Outbound Wiki

CAN-SPAM and CASL penalties

The regulators, private rights, fines, and enforcement risks associated with violating CAN-SPAM or CASL.

Penalty exposure starts with classification and routing. List size comes later. Before a cold email goes out, classify it, identify the recipient's country, and test whether the sending setup can stop future messages. A single cold email to a single prospect is covered by CAN-SPAM.1 Canada uses an opt-in model.2 Use these checks to decide whether to send, what to preserve, and when to stop.

Start with the message

Classify the message before reviewing the copy. That tells you which rule set applies and what to verify before sending.

CAN-SPAM covers all commercial messages, including email that promotes content on commercial websites, and defines a commercial message by its primary purpose of advertising or promoting a commercial product or service.3 Under CASL, a commercial electronic message is any electronic message that encourages participation in a commercial activity, whether or not profit is expected.4 Promoting a product or service and inviting a prospective customer to an event are examples.5

Ask whether the message encourages participation in a commercial activity or promotes a commercial product or service. Decide whether it is legitimate outbound or spam before checking the compliance mechanics.6

Route the recipient

Country determines the consent path. Keep that route with the recipient record so the sending decision does not depend on a rep's memory.

CAN-SPAM makes no exception for business-to-business email.7 It does not require prior permission to send an email.8 For a Canadian recipient, use the opt-in route and require the permission basis before sending. Ask where that basis came from, what message it covers, and whether the record is still usable. Move on only when you can explain why the message may be sent under the route you selected.

Check the stop path

Test the live message and the suppression behavior. A written policy does not help if the recipient's decision cannot reach the sending system.

CAN-SPAM regulates how messages are sent and gives every recipient the right to make the sender stop sending further messages.9 Check what happens when someone unsubscribes, replies with a stop request, or appears on a suppression list. Review every future send that could reach that person, since a stop request changes the sending decision after the original message.

Map the enforcement risk

Map each rule to who can act, what can trigger exposure, and who may carry the liability. That gives the team a clear place to escalate when a route is uncertain.

The FTC enforces the CAN-SPAM Act and the accompanying CAN-SPAM Rule.10 Each separate violating email can carry a penalty of up to $53,088.11 Federal, state, and private parties can bring claims for violations.12 Fraudulent activities can also carry criminal penalties.13 The company whose product or service is advertised and the person or entity sending the message may both be liable.14

The CRTC enforces CASL alongside the Competition Bureau and the Office of the Privacy Commissioner. CASL's private right of action, which would let individuals sue for statutory damages, remains not in force, so regulators are still the only route to enforcement.15 CASL penalties can reach $10 million for an organization and $1 million for an individual.16

Use those figures as a reason to resolve uncertainty before sending. Penalties and enforcement approaches can change, so verify the current framework before assuming an outreach practice is low risk.17

What not to do

Keep these failure modes beside the send review and test each control before approval.

  • Do not use false or misleading header information.18
  • Do not let the From, To, Reply-To, or routing information obscure who initiated the message. Those fields, including the originating domain name and email address, must be accurate and identify the initiating person or business.19
  • Do not send a commercial electronic message without first obtaining the recipient's consent.20
  • Do not send a message with a missing postal address, a failed opt-out link, or a suppression list that covers only one campaign. These are mechanical failure points.21

Run this review before approving a new route. Preserve the permission or suppression decision with the recipient record. Escalate any unclear route for legal review before treating it as low risk.17

Sources

  1. 1
    “A single cold email to a single prospect is covered by the same law as a million-address blast.”
  2. 2
    “While the U.S. has enacted an anti-spam law promoting an opt-out model, Canada has adopted an opt-in model.”
  3. 3
    “It covers all commercial messages, which the law defines as “any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service,” including email that promotes content on commercial websites.”
  4. 4
    “A CEM is any electronic message (email, text, etc.) that encourages participation in a commercial activity, regardless of whether there is an expectation of profit.”
  5. 5
    “Examples of CEMs are promoting your products or services or inviting a prospective customer to one of your events.”
  6. 6
    “Deciding whether a message qualifies as legitimate outbound at all often starts earlier than compliance mechanics, with the distinction between cold email and spam.”
  7. 7
    “The CAN-SPAM Act makes no exception for business-to-business email.”
  8. 8
    “What the Act does not do is require permission.”
  9. 9
    “It regulates how you send, and it gives every recipient the right to make you stop.”
  10. 10
    “The FTC enforces the CAN-SPAM Act and the accompanying CAN-SPAM Rule.”
  11. 11
    “Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088, so non-compliance can be costly.”
  12. 12
    “the Act also allows various federal, state and private parties to bring claims for violations.”
  13. 13
    “the Act also carries criminal penalties for fraudulent activities.”
  14. 14
    “Both the company whose product or service is advertised as well as the individual or entity sending the message are potentially liable for violations of the Act.”
  15. 15
    “Enforcement sits with the CRTC, working alongside the Competition Bureau and the Office of the Privacy Commissioner. CASL's private right of action, which would let individuals sue for statutory damages, was suspended before it came into force and remains not in force, so regulators are still the only route to enforcement.”
  16. 16
    “The penalties for failing to comply with CASL are significant: up to $10 million for an organization and up to $1 millionfor an individual.”
  17. 17
    “Because the penalties and enforcement approach can change, verify the current framework and talk to a lawyer before assuming your outreach practices are low-risk.”
  18. 18
    “Don’t use false or misleading header information.”
  19. 19
    “Your “From,” “To,” “Reply-To,” and routing information – including the originating domain name and email address – must be accurate and identify the person or business who initiated the message.”
  20. 20
    “It’s a law, which among other things, prevents commercial electronic message from being sent without first obtaining consent from the recipient.”
  21. 21
    “That combination is why US outbound is legal and why the mistakes that get people caught are mechanical ones: a missing postal address, an opt-out link that fails, a suppression list that only covers one campaign.”