Canada: Canada's Anti-Spam Legislation Will Change The E-Communication Landscape

Last Updated: December 19 2014

On December 4, 2013, the Government of Canada announced that most of Canada's Anti-Spam Legislation (CASL), including the provisions applicable to commercial electronic messages (CEMs), will come into force on July 1, 2014. Many had expected that the government would provide a longer grace period for businesses to develop compliance programs to comply with CASL once the Industry Canada Regulations were finalized. Instead, the government has balanced this shorter coming into force period with a delay as to when the private right of action provisions come into force (discussed at the end of this bulletin). 

Considered one of the most stringent anti-spam regimes in the world given its breadth, scope and penalties, CASL will have a significant impact on the electronic communication practices of businesses operating in the Canadian marketplace. This bulletin focuses on what businesses need to know to comply with CASL's anti-spam provisions. CASL also contains provisions related to the unsolicited installation of computer programs or software but those provisions do not come into force until January 15, 2015, and are not addressed in this bulletin.


CASL was enacted in December 2010, but significant concerns raised by Canadian stakeholders regarding the potential impact of the legislation resulted in multiple rounds of public consultation and lengthy delays. The Canadian Radio-television and Telecommunications Commission's Electronic Commerce Protection Regulations (CRTC) (CRTC Regulations) were finalized in March 2012. Final Industry Canada Electronic Commerce Protection Regulations (IC Regulations) were announced on December 4, 2013, along with CASL's coming into force dates, but will not be officially published in the Canada Gazette until December 18.


Subject to limited exceptions, CASL prohibits the sending of a CEM to an electronic address unless: (1) the person to whom the message is sent has consented to receiving it; and (2) the message complies with prescribed form and content requirements. An electronic message that is sent for the purposes of obtaining consent to send CEMs is itself considered a CEM, which may not be sent without consent (subject to the exceptions discussed below). This is a significant distinction from the CAN-SPAM Act in the U.S.

A CEM is defined broadly as an electronic message (e.g., email, text message, social media message) that has as its purpose, or one of its purposes, to encourage participation in a commercial activity. Commercial activity includes any transaction, act or conduct or any regular course of conduct that is of a commercial character, whether or not the person who carries it out does so in the expectation of profit.


In general, consent to receive a CEM must be express. However, CASL also permits implied consent in certain limited circumstances, which are discussed in more detail below.

Guidance documents published by the CRTC have made it clear that "a positive or explicit indication of consent is required" to comply with the express consent requirements of CASL. This impacts a common industry practice of using an opt-out or negative option method of obtaining consent for marketing, such as a pre-checked consent box that a consumer has to un-check to signify they do not want to receive marketing messages. Instead, a consumer must take an active step (e.g., checking a box) to indicate his or her consent. The guidelines also state that requests for consent cannot be "subsumed in or bundled with requests for consent to the general terms and conditions of use or sale" but rather must be clearly and separately identified.

To be valid, a request for express consent under CASL must set out "clearly and simply":

  • The purpose for which consent is being sought
  • The name (or if different, business name) of the person seeking consent
  • If the consent is sought on behalf of another person, the name (or if different, business name) of the person on whose behalf consent is sought and a statement indicating which person is seeking consent and which person on whose behalf consent is sought
  • The mailing address, and one of a telephone number providing access to an agent or voice messaging system, an email address or a web address of the person seeking consent or, if different, the person on whose behalf consent is sought
  • A statement that the person can withdraw their consent.

Although CASL generally requires express consent, consent will be implied in the following circumstances:

  • Where the recipient and the sender have an "existing business relationship" or an "existing non-business relationship."
    • An existing business relationship exists where the sender and recipient have engaged in certain specified types of business together in the two years preceding the date on which the CEM is sent (for example, a purchase or lease of a product, or entering into or continuing a written contract) or where the recipient of the CEM has made an inquiry to the sender in the previous six months.
    • An existing non-business relationship exists where an individual has made a donation or gift in the last two years, or performed volunteer work in the last two years, to or for a registered charity or political party, organization or candidate or where the individual is a member of certain clubs, associations or voluntary organizations.
  • Where a recipient has "conspicuously published" his or her electronic address, the publication is not accompanied by a statement that the recipient does not wish to receive unsolicited CEMs, and the CEM is relevant to the person's business, role, functions or duties in a business or official capacity.
  • Where a recipient has disclosed his or her electronic address to the sender without indicating that the recipient does not wish to receive unsolicited CEMs and the CEM is relevant to the person's business, role, functions or duties in a business or official capacity. This is sometimes dubbed the "business card" exemption.


CASL exempts the following types of CEMs from its anti-spam prohibition altogether:

  • CEMs sent by an individual to an individual recipient with whom the sender has a personal or family relationship ("personal relationship" and "family relationship" are specifically defined in the IC Regulations).
  • CEMs sent to a person engaged in a commercial activity and consist solely of an inquiry or application related to that activity.

