Your website is not “CASL compliant” or “CASL non-compliant” as a whole. CASL binds three specific things your site does: the messages you send after someone fills in a form, the identification and unsubscribe details inside those messages, and the scripts your site installs on a visitor’s device. Most Canadian small business sites fail on the first and have never even looked at the third.
Written by Cody Wise, founder of Wise Media. Last updated 7 September 2026. This is general information for business owners, not legal advice. Verify your own position with counsel before relying on any of it.
Summary
- CASL does not regulate websites directly. It regulates commercial electronic messages (CEMs) and the installation of computer programs. Your website is where both of those get triggered.
- Every CEM needs three things: valid consent, sender identification, and a working unsubscribe mechanism.
- Express consent does not expire. Implied consent does, and the clocks are short: 24 months from a purchase or contract, 6 months from an enquiry.
- The burden of proving consent sits on you, not on the recipient. If your form does not record what was agreed to and when, you have no defence.
- Maximum administrative monetary penalties are $1 million CAD per violation for an individual and $10 million CAD per violation for a business.
- The private right of action has been suspended since 2017 and remains suspended. CRTC enforcement was never suspended.

Table of contents
- Does CASL actually apply to my website?
- What counts as a commercial electronic message
- The three requirements every message must meet
- Express vs implied consent, and the clocks that run out
- Your contact form is a consent record, and most are not
- Does CASL cover cookies and tracking pixels?
- The 2026 website CASL audit, step by step
- Six mistakes we find on almost every site
- What it costs to fix
- FAQ
Does CASL actually apply to my website?
If your business sends any electronic message that encourages participation in a commercial activity, and a computer system in Canada is used to send or access it, CASL applies. There is no small business exemption, no revenue threshold, and no exemption for a business that only emails people who asked to hear from it.
That last point is where most owners get comfortable and should not. “They signed up on my site” is a claim about consent. CASL cares whether you can prove it, in what form it was given, and whether the form itself was compliant at the moment it was submitted. Innovation, Science and Economic Development Canada sets out the basic framework in its overview of the legislation.
Geography does not save you either. CASL is drafted around the location of the computer system used to send or access the message, so a business outside Canada emailing Canadian recipients is in scope, and a Canadian business emailing internationally is in scope for the sending side.
What CASL does not do
CASL is not a privacy statute. It does not govern how you store personal information, how long you keep it, or whether you can share it. That is PIPEDA, and in Quebec, Law 25. CASL is narrower and sharper: consent to send, identification in the message, a way out of the list, and consent to install software. Treating CASL as a general privacy law is the fastest way to build the wrong fix.

What counts as a commercial electronic message
A commercial electronic message is any electronic message that, judged by its content, its links, or its contact information, could reasonably be taken as encouraging participation in a commercial activity. Email is the obvious case. So are SMS, direct messages on social platforms, and messages sent through a messaging app.
Things that catch people out:
- A newsletter with no offer in it, but a signature block linking to your services page, is still commercial.
- A “just checking in” follow-up to a lead is commercial.
- A cold outreach email to an address you found on a company website is commercial, and the published-address exemption is narrower than most people assume.
- A transactional message, such as a receipt, booking confirmation, or warranty notice, is generally exempt from the consent requirement but not from the honesty requirements. Bolting a promotion onto a receipt can change its character.

The three requirements every message must meet
Short answer: consent, identification, and unsubscribe. All three, in every message, every time. Missing one is a violation even if the other two are perfect.
1. Consent
Either express or implied, covered in detail in the next section. The onus of proving it is on the sender.
2. Identification
Every message must name the sender, and if you are sending on behalf of another party, name them too. It must include a mailing address, plus at least one of a phone number, email address, or web address. Those contact details must stay valid for at least 60 days after the message is sent.
A PO box is acceptable as a mailing address. “Sent from our Calgary office” is not an address. A logo is not a name.
