CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Data Privacy Standards

What does CASL stand for in Canada?

Back to InsightsWhat does CASL stand for in Canada?

What does CASL stand for in Canada?

Key Facts

What CASL Stands For — and Why It Exists

If your business sends emails, texts, or messages to anyone in Canada, four letters should shape how you operate: CASL. The acronym stands for Canada's Anti-Spam Legislation, and it carries more legal weight than most senders realize.

According to Innovation, Science and Economic Development Canada, CASL was enacted in 2014 to combat spam and related cyber threats, including identity theft, phishing, and malware. The CRTC, Canada's telecommunications regulator, has enforced it since it came into force.

Legal experts do not describe CASL lightly. Stikeman Elliott calls it "among the strictest and most complex anti-spam laws in the world." That reputation comes from how the law is built: consent is the default requirement, and the burden of proving it sits entirely on the sender.

CASL applies when two elements are present — a commercial electronic message (CEM) sent to an electronic address. Per the CRTC's official FAQ, electronic addresses include:

  • Email messages
  • SMS and text messages
  • Instant messaging
  • Social media messaging, such as Facebook Messenger and LinkedIn messages

Every CEM must meet three requirements: obtain consent (express or implied), provide identification information, and include a working unsubscribe mechanism. Express consent never expires on its own — it remains valid until the recipient withdraws it, and the sender must be able to prove it existed.

One distinction matters enormously for calling operations: CASL does not apply to live voice or automated telemarketing calls. Those fall under the separate Unsolicited Telecommunications Rules. But for multi-touch campaigns that combine calls with texts and emails — like the database reactivation campaigns we run at My AI Call Center — the text and email components sit squarely under CASL's rules, which is why list source and consent records get reviewed before anything launches.

The penalties explain why businesses take this seriously. Violations can bring fines of up to $10 million for corporations and $1 million for individuals, and directors and officers can be held personally liable. Enforcement is real: the CRTC's first action in 2015 brought a $1.1 million penalty against Compu-Finder, a company behind more than 25% of all spam complaints the regulator received. Even a broken unsubscribe mechanism alone drew a $48,000 fine in one case.

The law's impact has been measurable. Within a year of CASL's introduction, government data shows a 37% decrease in Canadian-based spam and 29% less email landing in Canadians' inboxes. In 2014, Canada hosted 7 of the world's top 100 spamming organizations; by 2019, none remained.

For any organization sending electronic messages to Canadians — including U.S.-based senders, since CASL covers messages received in Canada from other countries — understanding this law is not optional. It is the foundation every compliant outreach program is built on.

What CASL Covers — and the Critical Voice-Call Exception

If you're planning outreach that touches Canadian contacts, the single most important scope question is which channel each message travels through. CASL's reach is broader than many marketers assume — and narrower in one place that matters enormously for calling operations.

Under the CRTC's own guidance, CASL applies when two elements come together: a commercial electronic message (CEM) sent to an electronic address. That covers email, SMS/text messaging, instant messaging, and social media messaging such as Facebook Messenger and LinkedIn. The law is deliberately technology-neutral, so it also captures websites, applications, blogs, and VoIP, according to the Competition Bureau.

Every CEM must meet three requirements: obtain consent (express or implied), provide identification information, and include a working unsubscribe mechanism. The burden of proof sits squarely on the sender, and express consent remains valid until the recipient withdraws it. Consent is, in the CRTC's words, a "fundamental principle" of the legislation — and the penalties reflect that, with fines up to $10 million for corporations.

Here's the critical exception for anyone running calls alongside texts and emails. Per the CRTC FAQ, CASL does not apply to live voice or automated telemarketing calls to telephone numbers. Those fall under the separate Unsolicited Telecommunications Rules instead. For multi-touch campaigns that combine calls, texts, and emails, that means two different rulebooks apply at once:

  • Text and email touches require CASL consent, identification, and unsubscribe compliance.
  • Voice calls follow the Unsolicited Telecommunications Rules, not CASL.
  • B2B messages get no exemption — the first CASL enforcement action was a $1.1 million penalty against Compu-Finder for unsolicited B2B emails.
  • Cross-border reach applies: CASL covers messages received in Canada from other countries, not just those sent from within it.

This distinction shapes how structured outbound programs get built. At My AI Call Center, the list and consent review step checks list source and consent records before any campaign launches — and every non-voice touch in a multi-touch campaign still has to clear CASL's three-part test. Text-message spam is also on the rise per complaint data, so the SMS components of any campaign face heightened scrutiny.

The practical takeaway: know which rulebook governs each channel before you launch. Voice calls and electronic messages may sit in the same campaign, but they answer to different laws.

