What CASL actually covers

CASL applies to what the law calls a commercial electronic message — essentially any message sent electronically that encourages someone to take part in a commercial activity. That is broader than it sounds. A newsletter, a promotional email, a "we miss you" discount, a follow-up after a quote, a notice about a sale: all commercial electronic messages. It covers email, and it also reaches texts and some direct social messages. If you are sending something electronic to market your business, assume CASL applies.

A few things fall outside it. A message someone is genuinely expecting because they just bought from you or asked you a question — a receipt, a reply to their enquiry, a shipping notice — is treated differently, because they clearly wanted it. Purely personal or non-commercial messages are outside it. But the moment you are emailing a list of people to promote your business, you are in CASL territory, and the fact that they are past customers or people you met at an event does not automatically make it legal. That assumption is exactly where businesses get caught.

The three rules every message must follow

CASL boils down to three requirements, and every marketing message you send has to satisfy all three. First, consent: you must have permission to message the person, either express or implied (more on the difference below). Second, identification: the message must clearly say who you are, on behalf of whom it is sent, and how to reach you — your business name and a valid mailing address and a way to contact you, right there in the message. Third, an unsubscribe mechanism: every message must include a clear, working way to opt out, it has to be easy to use, and you must honour it promptly, within ten business days.

None of these is hard. Any reputable email marketing platform builds identification and unsubscribe into every send by default — your business address in the footer, a one-click unsubscribe link that actually works. The part that trips people up is the first requirement, consent, because that is the one you cannot bolt on at send time. You either had permission before you emailed them, or you did not.

CASL recognises two kinds of consent, and knowing the difference is most of the battle. Express consent is when someone actively and knowingly agrees to receive your messages — they ticked a box, filled in a signup form, or told you yes. Express consent is the gold standard because it does not expire on its own; it lasts until the person withdraws it. This is what you want for your newsletter and your marketing list, and it is why a clean website signup form is so valuable: it manufactures express consent, with a record, every time someone uses it.

Implied consent is weaker and temporary. It exists in specific situations — most commonly an existing business relationship, such as someone who has bought from you or made an enquiry. The catch is that implied consent has an expiry date: generally two years after a purchase, or six months after an enquiry, and then it lapses. Businesses get into trouble by treating an old customer list as a permanent marketing list. Someone who bought from you three years ago and never signed up for anything else has, under CASL, expired out of implied consent. Emailing them a promotion is a violation, even though they were once a real customer. The safe move is to convert implied consent into express consent while it is still valid, by inviting those contacts to formally sign up.

Getting your website signup form right

Your website is the best consent-collecting machine you have, so build the form properly. The person must be taking a clear, deliberate action to opt in. That means a checkbox to subscribe should be unchecked by default — a pre-ticked box does not count as consent under CASL, because the person did not actively choose it. Say plainly what they are signing up for and who will be sending it: "Subscribe to occasional email updates from" your business name. Do not bury the marketing consent inside a checkbox that also agrees to your terms; bundling consent so someone cannot say yes to one without the other is exactly the kind of thing the law frowns on.

Two more touches make a signup both compliant and better. A confirmation step, where the person receives an email and clicks to confirm they really want in, gives you a clean, dated, double record of consent and quietly weeds out fake and mistyped addresses. And keeping the ask honest — telling people roughly how often you will email and actually sticking to it — earns you the kind of list that opens your messages instead of reporting them. Good CASL practice and good marketing turn out to be the same thing: permission freely given to people who actually want to hear from you.

Keep records, because the burden is on you

Here is the detail that surprises people most. Under CASL, if a question is ever raised, the burden of proof is on you, the sender, to show you had consent — not on the regulator to prove you did not. That flips the usual assumption. It means a vague "I’m pretty sure they signed up" is worth nothing; you need to be able to point to when and how each person consented.

In practice this is an argument for letting your email platform and your website do the record-keeping for you. When consent comes through a signup form with a confirmation step, the system logs the date, the address, and often the very page and wording the person agreed to. That log is your proof. It is one more reason to run your list through a proper platform rather than a personal address and a spreadsheet: the platform is quietly building the evidence file you would need if anyone ever asked, and you never have to think about it.

Common myths that get businesses in trouble

A few persistent myths cause most CASL violations. "They gave me their card, so I can email them." Handing you a business card is not consent to add someone to a marketing list unless they indicated they wanted your messages. "I bought this list, so it’s the seller’s problem." Purchased lists are radioactive under CASL — the consent does not transfer to you, and emailing a bought list is a direct violation. "It’s just a small newsletter, nobody cares." The law does not have a small-business exemption, and complaints, not size, are what draw attention.

And the big one: "They’re old customers, they won’t mind." Whether they mind is not the legal test — whether you have current consent is. The whole game is to keep everyone on your list in a state of valid, provable consent, ideally express consent gathered through your website, so that every message you send clears all three requirements without you having to think about it. Do that and CASL stops being a threat and becomes background hygiene.

The bottom line

CASL sounds intimidating because of the size of the penalties, but the compliant version of your email marketing is also simply the better version. Collect express consent through a clear website signup with an unchecked box and a confirmation step. Use a real email platform so identification, unsubscribe, and consent records are handled automatically. Honour every unsubscribe quickly. Stop emailing people whose implied consent has expired, and invite them to properly opt back in while you still can. Never touch a purchased list.

Do those things and you are not just avoiding a ten-million-dollar tail risk — you are building a list of people who genuinely want to hear from you, which is the only kind of list worth having. If you want your website signup form, your consent records, and your email setup checked and tidied up so this is all handled properly from the start, that is the kind of practical compliance work I help Canadian businesses with through Design Menu. This article is general information, not legal advice; for a specific situation, talk to a lawyer who works in Canadian privacy and marketing law.