3. Unsubscribe
The mechanism must be set out clearly and be able to be readily performed. It must work through the same electronic means the message was sent by, cost the recipient nothing, and stay functional for at least 60 days after the message is sent. You then have 10 business days to give effect to the request, and you cannot require a login, a reason, or a reply email to process it.
“Readily performed” is the phrase doing the work. A one-click link that lands on a preference centre with a single clear “unsubscribe from everything” option is fine. A link that lands on a login wall is not. The CRTC covers the mechanics in its CASL frequently asked questions.
Express vs implied consent, and the clocks that run out
Express consent is given actively and does not expire. Implied consent is inferred from a relationship or a published address, and every category of it has an expiry date. This table is the single most useful thing to pin above your desk.
| Basis | How it arises | How long it lasts |
|---|---|---|
| Express consent | An unchecked box the person ticks, or a clear oral or written agreement, with full disclosure of who is asking and why | Until the person withdraws it |
| Implied, existing business relationship | A purchase, an accepted business or investment opportunity, or a written contract | 24 months from the date of that transaction or the contract’s expiry |
| Implied, enquiry | An enquiry or application about a product, service, or business opportunity | 6 months from the enquiry |
| Implied, non-business relationship | Donation, volunteer work, or membership in a club, association or voluntary organisation | 24 months |
| Conspicuously published address | An address published without a statement refusing messages, where your message relates to the person’s role | No fixed expiry, but heavily conditioned and easy to get wrong |
The CRTC’s guidance on implied consent is the primary source here, and the ISED page on getting consent to send email is the plain-language version.
The rolling clock nobody manages
Here is the part that quietly breaks a list. Implied consent is not a one-time flag. It is a rolling window measured from a specific dated event. Someone who bought from you in March 2024 stops being reachable on implied consent in March 2026 unless they bought again, contracted again, or gave you express consent in the meantime.
Almost no small business list is segmented this way. The typical setup is one list, one tag, no purchase dates, and no distinction between a person who ticked a box and a person who once asked for a quote. When the clock runs out on the second group, nothing in the system notices.
The practical fix is not clever. Store the consent basis and the consent date as fields against every contact, and build a rule that suppresses implied-consent contacts once their window closes. Any competent email platform can do this. Almost none does it by default.
Your contact form is a consent record, and most are not
This is the gap we find on almost every Canadian site we audit, and it is the one that connects CASL directly to web design rather than to email software.
A contact form that captures a name, an email, and a message gives you six months of implied consent for the subject the person enquired about. It does not give you express consent for a newsletter, and it does not give you 24 months. If your form pushes every submission straight into a marketing list, you have built a machine that manufactures a violation every time someone asks a question.
What a compliant form actually looks like
- An unchecked opt-in box, separate from the submit action. Pre-ticked boxes do not produce express consent, and neither does a line of small print saying that submitting the form signs you up.
- Plain language beside the box naming who will be sending, what kind of messages, and that consent can be withdrawn at any time.
- Your business name and mailing address reachable from the form, normally through a linked privacy page rather than crammed into the form itself.
- A stored record of the submission: timestamp, IP address, the exact wording shown at the time, and whether the box was ticked. Wording changes over the years, so keep the version.
- Separate destinations. Enquiry submissions go to your inbox or CRM. Only ticked submissions go to the marketing list.
Point four is the one people skip and the one that matters in a dispute. Consent you cannot evidence is consent you do not have. If your form plugin stores nothing and forwards straight to email, your entire proof is a message in an inbox that your mail provider may have pruned two years ago.
If you are rebuilding forms anyway, it is worth doing the speed and routing work at the same time, because the same submissions are usually leaking on the follow-up side too. We covered that in Speed to Lead.
Does CASL cover cookies and tracking pixels?
Partly, and the internet gets this badly wrong in both directions. Here is the accurate version.
Section 8 of CASL prohibits installing a computer program on another person’s computer system in the course of commercial activity without express consent. A browser is a computer system, and scripts you serve are capable of being computer programs. That is why the question comes up at all. The CRTC’s page on requirements for installing computer programs is the primary source.

