Table of content
TL;DR:
CASL compliance means getting consent before you send a commercial email to anyone in Canada. Canada's Anti-Spam Legislation covers three things: commercial email and texts, software installed without permission, and rerouted messages. It runs on opt-in, not opt-out like the US CAN-SPAM rules. And it applies based on where your message is read, not where your company sits.
- CASL covers email, SMS, and some direct social messages. It does not cover phone calls, fax, or courier mail.
- You need express or implied consent before the first message goes out. Silence is not consent.
- Implied consent expires: two years after a purchase or contract, six months after an inquiry.
- The business-to-business exemption is narrow. It does not cover cold prospecting into companies you have never dealt with.
- Every message needs sender identification, a valid mailing address, and a working unsubscribe link honoured within 10 business days.
- Penalties reach $1 million per violation for individuals and $10 million for corporations. Directors and officers can be personally liable.
"Add an unsubscribe link, mention B2B, hit send." That is how a lot of outbound teams handle Canada.
It is also roughly how a Quebec training company called Compu-Finder ended up on the wrong end of the first major CASL enforcement action. In March 2015 the CRTC issued a $1.1 million notice of violation. It covered three patterns of commercial email sent over roughly ten weeks. An unsubscribe mechanism that did not work properly made up a fourth problem.
The company fought it for five years. In 2017 the CRTC cut the penalty to $200,000, partly because the original figure threatened the business's survival. Then in June 2020 the Federal Court of Appeal dismissed the appeal. The court upheld the CRTC's reading of the consent rules, including the business-to-business exemption Compu-Finder had leaned on.
Five years of litigation over three email campaigns. That is the part worth sitting with.
What Is CASL and What Does It Cover?
CASL, or Canada's Anti-Spam Legislation, took effect on July 1, 2014. Its scope is wider than the nickname suggests. The law regulates three separate things:
- Commercial electronic messages (CEMs), which is what matters for outbound teams
- Installing computer programs on someone else's device without their consent
- Altering transmission data to reroute electronic messages
Three federal bodies share enforcement. The CRTC handles the message and software rules. The Competition Bureau handles false or misleading claims. The Office of the Privacy Commissioner handles address harvesting and spyware.
What counts as a commercial electronic message?
A CEM is any electronic message sent to promote a business. Even one commercial purpose is enough. In practice, that covers:
- Text messages (SMS and MMS)
- Direct messages on social platforms
Public social posts do not count. Direct messages do.
One detail catches teams off guard constantly. CASL applies based on where someone reads the message, not where you send it from. Picture a rep in Austin emailing a procurement lead in Toronto. CASL covers that message, even with no Canadian entity, no Canadian customers, and no Canadian servers. In my experience this is the single most misunderstood part of the law. Teams check whether they have a Canadian office, decide the answer is no, and move on. Wrong question entirely.
Does CASL Apply to Cold Calling?
No. The CRTC says so plainly. CASL does not cover live voice calls or automated telemarketing calls.
Phone calls fall under a different rulebook. That rulebook, the Unsolicited Telecommunications Rules, holds the National Do Not Call List rules and the Telemarketing Rules. Same regulator. Different rules. Different penalties. Run both channels into Canada and you have two separate sets of obligations to satisfy. A comparison of cold email and cold calling helps before you decide how to split effort between them.
Everything below this point concerns email.
Express vs Implied Consent Under CASL
CASL runs on opt-in. The CAN-SPAM Act in the US lets you email a stranger until they opt out. CASL flips that. You need consent before the first message, and the burden of proving you had it sits with you.
Express consent means someone took a clear, deliberate action. They filled out a form, ticked an unchecked box, or said yes to a specific request. It does not expire until they withdraw it. Pre-ticked boxes do not count.
Implied consent is what makes B2B cold email workable in Canada. It also has an expiry date.
Existing business relationship
You have implied consent for two years if the recipient bought or leased something from you, or entered a written contract with you. The clock runs from the date of the purchase or the end of the contract.
An inquiry gets you six months, not two years. Someone who asked about pricing in March gives you until September, and no longer.
