
What are the laws in Canada regarding spam emails?
Key Facts
- Since July 1, 2014, CASL has been one of the world's strictest anti-spam laws, with corporate fines of $10 million.
- CASL covers email, texts, voice messages, and social media; 'electronic address' includes telephone numbers.
- Under CASL, pre-checked boxes cannot secure consent; senders must prove a positive opt-in.
- Implied consent lasts two years after a purchase or contract, but only six months after an inquiry.
- Flawed unsubscribe mechanisms alone drew a $48,000 penalty; CASL requires opt-outs within 10 business days.
- The first CASL enforcement case ended in a $1 million fine, signaling regulators would use the law.
- Unlike U.S. CAN-SPAM, Canada requires consent before messaging — no permission, no message.
Why Canada's Anti-Spam Law Catches Businesses Off Guard
Canada's Anti-Spam Legislation (CASL) has proven to be a formidable compliance challenge for businesses, particularly those operating across borders. Enacted on July 1, 2014, CASL is one of the strictest anti-spam laws globally, requiring prior consent for commercial electronic messages (CEMs) and imposing severe penalties for violations. Industry experts note its rigorous framework, which extends to emails, texts, voice messages, and even social media interactions.
CEMs under CASL include any electronic communication for a “commercial activity,” such as promoting products, services, or fundraising. Research highlights that the law applies to all organizations, including nonprofits and associations, with no exemptions. This broad scope often catches businesses unprepared, especially those relying on legacy contact lists or informal consent practices.
The stakes are high: corporations face fines up to $10 million, while individuals could be penalized $1 million. Enforcement cases include a $1 million fine for the first CASL violation and a $48,000 penalty for flawed unsubscribe mechanisms. Crucially, the burden of proof rests on the sender to demonstrate compliance, a requirement that complicates even well-intentioned campaigns.
- CEMs must include sender identification, contact details, and an unsubscribe mechanism
- Implied consent expires after 2 years for business relationships or 6 months for inquiries
- Voice messages and texts are explicitly classified as CEMs under CASL
For managed services like My AI Call Center, CASL’s emphasis on “approved, permissioned, or reviewed” lists aligns with its operational discipline. The company’s pre-launch consent reviews and immediate opt-out logging exceed CASL’s 10-business-day unsubscribe deadline, reducing legal exposure. As legal analysis underscores, businesses lacking rigorous compliance systems often underestimate the complexity of proving consent—especially when targeting dormant audiences or cross-border contacts.
The Three CASL Requirements: Consent, Identification, Unsubscribe
The first thing CASL asks is not "what did you send?" but "can you prove they said yes?" Since July 1, 2014, every commercial electronic message to a Canadian recipient must satisfy three requirements: consent, identification, and a working unsubscribe mechanism. Miss any one, and the penalties reach up to $10 million for corporations.
Consent comes first. Express consent requires a positive opt-in action — pre-checked boxes are prohibited, and you cannot bundle a consent request with terms-and-conditions acceptance. Once given, express consent lasts until the recipient withdraws it. The burden of proof rests on the sender, which means you need records showing when and how consent was obtained.
Implied consent offers a fallback, but only on a clock:
- A purchase, business opportunity, or written contract creates implied consent for a two-year look-back window.
- An inquiry or application supports messaging for only six months.
- Donations, volunteer work, or club memberships also create a two-year implied-consent window.
That timing matters for reactivation work. A dormant customer from 18 months ago may still fall inside the window; one from three years ago does not. This is why My AI Call Center reviews list source and consent records before any campaign launches — bought lists without clear permission records get flagged, and in most cases declined, before a client spends anything.
Identification is the second requirement. Every message must identify the sender and any person on whose behalf it was sent (a hyperlink works), plus provide contact information including a mailing address — a P.O. box is acceptable. Recipients should never have to guess who is messaging them or how to reach a real person.
The unsubscribe mechanism is the third. It must be easy to use, free, and honored within 10 business days. Enforcement takes this seriously: one dating site received a $48,000 penalty for flawed unsubscribe mechanisms alone, and the first-ever CASL enforcement case carried a $1 million fine. At My AI Call Center, opt-outs are logged and honored immediately — a standard that exceeds the CASL floor.
Finally, note how CASL differs from U.S. CAN-SPAM. Identification and unsubscribe rules are broadly similar, but CAN-SPAM does not require consent — American senders can email first and offer an opt-out later. Canada flips that default: no permission, no message. For any organization messaging into Canada, that single difference changes how lists must be built and documented from day one.
What CASL Enforcement Looks Like in Practice
Three regulators share the job of policing Canadian inboxes, and they have shown they are willing to use it. The first-ever CASL enforcement case resulted in a $1 million fine, a number that made it clear from the start that this law would not sit on the shelf.
Enforcement is led by the CRTC, working alongside the Office of the Privacy Commissioner and the Competition Bureau. Each agency brings its own lens — telecommunications, privacy, and fair competition — so a single non-compliant campaign can attract attention from more than one direction. That overlap raises the practical stakes for anyone sending commercial messages into Canada.