The IC Regulations also add the following exemptions from the anti-spam prohibition:

  • CEMs sent by an employee, representative, consultant or franchisee of an organization to another employee, representative, consultant or franchisee of the same organization (i.e., intra-business) which concern the activities of the organization.
  • CEMs sent by an employee, representative, consultant or franchisee of an organization to an employee, representative, consultant or franchisee of another organization (i.e., inter-business), as long as the organizations have a relationship and the message concerns the activities of the organization to which the message is sent.
    • This exemption is intended to address concerns regarding the potential application of CASL to ordinary business-to-business communications, and has been slightly broadened from the last draft of the IC Regulations. In particular, the requirement in the last draft for a "business relationship" between the two organizations is now only a requirement for a "relationship".
  • CEMs sent in response to an individual's request, inquiry or complaint or where the CEM was otherwise solicited by the person to whom the CEM is sent.
  • CEMs sent to satisfy a legal obligation or to enforce or provide notice of existing or pending legal rights or actions.
  • CEMs sent and received on an electronic messaging service, such as one provided through a social media platform, if the information and unsubscribe mechanism that are required under CASL are conspicuously published and readily available on the user interface through which the message is accessed, and the person to whom the message is sent consents to receive it either expressly or by implication.
  • CEMs sent to a limited-access secure and confidential account, such as a message centre in an online banking account, to which messages can only be sent by the person who provides the account to the person who receives the message.
  • CEMs sent by a person who reasonably believes the message will be accessed in a foreign state that is listed in the schedule to the IC Regulations and the message conforms to the law of the foreign state that addresses conduct that is substantially similar to conduct prohibited under CASL's anti-spam prohibition.
  • CEMs sent by or on behalf of a registered charity as defined in the Income Tax Act and the message has as its primary purpose raising funds for the charity.
  • CEMs sent by or on behalf of a political party or organization, or a person who is a candidate for publicly elected office, and the message has as its primary purpose soliciting a contribution as defined in theCanada Elections Act.

CASL also exempts the following CEMs from the consent requirement (though these CEMs must still comply with CASL's form and content requirements), if the CEM solely:

  • Provides a quote or estimate for the supply of a product, good or service, if the quote or estimate was requested by the recipient
  • Facilitates, completes or confirms a commercial transaction between the parties where the recipient previously agreed to enter into such a transaction
  • Provides warranty, product recall, safety or security information about a product, good or service that the recipient uses, has used or has purchased
  • Provides notification of factual information about the ongoing use or purchase by the recipient of a product, good or service offered under a subscription, membership, account, loan or similar relationship
  • Provides notification of factual information about an ongoing subscription, membership, account or loan
  • Provides information directly related to an employment relationship or benefit plan in which the recipient is currently involved, participating or enrolled, or
  • Delivers a product, good or service, including updates or upgrades further to a transaction that has been previously entered into.

The IC Regulations also set out an additional exemption that applies only to the first CEM sent to an individual following a referral, provided the referral is from an individual who has an existing business, non-business, personal or family relationship with both the recipient and the sender. The CEM must disclose the full name of the referring party and state that the CEM is sent as a result of the referral.


CASL provides that a person may, on behalf of an unknown third party, obtain the express consent of another person to receive CEMs from the third party, as long as certain conditions set out in CASL and the IC Regulations are met. The IC Regulations set out somewhat burdensome conditions for the use of this type of consent by third parties.


In addition to the consent requirement, CASL sets out specific form and content requirements for CEMs. In particular, each CEM must identify the sender, provide prescribed contact information for the sender, and set out an "unsubscribe" mechanism. The prescribed contact information includes:

  • The name of the person sending the message
  • If the message is being sent on behalf of another person, the name of the person on whose behalf the message is being sent
  • A statement indicating which person is sending the message and which person on whose behalf the message is being sent
  • The mailing address and one of a telephone number providing access to an agent or voice message system, or an email address, or a web address of the person sending the message or the person on whose behalf the message is sent.

The unsubscribe mechanism that must be included in each CEM must enable the recipient to indicate, at no cost to them, that they no longer wish to receive CEMs from the sender. The unsubscribe mechanism must be valid for at least 60 days after the CEM is sent, and effect must be given to the unsubscribe mechanism without delay, and without limitation in no more than 10 business days.


Under CASL, it is an offence "to aid, induce, procure or cause to be procured the doing of any act contrary to" certain sections, including the provisions relating to sending CEMs. Accordingly, refer-a-friend promotions must be carefully structured to take into account requirements under CASL.


The potential penalties for non-compliance under CASL are significant and include administrative monetary penalties of up to C$1-million for individuals and C$10-million for corporations.

