ComplianceJuly 5, 2026· 10 min read

CASL Compliance for Websites: The 2026 Technical and Legal Checklist

A comprehensive implementation guide for Canadian Anti-Spam Legislation compliance — covering consent mechanisms, record-keeping, unsubscribe infrastructure, and hosting requirements.

CASL Enforcement Is Increasing — Not Decreasing

The Canadian Radio-television and Telecommunications Commission (CRTC) has issued over $20 million in penalties under CASL since the legislation took effect. In 2024 alone, enforcement actions targeted companies ranging from national telecoms to regional service businesses.

CASL applies to any commercial electronic message (CEM) sent to or from a Canadian address. If your website collects email addresses, phone numbers, or uses web forms that trigger automated messages, CASL applies to your business — regardless of your company size or industry.

The legislation carries penalties of up to $10 million per violation for organizations and $1 million for individuals. Private right of action (suspended since 2017) remains available for future activation by the Governor in Council.

What Qualifies as a Commercial Electronic Message

A CEM is any electronic message that has as one of its purposes to encourage participation in a commercial activity. This includes:

  • Marketing emails and newsletters
  • Promotional text messages
  • Automated order confirmations that include upsell content
  • Welcome emails with promotional elements
  • Social media messages sent for commercial purposes
  • Push notifications with commercial content

Messages that are purely transactional — password resets, shipping notifications, appointment confirmations with no promotional content — are generally exempt. However, if a transactional email includes a promotional footer or cross-sell section, the entire message may fall under CASL.

The Consent Framework

CASL recognizes two types of consent:

Express consent is affirmative, documented permission. The recipient actively opted in through a clear mechanism. Express consent does not expire (unless withdrawn).

Requirements for valid express consent:

  • Clear description of the purpose
  • Identification of who is seeking consent (and on whose behalf)
  • Statement that consent can be withdrawn at any time
  • Separate checkbox (not pre-checked, not bundled with terms of service)

Implied consent exists in specific circumstances:

  • Existing business relationship (purchase within last 2 years)
  • Existing inquiry relationship (inquiry within last 6 months)
  • Publicly available email addresses (with conditions)
  • Business card exchange

Implied consent expires. If a customer purchased from you 25 months ago and hasn't purchased since, implied consent has lapsed.

Technical Implementation Checklist

### 1. Consent Collection Mechanisms

Email signup forms must include:

  • [ ] Clear statement of what the subscriber will receive
  • [ ] Frequency disclosure ("Weekly newsletter" not just "Subscribe")
  • [ ] Identification of your organization by name
  • [ ] Unchecked checkbox (no pre-selected consent)
  • [ ] No consent bundling (newsletter consent separate from account creation)
  • [ ] Double opt-in confirmation email

Contact forms must include:

  • [ ] Purpose limitation statement
  • [ ] No automatic newsletter enrollment from contact form submission
  • [ ] Clear distinction between "respond to my inquiry" and "add me to marketing"

E-commerce checkout must include:

  • [ ] Separate marketing consent checkbox (not pre-checked)
  • [ ] Order confirmation emails must be purely transactional (no promotional content mixed in)
  • [ ] Post-purchase marketing sequences triggered only with express consent

### 2. Consent Record-Keeping

For every contact in your database, you must be able to produce:

  • [ ] Type of consent (express or implied)
  • [ ] Date consent was obtained
  • [ ] Method of consent (form URL, in-person, phone)
  • [ ] Exact wording of the consent request shown to the user
  • [ ] IP address and timestamp (for web forms)
  • [ ] Source URL where consent was collected

Store these records indefinitely — or at minimum, for 3 years beyond the last message sent. If challenged by the CRTC, the burden of proof is on you to demonstrate valid consent existed at the time of sending.

### 3. Unsubscribe Infrastructure

Requirements:

  • [ ] Every CEM includes a functional unsubscribe mechanism
  • [ ] Unsubscribe must be processed within 10 business days (best practice: immediate)
  • [ ] Unsubscribe mechanism must remain functional for 60 days after sending
  • [ ] No "login required" to unsubscribe
  • [ ] No "confirm your unsubscribe" re-consent attempts
  • [ ] One-click unsubscribe header (List-Unsubscribe) for email clients

Technical implementation:

  • Use a dedicated unsubscribe endpoint that processes requests without authentication
  • Implement List-Unsubscribe and List-Unsubscribe-Post headers
  • Log all unsubscribe events with timestamp
  • Suppress unsubscribed addresses at the sending infrastructure level (not just the application level)

### 4. Message Identification Requirements

Every commercial electronic message must include:

  • [ ] Sender's legal name or operating name
  • [ ] Physical mailing address (street address, not just P.O. box)
  • [ ] Contact mechanism (phone, email, or web URL)
  • [ ] Clear identification of the person sending on whose behalf

### 5. Hosting and Data Storage

While CASL doesn't explicitly mandate Canadian hosting, your infrastructure decisions affect compliance posture:

  • [ ] Consent records stored securely with access controls
  • [ ] Email lists protected from unauthorized access
  • [ ] Personal information (email, phone, name) stored with appropriate safeguards
  • [ ] Backup copies of consent records maintained separately from production data
  • [ ] Data breach response plan in place (mandatory 72-hour notification under PIPEDA amendments)

Storing consent records and personal information on Canadian infrastructure strengthens your compliance position if challenged. It eliminates questions about cross-border data access and demonstrates "appropriate safeguards" under PIPEDA's Accountability Principle.

Common CASL Violations on Websites

Pre-checked consent boxes: Still the most common violation. Any pre-selected checkbox for marketing consent is invalid under CASL.

Bundled consent: "By creating an account, you agree to receive marketing emails" is not valid consent. Account creation and marketing consent must be separate actions.

Missing sender identification: Emails sent from "noreply@company.com" without clear organizational identification in the body violate the identification requirement.

Broken unsubscribe links: If your unsubscribe mechanism is non-functional (returns 404, requires login, or fails silently), every message sent with that link is a violation.

Purchased email lists: Buying a list of "Canadian business emails" does not create consent. Sending to purchased lists without express consent is a per-message violation.

Implied consent overreliance: Businesses that assume a 3-year-old customer is still under implied consent. The 2-year window from last purchase is strict.

Audit Your Current Setup

Run through these questions for your website today:

  1. Does every email signup form clearly state what the subscriber will receive?
  2. Are consent checkboxes unchecked by default?
  3. Can you produce consent records (date, method, wording) for every contact in your list?
  4. Does every marketing email include your legal name, address, and working unsubscribe?
  5. Are unsubscribes processed within 10 days?
  6. Is marketing consent collected separately from account creation?
  7. Do transactional emails contain any promotional content?
  8. Are your consent records backed up and retained?

If you answered "no" or "I'm not sure" to any of these, you have compliance exposure.

TransPark's CASL-Aligned Infrastructure

TransPark's hosting platform is designed with CASL compliance in mind:

  • All data stored in Canada (AWS ca-central-1, Montreal)
  • Daily encrypted backups retained for 30 days
  • Per-client isolation (no shared database environments)
  • Transactional email with built-in List-Unsubscribe header support
  • Access logging for audit trail requirements

Your hosting provider can't make you CASL-compliant — that requires proper consent practices and internal processes. But your hosting provider can eliminate the data residency question entirely, and that's one less audit finding to defend.

Ready to host in Canada?

Start with a 30-day money-back guarantee.