Canada's Anti-Spam Legislation (CASL)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CASL: Address Harvesting and Misleading Representations
CASL (s.82) amended PIPEDA (s.7.1) to prohibit collecting electronic addresses through address-harvesting software or dictionary attacks, and using addresses so collected, without consent.
- evidence marketing lists are not built via address-harvesting or dictionary attacks
- provenance of email address lists
- use of harvested or purchased lists of unknown provenance
- dictionary-attack address generation
CASL amended the Competition Act (s.74.011) to prohibit false or misleading sender information, subject-matter information, or locator (e.g. URL) in electronic messages.
- review that sender names, subject lines and URLs are accurate and not misleading
- controls against deceptive header/subject information
- misleading subject lines or sender names
- deceptive URLs/locators in messages
CASL: Altering Transmission Data (s.7)
s.7: it is prohibited to alter the transmission data in an electronic message, in the course of a commercial activity, so that the message is delivered to a destination other than or in addition to that specified by the sender, without consent.
- controls preventing unauthorised alteration of message routing/transmission data
- consent records where transmission data is altered
- routing altered without sender consent
- no control over transmission-data manipulation
CASL: Commercial Electronic Messages (s.6)
CASL (S.C. 2010, c.23) prohibits sending a commercial electronic message (CEM) to an electronic address without compliance. Determine which messages and activities (CEMs, transmission-data alteration, software installation) are in scope and whether the sender or a person on whose behalf the message is sent is subject to the Act.
- analysis of which electronic messages are commercial electronic messages (CEMs) within s.6
- identification of senders and persons on whose behalf messages are sent
- scope assessment covering CEMs, transmission-data alteration (s.7) and software installation (s.8)
- marketing messages not assessed as CEMs
- messages sent on behalf of the org by affiliates/agents not in scope
- assuming exemptions apply without analysis
s.6 covers the person on whose behalf a CEM is sent; s.9 prohibits aiding, inducing or procuring a contravention. Organisations are responsible for CEMs sent by service providers, affiliates or agents on their behalf.
- contracts with email service providers / agencies requiring CASL compliance
- oversight of third parties sending CEMs on the org behalf
- due-diligence over affiliates
- no CASL clauses in vendor contracts
- no oversight of third-party senders
s.6(2)(a): the CEM must set out prescribed information identifying the person who sent the message and the person, if different, on whose behalf it is sent.
- CEM templates showing sender (and on-behalf-of) identification
- accuracy of identifying information
- sender or on-behalf-of party not identified
- identification information inaccurate or generic
s.6(2)(b) and s.6(3): the CEM must enable the recipient to readily contact the sender, and the contact information must remain valid for at least 60 days after the message is sent.
- CEM templates with valid contact information (mailing address + one of phone/email/web)
- evidence contact channels remain monitored and valid for >=60 days
- contact information missing or stale
- contact channel decommissioned within 60 days
s.6(2)(c): the CEM must set out an unsubscribe mechanism in accordance with s.11(1).
- CEM templates showing a clearly set-out unsubscribe mechanism
- no unsubscribe mechanism
- unsubscribe not clearly/prominently presented
CASL: Consent (s.10)
Electronic Commerce Protection Regulations (SOR/2013-221): limited exceptions, e.g. a first CEM sent following a referral by an individual with an existing relationship, and personal/family relationships.
- documentation of any reliance on the referral exception (first message only, referrer disclosed)
- basis for personal/family-relationship exemption
- referral exception relied on for more than the first message
- exception claimed without the qualifying relationship
Electronic Commerce Protection Regulations: CEMs sent between organisations with an existing relationship, and other prescribed exclusions (e.g. messages solely providing quotes, completing a transaction, or warranty/safety information).
- analysis supporting any B2B exemption (existing relationship, message relevant to the recipient business)
- classification of transactional/relationship messages excluded from CEM rules
- B2B exemption claimed without an existing business relationship
- transactional-message exclusion over-applied to marketing
s.6(1)(a) and s.10: a CEM requires consent. Express consent must be obtained by clearly setting out the purpose(s), the identity of the person seeking consent (and any person on whose behalf), and how consent can be withdrawn; consent cannot be bundled or pre-checked.