The deemed consent rule that most vendor blogs omit
CASL does not require a cookie banner. Subsection 10(8) treats a person as having consented to the installation of certain program types, including cookies, HTML, JavaScript and operating systems, provided the person’s conduct makes it reasonable to believe they consent. Browsing a normal website is ordinarily that conduct.
The condition attached to it is the part worth knowing: if a person has disabled cookies in their browser, you are not deemed to have consent to install them. Their conduct now says the opposite.
So the accurate summary is this. Ordinary analytics and functional cookies on a Canadian website are not a CASL problem in the normal case. Software that goes further, collects data beyond what the user would reasonably expect, changes settings, or is difficult to remove, sits outside the deemed consent categories and needs genuine express consent with enhanced disclosure.
Why you probably still want a consent banner
Not because of CASL. Because of PIPEDA’s meaningful consent expectations, because Quebec’s Law 25 sets a materially higher bar for tracking technologies, and because any advertising platform you use will have its own contractual consent requirements. CASL is the weakest of the three arguments for a banner, which is exactly why articles that lead with CASL on this point tend to be selling banner software.
The 2026 website CASL audit, step by step
Budget an afternoon. You need admin access to your website, your email platform, and your CRM if you have one.
- List every place an address enters your business. Contact form, quote form, newsletter box in the footer, gated download, event signup, chat widget, offline sign-up sheet, business cards from a trade show. Most owners find between four and nine.
- For each one, write down what the person actually agreed to. Not what you intended. The literal wording shown on screen at the moment of submission.
- Check whether any of them uses a pre-ticked box or bundles consent into the submit button. If so, everything collected through it is implied consent at best, with the shorter clock.
- Check whether the submission is stored anywhere. Open your form plugin and look for saved entries. If there are none, you have no consent evidence and that needs fixing before anything else.
- Export your marketing list and look for a consent field. If there is no column recording basis and date, you cannot currently prove consent for any contact on it.
- Send yourself a live campaign email and check it against the three requirements. Sender name, mailing address, one contact method, working unsubscribe, and whether the unsubscribe completes in one step.
- Time your unsubscribe processing. Unsubscribe from your own list and check when the suppression actually applies. Ten business days is the ceiling, not the target.
- Review your script inventory. Open the page source or your tag manager and list every third-party script. You are looking for anything doing more than analytics or functionality.
- Set a suppression rule for expired implied consent. 24 months from transaction, 6 months from enquiry.
- Write it down. A one-page internal note recording what you found and what you changed is the closest thing to a due diligence defence a small business realistically maintains.
Six mistakes we find on almost every site
- One list, no segments. Express and implied consent contacts mixed together, so the whole list moves at the speed of its weakest consent basis.
- The pre-ticked box. Still shipping on Canadian sites in 2026, usually because it came with a theme demo.
- An unsubscribe link that requires a login. Common on membership sites and anything running through a portal.
- No mailing address in the footer of the email. The single most common failure, and the easiest to fix.
- Purchased or scraped lists. There is no version of a bought list that carries valid CASL consent. The seller’s consent does not transfer to you.
- Form entries that are never stored. Everything forwarded to an inbox and nothing retained, so the consent record depends on an email you may have deleted.
What it costs to fix
These are illustrative planning ranges in Canadian dollars for the work itself, based on the scope we typically see. They are not a quote and they exclude legal review, which is a separate professional cost you should budget for if your exposure is meaningful.
| Work | Illustrative range (CAD) | Notes |
|---|---|---|
| Form consent rebuild, single site | $400 to $1,200 | Opt-in checkbox, disclosure copy, entry storage, split routing |
| Email template compliance pass | $250 to $700 | Identification block, unsubscribe path, one-step confirmation |
| List segmentation and consent field backfill | $600 to $2,500 | Scales with list size and how much source data survives |
| Script and tag inventory | $300 to $900 | Usually bundled with a privacy or performance review |
| Re-permission campaign | $500 to $1,500 | Only worth running before implied consent expires, not after |
The re-permission point deserves emphasis. Once implied consent has expired, an email asking the person to re-consent is itself a commercial electronic message you no longer have consent to send. Run the campaign inside the window or not at all.

