
What are the requirements of CASL?
Key Facts
- 53% of CASL complaints stem from lack of consent, making it the most common violation category according to CRTC enforcement reporting.
- CASL penalties can reach $1 million per violation, with the burden of proof resting entirely on the sender industry reports confirm.
- CASL applies to every commercial electronic message sent to or from Canada, regardless of where the sender is located research highlights.
- Every commercial message must include a functional unsubscribe mechanism valid for at least 60 days, with requests honored promptly as compliance analysis notes.
- The CRTC puts the burden squarely on senders: they must prove consent was obtained, not the other way around per the CRTC's compliance FAQ.
- Implied consent expires and requires ongoing record-keeping, while express consent never does the CRTC's guide explains.
- Canada is no longer among the top 10 worst spam countries, a shift credited to CASL enforcement government performance reporting shows.
The Compliance Burden: Why CASL Catches Canadian Marketers Off Guard
The Compliance Burden: Why CASL Catches Canadian Marketers Off Guard
Canadian marketers often underestimate the reach and rigor of the Canadian Anti-Spam Law (CASL), which applies to all commercial electronic messages (CEMs) sent to or from Canada, regardless of the sender’s location. Research highlights that this broad jurisdiction creates unexpected compliance challenges, particularly for organizations operating across multiple regions. For businesses, the stakes are high: 53% of CASL complaints stem from lack of consent, a figure that underscores the critical importance of meticulous record-keeping.
Penalties for non-compliance can escalate rapidly, with fines reaching up to $1 million per violation. Industry reports emphasize that the burden of proof lies entirely with the sender, requiring businesses to demonstrate explicit or implied consent for every message. This creates a significant compliance burden, especially for multi-location organizations managing complex outbound campaigns.
- Maintain detailed consent records, including dates and methods of acquisition
- Implement clear opt-in processes and functional unsubscribe mechanisms
- Regularly audit consent management practices to align with evolving regulations
For businesses like My AI Call Center, navigating CASL requires a disciplined approach to list quality and consent verification. Their managed outbound calling service prioritizes approved, permissioned, or reviewed contact lists, ensuring compliance before any campaign launches. By scrutinizing list sources and consent records, they mitigate risks associated with unverified data. This process aligns with CASL’s emphasis on transparency, as official guidance advises businesses to avoid implied consent where possible, opting instead for explicit permission to reduce legal exposure.
Multi-location organizations face unique challenges in harmonizing CASL requirements across jurisdictions. The law’s strict enforcement, including warning letters and preservation demands, demands proactive compliance strategies. Enforcement trends show that even minor oversights can trigger costly penalties, making it imperative for businesses to integrate robust consent management systems. By prioritizing list discipline and compliance-forward processes, organizations can avoid the pitfalls that trap many marketers in CASL violations.
The Core Requirements: Consent, Proof, and Unsubscribe Mechanisms
Under CASL, the government does not chase down proof of permission for you. The CRTC puts the full weight of that burden on the sender: "The onus is on the person who is sending the message to prove they have obtained consent to send the message," according to the CRTC's compliance FAQ. That single sentence shapes everything else about the law.
CASL recognizes two routes to consent before you send a commercial electronic message — whether that's an email, a text, or another electronic message to or from Canada. Express consent is explicit permission the contact gave you directly. Implied consent arises in narrower circumstances, such as an existing business relationship, and it comes with deadlines and expiry dates attached.
The CRTC's guidance is blunt about what implied consent demands: "If you continue to send CEMs over time, based on implied consent, there is an ongoing need to maintain accurate records," per the CRTC's electronic messages guide. Implied consent is not a set-and-forget permission. It decays, and you have to track it.
That tracking is where many businesses stumble. At minimum, your consent records should capture:
- The date consent was obtained
- The method used to obtain it (form, phone call, in-person signup)
- The exact wording the contact agreed to
- The identity of the person or business that sought consent
The stakes are real. Lack of consent is the most common complaint category under CASL, accounting for 53% of complaints, according to CRTC enforcement reporting. And the financial exposure is significant — penalties for non-compliance can reach up to $1 million, as reported by Bizibl.
