CASL Compliance for Cold Email: What Canadian Law Requires
Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.

CASL requires consent before you email a Canadian recipient, and it puts the burden of proving it on the sender. Cold outbound normally relies on implied consent through conspicuous publication, which needs a published address, no refusal statement, and relevance to that person's role. Messages also need identification and a working unsubscribe.
Key takeaways
- Consent, sender identification and a working unsubscribe are all required; a message missing any one of them is non-compliant.
- Implied consent runs two years from a transaction or contract and only six months from an inquiry, which is the window people forget.
- Conspicuous publication needs three conditions together: a published address, no statement refusing unsolicited messages, and relevance to that person's role.
- Contact information and the unsubscribe mechanism must stay valid for at least 60 days, and unsubscribes must be processed within 10 business days.
Reviewed and updated September 5, 2026
CASL Compliance for Cold Email: What Canadian Law Actually Requires
Canada's Anti-Spam Legislation flips the default that US senders are used to. Under CAN-SPAM you may email anyone until they ask you to stop. Under CASL you may not email anyone until you can show you were allowed to, and if a regulator asks, the burden of proving it sits on you rather than on them.
That single difference is why outbound teams that treat Canada as an extension of their US list end up exposed. Here is what the law requires, where the exemptions actually apply, and how to run Canadian outbound without guessing.
- you may email anyone until they ask you to stop
- you may not email anyone until you can show you were allowed to
- the burden of proving it sits on you rather than on them
This is not legal advice. It is an operator's reading of CASL and the CRTC's published guidance.
What CASL covers
CASL regulates commercial electronic messages, or CEMs: any electronic message that encourages participation in a commercial activity, sent to or accessed from a computer system in Canada. A cold sales email is squarely a CEM.
Three things must be true for a compliant send:
- You have consent, express or implied, or a listed exemption applies.
- The message identifies the sender and anyone on whose behalf it is sent, with valid contact information.
- The message contains a working unsubscribe mechanism.
Miss any one and the message is non-compliant even if the other two are perfect.
Express consent
Express consent is a positive, informed opt-in. The request must set out the purpose the consent is being sought for, identify who is seeking it and on whose behalf, give a mailing address plus a phone number, email, or web address, and state that consent can be withdrawn. Pre-checked boxes do not count. Consent obtained by implication from a terms-of-service acceptance does not count.
The compensation for that friction is durability: express consent does not expire. Implied consent does.
Implied consent, the route most cold email relies on
Two categories matter for outbound.
Existing business relationship
Consent is implied for a defined window after a qualifying interaction:
| Trigger | Window |
|---|---|
| Purchase or lease of a product, goods, service, or land | 2 years from the transaction |
| Acceptance of a business, investment, or gaming opportunity | 2 years |
| A written contract, current or expired | 2 years from expiry |
| An inquiry or application about any of the above | 6 months |
The six-month inquiry window is the one people forget. Someone who filled out a form and went quiet is a lawful recipient for six months, not two years.

Conspicuous publication
This is the workhorse for cold outbound, and it has three conditions that must all hold:
- The recipient conspicuously published the address, or caused it to be published. A company website, a public directory listing, a published staff page. An address scraped from a private database or guessed from a naming pattern does not qualify.
- The publication carries no statement saying the person does not wish to receive unsolicited commercial messages. A "no unsolicited sales enquiries" line on the contact page removes the implied consent.
- The message is relevant to that person's business, role, functions, or duties in a business or official capacity.
Condition three is the one that fails in practice. Emailing a CFO about a marketing tool is not relevant to their role, and relevance is judged against the individual's actual function, not against the company's general interest in growth.
Practical consequence: capture the evidence at collection time. The source URL, a timestamp, and ideally a snapshot. Implied consent you cannot evidence is, for enforcement purposes, no consent.
The business-to-business exemption, and why it is narrower than it sounds
Section 3(a)(ii) of the Governor in Council Regulations exempts messages sent by an employee or representative of one organization to an employee or representative of another, where the two organizations have a relationship and the message concerns the recipient organization's activities. When it applies, CASL's requirements do not apply to that message at all.
