CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Data Privacy Standards

What does CASL prohibit?

Back to InsightsWhat does CASL prohibit?

What does CASL prohibit?

Key Facts

  • CASL bans six activities outright including unsolicited commercial messages, altering transmission data, unauthorized software installs, misleading representations, address harvesting, and illegal personal data collection per the official ISED source
  • The first major CASL enforcement action against Compu-Finder carried a $1.1M notice of violation for roughly ten weeks of emails according to compliance analysts
  • CASL penalties reach $10 million per violation for organizations and attach per violation so one campaign can generate multiple fines per regulatory analysis
  • CASL applies based on where the message is read not where it's sent from so a US team texting a Toronto lead is fully covered per compliance guidance
  • CASL does not cover voice calls at all — those fall under CRTC's Unsolicited Telecommunications Rules with corporate penalties up to $15,000 per call per outbound calling analysis
  • Express consent requires a positive action like checking an unchecked box — pre-checked boxes, silence, and inaction never count per compliance guidance
  • Purchased lists rarely arrive with usable proof of consent for any single address making them a liability not an asset per compliance analysts

The Six Activities CASL Explicitly Bans

Canada's Anti-Spam Legislation doesn't just discourage bad behaviour — it bans it outright. According to the official ISED source on Canada's Anti-Spam Legislation, six specific activities are prohibited, and regulators have shown they will enforce them: the first major enforcement action, against Compu-Finder, carried a $1.1M notice of violation.

The six banned activities are:

  • Sending unsolicited commercial electronic messages (CEMs) — email, SMS, and instant messages — without valid consent
  • Altering transmission data in an electronic message without authorization, redirecting it for commercial gain
  • Installing computer programs on someone's device without consent, including spyware and malware
  • Making false or misleading electronic representations, including deceptive websites and sender identities
  • Harvesting email addresses by collecting them without permission through automated tools
  • Collecting personal information by illegally accessing a computer system or electronic device

CASL is opt-in by design, and that distinction matters more than any other. Consent — express or implied — must exist before the first message goes out. Silence is not consent, and compliance guidance is clear that pre-checked boxes, silence, or inaction do not constitute valid consent. Express consent requires a positive action, such as checking an unchecked box.

The burden of proof sits entirely with the sender. If a regulator asks, you must be able to produce records showing when and how consent was obtained. That's why compliance experts note that a purchased list rarely arrives with usable proof of consent for any single address on it — a reality that shapes how responsible campaign operators work. My AI Call Center checks list source and consent records before any campaign launches, and flags bought lists without clear permission records for the same reason.

Two more points deserve attention. First, penalties are steep: up to $10 million per violation for organizations, and penalties attach per violation, so one campaign can generate multiple counts. Second, the law applies based on where the message is read, not where it's sent from — a US-based team emailing or texting a Toronto lead is fully covered.

One nuance worth knowing: CASL does not cover voice calls, which fall under the CRTC's Unsolicited Telecommunications Rules. But any SMS or email follow-up in a multi-touch campaign does fall under CASL, with all six prohibitions and the consent rules in full force.

What CASL Does Not Cover: Voice Calls and the UTR Boundary

Here's a fact that surprises many US-based teams: CASL does not apply to voice calls at all — not live telemarketing, not automated voice calls, not robocalls. Canada regulates its phone channel under an entirely separate framework: the CRTC's Unsolicited Telecommunications Rules (UTR).

That distinction matters because the two regimes carry different obligations, different record-keeping requirements, and different penalties. Under the UTR, corporate violations can reach $15,000 per call — a figure that compounds quickly across a campaign. And companies remain responsible for compliance violations by vendors or lead generators acting on their behalf, so outsourcing your calling does not outsource your liability.

Key UTR requirements for calling campaigns include:

  • Calling hour windows: weekdays 9:00 a.m.–9:30 p.m., weekends 10:00 a.m.–6:00 p.m. local time
  • The National DNCL version used must be no more than 31 days old — a refresh rule teams frequently miss
  • Internal do-not-call lists must be retained for 3 years plus 14 days
  • ADAD (automated dialing-announcing device) calls — robocalls — require prior express consent

The boundary gets tricky with multi-channel campaigns. A voice call may sit outside CASL, but the moment you follow it with an SMS or email, that message is a commercial electronic message and falls squarely under CASL. The text needs valid consent, sender identification, and a working unsubscribe mechanism honored within 10 days. A common mistake is assuming a customer who answered a call has consented to texts — TCPA-style habits do not carry over, and providing a phone number is not SMS consent.

Jurisdiction adds another wrinkle. CASL applies based on where the message is read, not where it is sent — so a US-based team texting a Toronto lead is fully covered. Operating from Austin does not exempt Canadian-bound texts and emails from compliance.