- express opt-in consent records with date, method and the wording presented
- evidence the purpose and identity were disclosed at point of consent
- no pre-checked boxes / bundled consent
- consent assumed from inaction
- purpose or identity not disclosed at opt-in
- consent wording not retained
s.10(9): implied consent may exist through an existing business relationship or existing non-business relationship (within defined time limits), conspicuous publication, or disclosure of the address without a do-not-contact notice. Transitional implied consent provisions also apply.
- records substantiating the existing business/non-business relationship and its date
- tracking of the implied-consent expiry windows (e.g. 2 years from transaction, 6 months from inquiry)
- basis for conspicuous-publication implied consent
- implied consent relied on past its time limit
- no record of the qualifying relationship
- conspicuous-publication basis not relevant to the message topic
CASL: Enforcement and Compliance
Handling of complaints and reports (including via the Spam Reporting Centre) as part of the CRTC enforcement regime and a documented compliance program.
- process for receiving and actioning CASL complaints
- monitoring of the Spam Reporting Centre referrals
- remediation records
- no complaint-handling process
- complaints not tracked or remediated
s.33: a person is not to be found to have contravened ss.6-9 if they establish that they exercised due diligence to prevent the contravention - in practice, a documented compliance program.
- documented CASL compliance program (policies, procedures, training, monitoring, records)
- evidence the program is maintained and effective
- no documented compliance program
- program exists on paper but not operated
CRTC compliance guidance: a credible due-diligence defence includes staff training and awareness on CASL obligations.
- CASL training materials and completion records for relevant staff
- awareness of consent, unsubscribe and record-keeping obligations
- staff sending CEMs untrained on CASL
- no completion tracking
s.20: administrative monetary penalties (up to $1,000,000 for an individual and $10,000,000 for any other person) enforced by the CRTC; ss.13-46 cover investigations, notices of violation and undertakings.
- awareness of AMP exposure and CRTC enforcement powers
- process for responding to a notice of violation or undertaking
- no process for responding to CRTC enforcement
- officers/directors unaware of personal liability (s.31)
s.13 places the onus of proving consent on the person who alleges it. Maintain records of consent (express and implied) sufficient to discharge this burden.
- retained consent records (who, when, how, wording) for express consent
- records evidencing implied-consent relationships and dates
- retention aligned to limitation periods
- no system of record for consent
- records insufficient to prove consent if challenged
Records supporting the due-diligence defence (s.33) and demonstrating ongoing compliance: message logs, consent logs, unsubscribe handling, and complaint records.
- CEM sending logs and unsubscribe-handling logs
- documented compliance program records
- evidence retained to support a due-diligence defence
- no audit trail of CEM activity
- compliance program undocumented
CASL: Installation of Computer Programs (s.8)
s.8: it is prohibited to install or cause to be installed a computer program on another person device in the course of a commercial activity without express consent.
- express consent records before installing software on user devices
- disclosure of program purpose at install
- software installed without express consent
- consent not obtained before installation
s.10(3)-(5): for programs that perform specified functions (e.g. collecting personal information, changing settings, interfering with control), enhanced, separate disclosure of the function, purpose and impact is required before consent.
- enhanced disclosure documents for programs performing specified functions
- separate acknowledgement of material functions before install
- material functions buried in a general EULA
- no separate disclosure for specified functions
s.10(6)-(8): consent for updates and upgrades to a previously consented program, including conditions for relying on prior consent.
- consent basis for software updates/upgrades
- records of update consent or reliance on prior consent conditions
- updates pushed without a valid consent basis
CASL: Unsubscribe Mechanism (s.11)
s.11: the unsubscribe mechanism must be able to be readily performed at no cost, specify an electronic address or web link valid for 60 days, and the request must be given effect without delay and in any event within 10 business days.
- evidence unsubscribe is free and easy to use
- records that unsubscribe requests are actioned within 10 business days
- the unsubscribe address/link valid for at least 60 days
- unsubscribe requires login or fee
- requests not honoured within 10 business days
- unsubscribe link expires too soon
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.