The Federal Court of Appeal narrowed the reading in its June 2020 CompuFinder decision. The relationship has to be between the organizations, not merely between a handful of individuals inside them. A limited contractual relationship covering a small number of transactions affecting a few employees was held insufficient.
CompuFinder is also the case that shows the enforcement arc. The CRTC issued a notice of violation with a $1.1 million administrative monetary penalty over three 2014 email campaigns, found 317 messages sent without consent, and reduced the penalty to $200,000 in October 2017 after weighing the company's lack of prior violations and ability to pay. The Federal Court of Appeal dismissed CompuFinder's appeal in full in 2020, confirming CASL is constitutionally valid.
The operating lesson: the B2B exemption is a defence for messages between organizations that already work together. It is not a general carve-out for B2B cold email.
Deciding whether one prospect is lawful
The three sections above describe the law. This is the order to apply it in, prospect by prospect, before a send rather than after a complaint.
- Step 1Express consent on record?
If yes, send. It does not expire, and the record is the defence
- Step 2Qualifying interaction inside the window?
Two years from a transaction or contract, six months from an inquiry
- Step 3Address conspicuously published?
Company site or public directory, captured with its source URL
- Step 4No refusal statement on that page?
A no unsolicited enquiries line removes the implied consent
- Step 5Relevant to that person's actual role?
Judged against their function, not the company's general interest
- Step 6Identification, address and unsubscribe present?
All three, in the message, or it is non-compliant anyway
The order matters because each step is cheaper than the one after it. Checking a suppression record costs nothing; re-reading a contact page to look for a refusal statement costs a fetch; judging role relevance costs a human. Running them in this order means the expensive check only runs on prospects that survived the cheap ones.
Note what is missing from that sequence: there is no step that rescues a failure further down. A prospect who fails the relevance test is not made lawful by the quality of the copy, by an unsubscribe link, or by the address having been published. Each condition is necessary on its own.
Form and content requirements

Every CEM must include:
- Identification of the sender and anyone on whose behalf the message is sent. If it will not fit in the message, a hyperlink to a readily accessible, free webpage is acceptable.
- Contact information, including a mailing address that stays valid for at least 60 days after sending. A street address, PO box, rural route, or general delivery address all qualify.
- An unsubscribe mechanism that can be readily performed: a link to an accessible page, or a reply keyword for SMS. It must remain valid for at least 60 days after the message is sent.
- Processing of unsubscribes without delay, and no later than 10 business days. No confirmation step that the recipient has to complete.
Sixty days is longer than CAN-SPAM's 30-day requirement, which means a single global standard of 60 days clears both.

Penalties and who enforces
Maximum administrative monetary penalties are $1 million per violation for an individual and $10 million per violation for any other person, which in practice means corporations. Directors and officers can be personally liable, and a company can be vicariously liable for what its employees or agents send.
Enforcement sits with the CRTC, working alongside the Competition Bureau and the Office of the Privacy Commissioner. CASL's private right of action, which would let individuals sue for statutory damages, was suspended before it came into force and remains not in force, so regulators are still the only route to enforcement.
What the evidence has to look like
CASL puts the burden of proof on the sender, so the operating question is not whether you were allowed to send, it is whether you can show it a year later. Implied consent you cannot evidence is, for enforcement purposes, no consent.
For a conspicuous-publication send, the record that survives an audit is per prospect, not per campaign: the source URL the address was published on, the date it was captured, ideally a stored copy of the page as it looked, and a note of which role the relevance test was satisfied against. A list that records only "scraped from company websites" describes a method rather than evidencing a prospect.
Two failure modes are worth naming because they are quiet. A page that carried no refusal statement when you captured it may carry one now, so a record captured long ago and sent to today is weaker than its timestamp suggests: re-check anything older than your own comfort window before a send. And a captured address proves the address was published, which is only one of the three conditions. Relevance and the absence of a refusal statement have to be recorded separately, or the evidence file answers a question nobody asked.
