CASL Compliance for Email: Canada's Anti-Spam Law Explained

Published

The email law most senders don’t know they’re breaking

Canada’s Anti-Spam Legislation (CASL) took effect on July 1, 2014, and it’s among the strictest email-marketing laws in the world. It applies to any Commercial Electronic Message (CEM) sent “to” a computer system located in Canada — meaning a recipient who receives or accesses the message in Canada — regardless of where the sender is based. If your list includes Canadian subscribers, CASL applies to you.

The biggest difference from the US CAN-SPAM Act is consent. CAN-SPAM lets you send first and let people opt out later. CASL reverses that: you generally need consent before you send the first message, and you have to be able to prove you have it. The maximum administrative monetary penalties are significant — up to CAD $1 million per violation for individuals and CAD $10 million per violation for businesses — and enforcement by the CRTC, the Competition Bureau, and the Office of the Privacy Commissioner of Canada is active.

If you’ve already read our CAN-SPAM Act Explained and GDPR for Email, this article completes the compliance trio — covering how Canada’s law differs, what it requires, and what to put in every email.

What CASL actually requires

CASL lays out a small set of mandatory requirements for Commercial Electronic Messages:

  1. Get consent before you send. You must have either express consent (the subscriber explicitly agreed to receive your commercial messages) or implied consent (an existing business or non-business relationship as defined by the law). Without one of the two, you can’t send.
  2. Identify yourself clearly. Every message must include the sender’s name and the name of anyone on whose behalf the message is sent.
  3. Include a physical address and contact information. A mailing address (street, post office box, or other recognized address) plus at least one working way to reach you — email, phone, or web. This is broader than CAN-SPAM, which only requires a postal address.
  4. Tell the reader they can unsubscribe. The message must clearly state that the recipient can opt out of future messages, in a way that’s easy to find and easy to act on.
  5. Provide a working unsubscribe mechanism. The opt-out must function for at least 60 days after the message is sent, and it has to work without the reader having to log in, pay a fee, or do anything beyond a simple reply or click. See Email Unsubscribe Best Practices.
  6. Honor opt-out requests within 10 business days. Once a reader unsubscribes, you have at most 10 business days to stop sending. The deadline is a maximum, not a target — process opt-outs immediately.
  7. Don’t use misleading subject lines or sender information. The “from” name, email address, and subject line must not be deceptive. Information that could trick someone into opening the message is a violation on its own.

Why it matters

  • Consent-first means stricter rules than CAN-SPAM. CAN-SPAM lets you send first and offer an opt-out later. CASL requires consent before the first message. Sending to someone you don’t have a relationship with — and don’t have express consent from — is a violation from message one.
  • Penalties scale per violation. Maximum administrative monetary penalties are CAD $1 million for individuals and CAD $10 million for businesses per violation. A single non-compliant send to a large list multiplies that exposure fast.
  • It applies outside Canada. CASL isn’t limited to Canadian senders. It applies whenever a message is sent “to” a computer system located in Canada. If you have Canadian subscribers — and most international lists do — the law applies even if your business is in the United States, the EU, or anywhere else.
  • Consent-based lists perform better. Lists built on real opt-in consent have higher engagement, fewer spam complaints, and lower unsubscribe rates than scraped or purchased lists. CASL’s consent rule overlaps with what good email marketers already do.
  • The principles travel. CASL is part of the same global trend as GDPR (EU), LGPD (Brazil), and Australia’s Spam Act. Building CASL-friendly practices today means less rework when the next jurisdiction tightens its rules.

How to comply with CASL

  1. Decide which consent type applies to each subscriber. Express consent means the subscriber actively agreed to receive your messages — usually through an unchecked signup checkbox. Implied consent covers defined situations, like an existing business relationship (a recent purchase or inquiry by the subscriber), certain former customer relationships, or a publicly-listed business contact you have a genuine relationship with. When in doubt, get express consent.
  2. Capture and keep consent records. If the regulator asks, you need to prove when, how, and what a subscriber consented to. Your ESP or signup tool should record this — verify that it does, and don’t rely on assumptions.
  3. Use a clear, unchecked opt-in at signup. Pre-ticked boxes, bundled consent (“by signing up you agree to receive marketing”), or assumed consent don’t meet CASL’s standard for express consent. Make the opt-in explicit and specific to what you’ll actually send.
  4. Don’t use purchased or scraped lists. A purchased list almost never carries valid CASL consent — consent is given to the original collector, not to you, and it’s not transferable. Sending to a purchased list is a CASL violation and a deliverability disaster.
  5. Include the full identification block in every email. Sender name, physical address, and at least one working contact method (email, phone, or web). Build this into your footer block once as a reusable layout so it’s never missing.
  6. Make the unsubscribe obvious and immediate. Place the unsubscribe link in the footer, in a normal-size font, with no login or survey required. The mechanism must work for at least 60 days after the send. See Email Unsubscribe Best Practices.
  7. Honor opt-outs within 10 business days. Most ESPs process unsubscribes instantly. Verify yours does, and watch for any sync delay between your ESP and your subscriber database.
  8. Review consent periodically. Implied consent has time limits — an existing business relationship generally expires after a defined period of inactivity. Run a list review to expire implied-consent subscribers who no longer qualify, and re-permission them with a fresh opt-in campaign if you want to keep them.