Every message also needs a functional unsubscribe mechanism that remains valid for at least 60 days, and requests must be honored promptly. An unsubscribe link that goes nowhere, or that you ignore, undermines the consent framework entirely.
Given all this, the practical advice from compliance commentators is simple: "To keep things simple and safe... you're better off getting explicit permission... rather than dealing with the deadlines, red-tape and headaches associated with implied permission," according to Bizibl's CASL coverage. Express consent never expires, so the record you keep at signup does most of the work for you.
This is the standard we apply at My AI Call Center before any campaign launches. We review list source and consent records — the date, the method, the permission trail — and we tell you plainly if the list will not support the campaign, before you spend anything. Bought lists without clear permission records are flagged, and in most cases declined.
Building this discipline into your own program means implementing a comprehensive consent management system with clear opt-in processes, record-keeping, and unsubscribe mechanisms, as recommended by Osler's CASL compliance planning guidance. It is less glamorous than campaign creative, but it is what keeps the whole program lawful.
Consent Records: What You Must Document and How Long You Must Keep It
Under CASL, consent isn't just something you obtain — it's something you must be able to prove. If a regulator ever asks, "the onus is on the person who is sending the message to prove they have obtained consent to send the message," as the CRTC's own guidance makes clear. A contact list you can't document is, for compliance purposes, a list you may not have permission to use at all.
What a proper consent record contains
The CRTC requires businesses to maintain records that show the date and method of consent for every contact they message. That means for each person on your list, you should be able to answer: when did they consent, how did they consent (web form, verbal, existing business relationship), and what was the scope of that consent?
For implied consent, the record-keeping burden is heavier, not lighter. Because implied consent can expire, the CRTC notes that "if you continue to send CEMs over time, based on implied consent, there is an ongoing need to maintain accurate records" (CRTC CASL guide). You need to track the relationship or event that created the implied consent so you know when it lapses.
Why documentation is non-negotiable
The stakes are real. Penalties for non-compliance can reach $1 million, and enforcement is active — the CRTC continues to issue warning letters, notices to produce, and preservation demands (CRTC enforcement activity). A notice to produce, in particular, means the regulator is asking you to show your records — and "we're pretty sure they opted in" doesn't satisfy that request.
Lack of consent is already the most common complaint category under CASL, accounting for 53% of complaints. That tells you where regulators and Canadians are focused.
A workable consent record should capture:
- The date consent was obtained, so you can track expiry windows for implied consent
- The method of consent — web form, written agreement, or the business relationship that created implied consent
- The scope of consent — what the person agreed to receive, and from whom
- Opt-out history, so withdrawn consent is honored across every future campaign
This is why list discipline matters as much as list size. At My AI Call Center, list source and consent records are reviewed before any campaign launches, and bought lists without clear permission records are flagged — in most cases, declined outright. The same logic applies to your own outreach: a smaller list you can document beats a bigger list you can't.
Where possible, get express consent instead. As one compliance analysis puts it, you're better off getting explicit permission than dealing with the deadlines and headaches of implied consent — express consent doesn't expire, and it's far easier to prove. Build your records at the moment consent happens, and the documentation requirement takes care of itself.
How to Build a CASL-Compliant Consent Verification Process
Under CASL, the burden of proof sits with you, not the recipient. As the CRTC puts it, "the onus is on the person who is sending the message to prove they have obtained consent" — which means a consent process you cannot document is, functionally, no consent at all. With lack of consent accounting for 53% of CASL complaints, verification is where most compliance programs fail.
Building a defensible process comes down to four disciplines.
Start with a clear opt-in process. Express consent is generally safer than implied consent, because you avoid the deadlines and record-keeping headaches tied to implied permission. Capture consent at the point of contact, and record the date, method, and wording the person agreed to. If you rely on implied consent for existing relationships, remember there is an ongoing need to maintain accurate records as time passes.