For express consent, keep the wording of the request itself alongside the timestamp. The rules are about what the person was told when they agreed, so a consent record without the request text cannot demonstrate compliance with them.
Keep unsubscribe logs on the same footing. The obligation is to process a withdrawal without delay and no later than ten business days, and the only way to show that was met is a timestamped record of when the request arrived and when the suppression took effect.
How to run Canadian outbound
- Segment Canada out of your global list. Different rules mean a different process, not a footnote in the same one.
- Build on conspicuous publication. Source addresses from company sites and public directories, store the source URL and date on every record, and re-check before a send if the record is old.
- Enforce the relevance test at the targeting layer. If your ICP filter cannot explain why this role would care about this offer, the message fails condition three regardless of copy quality.
- Respect refusal statements. Scrapers do not read a "no unsolicited enquiries" line on a contact page. A human review pass or a keyword filter on the source page should.
- Track implied consent expiry. Six months on inquiries, two years on transactions, and a suppression rule that fires when the clock runs out.
- Publish a real mailing address and a 60-day unsubscribe in every message, and suppress globally on the first request.
- Keep the records. Consent evidence, unsubscribe logs, and send logs are your only defence, and CASL puts the burden on you.
Compliance and deliverability reinforce each other here. Sourcing from published addresses, targeting by genuine role relevance, and honouring opt-outs instantly are also the behaviours that keep complaint rates low, which is what Google Postmaster Tools measures and what spam rate benchmarks track.
Message contents pull the other way, and the deliverability cost of an open pixel weighs a rewritten link against the cleanest possible first message.
For the wider picture across regimes, see is cold email legal. On the technical side, make sure your authentication records are correct, your list is properly verified before it ships, and you know how to check and clear a blacklisting if one appears. The fundamentals live in the cold email deliverability guide.
Running outbound into Canada and want the consent and evidence layer built in? Get a free campaign plan and we will walk through how it works.
Frequently asked questions.
Frequently asked questions- Is cold email legal in Canada?
- It can be, and the rules are stricter than under CAN-SPAM. CASL requires consent before you send rather than after a complaint, and the burden of proving it sits with the sender. Cold outbound normally relies on implied consent through conspicuous publication, which works only when all three of its conditions hold at once.
- What is conspicuous publication under CASL?
- It is the implied-consent route most cold outbound depends on. The recipient must have published the address or caused it to be published, the publication must carry no statement refusing unsolicited commercial messages, and your message must be relevant to that person's role or duties. Relevance is the condition that fails most often in practice.
- Does the business-to-business exemption cover cold email?
- Generally not. The exemption applies to messages between organisations that already have a relationship, and the Federal Court of Appeal read that narrowly in the CompuFinder decision: the relationship has to be between the organisations rather than between a few individuals inside them. It is a defence for existing partners, not a carve-out for cold outreach.
- What records do I need to keep?
- Per prospect rather than per campaign. For a conspicuous-publication send, keep the source URL, the capture date, ideally a stored copy of the page, and a note of the role the relevance test was satisfied against. Keep unsubscribe logs with timestamps too, since the obligation is to process a withdrawal within ten business days.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden · CRO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
CAN-SPAM Act Compliance for B2B Cold Email: The Rules
The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.
Cold Email in HubSpot: What Its Anti-Spam Policy Says
Whether HubSpot can send cold email is a feature question. What it permits is a contract question, and HubSpot answers it in writing on a page most buyers never open.
How to Write a New Year Outreach Email, Line by Line
A new year outreach email works only where January is a fact about the account. Who that is, the structure line by line, and two worked examples.
How to Write a Third Follow Up Email, Line by Line
A third follow up email belongs only in a thread where the person replied or agreed to something. When to send one, and how to write it line by line.
CEO Email Addresses: Finding One That Resolves
Seniority is the thinnest coverage band in every contact database. How an executive address is resolved, why verification is a separate purchase, and when to stop.
Email Tracking Software: Six Tools, Priced and Capped
Streak, Mailsuite, Right Inbox, Mixmax, Yesware and HubSpot compared on free-tier caps and published prices, plus what an open event still proves.