CASL also creates a private right of action for persons who have been affected by a contravention of any number of CASL's provisions, including the anti-spam provisions. The provisions of the statute providing for a private right of action will not come into effect until July 1, 2017. This three-year delay is welcome news for industry, which has been very concerned about class action lawsuits being instituted while both industry and the regulators are trying to navigate the new regime. Despite the private right of action not coming into force for another three years, industry should be aware that risks of claims nonetheless exist and should strive to achieve compliance with the statute.


Given the shorter-than-expected grace period, organizations will need to act swiftly to build and implement compliance programs that meet the strict standards of CASL. In order to get onside with the law, organizations should:

  • Identify their current practices for sending electronic messages and assess which ones will be covered by CASL.
  • Seek express consents in accordance with CASL's requirements. Since requests for consent will constitute CEMs after the law comes into force, requests for consent should be sent out before July 1, 2014.
  • Track and document implied consents and ensure there are systems in place to identify when an implied consent expires. Consider requesting express consent, which is not time limited and remains valid until consent is withdrawn.
  • Render fully operational unsubscribe mechanisms that meet the requirements of the legislation.
  • Develop and implement policies and procedures for compliance with CASL.
  • Train employees on applicable CASL policies and procedures.
  • Review contracts with vendors and service providers that send CEMs on behalf of the organization to ensure they are contractually obligated to comply with CASL.
This document is not intended to create an attorney-client relationship. You should not act or rely on any information in this document without first seeking legal advice. This material is intended for general information purposes only and does not constitute legal advice. If you have any specific questions on any legal matter, you should consult a professional legal services provider.

To print this article, all you need is to be registered on

Click to Login as an existing user or Register so you can print this article.

Contact the Author?
Click here to email the Author
In Association with
In Partnership with
Other Canada Advice Centres
Competition and Antitrust
Mergers and Acquisitions
Labour and Employment
More Advice Centers
Significant Recent Cases
A list of the most recent and notable Blakes cases that gives you an overview of the firm's depth of knowledge and experience.
Useful Resources
Organizations should take preventative steps prior to a breach occurring by having reasonable policies and procedural safeguards in place, and conducting necessary training.
This checklist is intended to help organizations take the appropriate steps in the event of a privacy breach and to provide guidance in assessing whether notification to affected individuals is required.
Organizations subject to the Personal Information Protection Act (PIPA) are required to report a breach of personal information to the Commissioner.
An Act to support and promote electronic commerce by protecting personal information that is collected, used or disclosed in certain circumstances, by providing for the use of electronic means to communicate or record information or transactions and by amending the Canada Evidence Act, the Statutory Instruments Act and the Statute Revision Act.
Designed as one of the most stringent anti-spam regimes in the world, the legislation imposes important restrictions on the use of electronic messages to encourage participation in commercial activities.
Upcoming Events
Our professional development seminars provide legal and other professionals with access to programs that have been accredited by those governing bodies in various jurisdictions across Canada that have set educational credit requirements.
Font Size:
Mondaq on Twitter
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
Email Address
Company Name
Confirm Password
Mondaq Topics -- Select your Interests
 Law Performance
 Law Practice
 Media & IT
 Real Estate
 Wealth Mgt
Asia Pacific
European Union
Latin America
Middle East
United States
Worldwide Updates
Check to state you have read and
agree to our Terms and Conditions

Terms & Conditions and Privacy Statement (the Website) is owned and managed by Mondaq Ltd and as a user you are granted a non-exclusive, revocable license to access the Website under its terms and conditions of use. Your use of the Website constitutes your agreement to the following terms and conditions of use. Mondaq Ltd may terminate your use of the Website if you are in breach of these terms and conditions or if Mondaq Ltd decides to terminate your license of use for whatever reason.

Use of

You may use the Website but are required to register as a user if you wish to read the full text of the content and articles available (the Content). You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these terms & conditions or with the prior written consent of Mondaq Ltd. You may not use electronic or other means to extract details or information about’s content, users or contributors in order to offer them any services or products which compete directly or indirectly with Mondaq Ltd’s services and products.


Mondaq Ltd and/or its respective suppliers make no representations about the suitability of the information contained in the documents and related graphics published on this server for any purpose. All such documents and related graphics are provided "as is" without warranty of any kind. Mondaq Ltd and/or its respective suppliers hereby disclaim all warranties and conditions with regard to this information, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Mondaq Ltd and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use or performance of information available from this server.

The documents and related graphics published on this server could include technical inaccuracies or typographical errors. Changes are periodically added to the information herein. Mondaq Ltd and/or its respective suppliers may make improvements and/or changes in the product(s) and/or the program(s) described herein at any time.


