Rules
How to build a CASL compliant email template for Canadian subscribers
A CASL compliant email template needs CRTC consent wording, sender identification, a working unsubscribe link and consent records you can produce on demand.
What to take away
- A CASL compliant email template carries four things: consent you can prove, sender identification, a working unsubscribe mechanism, and a record of all three.
- The CRTC enforces Canada's Anti-Spam Legislation. ISED writes the guidance that explains how the rules apply.
- Express consent is a positive opt-in. Implied consent comes from an existing business relationship or a published business address, and it expires.
- Sender identification means your legal name, a physical mailing address and a way to reach you, in every message.
- Unsubscribe requests must take effect within ten business days, and the mechanism has to stay live for at least 60 days after sending.
- Quebec's Law 25 and PIPEDA sit on top of CASL. A template that satisfies all three is the safe default for a national list.
Where CASL consent rules come from: CRTC enforcement and ISED guidance
Canada's Anti-Spam Legislation came into force in 2014 and covers commercial electronic messages sent from or received in Canada. A commercial electronic message is any electronic message that encourages participation in a commercial activity, which includes most marketing email, most newsletters with a promotional element, and a good deal of transactional mail that carries an offer.
The Canadian Radio-television and Telecommunications Commission is the enforcement body. The CRTC investigates complaints, issues notices, and can levy administrative monetary penalties against organizations and individuals. Its published guidance describes what it expects to see in a consent record and how it reads the identification and unsubscribe rules.
Innovation, Science and Economic Development Canada publishes the companion guidance and the compliance and enforcement framework. When the two documents disagree in tone, treat the CRTC position as the one you will be tested against.
The statute itself sits in the federal consolidation, and you can locate the current text through the Justice Laws Website, which is the authoritative index for federal legislation.
For the wider regulatory picture, the business and industry hub on Canada.ca is the sensible starting point. It links to the CRTC, the Office of the Privacy Commissioner, the Competition Bureau Canada and the Canada Revenue Agency, which matters if your email carries pricing, testimonials or contest terms.
The federal business and industry hub also gathers the licensing and registration material most new senders need early on.
Two other bodies shape what goes inside the template. The Competition Bureau Canada polices misleading advertising, so claims in a subject line or hero image fall under its remit as much as the body copy.
Ad Standards administers the Canadian Code of Advertising Standards, and the Canadian Marketing Association publishes a code of ethics that many Canadian marketers treat as the practical baseline.
If you are starting from a blank file rather than an existing one, the fastest route is to adapt a working CASL-compliant email template and then strip out anything that assumes American rules. CAN-SPAM logic does not transfer. The opt-out standard, the identification requirements and the consent model are all different.
Express versus implied consent: what a Canadian subscriber record must hold
Express consent is a clear, positive action by the subscriber. A checked box, a confirmed double opt-in, a signed form, a recorded verbal agreement. The key word is positive. A pre-ticked box is not express consent, and neither is a statement that consent is assumed unless the subscriber objects.
An express consent does not expire on its own. It lasts until the subscriber withdraws it. That is why the unsubscribe mechanism matters so much: it is the only routine way consent ends.
Implied consent is narrower and time limited. It arises from an existing business relationship, such as a purchase or a contract within the previous two years, or from an inquiry within the previous six months. It also arises when a subscriber conspicuously publishes a business address and the message is relevant to that person's role or business.
The practical difference is what you can prove. Express consent is documented at the point of collection. Implied consent is inferred from a transaction record elsewhere in your systems, which is a much weaker position in a complaint.
A subscriber record should hold the email address, the date and time of consent, the source of consent, the exact wording the subscriber agreed to, and the IP address or form identifier where the consent was captured. Add the consent type, the expiry date for implied consent, and the date of any withdrawal.
Store the wording, not just a version number. If you change your sign-up language in March, you need to know which subscribers saw the February version. That single habit resolves most disputes before they reach the CRTC.
Keep the record for as long as you rely on the consent, plus a reasonable period after. Three years after withdrawal is a common internal standard, though the legislation sets the outer limits rather than a fixed retention clock.
The privacy guidance for businesses from the Office of the Privacy Commissioner frames these duties and is worth reading alongside the CRTC material, particularly on limiting collection to what you need.
Building the identification block: sender name, mailing address and CASL wording
The identification block is the part of the template most often got wrong, because it is inherited from a US design and never revisited. Three elements are required in every commercial electronic message.
First, the sender's name. Use the legal entity or the registered trade name the recipient would recognize. A brand name is acceptable if it is the name the business actually operates under. A made-up campaign alias is not.
