
What are the penalties for violating CASL?
Key Facts
- CASL violations can cost organizations up to $10 million per violation — and individuals up to $1 million — according to BLG's legal analysis.
- In October 2023, the CRTC imposed a $40,000 penalty on a Quebec resident for phishing — the only published CASL enforcement action that year, per legal analysis.
- Spam sent into Canada falls under CASL regardless of its country of origin, Canada's official performance report states.
- More than half of spam and malicious emails are now AI-generated, making violations more convincing and harder to detect, the OECD reports.
- In November 2024, the CRTC analyzed roughly 25 high-complaint companies and warned continued non-compliance may trigger enforcement, per the ISED report.
- The FCC confirmed in February 2024 that AI-generated voices count as artificial voices requiring prior express consent, in its Declaratory Ruling.
- TCPA class-action settlements have reached $9.95 million, with filings up 95% year-over-year and verdicts exceeding $925 million, per compliance analysis.
What CASL Violations Actually Cost: The Penalty Numbers
The numbers behind a CASL violation are not subtle. Organizations face penalties of up to $10 million per violation, while individuals can be hit for up to $1 million per violation, according to legal analysis from BLG. And the liability doesn't stop at the corporate entity — it extends to directors and officers personally, though a due diligence defence exists for those who can demonstrate genuine compliance efforts.
Enforcement is real, even if published actions are relatively rare. In October 2023, the CRTC imposed a $40,000 administrative monetary penalty on a Quebec resident for running a high-volume phishing campaign — the only published enforcement action that entire year. That single case signals how the regulator responds when violations are flagrant and consent discipline is entirely absent.
CASL's reach also crosses borders. The official ISED performance report states it plainly: "Spam sent into Canada is subject to CASL, regardless of its country of origin." A campaign dialed from Austin into Canadian inboxes is just as exposed as one launched from Halifax — which is why any organization messaging Canadian recipients needs consent standards that hold up on both sides of the border.
The CRTC's enforcement approach is tiered rather than purely punitive, escalating through:
- Education, outreach, and industry information sessions reminding senders of penalty exposure
- Warning letters — in November 2024, the CRTC analyzed roughly 25 high-complaint companies and cautioned that continued non-compliance may trigger further enforcement
- Administrative monetary penalties, the tier reserved for serious or repeated violations
That escalation ladder creates a practical takeaway: consent records, opt-out logs, and documented list discipline are your evidence for the due diligence defence. This is why pre-launch list review matters so much — My AI Call Center checks list source and consent records before any campaign runs, and declines bought lists without clear permission records, precisely because that documentation is what separates a defensible campaign from a penalty.
The stakes are rising as AI amplifies the problem. The OECD reports that more than half of spam and malicious emails are now AI-generated, making violations both more convincing and more likely to draw complaints — the 38,000+ visits to Canada's report-spam form in 2024–25 show regulators have no shortage of leads.
Why the Brand Pays, Not the Vendor: The Compliance Risk You Can't Outsource
Hiring a vendor to place your calls does not hire away your legal exposure. If your brand benefits from the call, the regulator and the courts come looking for you — not the company that dialed the number.
The clearest proof sits in U.S. case law. Under Lamb v. Mortgage One Funding, the entity on whose behalf calls are made bears compliance responsibility even when a third-party vendor places them. As one TCPA compliance analysis puts it bluntly: if you're buying AI calling from a third party and assuming the third party owns the compliance risk, Lamb is the case that proves you wrong.
The financial stakes explain why this matters. TCPA violations carry statutory damages of $500–$1,500 per call, with no aggregate cap and no requirement to prove actual injury, and recent class-action settlements have reached $9.95 million. Filings are up 95% year-over-year, and aggregate TCPA verdicts exceed $925 million. Canadian businesses should pay attention too: CASL penalties reach up to $10 million per violation for organizations, with liability extending to directors and officers.
The AI question raises the stakes further. The FCC's February 2024 Declaratory Ruling confirmed that AI-generated voices count as "artificial or prerecorded voice" under the TCPA — meaning AI voice calls require prior express consent before dialing. That ruling is American, not Canadian, but it signals exactly where enforcement is heading for AI-assisted calling generally, and Canada's regulator is already watching the AI threat landscape closely.
What this means in practice for any business buying outbound calling:
- Verify list source and consent records before any campaign launches — bought lists without clear permission records are a liability, not an asset.
- Demand opt-out and DNC logs from your provider; the U.S. standard requires honoring revocation within ten business days and retaining documentation for at least four years.
- Require AI disclosure on every call, with a clear path to a human or an opt-out.
- Approve scripts, disclosures, and escalation paths before anything dials.
This is why list discipline cannot be an afterthought. A managed calling provider should tell you plainly, before you spend anything, whether a list will support the campaign — and decline it if it won't. At My AI Call Center, that pre-launch consent review is standard, because the alternative leaves the brand holding the risk.
Compliance risk follows the beneficiary of the call — the brand, not the vendor. Choose partners who treat it that way.
The Consent and Documentation Discipline That Builds a Due Diligence Defence
When regulators investigate a CASL complaint, they don't just ask whether you had permission — they ask whether you can prove it. That distinction is where consent discipline and documentation become your strongest protection.