The penalties are not reserved for spam empires. A dating site received a $48,000 penalty for flawed unsubscribe mechanisms alone — no complaint about consent, no allegation of deceptive content, just an opt-out process that did not work properly. Since CASL requires unsubscribe requests to be honored within 10 business days, even the plumbing of your email program carries financial risk.
Who is on the hook matters too. Under CASL:
- Corporations face maximum penalties of up to $10 million per violation.
- Individuals face maximum penalties of up to $1 million.
- Directors, officers, and agents can be held personally liable if they directed, authorized, or participated in a violation.
That personal liability provision is worth pausing on. A marketing decision made inside a company can follow the person who made it, not just the company itself. For multi-location organizations where campaigns are approved locally, this makes clear internal sign-off processes a genuine protection.
There is one less urgent threat, for now. CASL was designed to include a private right of action, which would have let individuals sue senders directly, but it has been postponed due to stakeholder concerns. Regulators still do all the enforcing today, though a reconsideration remains possible, so treating the pause as permanent would be a mistake.
The most important practical point is this: under CASL, the burden of proof sits with the sender. As the Stikeman guide puts it, the sender must be able to prove it had the necessary consent or that an exemption applied. In an enforcement conversation, "we assumed they were okay with it" carries no weight — records do.
That is why consent documentation is the only real defense in practice. When we review list source and consent records before any My AI Call Center campaign launches, it is not bureaucratic caution — it is building the evidence file you would need if a regulator ever asked. Bought lists without clear permission records are flagged, and in most cases declined, precisely because they cannot survive that burden of proof.
If you are planning outbound campaigns into Canada and want a second set of eyes on your list and consent records before launch, that review is free, and the full campaign cost is known before you approve anything.
Building a Consent-First Outreach Program That Passes a CASL Review
If a regulator ever asks you to prove consent for a single message in your database, would you be able to? Under CASL, the burden of proof sits entirely with the sender — you must demonstrate you had consent or a valid exemption, not the other way around (Canadian legal guidance from Stikeman confirms this explicitly). That reality is why a consent-first outreach program isn't optional for multi-location businesses; it's your only defensible position.
Start every campaign with a full audit of list sources and consent records. Map where each contact came from, when consent was captured, and in what form. Express consent requires a positive opt-in — pre-checked boxes don't count, and consent can't be bundled into terms-and-conditions acceptance — but once obtained, it doesn't expire until withdrawn (legal analysis from Whiteford notes).
Dormant contacts deserve special scrutiny before any win-back or reactivation effort. Implied consent based on an existing business relationship only lasts two years from a purchase or contract, and just six months for inquiries (per Whiteford's guidance). A 12-to-24-month dormant list may still be inside the window — but you need the relationship date on record to prove it.
Your pre-launch checklist should cover:
- Documented list source and consent record for every contact, before any campaign launches
- A dormancy screen that flags contacts outside the two-year implied-consent window
- Immediate opt-out handling, logged — CASL requires honoring unsubscribes within 10 business days, and a flawed mechanism alone drew a $48,000 penalty (enforcement data shows)
- The same discipline applied to voice and text, since CASL's definition of commercial electronic messages includes sound and voice, and "electronic address" covers telephone (per Whiteford)
That last point matters more than most businesses realize. A calling campaign to a Canadian contact is held to the same consent standard as an email blast, with penalties reaching up to $10 million for corporations (Stikeman reports). Directors and officers can even face personal liability for violations they authorize (Whiteford warns).
This is exactly why a managed, permissioned-list calling service like My AI Call Center runs a list and consent review before any campaign launches — checking list source, consent records, and calling windows, and flagging bought lists without clear permission records. If a list won't support the campaign, you learn that before spending anything, not after a regulator does.
Frequently Asked Questions
Does Canada's anti-spam law apply to my business if I'm not based in Canada?
What counts as a commercial electronic message under CASL?
What's the difference between express and implied consent under CASL?
How quickly do I have to honor an unsubscribe request?
What are the penalties for violating CASL?
How is CASL different from U.S. CAN-SPAM?
Navigating CASL Compliance: A Strategic Imperative for Canadian Businesses
Canada’s Anti-Spam Legislation (CASL) demands rigorous compliance, requiring businesses to secure express or implied consent, provide clear sender identification, and implement functional unsubscribe mechanisms. With penalties reaching up to $10 million for corporations and personal liability for executives, the burden of proof lies squarely on the sender. For organizations operating across borders, understanding these rules is not just a legal necessity but a strategic advantage. My AI Call Center’s proactive approach—auditing list sources, verifying consent records, and honoring opt-outs immediately—exemplifies how compliance can be integrated into operations without compromising efficiency. As CASL enforcement remains strict, businesses must prioritize transparency and documentation to avoid costly missteps. By aligning with regulations like CASL, companies protect their reputation and reduce legal risks. For those planning outbound campaigns, a free list review can reveal gaps before they become liabilities. Research shows even minor oversights, like flawed unsubscribe processes, can trigger significant fines. Take a proactive step today: evaluate your contact practices and ensure every message adheres to Canada’s high standards. The cost of compliance is far less than the price of non-compliance.