
What is CASL in Canada?
Key Facts
- CASL carries maximum fines of $10 million for corporations and $1 million for individuals, with directors potentially personally liable per legal analysis
- The first-ever CASL finding resulted in a $1 million penalty, and a dating site was fined $48,000 over a faulty unsubscribe mechanism according to enforcement records
- CASL applies to messages sent to or from Canada regardless of sender location — U.S. companies emailing Canadian contacts must comply per compliance guidance
- Unlike CAN-SPAM which requires no explicit consent, CASL mandates express or implied consent before sending any commercial electronic message a key distinction
- Implied consent expires automatically — 6 months after an inquiry and 24 months after a purchase — while express consent never expires practitioners note
- Live voice and automated telemarketing calls fall outside CASL entirely — they're governed by separate Unsolicited Telecommunications Rules — but SMS texts are fully covered per the CRTC
- The burden of proof sits entirely with the sender: if you cannot document how and when consent was obtained, it effectively does not exist the CRTC states plainly
Why CASL Catches Canadian Marketers Off Guard
Most Canadian marketers first hear about CASL when a fine letter arrives — not before. Canada's Anti-Spam Legislation, formally Bill C-28, took effect July 1, 2014, and legal analysts consistently rank it among the strictest and most complex anti-spam laws in the world.
The penalties explain why. CASL carries maximum fines of $10 million for corporations and $1 million for individuals, with directors and officers potentially personally liable (legal analysis notes this exposure reaches individual decision-makers, not just companies). Enforcement is not theoretical. The first-ever CASL finding resulted in a $1 million penalty, a dating site was fined $48,000 over a faulty unsubscribe mechanism, and one individual paid $75,000 for a spam campaign run between 2016 and 2018.
What catches marketers off guard is scope. CASL does not just cover email — the CRTC's own guidance confirms it applies to:
- Email and text/SMS messages, including Bluetooth messages
- Direct messages on social platforms like Facebook Messenger and LinkedIn
- Messages sent to or from Canada, regardless of where the sender is located
- Any message — sound, voice, or image — sent to an electronic address
That last point matters most for cross-border teams. A U.S. company emailing Canadian contacts must comply, and compliance guidance is clear that CASL applies to Canadian contacts "not just by Canadian companies." The CRTC's stated best practice is that all commercial electronic messages should comply, even those sent abroad.
One nuance worth knowing: live voice and automated telemarketing calls to telephone numbers are regulated separately under the Unsolicited Telecommunications Rules, not CASL — but SMS texts are fully covered (per the CRTC). This distinction shapes how multi-touch campaigns combining calls, texts, and emails must be structured. At My AI Call Center, that is exactly why list source and consent records are reviewed before any campaign launches.
The financial penalty, despite being huge, is only part of the cost. As compliance practitioners observe, consumers lose trust in businesses that use misleading tactics, and brand reputation can take years to recover. Negative publicity from enforcement activity does lasting damage that no fine schedule captures.
The practical takeaway is simple: the burden of proof sits entirely with the sender. If you cannot document consent, you do not have consent.
The Three Core Requirements: Consent, Identification, Unsubscribe
CASL surprises many marketers because it doesn't ban commercial messages at all. Instead, Canada's regulator frames it as three requirements every commercial electronic message must meet: obtain consent, identify the sender, and provide a working unsubscribe mechanism.
Requirement 1: Consent. This is where CASL diverges sharply from the U.S. CAN-SPAM Act, which requires no explicit consent to send email — a key distinction Canadian businesses must internalize. CASL recognizes two types:
- Express consent requires a positive opt-in action, such as an unchecked checkbox the recipient actively ticks. Pre-checked boxes are prohibited, and consent requests cannot be bundled into accepting terms and conditions. Express consent never expires, though recipients can withdraw it at any time.
- Implied consent arises from existing relationships: it lasts 6 months after an inquiry or application, and 24 months after a purchase or accepted business opportunity, per practical compliance guidance.
The critical point: the burden of proof sits entirely with the sender. The CRTC states plainly that the onus is on the person sending the message to prove consent was obtained. If you can't produce records showing how and when consent was granted, it effectively doesn't exist. This is why disciplined list hygiene — reviewing list sources and consent records before any outreach — matters so much. At My AI Call Center, every campaign begins with exactly that review, and lists without clear permission records are flagged or declined before launch.
Requirement 2: Identification. Every commercial electronic message must identify the sender and anyone on whose behalf it's sent, and include valid contact information such as a mailing address, according to legal analysis of the rules. Anonymous marketing isn't an option.
Requirement 3: A working unsubscribe. The unsubscribe mechanism must be distinct, easy to use, and free. It must remain valid for at least 60 days, and unsubscribe requests must be processed within 10 days — compliance practitioners note some sources frame this as 10 business days. Getting this wrong is expensive: the CRTC levied a $48,000 fine over a faulty unsubscribe mechanism alone.
One nuance worth noting: live voice and automated telemarketing calls to telephone numbers fall outside CASL, regulated separately under the Unsolicited Telecommunications Rules — but SMS and text messages are covered, which matters for any multi-touch campaign combining calls, texts, and emails.
The Calls-vs-Messages Distinction Most Businesses Miss
Here's a detail that surprises most businesses running outbound campaigns in Canada: CASL's name says "anti-spam," but it doesn't actually apply to the phone calls you make. Getting this distinction wrong means either over-restricting your calling program or under-protecting your texting program — and both mistakes are expensive.