This is why structured campaign operators treat list and consent review as a pre-launch step rather than an afterthought. At My AI Call Center, every campaign checks list source, consent records, and calling windows before anything launches — because a call, a text, and an email in the same cadence may each face different rules. One multi-touch sequence can span two regulatory frameworks at once, and the only safe assumption is that each channel must stand on its own consent footing.

Most CASL violations don't come from malicious spammers — they come from businesses that assumed their consent was valid when it wasn't. Canada's anti-spam law is opt-in, not opt-out: consent is required before the first message, silence never counts, and the burden of proving consent sits entirely with the sender.

Express consent demands a positive action. The recipient must do something — typically checking an unchecked box. Pre-checked boxes, silence, and inaction do not constitute valid consent, and you cannot use misleading language to acquire addresses. If your signup form defaulted people into "yes," you don't have consent under CASL.

Implied consent runs on strict clocks, and each channel has its own window:

  • SMS: 24 months from the most recent purchase, with each new purchase resetting the clock, and 6 months for prospects who provided their contact info
  • Email: 2 years after a purchase or contract, and 6 months after an inquiry or application
  • Referrals: implied consent exists only if the referrer is not on the National Do Not Call List — and abandoned shopping carts trigger nothing

The B2B exemption is narrower than most teams expect. It requires an existing relationship between the companies and message content relevant to the recipient's role. Cold prospecting to companies you've never dealt with does not qualify, and the Federal Court of Appeal upheld the CRTC's narrow reading in the Compu-Finder case — a matter that began with a $1.1 million notice of violation covering roughly ten weeks of emails.

That brings us to purchased lists. As compliance analysts put it plainly, a purchased list rarely arrives with usable proof of consent for any single address on it. Since the sender carries the burden of proof, a list without documentation is a liability, not an asset — which is why My AI Call Center checks list source and consent records before any campaign launches, and flags or declines bought lists that lack permission records.

The practical takeaway: verify consent before launch, and keep records that can support a due diligence defense — documented consent, written policies, and training. Penalties can reach $10 million per violation for organizations, and one campaign can generate multiple violations. A consent review step isn't red tape; it's the cheapest insurance in your outbound program.

Message Requirements That Make Every SMS and Email Compliant

Running compliant SMS and email campaigns means embedding specific, non-negotiable elements into every commercial electronic message you send. Under CASL, each message must clearly identify the sender by including the organization’s name, a valid mailing address, and at least one way to contact them—such as a phone number, email address, or website URL. This ensures recipients know exactly who is reaching out and how to verify legitimacy. For businesses like My AI Call Center managing multi-channel outreach, this transparency builds trust while meeting legal obligations from the first touchpoint.

Equally critical is a functional unsubscribe mechanism that remains valid for at least 60 days from the message send date. Recipients must be able to opt out easily, and any unsubscribe request must be honored without delay—within 10 business days of receipt. For SMS specifically, CASL recognizes four valid opt-out keywords: STOP, END, QUIT, and UNSUBSCRIBE. Using any of these terms in a reply triggers the obligation to cease further commercial messages promptly. Messages must also avoid false or misleading content, including deceptive subject lines or fabricated sender details, as such practices violate CASL’s core prohibitions against misleading electronic representations. These requirements apply regardless of where the sender is located, since jurisdiction is based on where the message is read—not where it originates—making compliance essential for U.S.-based teams engaging Canadian audiences. Industry guidance confirms that missing or obscured sender information and non-functional unsubscribe links are among the most common CASL violations, often leading to enforcement actions even when consent was initially valid. Technical specifications further clarify that the unsubscribe process must be simple, immediate, and free of charge or unnecessary steps. Compliance analyses note that penalties for non-compliance can reach up to $10 million per violation for organizations, underscoring the cost of overlooking these foundational elements. Businesses running integrated campaigns—such as voice calls followed by SMS reminders or email surveys—must ensure that the text and email components meet these standards, even if the voice portion falls under separate regulations like the CRTC’s Unsolicited Telecommunications Rules. By embedding sender identification and reliable opt-out functionality into every message, organizations turn compliance into a signal of respect, reinforcing list quality and long-term engagement.

Enforcement Reality: Penalties, Vicarious Liability, and the US-Base Trap

Enforcement Reality: Penalties, Vicarious Liability, and the US-Base Trap

CASL carries significant financial risk, with maximum penalties reaching $10 million per violation for corporations and $1 million per violation for individuals, as confirmed by multiple regulatory analyses. One enforcement source notes that penalties can escalate to $15 million for subsequent corporate violations, highlighting the law’s teeth when compliance failures persist. These penalties attach per violation, meaning a single non-compliant campaign — such as sending SMS without valid consent — could trigger multiple fines if sent to numerous recipients.

