weighed in with a clear philosophy. Rather than regulating dialing technology, M3AAWG argues rules should be built around outcomes and meaningful consent. Its proposed test, per its consultation submission, is whether a person received an unwanted automated call without meaningful consent, without disclosure, and without anyone accountable for it.
M3AAWG's specific recommendations include:
- Replacing the outdated sequential/random dialing distinction with standards based on call volume and whether valid consent exists
- Requiring upfront disclosure whenever a call is made by a machine
- Holding both the calling platform and the client accountable for violations
No volume numbers have been adopted yet. But the direction is clear: future rules will likely ask not just "what technology did you use?" but "did the person consent, were they told, and who is responsible?"
Notice what those recommendations have in common — they describe practices that disciplined callers already follow. Organizations that disclose AI on every call, log and honor opt-outs immediately (well inside the 14-day processing deadline the CRTC currently allows), and verify consent records before a single dial are already operating to the standard the regulator is moving toward.
This is the operating model behind My AI Call Center's campaigns: list source and consent records are reviewed before launch, AI disclosure happens on every call, and opt-outs are logged and honored the moment they occur. When disclosure and consent become hard legal requirements rather than best practices, that workflow doesn't need to change.
The practical lesson for any organization running outbound calling into Canada is simple. Don't wait for the final rules to define your obligations. Build around consent, disclosure, and accountability now — because the regulatory curve is bending toward exactly those three things, and the enforcement history shows the CRTC does not hesitate to act once rules are in place.
Frequently Asked Questions
Is there a specific number of calls or texts that counts as harassment in Canada?
If there's no magic number, what actually triggers a CRTC violation?
Do the same rules apply to text messages as they do to phone calls?
What counts as valid consent for calling someone in Canada?
How quickly do I need to honor a do-not-call request?
Are the rules changing for AI-powered calls?
Stop Counting Messages — Start Counting Consent
The search for a magic harassment number ends here: it doesn't exist. Canadian telemarketing rules judge your campaigns on consent, disclosure, calling hours, and opt-out handling — not on how many touches you send. One call to a DNCL-registered number without valid consent is a violation; ten calls to a consenting customer within permitted hours may be perfectly fine. And with the CRTC's enforcement record showing over $17.6 million in penalties, the cost of guessing wrong is real. The practical path forward is clear: verify list source and consent records before launch, honor opt-outs immediately, respect calling windows, and disclose AI on every call. That's the standard My AI Call Center builds into every campaign review — and it's the same standard the CRTC's rule modernization is moving toward. If you're planning outbound calling into Canada and want a second set of eyes on your list before you spend anything, the first campaign review is free. Plan your campaign at myaicallcenter.app/campaigns.