The Three Rules Every Message Must Follow

Every commercial electronic message that lands in a Canadian inbox or phone passes the same three-part test — and the sender, not the recipient, carries the burden of proving it was sent legally. The CRTC's own guidance is clear: any commercial electronic message sent to an electronic address must satisfy consent, identification, and unsubscribe requirements simultaneously.

Rule 1: Consent, and the sender must prove it. Consent can be express or implied, but the legal weight falls entirely on the sender. According to legal analysis from Stikeman Elliott, "the onus is on the sender of a commercial electronic message to be able to prove that it had the necessary consent." If you cannot produce records showing when and how consent was obtained, the consent does not legally exist.

Express consent is also durable — it remains valid until the recipient withdraws it, with no expiry date. This is why disciplined list management matters so much. My AI Call Center checks list source and consent records before any campaign launches, and declines bought lists that lack clear permission documentation — a practice that maps directly onto CASL's evidentiary burden.

Rule 2: Identify yourself clearly. Every message must state who is sending it and how the recipient can reach you. Anonymity is not an option, and vague sender names do not satisfy the requirement.

Rule 3: Provide a working unsubscribe mechanism. This is not a formality. A dating site operator was fined $48,000 for an unsubscribe mechanism violation alone — no consent violation required.

The consequences of skipping these rules compound quickly:

  • Corporations face maximum penalties of $10 million; individuals, including directors and officers, face up to $1 million in personal liability
  • Over $3.2 million in administrative monetary penalties have been issued since CASL came into force in 2014
  • Directors and officers can be personally liable if they authorized or participated in a violation
  • 216,800+ complaints reached the Spam Reporting Centre between October 2023 and March 2024 alone

One misconception deserves special attention: B2B messages are not exempt. The first CASL enforcement action — a $1.1 million penalty against Compu-Finder in March 2015 — involved unsolicited business-to-business emails. The CRTC described the violations as "flagrant," and Compu-Finder's activity generated more than 25% of all spam complaints the regulator received.

As CRTC Chief Compliance and Enforcement Officer Steven Harroun put it, "Obtaining consent is a fundamental principle of Canada's anti-spam legislation." Treat every outbound text and email touch — including the messaging components of multi-channel campaigns — as needing documented consent, clear identification, and an unsubscribe path that actually works.

What Happens When You Get It Wrong: Penalties and Enforcement

CASL is not a law with soft consequences. The fines are large, the liability is personal, and the enforcement record shows regulators follow through.

The maximum penalties are striking. Under CASL, corporations face fines of up to $10 million per violation, while individuals — including directors, officers, and agents — face up to $1 million each, according to Stikeman Elliott's legal analysis. The Competition Bureau confirms that directors and officers can be held personally liable if they directed, authorized, or participated in a violation.

These are not theoretical numbers. Since CASL came into force in 2014, the CRTC has issued over $3.2 million in administrative monetary penalties. The enforcement actions themselves tell the story:

  • Compu-Finder, $1.1 million (2015): The first CASL enforcement action penalized the company for four violations, including unsolicited B2B emails. Its messages generated more than 25% of all spam complaints the CRTC received, per Hogan Lovells' case review.
  • Scott William Brewer, $75,000: The largest penalty ever issued to an individual, for allegedly sending more than 670,000 emails without consent between 2015 and 2018, per the CRTC's announcement.
  • Dating site operator, $48,000: A fine issued over a broken unsubscribe mechanism alone — proof that technical failures, not just bad intent, carry real cost, per legal reporting on the case.
  • Sami Medouni, $40,000: Penalized for a phishing campaign that sent over 30,000 text messages without consent, per the CRTC's enforcement report.

Complaint volume shows no sign of slowing. The Spam Reporting Centre received more than 216,800 complaints between October 2023 and March 2024 alone, and "consent for messages" was the single largest complaint category. Text-message spam in particular is on the rise, according to ISED Canada's data — meaning SMS components of any campaign face growing scrutiny.

The through-line across every case is the same: the sender must prove consent existed. As CRTC Chief Compliance and Enforcement Officer Steven Harroun put it, "individuals are just as accountable as businesses" when it comes to respecting consent.

This is exactly why list discipline matters before a single message goes out. At My AI Call Center, every campaign starts with a list and consent review — list source, permission records, and opt-out handling checked before launch, with bought lists lacking clear consent records flagged or declined. When the penalty for guessing wrong runs into the millions, verifying permission first is not caution. It is the cost of doing business in Canada.

How to Run CASL-Safe Campaigns (and How We Handle It)

Knowing CASL stands for Canada's Anti-Spam Legislation is one thing; running campaigns that survive scrutiny is another. The law's three-part test, its consent burden, and its penalties translate into a small number of concrete pre-launch habits.