Audit your consent records regularly. A consent management system only works if the records stay current. Review them on a fixed schedule, confirm each entry shows when and how permission was obtained, and flag gaps before they become enforcement problems — CRTC enforcement remains active through warning letters, notices to produce, and preservation demands.
Log and honor opt-outs immediately. Every unsubscribe request should be recorded the moment it arrives and honored across all channels and campaigns, not just the one it came through. Keep those logs. They are proof your unsubscribe mechanism works and that you respect withdrawals of consent.
Review every list before a campaign launches. This is the step that catches problems early. Before any outreach, verify the list source, confirm consent records exist for the contacts on it, and decline anything you cannot verify. Bought lists without clear permission records should be flagged, and in most cases declined outright.
This pre-campaign review is how My AI Call Center operates. Before any campaign launches, the team reviews list source, consent records, and calling windows — and tells you plainly if the list will not support the campaign, before you spend anything. That discipline matters whether you are running calls in-house or through a managed service.
A few practical checks to build into your own process:
- Record the date, method, and wording of every consent captured
- Prefer express consent over implied consent wherever possible
- Audit consent records on a recurring schedule, not just at launch
- Log opt-outs immediately and carry them across every campaign and channel
- Decline any list that lacks verifiable permission records
None of this is optional housekeeping. Penalties for non-compliance can reach $1 million, and the law applies to every commercial electronic message sent to or from Canada regardless of where the sender sits. A documented, repeatable consent verification process is the difference between a campaign you can defend and one you cannot.
Getting Campaign-Ready: A Pre-Launch CASL Checklist
A single oversight in consent management can derail a campaign and invite costly penalties. With 53% of CASL complaints stemming from insufficient consent records, proactive preparation is non-negotiable. Businesses must align processes with legal requirements before launching outbound calls or messages.
Verify list source and confirm consent records to ensure compliance. According to CRTC guidelines, businesses must maintain detailed records of how and when consent was obtained. This includes dates, methods, and explicit or implied permissions. Over 70,000 cyber security incidents in Canada in 2023 highlight the risks of lax data practices.
- Set approved calling windows to avoid violations of time restrictions
- Define clear opt-out mechanisms and escalation paths for complaints
- Secure legal review to address jurisdictional nuances and industry-specific rules
My AI Call Center emphasizes list discipline, verifying consent records before any campaign launches. This approach aligns with expert advice to prioritize express consent over implied alternatives. Businesses that fail to document consent face penalties of up to $1 million, as noted in CRTC enforcement reports.
Before deployment, ensure all messaging includes unsubscribe options valid for 60 days, as mandated by CASL. Regularly audit consent management systems to adapt to evolving regulations. With 40% of Canadian organizations experiencing data breaches in 2023, rigorous compliance processes protect both businesses and recipients.
Plan your campaign with a free review to validate compliance and avoid costly missteps. Start your campaign today and ensure every call meets legal standards.
Frequently Asked Questions
What are the main requirements of the Canadian Anti-Spam Law (CASL) for businesses sending commercial electronic messages?
What is the difference between express and implied consent under CASL?
How long do businesses have to honor unsubscribe requests under CASL?
What are the potential penalties for non-compliance with CASL?
How can businesses ensure they are compliant with CASL when sending commercial electronic messages?
What is the importance of maintaining detailed consent records under CASL?
Consent You Can Prove: The Real CASL Standard
CASL comes down to one principle: if you cannot prove consent, you do not have it. The burden sits entirely with the sender, lack of consent drives 53% of CASL complaints, and penalties can reach $1 million per violation. That makes your records as valuable as your list. Prefer express consent over implied wherever possible, document the date, method, and wording of every opt-in, honor unsubscribe requests immediately, and audit your records on a fixed schedule rather than only at launch. A smaller list you can document always beats a bigger list you cannot. If you are running outbound campaigns, this discipline has to exist before the first call goes out — which is why My AI Call Center reviews list source and consent records before any campaign launches, and tells you plainly if a list will not hold up. Start with a free campaign review to validate your lists and consent records before you spend anything, and run calls you can defend.