According to the CRTC's own guidance, live voice calls and automated telemarketing calls to telephone numbers fall outside CASL entirely. They're governed instead by the CRTC's Unsolicited Telecommunications Rules — the framework covering the National Do Not Call List, calling hours, and identification requirements.
Text messages, however, are a different story. SMS is explicitly covered by CASL, as are emails and direct messages on platforms like Facebook Messenger and LinkedIn. The CEM definition spans email, text, sound, voice, and image messages — far broader than the U.S. CAN-SPAM Act, which covers email only.
This split matters enormously for multi-touch campaigns. A database reactivation sequence that combines calls, texts, and emails operates under two separate regulatory regimes at once:
- Calls must respect the Unsolicited Telecommunications Rules, including National DNCL registration and permitted calling windows.
- Texts and emails require CASL-compliant consent, sender identification, and a working unsubscribe mechanism.
- Consent records for one channel don't automatically satisfy the other — each list needs source and permission documentation reviewed before launch.
- Opt-outs must be honored per channel, with CASL unsubscribe requests processed within 10 days.
Several exemptions soften CASL's reach for legitimate business communication. Messages within existing B2B relationships and responses to customer inquiries are excluded, as are messages between individuals with a genuine personal relationship — though the CRTC interprets "personal relationship" strictly and notes that corporations cannot have personal relationships at all.
Implied consent also creates compliant windows: roughly six months after an inquiry and 24 months after a purchase. But implied consent expires on a rolling basis, and the burden of proof sits with the sender — which is why disciplined record-keeping isn't optional. This is exactly why My AI Call Center reviews list source and consent records before any campaign launches and flags bought lists that lack clear permission trails.
One more nuance businesses often miss: the private right of action that would have let individuals sue over CASL violations was scheduled for July 1, 2017, but the Government of Canada chose not to implement it following stakeholder concerns. That doesn't reduce the stakes — enforcement remains with the CRTC, which has already issued penalties including a $48,000 fine over a faulty unsubscribe mechanism and a $1 million fine in the first-ever CASL finding.
The practical takeaway: map every touchpoint to its regime before launch. Calls, texts, and emails in the same campaign carry different consent standards, different opt-out mechanics, and different regulators. Teams that treat "CASL compliance" as a single checkbox tend to discover the gap only after a complaint lands.
Building a Consent-First Outreach Program That Holds Up
Knowing the rules is only half the battle — the other half is proving you followed them. Under CASL, the burden of proof sits entirely with the sender, who must demonstrate consent was obtained before any commercial electronic message went out, according to the CRTC's own guidance.
That single fact should shape how you build every outreach program. If you cannot produce a record showing how and when consent was given, you effectively have no consent at all. Legal analysts at Stikeman Elliott note the onus extends to proving a message fell under an available exemption — silence is not a defense.
An audit-ready consent file answers three questions instantly: who consented, how, and when. Practitioner guidance from Opensense recommends capturing opt-in screenshots, the consent language used, and expiry dates for any implied consent.
Your records should include:
- Consent type and timestamp — express or implied, with the exact date it began.
- Proof of the opt-in itself — form screenshots, checkbox states, or the inquiry that triggered implied consent.
- Expiry dates for implied consent — 6 months after an inquiry, 24 months after a purchase.
- Withdrawal history, so re-consent requests never go to people who opted out.
Implied consent is a countdown, not a permanent pass. Because it expires on a rolling basis — as consent management documentation from Envoke explains — the practical move is converting it to express consent well before the clock runs out. Express consent, by contrast, does not expire, though recipients can withdraw it at any time per the CRTC FAQ.
This is why list review belongs at the start of every campaign, not the end. Before any launch, examine where each list came from, what permission supports it, and whether that permission is still valid. Bought lists without clear permission records are a particular risk — and with corporate fines reaching up to $10 million under CASL, an unvetted list is an expensive shortcut.
At My AI Call Center, this discipline is built into the process: every campaign begins with a list and consent review covering source, permission records, and calling windows. Lists are only run if they are approved, permissioned, or reviewed — and if a list cannot support the campaign, we tell you plainly before you spend anything.
Want a second set of eyes on your list before you launch? The first campaign review is free — plan your campaign at myaicallcenter.app, with managed outbound calling from 9¢ per connected minute.
Frequently Asked Questions
What is CASL in Canada, and what does it actually require?
Does CASL apply to phone calls, or just emails and texts?
What are the penalties for violating CASL?
What's the difference between express and implied consent under CASL?
Does CASL apply to U.S. or foreign companies emailing Canadians?
How do I prove consent if the CRTC investigates?
CASL Compliance Is Simpler Than It Looks — If You Keep the Records
CASL comes down to three things: get consent, identify yourself, and honor unsubscribes within 10 days. The rules reach further than most marketers expect — covering texts, social DMs, and messages crossing into Canada, with fines up to $10 million for corporations and $1 million for individuals — while leaving live voice calls to a separate regime entirely. The thread running through all of it: the burden of proof sits with the sender. If you can't document when and how consent was granted, you effectively don't have it. So your next step is an honest audit — check where each list came from, whether implied consent windows have expired, and whether every channel in your campaign maps to the right rules. If that sounds like work you'd rather hand off, My AI Call Center reviews list source and consent records before every campaign and tells you plainly if a list won't hold up. The first campaign review is free — plan yours at myaicallcenter.app, with managed outbound calling from 9¢ per connected minute.