Second, a physical mailing address. A post office box alone is not enough. It has to be a mailing address where the business can receive mail, and it has to be current. If your office moved in the spring, the footer moved with it.
Third, at least one of a phone number, an email address or a web address where the recipient can reach you. A contact form behind a login does not count as a route to unsubscribe, though it can serve as the general contact method if the unsubscribe link is separate and working.
The wording itself can be plain. Something like: This message was sent by [Legal Name], [mailing address], [contact]. You are receiving it because you consented to receive email from us. You can withdraw consent at any time using the link below.
Do not bury it. A footer in 8pt grey on a dark background fails on accessibility grounds and looks evasive. Put the identification block in a readable size, in a contrasting colour, and keep it in the same place in every send.
One more habit worth building: the footer should name the sending domain, not just the brand. Recipients who report spam to their provider are often reacting to a name they do not recognize, and a clear domain line reduces that.
Designing the unsubscribe mechanism so it works within ten business days
The unsubscribe mechanism must be conspicuous, easy to use, and functional. The CRTC expects it to be available in the message itself, not behind a login or a support ticket. A single click that opens a page with a confirm button is generally acceptable. A link that asks the subscriber to email an address and wait is not.
Timing is the part that catches teams out. Once a request is received, it must be honoured within ten business days, without any further action from the subscriber and without any fee.
Ten business days is not ten calendar days, and it is not a target. Build the process so the removal happens the same day and the ten day window is pure headroom.
If you run a preference centre, the unsubscribe path must still be a single action. Offering frequency options is fine. Requiring the subscriber to choose a frequency before the unsubscribe takes effect is not.
The mechanism has to remain available for at least 60 days after the message is sent. If your unsubscribe link resolves to a page that is only generated for the current campaign, older messages will break. Use a persistent link tied to the subscriber record.
Suppression is the other half. A subscriber who unsubscribes from one list should not reappear in another unless they opted in there separately. Keep a global suppression table and check it at send time, not at import time.
Finally, make sure the unsubscribe action is logged with a timestamp. You will need that timestamp if a complaint arrives, and it is the proof that the ten day rule was met.
Consent language for sign-up forms, checkouts and gated downloads
Different collection points need different wording. A newsletter sign-up is the easy case. A checkout is the case where most Canadian lists quietly go wrong.
At sign-up, keep the consent box unchecked, describe what the subscriber will receive, and name the sender. Something like: I agree to receive marketing emails from [Legal Name] about [topic]. I can unsubscribe at any time. That is express consent, and the form should record the wording shown.
At checkout, do not treat the transaction as blanket marketing consent. A purchase creates an implied consent for messages about that transaction and related products, and it lasts two years. If you want to send unrelated promotions, ask separately with its own unchecked box.
Gated downloads follow the same logic. The download itself is the transaction. Consent to receive the download is not consent to receive a nurture sequence. Add a separate, unchecked opt-in for the sequence and record which box was ticked.
Contests and event registrations are the highest risk. Contest rules often imply consent, but the implied consent is limited to messages about the contest. Anything beyond that needs its own express opt-in, and the rules should say so without legal jargon.
If your forms are inconsistent across regions, a canadian marketing budget template is a useful way to audit each collection point before you rewrite the wording. Work through it once per form, not once per campaign.
One test for any consent sentence: could a reasonable subscriber read it and know exactly what they are agreeing to receive, from whom, and how to stop it? If not, rewrite it.
Record keeping: what to log, how long to keep it, and who owns the list
CASL record keeping is not a separate system. It is the audit trail behind every consent decision your organization makes. If the CRTC asks how a subscriber ended up on your list, the answer has to be a record, not a recollection.
At minimum, log the email address, the consent type, the date and time, the source, and the exact wording. Add the withdrawal date where one exists, plus the campaign or form identifier and the IP address captured at sign-up. If consent came from a partner or a co-registration, log the partner name and the specific list.
Retention should outlast reliance. Keep the record while you are sending, and keep it for a defined period after withdrawal. Three years is a workable internal standard. Document that standard so a new team member applies the same clock.
The harder question is ownership. The list belongs to the organization that collected the consent, not to the agency that ran the campaign and not to the platform that stores it. If you use an agency, the contract should say the consent records transfer to you on request and on termination.
Platform exports matter here. Many email platforms store consent metadata in a way that is awkward to extract. Test the export before you need it. A record you cannot produce in a readable format is not a record.
Access requests are the other pressure. Subscribers can ask what you hold about them, and the information for individuals published by the Office of the Privacy Commissioner explains the rights they can exercise. Your consent log should answer a request without a manual reconstruction.