Common mistakes

  • Sending to Canadian subscribers without consent. “We’re not a Canadian company.” CASL doesn’t care where you’re based — it cares where the recipient is. If your list has Canadian subscribers, the law applies.
  • Buying a “CASL-compliant” list. A list purchased from a vendor cannot carry valid CASL consent for you — consent is given to a specific sender, not transferred. The vendor can’t sell you consent.
  • Pre-ticked opt-in checkboxes. The reader didn’t actively consent — they failed to uncheck a box. This isn’t express consent under CASL.
  • Missing the contact information. Many senders include a postal address (because CAN-SPAM requires it) but forget the additional email, phone, or web contact that CASL requires on top.
  • Slow unsubscribe processing. A reader unsubscribes but keeps receiving emails because the ESP sync takes a week. The 10-business-day deadline is a ceiling; aim for instant.
  • Hiding the unsubscribe link. Tiny text, light-on-white, or buried under legal disclaimers. CASL requires the mechanism to be readily accessible.
  • Letting implied consent lapse. A subscriber’s existing-business-relationship consent expires after a period of inactivity. Sending to them after that without re-permission is a violation.
  • Assuming CASL only covers email. It also covers SMS, instant messaging, and some social-media outreach. If your channel qualifies as a Commercial Electronic Message, CASL applies.

How CASL relates to Temway

Temway is a builder and exporter — it produces the HTML for your emails. The hardest parts of CASL compliance (capturing consent, storing consent records, processing opt-outs, suppressing lapsed implied-consent subscribers) happen at the ESP level, not in the email builder.

What Temway does help with is the content side of compliance — the elements that must appear inside every email. Build your footer block once with the full CASL identification set: sender name, physical address, and a working email or phone contact, alongside the unsubscribe link. Save it as a reusable layout and drop it into every email, so the compliance block is built in rather than re-added per send. Templates like the welcome email template ship with that footer already in place — a useful starting point.

When the email is ready, export the HTML or push it to your ESP, where consent records, subscriber management, and opt-out processing are handled automatically.

Frequently asked questions

Does CASL apply to senders outside Canada?

Yes. CASL applies to any Commercial Electronic Message sent “to” a computer system located in Canada — meaning a recipient who is in Canada when they receive or access the message. If your list includes Canadian subscribers, the law applies even if your business is based entirely in another country.

What counts as express consent under CASL?

Express consent is an active, informed opt-in. The subscriber must know what they’re agreeing to — typically, receiving marketing messages from your brand — and affirmatively agree, usually by checking an unchecked box. Pre-ticked boxes, bundled language, or assumed consent don’t qualify.

How long do I have to honor an unsubscribe request?

Up to 10 business days. That’s the maximum, not the target — most ESPs process opt-outs immediately. You can’t charge a fee, require a password, or ask the reader to do anything beyond confirming their email address or simply clicking a one-click link.

How is CASL different from CAN-SPAM?

The biggest difference is consent. CAN-SPAM allows you to send first and provide an opt-out, while CASL requires express or implied consent before the first message. CASL also requires more identification (sender name plus physical address plus contact information), and the maximum penalties are significantly higher. See our CAN-SPAM Act Explained for the US-side rules.

Does CASL apply to transactional emails?

Generally no. CASL applies to Commercial Electronic Messages — messages whose purpose is to encourage a commercial transaction. Pure transactional messages (an order confirmation, a shipping update, a password reset) are usually outside CASL’s scope. But messages that mix transactional and promotional content fall under the law — when in doubt, include the compliance elements.

Where to go next

Explore: Email Deliverability

Getting emails into the inbox — authentication, sender reputation, spam filters, list hygiene, and the laws that govern sending.