Mondaq Ltd requires you to register and provide information that personally identifies you, including what sort of information you are interested in, for three primary purposes:

  • To allow you to personalize the Mondaq websites you are visiting.
  • To enable features such as password reminder, newsletter alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our information providers who provide information free for your use.

Mondaq (and its affiliate sites) do not sell or provide your details to third parties other than information providers. The reason we provide our information providers with this information is so that they can measure the response their articles are receiving and provide you with information about their products and services.

If you do not want us to provide your name and email address you may opt out by clicking here .

If you do not wish to receive any future announcements of products and services offered by Mondaq by clicking here .

Information Collection and Use

We require site users to register with Mondaq (and its affiliate sites) to view the free information on the site. We also collect information from our users at several different points on the websites: this is so that we can customise the sites according to individual usage, provide 'session-aware' functionality, and ensure that content is acquired and developed appropriately. This gives us an overall picture of our user profiles, which in turn shows to our Editorial Contributors the type of person they are reaching by posting articles on Mondaq (and its affiliate sites) – meaning more free content for registered users.

We are only able to provide the material on the Mondaq (and its affiliate sites) site free to site visitors because we can pass on information about the pages that users are viewing and the personal information users provide to us (e.g. email addresses) to reputable contributing firms such as law firms who author those pages. We do not sell or rent information to anyone else other than the authors of those pages, who may change from time to time. Should you wish us not to disclose your details to any of these parties, please tick the box above or tick the box marked "Opt out of Registration Information Disclosure" on the Your Profile page. We and our author organisations may only contact you via email or other means if you allow us to do so. Users can opt out of contact when they register on the site, or send an email to with “no disclosure” in the subject heading

Mondaq News Alerts

In order to receive Mondaq News Alerts, users have to complete a separate registration form. This is a personalised service where users choose regions and topics of interest and we send it only to those users who have requested it. Users can stop receiving these Alerts by going to the Mondaq News Alerts page and deselecting all interest areas. In the same way users can amend their personal preferences to add or remove subject areas.


A cookie is a small text file written to a user’s hard drive that contains an identifying user number. The cookies do not contain any personal information about users. We use the cookie so users do not have to log in every time they use the service and the cookie will automatically expire if you do not visit the Mondaq website (or its affiliate sites) for 12 months. We also use the cookie to personalise a user's experience of the site (for example to show information specific to a user's region). As the Mondaq sites are fully personalised and cookies are essential to its core technology the site will function unpredictably with browsers that do not support cookies - or where cookies are disabled (in these circumstances we advise you to attempt to locate the information you require elsewhere on the web). However if you are concerned about the presence of a Mondaq cookie on your machine you can also choose to expire the cookie immediately (remove it) by selecting the 'Log Off' menu option as the last thing you do when you use the site.

Some of our business partners may use cookies on our site (for example, advertisers). However, we have no access to or control over these cookies and we are not aware of any at present that do so.

Log Files

We use IP addresses to analyse trends, administer the site, track movement, and gather broad demographic information for aggregate use. IP addresses are not linked to personally identifiable information.


This web site contains links to other sites. Please be aware that Mondaq (or its affiliate sites) are not responsible for the privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of these third party sites. This privacy statement applies solely to information collected by this Web site.

Surveys & Contests

From time-to-time our site requests information from users via surveys or contests. Participation in these surveys or contests is completely voluntary and the user therefore has a choice whether or not to disclose any information requested. Information requested may include contact information (such as name and delivery address), and demographic information (such as postcode, age level). Contact information will be used to notify the winners and award prizes. Survey information will be used for purposes of monitoring or improving the functionality of the site.


If a user elects to use our referral service for informing a friend about our site, we ask them for the friend’s name and email address. Mondaq stores this information and may contact the friend to invite them to register with Mondaq, but they will not be contacted more than once. The friend may contact Mondaq to request the removal of this information from our database.


This website takes every reasonable precaution to protect our users’ information. When users submit sensitive information via the website, your information is protected using firewalls and other security technology. If you have any questions about the security at our website, you can send an email to

Correcting/Updating Personal Information

If a user’s personally identifiable information changes (such as postcode), or if a user no longer desires our service, we will endeavour to provide a way to correct, update or remove that user’s personal data provided to us. This can usually be done at the “Your Profile” page or by sending an email to

Notification of Changes

If we decide to change our Terms & Conditions or Privacy Policy, we will post those changes on our site so our users are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If at any point we decide to use personally identifiable information in a manner different from that stated at the time it was collected, we will notify users by way of an email. Users will have a choice as to whether or not we use their information in this different manner. We will use information in accordance with the privacy policy under which the information was collected.

How to contact Mondaq

You can contact us with comments or queries at

If for some reason you believe Mondaq Ltd. has not adhered to these principles, please notify us by e-mail at and we will use commercially reasonable efforts to determine and correct the problem promptly.