Testing a CASL compliant email template before it goes live
Test the template as a system, not as a design. The visual check is the easy part. The compliance check is where the work sits.
- Send a live test to an address you control and confirm the identification block renders with the legal name, mailing address and contact route visible without scrolling to a tiny footer.
- Click the unsubscribe link from a desktop client, a mobile client and a webmail client, and confirm all three land on a working page.
- Submit an unsubscribe request and time how long the removal takes to propagate to every list the address appears on.
- Check the suppression table to confirm the address is blocked at send time, not just removed from one list.
- Open the consent record for the test address and confirm the wording, source and timestamp were captured.
Run these before every template change, not just before launch. A footer edit can break a link, and a link edit can break a record.
Then check the rendering. Canadian subscribers open mail in Outlook on Windows, Apple Mail on iPhone, Gmail in a browser, and a long tail of older clients. A template that survives email marketing templates is the one worth shipping, because a broken unsubscribe link is a compliance failure, not a design annoyance.
Keep a pre-send checklist on the template itself, so the checks travel with the file rather than living in someone's head.
- Legal name and mailing address present and current
- At least one contact route listed (phone, email or web)
- Unsubscribe link present, working and persistent
- Unsubscribe page reachable without login
- Global suppression checked at send time
- Consent wording and source logged for the segment
- Implied consent expiry dates reviewed for the segment
- French-language version available where required
That last item is not optional in Quebec. Which brings us to the provincial layer.
Provincial overlays: Quebec Law 25 and PIPEDA in the same template
CASL is federal, but it is not the only rule that touches your list. PIPEDA, the Personal Information Protection and Electronic Documents Act, governs how private-sector organizations handle personal information across Canada. It sets consent, collection, use, disclosure and access duties that run alongside the anti-spam rules.
The Office of the Privacy Commissioner of Canada publishes an overview of privacy laws in Canada that maps PIPEDA against the provincial regimes. Quebec, British Columbia and Alberta have their own private-sector statutes.
Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health-information laws. If your list crosses provincial lines, you are likely subject to more than one regime.
Quebec's Law 25 is the overlay most likely to change your template. It amends Quebec's private-sector privacy law and adds obligations on consent, transparency and privacy governance for organizations doing business in Quebec. Consent must be clear, free and informed, and it must be requested separately from other information.
That last point matters: a bundled consent line at checkout is a weak position under Law 25 even when it is defensible under CASL.
Law 25 also strengthens the requirement to be transparent about what you do with personal information, and it gives individuals stronger rights over their data. For email teams, that means the privacy notice linked in your footer should describe the mailing list, not just the website.
Language adds another layer. Quebec's Charter of the French Language, as amended by Bill 96, requires French-language commercial communications in most cases. The Office québécois de la langue française enforces that.
In practice, a Quebec-facing send needs a French version of the identification block and the unsubscribe path at minimum, and the consent wording itself should be available in French.
For a national list, the practical approach is one template with three layers: CASL identification and unsubscribe at the base, PIPEDA-grade consent language in the sign-up and privacy notice, and a Law 25 compliant French variant for Quebec subscribers. That is more work than a single English footer, but it is less work than rebuilding after a complaint.
If you are choosing a starting point, compare how a marketing budget template excel handles footer structure and multilingual variants. Most are built for American senders and will need the identification block replaced.
A final note on scope. CASL applies to messages sent from Canada and to messages received in Canada, so a US-based platform sending to Canadian subscribers is within reach of the CRTC. The sending tool does not change the obligation. Whoever sends the message carries it.
Common questions
Who enforces CASL in Canada? The Canadian Radio-television and Telecommunications Commission is the primary enforcement body, with support from the Office of the Privacy Commissioner and the Competition Bureau for the privacy and advertising parts of the legislation.
How long does implied consent last? Two years from the last purchase or contract, or six months from an inquiry. Express consent does not expire until the subscriber withdraws it.
How fast must an unsubscribe request be honoured? Within ten business days, with no fee and no further action required from the subscriber. Build for same-day removal so the window is headroom rather than a deadline.
Does a CASL compliant email template need a physical address? Yes. A mailing address where the business can receive mail is required, along with the sender's name and at least one contact route such as a phone number, email address or web address.
Do Quebec subscribers need different consent wording? Quebec's Law 25 requires clear, separate consent and stronger transparency, and Bill 96 requires French-language commercial communications in most cases. A French variant of the consent and identification wording is the safe approach.
How long should consent records be kept? For as long as you rely on the consent, plus a defined period after withdrawal. Three years after withdrawal is a common internal standard, and the retention rule should be written down.