Beyond fines, liability extends beyond the sender. Directors and officers can face personal liability if they directed, approved, or acquiesced in a violation, while employers remain vicariously liable for staff actions under the law. This responsibility also reaches third parties: companies are accountable for compliance failures by vendors or lead generators acting on their behalf, a principle reinforced under both CASL and the CRTC’s Unsolicited Telecommunications Rules. For managed services like My AI Call Center, this underscores the necessity of rigorous pre-campaign review, as outsourcing list procurement or message deployment does not shift legal responsibility.

Perhaps most critically for US-based operations, CASL applies based on where the message is read, not where it is sent from. A text or email dispatched from Austin, Texas, to a recipient in Toronto remains subject to CASL if the message is opened or viewed in Canada. This jurisdictional rule nullifies any assumption that an offshore operating base provides exemption — a common misconception among US teams engaging Canadian leads. The suspended private right of action adds complexity: while individuals cannot currently sue for damages, regulatory enforcement through the CRTC, Competition Bureau, and Privacy Commissioner remains active, though conflicting sources create uncertainty about its status.

To mitigate these risks, My AI Call Center embeds compliance into its pre-launch workflow. Every campaign undergoes list and consent review, verifying source legitimacy and permission records before any message is sent. This discipline directly addresses CASL’s burden of proof, which requires senders to demonstrate valid consent — a hurdle rarely cleared by purchased lists. By declining lists lacking clear permission trails and honoring opt-outs immediately, the service aligns with legal expectations while supporting clients’ outreach goals. This approach transforms compliance from a barrier into a foundation for trustworthy, permission-based communication.

Frequently Asked Questions

What are the six things CASL actually prohibits?
CASL bans six activities: sending unsolicited commercial electronic messages without valid consent, altering transmission data without authorization, installing programs on someone's device without consent, making false or misleading electronic representations, harvesting email addresses, and collecting personal information by illegally accessing a computer system, per the official ISED source. The first major enforcement action, against Compu-Finder, carried a $1.1M notice of violation covering roughly ten weeks of emails.
Does CASL apply if my business is based in the US but I'm texting Canadian leads?
Yes — CASL applies based on where the message is read, not where it's sent from, so a US-based team texting or emailing a Toronto lead is fully covered. Operating from Austin or anywhere else in the US does not exempt Canadian-bound texts and emails from CASL's consent, identification, and unsubscribe rules.
Does CASL cover phone calls too, or just texts and emails?
No — CASL does not apply to voice calls at all, including live telemarketing and robocalls; those are regulated under the CRTC's Unsolicited Telecommunications Rules, where corporate penalties can reach $15,000 per call. But any SMS or email follow-up in a multi-touch campaign does fall under CASL, so each channel needs its own consent footing.
Is a pre-checked consent box good enough under CASL?
No. CASL is opt-in by design, and pre-checked boxes, silence, and inaction do not constitute valid consent — express consent requires a positive action like checking an unchecked box. The burden of proof sits entirely with the sender, so you must be able to produce records showing when and how consent was obtained.
Can I use a purchased email or SMS list for Canadian campaigns?
It's risky — a purchased list rarely arrives with usable proof of consent for any single address on it, and since you carry the burden of proving consent, an undocumented list is a liability, not an asset. That's why My AI Call Center checks list source and consent records before any campaign launches and flags bought lists without clear permission records.
How big are the penalties for breaking CASL?
Penalties reach up to $10 million per violation for organizations and $1 million for individuals, and they attach per violation — so one campaign can generate multiple counts. Liability also extends to directors and officers who approved a violation, and companies remain responsible for compliance failures by vendors or lead generators acting on their behalf.

Compliance Is the Cheapest Insurance Your Outbound Program Will Ever Buy

CASL bans six activities outright — from unsolicited commercial messages to address harvesting — and it makes consent the sender's burden to prove. The stakes are real: penalties can reach $10 million per violation for organizations, and a single campaign can stack multiple counts. Remember the boundaries: voice calls fall under the CRTC's UTR, but any SMS or email follow-up lands squarely under CASL — and the law applies based on where the message is read, not where your team sits. Your next steps are straightforward: audit where every list came from, verify that consent records exist for each contact, embed sender identification and working unsubscribe mechanisms into every message, and honor opt-outs within 10 business days. If a list can't be proven, treat it as a liability, not an asset. That's the same discipline My AI Call Center applies before any campaign launches — list source and consent records are checked first, and we tell you plainly if a list won't support the campaign. Ready to run compliant, structured outreach? Plan your campaign and get a full quote before anything launches.

Get campaign planning tips