Start with consent records before anything goes out. Under CASL, the sender bears the burden of proving consent existed, and express consent stays valid only until the recipient withdraws it. That means "we think they opted in" is not a record — a timestamped source, method, and scope of permission is. This is why My AI Call Center checks list source and consent records before any campaign launches, and why bought lists without clear permission records are flagged and, in most cases, declined before you spend anything.

Next, apply the three-part test to every text and email touch. CASL covers commercial electronic messages sent to electronic addresses — email, SMS, instant messaging, and social media — but does not apply to voice calls, which fall under separate telemarketing rules. Multi-touch campaigns that mix calls, texts, and emails therefore need channel-by-channel review:

  • Consent: verified permission for the specific channel, with records you can produce on demand.
  • Identification: the message clearly states who is sending it and how to reach them.
  • Unsubscribe: a working opt-out mechanism in every text and email — a broken one alone drew a $48,000 fine against a dating site operator.

Opt-outs must then be honored immediately, across channels. Because consent exists only until withdrawn, an opt-out is a consent withdrawal, not a suggestion. Logging opt-outs and carrying them into DNC records — with the logs delivered as part of the campaign report — is the practical safeguard that keeps one request from becoming a violation on the next touch.

Finally, flag Canadian lists for CASL-specific review. CASL reaches messages received in Canada from other countries, and B2B is not exempt — the first enforcement action, a $1.1 million penalty against Compu-Finder, involved unsolicited B2B emails. With penalties up to $10 million for corporations and personal liability for directors and officers, a Canada flag on the list triggers a manual review rather than a standard template.

The common thread is simple: verify before launch, not after a complaint. A free first campaign review at myaicallcenter.app/campaigns covers list source, consent records, and calling windows — with the full number known before anything is approved. Questions about a Canadian list? Reach the team at [email protected].

Frequently Asked Questions

Does CASL apply to phone calls, or just emails and texts?
CASL does not apply to live voice or automated telemarketing calls — those are governed by the separate Unsolicited Telecommunications Rules, per the CRTC's official FAQ. However, the email, SMS, instant messaging, and social media touches in a multi-touch campaign sit squarely under CASL, so each channel needs to be checked against its own rulebook before launch.
What are the penalties for violating CASL?
Corporations face fines of up to $10 million per violation, and individuals — including directors and officers — face up to $1 million in personal liability, per Stikeman Elliott's legal analysis. Enforcement is real: the CRTC's first action in 2015 brought a $1.1 million penalty against Compu-Finder, and even a broken unsubscribe mechanism alone drew a $48,000 fine.
Does CASL apply to my U.S.-based business if we message Canadian contacts?
Yes. CASL covers commercial electronic messages received in Canada from other countries, not just messages sent from within Canada, according to the CRTC's FAQ. If any of your emails or texts land with Canadian recipients, you need documented consent, clear sender identification, and a working unsubscribe mechanism.
Are B2B emails exempt from CASL?
No — B2B messages get no exemption. The first CASL enforcement action was a $1.1 million penalty against Compu-Finder for unsolicited business-to-business emails, which the CRTC described as flagrant. Assuming business contacts are fair game is one of the costliest misconceptions under the law.
How long does consent last under CASL, and who has to prove it?
Express consent never expires on its own — it stays valid until the recipient withdraws it — and the burden of proving consent existed sits entirely on the sender, per the CRTC's guidance. If you can't produce records showing when and how consent was obtained, the consent doesn't legally exist. That's why we check list source and consent records before any campaign launches, and decline bought lists without clear permission documentation.
Is CASL actually enforced, or is it just a paper law?
It's actively enforced. The CRTC has issued over $3.2 million in administrative monetary penalties since CASL came into force in 2014, and the Spam Reporting Centre received more than 216,800 complaints between October 2023 and March 2024 alone. The law has also worked: government data shows a 37% decrease in Canadian-based spam within a year of its introduction.

Four Letters, One Rule: Prove Permission Before You Send

CASL — Canada's Anti-Spam Legislation — comes down to a simple discipline: every commercial text, email, or message sent to a Canadian contact needs documented consent, clear identification, and a working unsubscribe, with the burden of proof on the sender. Voice calls follow separate telemarketing rules, but the SMS and email touches in any multi-touch campaign sit squarely under CASL, where penalties reach $10 million for corporations and B2B messages get no exemption. The practical path forward is straightforward: verify list source and consent records before launch, honor opt-outs immediately across channels, and flag Canadian lists for manual review. That is exactly how My AI Call Center builds campaigns — approved, permissioned, or reviewed lists only, checked before anything goes out. If you are unsure whether your list can support a Canada-facing campaign, the first campaign review at myaicallcenter.app/campaigns is free, with the full number known before you approve launch. Questions? Reach the team at [email protected].

Get campaign planning tips