CASL is an opt-in regime: commercial electronic messages cannot be sent without express or limited implied consent, along with prescribed formalities like sender information and a working unsubscribe mechanism, according to a 2023 year-in-review from BLG. Pre-checked boxes do not count as consent — marketers must obtain express permission before sending commercial emails or texts, as Octillo Law points out.
The stakes of getting this wrong are substantial. Penalties run up to $10 million per violation for organizations and $1 million for individuals, with liability extending to directors and officers. In October 2023, the CRTC issued a $40,000 administrative monetary penalty against a Quebec resident for a high-volume phishing campaign.
Enforcement is currently education-first — in November 2024, the CRTC analyzed roughly 25 companies with high complaint volumes, checking their consent records and unsubscribe mechanisms before sending warning letters cautioning that continued non-compliance "may result in further enforcement action," per the official 2024–25 performance report. But the compliance bar itself is not softening.
Here is what the operational discipline looks like:
- Verify list source and consent records before any campaign launches — not after a complaint arrives
- Honor consent revocations within ten business days, the standard reflected in the U.S. Opt-Out Rule effective April 2025
- Retain opt-out documentation for at least four years
- Log every opt-out and DNC request immediately and carry it across all campaigns
That documentation is the evidence base behind the due diligence defence. Under CASL, an organization that can demonstrate it took reasonable steps to comply — maintained consent records, honored opt-outs, monitored its processes — has a path to avoid liability even when something goes wrong. An organization that cannot produce those records has no such argument.
One more caution: don't assume a vendor owns the compliance risk. Under U.S. case law like Lamb v. Mortgage One Funding, the entity on whose behalf calls are made bears responsibility even when a third party dials, as vendor analysis notes. This is why My AI Call Center reviews list source and consent records before any campaign launches — and flags bought lists without clear permission records, declining them in most cases before you spend anything.
Build the discipline into your process now. When a regulator asks, your records should answer for you.
How a Compliant Managed Calling Process Reduces CASL Risk Before Launch
With CASL penalties reaching up to $10 million per violation for organizations — and liability extending to directors and officers — the safest moment to manage risk is before a single call is placed. The good news: CASL recognizes a due diligence defence, and a disciplined pre-launch process is exactly what that defence looks like in practice.
The process starts with list and consent review. Because CASL is an opt-in regime where pre-checked boxes do not constitute valid consent, every list should be traced to its source and its permission records before dialing begins. Bought lists without clear permission documentation are the highest-risk asset in outbound calling — they should be flagged and, in most cases, declined outright.
Script and disclosure approval matters just as much. The FCC has confirmed that AI-generated voices count as artificial voices requiring prior express consent, and under U.S. case law like Lamb v. Mortgage One Funding, the brand — not the vendor — bears compliance responsibility for calls placed on its behalf. Approving scripts, AI disclosures, and escalation paths before launch is how a business proves it took those obligations seriously.
Opt-out handling is where documentation becomes defence. The U.S. opt-out framework now requires honoring consent revocation within ten business days and retaining records for at least four years — a useful benchmark for the operational rigor Canadian regulators expect. Immediate opt-out honoring and maintained DNC logs give you the evidence trail a due diligence defence requires.
A compliant managed calling process builds all of this into the campaign itself:
- List and consent review before launch — list source, consent records, and calling windows checked before any campaign goes live.
- Script, disclosure, and escalation approval — nothing dials until the client signs off.
- Opt-outs logged and honored immediately, with DNC requests carried across all campaigns.
- Disposition reports with opt-out and DNC logs delivered as standard campaign outputs.
My AI Call Center runs structured, one-clear-goal campaigns against approved, permissioned, or reviewed lists only — never indiscriminate cold calling. When a list will not support the campaign, clients are told plainly, before spending anything. That pre-launch discipline, paired with honest reporting of what actually happened, is the operational embodiment of due diligence: proof, documented in advance, that the business took consent seriously — which matters when penalties this large are on the line.
Frequently Asked Questions
What are the maximum penalties for violating CASL?
Does CASL apply to calls or emails sent from outside Canada?
If I hire a vendor to make calls on my behalf, am I still liable for CASL violations?
What steps can I take to build a due diligence defence under CASL?
Are AI-generated voice calls subject to CASL or similar consent rules?
How often does the CRTC actually enforce CASL penalties?
The Cheapest CASL Penalty Is the One You Never Incur
CASL penalties are not subtle — up to $10 million per violation for organizations, with liability reaching directors and officers personally. The one real protection is the due diligence defence, and it only works if you can prove consent discipline: verified list sources, logged opt-outs, approved scripts, and AI disclosure on every call. Remember the key lesson from the article: compliance risk follows the brand, not the vendor. If your business benefits from the call, you own the exposure — so choose partners who review list source and consent records before anything dials, and who tell you plainly when a list won't support the campaign. Your next steps are simple: audit your current lists, confirm your consent documentation, and demand opt-out and DNC logs from any calling provider. With more than half of spam now AI-generated, regulators have no shortage of leads. If you want a managed calling process built on approved, permissioned, reviewed lists from the start, book a free campaign review at myaicallcenter.app — the full cost is known before you approve anything.