How exposed are you, really?
Honest answer: less than the scare-copy suggests, and more than nothing.
The headline maximums are real. An administrative monetary penalty can reach $1 million CAD per violation for an individual and $10 million CAD per violation for a business. Those are statutory ceilings, not typical outcomes. The CRTC weighs the nature and scope of the violation, prior history, whether the party benefited financially, and ability to pay, and small business matters are commonly resolved through a negotiated undertaking rather than a maximum penalty. The CRTC publishes what it does in its enforcement actions record and describes the process in its compliance and enforcement overview, which is worth ten minutes of reading before you decide how worried to be.
The private right of action, which would have let individuals sue directly, was suspended in June 2017 and remains suspended. That suspension removed the class action risk. It did not touch CRTC enforcement, and it did not change a single substantive obligation.
The realistic risk for a Canadian small business is a complaint from an irritated recipient, an investigation that asks you to produce consent records, and the discovery that you do not have any. That is a paperwork problem you can solve this month for a few hundred dollars, or an expensive problem you solve later under time pressure.
FAQ
Does CASL require a cookie consent banner?
No. CASL treats cookies, HTML and JavaScript as categories where consent can be deemed from the user’s conduct, so ordinary browsing is normally enough. You may still want a banner for PIPEDA, for Quebec’s Law 25, or to satisfy an ad platform’s own requirements, but CASL is not the reason.
Someone filled in my contact form. Can I add them to my newsletter?
Not unless they separately agreed to it. An enquiry gives you implied consent for six months, tied to what they asked about. A newsletter is a different thing. Add an unchecked opt-in box to the form and only newsletter the people who tick it.
How long does implied consent from a purchase last?
Twenty-four months from the date of the purchase, or from the expiry of the written contract. A repeat purchase restarts the clock. An enquiry that never became a purchase gives you six months instead.
What has to be in the footer of a marketing email?
The sender’s name, a mailing address, and at least one of a phone number, email address or web address, all valid for at least 60 days after sending. Plus an unsubscribe mechanism that works through the same channel, costs nothing, and stays live for 60 days.
How fast do I have to action an unsubscribe?
Within 10 business days. Most modern email platforms suppress immediately, which is the safer default. Confirm yours does rather than assuming.
Can I email business addresses I found on company websites?
Sometimes. The conspicuously published address exemption requires the address to be published without any statement refusing unsolicited messages, and the message must relate to that person’s business role or functions. Scraping a list and emailing everyone on it about anything does not satisfy either condition.
Does CASL apply if my business is outside Canada?
Yes, where a computer system in Canada is used to send or access the message. A message sent from abroad and opened in Canada is in scope.
Can someone sue me personally under CASL?
Not currently. The private right of action was suspended indefinitely in 2017 and has not been brought into force. Government enforcement through the CRTC continues unaffected.
The bottom line
CASL compliance is not a plugin you install. It is a set of decisions baked into how your forms are built, where submissions go, what your email platform stores, and what your messages contain. Every one of those is a web build decision, which is why compliance keeps landing on the developer’s desk rather than the lawyer’s.
Work the ten-step audit above. Most businesses find two or three real gaps and fix them in a single sitting. If you would rather have it done properly and documented, that is the kind of work we build into every project through our website packages and maintain through website growth packages. It also pairs with the other two compliance questions Canadian owners keep asking us: whether your site is legally required to be accessible and whether it needs a French version.
Get your forms and list audited
If you want a second set of eyes on your forms, your email templates and your consent records, tell us what you are running and we will scope it. Start with our intake form and we will come back with a fixed scope rather than an hourly guess.