Track these dates properly. Consent windows expire quietly. B2B data decay makes it worse, since the record in your CRM looks exactly as fresh as it did two years ago.
Conspicuous publication
This is the basis most cold outreach leans on. You have implied consent when three conditions hold together:
- The recipient published their business email address publicly, or had it published
- No statement sits alongside it refusing commercial messages
- Your message relates directly to their role or business
That third condition does the heavy lifting, and teams skip past it. Pitching sales software to a VP of Sales is relevant. Sending that same pitch to a facilities manager at the same company is not. The published address does not grant you general permission to email that person about anything.
The CRTC's guidance on implied consent walks through worked scenarios for each basis. Worth thirty minutes if your team sends into Canada regularly.
The business-to-business exemption is narrower than you think
CASL's regulations do contain a business-to-business exemption. When it applies, the consent and unsubscribe rules drop away entirely.
The bar is high. The two companies need an existing relationship with each other. The message also has to relate to the work the receiving company does. Compu-Finder argued this exemption covered its mass training emails. The Federal Court of Appeal disagreed and upheld the CRTC's narrow reading of it.
So a cold email to a company you have never worked with does not qualify, regardless of how business-focused the pitch is. Buying a list does not help either. A purchased list rarely arrives with usable proof of consent for any single address on it. That is one reason buying email lists tends to create more risk than pipeline.
What Every CASL-Compliant Email Must Include
Consent gets you the right to send. These three elements make the message itself compliant:
Compu-Finder's unsubscribe failure was one of the violations that stuck. Not the headline issue, but it counted.
What to do: put the mailing address in your email signature, not buried in a footer image. Mail clients block images by default, and a blocked address counts as a missing address.
Who Carries the Liability for a CASL Violation
Most compliance guides skip this part. It is the part that should make leadership pay attention.
Directors and officers can be on the hook personally if they directed a violation, approved it, or went along with it. Employers also carry liability for what staff do on the job. So an SDR blasting a scraped Canadian list creates exposure for the company, not just for themselves.
There is a due diligence defence available. A company that can show documented consent records, written policies, and real training has a genuine argument. A company that cannot show any of that does not.
One piece of good news, and I think teams underrate it. CASL's private right of action would have let individuals and class actions sue over violations directly. The federal government suspended it in June 2017, weeks before it took effect. It has stayed suspended since. Enforcement runs through regulators, not plaintiffs' lawyers.
CASL Penalties and Enforcement Reality
Those are ceilings, not typical outcomes. Compu-Finder's $1.1 million became $200,000 after the CRTC weighed the company's ability to pay and its steps toward compliance.
The word doing the work in that table is "violation." Penalties attach per violation, and one campaign can generate more than one. The CRTC found four in the Compu-Finder case.
How to Build a CASL-Compliant Cold Email Process
None of this requires avoiding Canada. It requires records.
- Flag Canadian contacts separately in your CRM. A country field is enough. You cannot apply different rules to a segment you cannot identify.
- Log the consent basis for every Canadian contact. Pick one of the three: express, business relationship, or public listing. Record the source URL and the date you collected it.
- Set expiry reminders. Two years for relationships and contracts, six months for inquiries.
- Check role relevance before sending. If you rely on conspicuous publication, the message has to match what the person does for a living.
- Audit your unsubscribe flow quarterly. Confirm requests process within 10 business days and land on a permanent suppression list, not a paused campaign.
- Write the policy down and train the team. This is what a due diligence defence is built from.
Sourcing from compliant B2B data with documented provenance turns step two from a manual chore into something closer to automatic.
What CASL Compliance Buys You
The paperwork feels like a tax on outbound. I'd argue it's the opposite.
Every consent basis forces one question before you hit send: why this person, and why now? Teams that answer it honestly send fewer emails and book more meetings. The ones who can't answer it were never getting replies from that list anyway.
Canada writes that question into law. Europe does too. Most markets keep drifting toward opt-in rather than opt-out, so teams building provenance habits now won't rebuild them in three years.
Prove where your data came from. Better targeting follows on its own.




