Article
CASL Compliance for Cold Email: What Canadian Law ...
revenueflow.com
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
What CASL covers “CASL regulates commercial electronic messages, or CEMs: any electronic message that encourages participation in a commercial activity, sent to or accessed from a computer system in Canada. A cold sales email is squarely a CEM.” Three things must be true for a compliant send:
Three things must be true for a compliant send: “You have consent, express or implied, or a listed exemption applies.” The message identifies the sender and anyone on whose behalf it is sent, with valid contact information.
Publish a real mailing address and a 60-day unsubscribe in every message, and suppress globally on the first request. “Keep the records. Consent evidence, unsubscribe logs, and send logs are your only defence, and CASL puts the burden on you.” Compliance and deliverability reinforce each other here. Sourcing from published addresses, targeting by genuine role relevance, and honouring opt-outs instantly are also the behaviours that keep complaint rates low, which is what Google Postmaster Tools measures and what spam rate benchmarks track.
Maximum administrative monetary penalties are $1 million per violation for an individual and $10 million per violation for any other person, which in practice means corporations. Directors and officers can be personally liable, and a company can be vicariously liable for what its employees or agents send. “Enforcement sits with the CRTC, working alongside the Competition Bureau and the Office of the Privacy Commissioner. CASL's private right of action, which would let individuals sue for statutory damages, was suspended before it came into force and remains not in force, so regulators are still the only route to enforcement.” What the evidence has to look like
What CASL covers “CASL regulates commercial electronic messages, or CEMs: any electronic message that encourages participation in a commercial activity, sent to or accessed from a computer system in Canada. A cold sales email is squarely a CEM.” Three things must be true for a compliant send:
Three things must be true for a compliant send: “You have consent, express or implied, or a listed exemption applies.” The message identifies the sender and anyone on whose behalf it is sent, with valid contact information.
Express consent “Express consent is a positive, informed opt-in.” The compensation for that friction is durability: express consent does not expire. Implied consent does.
You have consent, express or implied, or a listed exemption applies. “The message identifies the sender and anyone on whose behalf it is sent, with valid contact information.” The message contains a working unsubscribe mechanism.
The message identifies the sender and anyone on whose behalf it is sent, with valid contact information. “The message contains a working unsubscribe mechanism.” Miss any one and the message is non-compliant even if the other two are perfect.
The message contains a working unsubscribe mechanism. “Miss any one and the message is non-compliant even if the other two are perfect.” Express consent
CASL Compliance for Cold Email: What Canadian Law Actually Requires “Canada's Anti-Spam Legislation flips the default that US senders are used to. Under CAN-SPAM you may email anyone until they ask you to stop. Under CASL you may not email anyone until you can show you were allowed to, and if a regulator asks, the burden of proving it sits on you rather than on them.” That single difference is why outbound teams that treat Canada as an extension of their US list end up exposed. Here is what the law requires, where the exemptions actually apply, and how to run Canadian outbound without guessing.
What the evidence has to look like “CASL puts the burden of proof on the sender, so the operating question is not whether you were allowed to send, it is whether you can show it a year later. Implied consent you cannot evidence is, for enforcement purposes, no consent.” For a conspicuous-publication send, the record that survives an audit is per prospect, not per campaign: the source URL the address was published on, the date it was captured, ideally a stored copy of the page as it looked, and a note of which role the relevance test was satisfied against. A list that records only "scraped from company websites" describes a method rather than evidencing a prospect.
Three things must be true for a compliant send: “You have consent, express or implied, or a listed exemption applies.” The message identifies the sender and anyone on whose behalf it is sent, with valid contact information.
What CASL covers “CASL regulates commercial electronic messages, or CEMs: any electronic message that encourages participation in a commercial activity, sent to or accessed from a computer system in Canada. A cold sales email is squarely a CEM.” Three things must be true for a compliant send:
Keep the records. Consent evidence, unsubscribe logs, and send logs are your only defence, and CASL puts the burden on you. “Compliance and deliverability reinforce each other here. Sourcing from published addresses, targeting by genuine role relevance, and honouring opt-outs instantly are also the behaviours that keep complaint rates low, which is what Google Postmaster Tools measures and what spam rate benchmarks track.” Message contents pull the other way, and the deliverability cost of an open pixel weighs a rewritten link against the cleanest possible first message.
For express consent, keep the wording of the request itself alongside the timestamp. The rules are about what the person was told when they agreed, so a consent record without the request text cannot demonstrate compliance with them. “Keep unsubscribe logs on the same footing. The obligation is to process a withdrawal without delay and no later than ten business days, and the only way to show that was met is a timestamped record of when the request arrived and when the suppression took effect.” How to run Canadian outbound
Step 4No refusal statement on that page? A no unsolicited enquiries line removes the implied consent “Step 5Relevant to that person's actual role? Judged against their function, not the company's general interest” Step 6Identification, address and unsubscribe present? All three, in the message, or it is non-compliant anyway
Keep the records. Consent evidence, unsubscribe logs, and send logs are your only defence, and CASL puts the burden on you. “Compliance and deliverability reinforce each other here. Sourcing from published addresses, targeting by genuine role relevance, and honouring opt-outs instantly are also the behaviours that keep complaint rates low, which is what Google Postmaster Tools measures and what spam rate benchmarks track.” Message contents pull the other way, and the deliverability cost of an open pixel weighs a rewritten link against the cleanest possible first message.
Contact information, including a mailing address that stays valid for at least 60 days after sending. A street address, PO box, rural route, or general delivery address all qualify. “An unsubscribe mechanism that can be readily performed: a link to an accessible page, or a reply keyword for SMS. It must remain valid for at least 60 days after the message is sent.” Processing of unsubscribes without delay, and no later than 10 business days. No confirmation step that the recipient has to complete.