Compliance

CASL and your newsletter: consent, unsubscribe, and the fines nobody reads about

August 30, 2026
Xavier PeichBy Xavier Peich

Express or implied consent, mandatory footer details, unsubscribe within 10 business days. What Canada's anti-spam law actually asks of a Quebec SMB.

CASL and your newsletter: consent, unsubscribe, and the fines nobody reads about

There is a federal law almost no small business has read and many are partly breaking. It's called Canada's Anti-Spam Legislation, CASL to its friends, and it applies the moment a commercial email leaves for an address. A newsletter sent to 300 people is covered exactly like a campaign of 300,000. It's one of the things we look at when we take over a site on subscription, because the whole thing gets settled in the signup form and the newsletter footer.

The usual way to write about this is to wave the $10,000,000 ceiling around and sell a compliance audit. We're going to do the opposite. The CRTC's enforcement record is public, decision by decision, and it tells a different story. What actually brings the regulator out rarely turns on a subtlety of consent. It's almost always an unsubscribe link that doesn't work. So this piece follows the real order of priorities.

The short answer, for the busy

CASL covers any commercial electronic message sent to an electronic address, which includes the newsletter of a four-person company, and it applies to SMS and instant messaging too. Three obligations hold it together. Consent first, express or implied. Identification second: your business name, a mailing address and a way to reach you, valid for at least 60 days after sending. An unsubscribe mechanism third, free to use, with requests actioned without delay and no later than 10 business days. Express consent doesn't expire until the person withdraws it. Implied consent does expire: two years after a purchase or a written contract, six months after a simple inquiry. And the proof is on you, since section 13 of the Act puts the onus on whoever claims the consent, which in practice means keeping the date, method and source for every address. The ceilings are $1,000,000 per violation for an individual and $10,000,000 for a business.

What the law covers, and what it doesn't

The test is one question: is one of the purposes of the message to encourage the recipient to take part in a commercial activity? If yes, it's a commercial electronic message and the three obligations apply. The CRTC notes that a logo, a hyperlink or contact details in a signature don't by themselves turn an email into a commercial message, while a line pushing a purchase does. The scope runs past email: the definition of electronic address also covers SMS and instant messaging, including social platform messaging.

The exclusions, on the other hand, are more generous than most people assume. The consent requirement doesn't apply to a message providing a quote the recipient requested, one that completes or confirms a transaction already agreed to, warranty or product recall information, or factual notice about an ongoing subscription or account. Your order confirmation, your appointment reminder, your invoice: outside the consent regime. What's left covered is the part you call marketing.

Express consent, implied consent, and the clock that runs

Express consent means the person took a deliberate action to say yes: a box they ticked themselves, a signup form, a verbal agreement. It doesn't expire. And a subtlety that catches people out: the email asking for that consent is itself a commercial message, so you can't use it to obtain consent cold.

Implied consent is a closed list of situations, not a general principle. The most common is the existing business relationship, which the CRTC boils down to four questions: did the person buy or lease something from you within the two years before the message? Did they accept a business opportunity within two years? Did they make an inquiry within six months? Do they have a written contract still in force, or expired less than two years ago? A yes gives you implied consent, for the stated period and no longer.

That clock is where the average SMB actually gets into trouble. A list built on real customers is legitimate the day it's assembled, then part of it invalidates itself, quietly, two years later. Your newsletter tool doesn't do that arithmetic for you: it has no idea when anyone transacted.

The purchased list: the one case where the answer is simple

The third form of implied consent is conspicuous publication: if someone publishes their work address publicly, without a statement refusing commercial messages, and your message is relevant to their role, you may write.

The Blackstone Learning Corp. decision shows how far that does not stretch. The company had sent 385,668 emails and relied on this exemption. The CRTC held that it sets a higher standard than the simple public availability of addresses, and the passage on lists is explicit: if a third party reproduces an address or sells a list of such addresses on its own initiative, that creates no implied consent, because neither the account holder nor the recipient published the address. Blackstone produced no record of where its addresses came from. Penalty imposed: $50,000, down from the $640,000 in the notice of violation.

This is where section 13 bites: the onus of proving consent rests on whoever relies on it. In practice, keep the date, the method and the source for every address. Serious newsletter tools record that by default. A spreadsheet assembled by hand over three years does not.

What every message has to carry

Innovation, Science and Economic Development Canada lists the mandatory content plainly: your business name and the name of anyone on whose behalf you're sending; a current mailing address and either a phone number, email or website address; accurate contact information that stays valid for at least 60 days after sending. If you work from home, a P.O. box will do, your home address isn't required.

Then the unsubscribe mechanism. The Act requires it to be free, to let the person refuse all messages or a specified class, and to point at an address or a web page. The CRTC offers a useful counter-example: a six-step path where the user has to hunt for the right link on a page, log into their account, then choose between deleting the account and unsubscribing does not meet the "readily performed" test.

The actual record: it's the unsubscribe that costs money

Three published decisions are enough to see the pattern. Compu.Finder, a Quebec training company whose emails went mainly to people working in Quebec, was issued a $1.1M notice of violation in 2015 for sending without consent and for a defective unsubscribe mechanism; after representations, the CRTC imposed $200,000. DAVIDsTEA entered a $40,000 undertaking in March 2023 over messages that did not consistently include an unsubscribe mechanism, or one that could readily be performed. Hudson's Bay Company signed a $120,000 undertaking in June 2024, on the same ground.

Three companies of wildly different sizes, one shared complaint. The CRTC confirms it in its enforcement report covering 1 October 2025 to 31 March 2026: complaints concern unwanted messages and difficulty unsubscribing, "often due to broken links or overly complicated unsubscribe processes." The same report warns that the CRTC "intends to take stronger enforcement measures when appropriate", CASL being, in its view, now well established and widely understood.

Two honest caveats on the numbers, in the same spirit as our piece on the real risk of Law 25 penalties. The $1M and $10M ceilings are statutory maximums per violation, not amounts observed against an SMB. And the private right of action the Act originally contemplated, the one that would have opened the door to class actions, was repealed before coming into force by Order in Council in June 2017. Your exposure today is the CRTC, and the CRTC arrives after complaints.

CASL and Law 25 don't overlap, they stack

Plenty of owners assume that satisfying one settles the other. The two laws ask different questions about the same object. CASL asks: do you have permission to write to this address? Law 25 asks: what are you doing with this address, which is personal information?

The concrete example is section 12 of Quebec's Act respecting the protection of personal information in the private sector. Information collected for one purpose can't serve another without consent, subject to exceptions including compatible purposes. And the text closes the door explicitly: commercial or philanthropic prospecting cannot be considered a compatible purpose. So the address you collected to ship an order can't slide into the newsletter under the compatibility heading. You have to have asked, and that gets settled at the form, a subject covered in our article on Law 25 applied to your website.

Where to start this week

Open your last newsletter and click the unsubscribe link yourself, from a phone. If you land on a login page, an error, or a form to fill in, you've just found the one problem the regulator genuinely penalizes. Then check the footer: business name, mailing address, a contact route that will still work in two months, on an address at your own domain preferably, for the reasons set out in our piece on professional email.

Only then look at the list. Where did the addresses come from, and can you show it? A list imported from an old system with no history is the real liability. And if your signup form is also the front door for spam, our article on web forms and spam handles the other end of the same pipe.

None of this needs a law firm. It needs an hour, and someone actually looking.

→ Tell us about your newsletter

This is a plain-language explainer, not legal advice. CASL and Law 25 both carry exceptions and edge cases that only a legal advisor can apply to your situation.

Xavier Peich

Written by

Xavier Peich