Skip to content

Evidence request lists

Canada's Anti-Spam Legislation (CASL)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CASL: Address Harvesting and Misleading Representations

CASL-17
Address Harvesting Prohibition

CASL (s.82) amended PIPEDA (s.7.1) to prohibit collecting electronic addresses through address-harvesting software or dictionary attacks, and using addresses so collected, without consent.

Artefacts an auditor will ask for
  • evidence marketing lists are not built via address-harvesting or dictionary attacks
  • provenance of email address lists
Where this commonly fails
  • use of harvested or purchased lists of unknown provenance
  • dictionary-attack address generation
CASL-18
False or Misleading Representations

CASL amended the Competition Act (s.74.011) to prohibit false or misleading sender information, subject-matter information, or locator (e.g. URL) in electronic messages.

Artefacts an auditor will ask for
  • review that sender names, subject lines and URLs are accurate and not misleading
  • controls against deceptive header/subject information
Where this commonly fails
  • misleading subject lines or sender names
  • deceptive URLs/locators in messages

CASL: Altering Transmission Data (s.7)

CASL-13
Alteration of Transmission Data

s.7: it is prohibited to alter the transmission data in an electronic message, in the course of a commercial activity, so that the message is delivered to a destination other than or in addition to that specified by the sender, without consent.

Artefacts an auditor will ask for
  • controls preventing unauthorised alteration of message routing/transmission data
  • consent records where transmission data is altered
Where this commonly fails
  • routing altered without sender consent
  • no control over transmission-data manipulation

CASL: Commercial Electronic Messages (s.6)

CASL-1
Scope and Applicability

CASL (S.C. 2010, c.23) prohibits sending a commercial electronic message (CEM) to an electronic address without compliance. Determine which messages and activities (CEMs, transmission-data alteration, software installation) are in scope and whether the sender or a person on whose behalf the message is sent is subject to the Act.

Artefacts an auditor will ask for
  • analysis of which electronic messages are commercial electronic messages (CEMs) within s.6
  • identification of senders and persons on whose behalf messages are sent
  • scope assessment covering CEMs, transmission-data alteration (s.7) and software installation (s.8)
Where this commonly fails
  • marketing messages not assessed as CEMs
  • messages sent on behalf of the org by affiliates/agents not in scope
  • assuming exemptions apply without analysis
CASL-10
Messages Sent on Behalf of Others / Third-Party Senders

s.6 covers the person on whose behalf a CEM is sent; s.9 prohibits aiding, inducing or procuring a contravention. Organisations are responsible for CEMs sent by service providers, affiliates or agents on their behalf.

Artefacts an auditor will ask for
  • contracts with email service providers / agencies requiring CASL compliance
  • oversight of third parties sending CEMs on the org behalf
  • due-diligence over affiliates
Where this commonly fails
  • no CASL clauses in vendor contracts
  • no oversight of third-party senders
CASL-4
Identification of Sender

s.6(2)(a): the CEM must set out prescribed information identifying the person who sent the message and the person, if different, on whose behalf it is sent.

Artefacts an auditor will ask for
  • CEM templates showing sender (and on-behalf-of) identification
  • accuracy of identifying information
Where this commonly fails
  • sender or on-behalf-of party not identified
  • identification information inaccurate or generic
CASL-5
Contact Information

s.6(2)(b) and s.6(3): the CEM must enable the recipient to readily contact the sender, and the contact information must remain valid for at least 60 days after the message is sent.

Artefacts an auditor will ask for
  • CEM templates with valid contact information (mailing address + one of phone/email/web)
  • evidence contact channels remain monitored and valid for >=60 days
Where this commonly fails
  • contact information missing or stale
  • contact channel decommissioned within 60 days
CASL-6
Unsubscribe Mechanism

s.6(2)(c): the CEM must set out an unsubscribe mechanism in accordance with s.11(1).

Artefacts an auditor will ask for
  • CEM templates showing a clearly set-out unsubscribe mechanism
Where this commonly fails
  • no unsubscribe mechanism
  • unsubscribe not clearly/prominently presented

CASL: Consent (s.10)

CASL-11
Referral and Relationship Exceptions

Electronic Commerce Protection Regulations (SOR/2013-221): limited exceptions, e.g. a first CEM sent following a referral by an individual with an existing relationship, and personal/family relationships.

Artefacts an auditor will ask for
  • documentation of any reliance on the referral exception (first message only, referrer disclosed)
  • basis for personal/family-relationship exemption
Where this commonly fails
  • referral exception relied on for more than the first message
  • exception claimed without the qualifying relationship
CASL-12
Business-to-Business and Other Regulatory Exceptions

Electronic Commerce Protection Regulations: CEMs sent between organisations with an existing relationship, and other prescribed exclusions (e.g. messages solely providing quotes, completing a transaction, or warranty/safety information).

Artefacts an auditor will ask for
  • analysis supporting any B2B exemption (existing relationship, message relevant to the recipient business)
  • classification of transactional/relationship messages excluded from CEM rules
Where this commonly fails
  • B2B exemption claimed without an existing business relationship
  • transactional-message exclusion over-applied to marketing
CASL-2
Express Consent

s.6(1)(a) and s.10: a CEM requires consent. Express consent must be obtained by clearly setting out the purpose(s), the identity of the person seeking consent (and any person on whose behalf), and how consent can be withdrawn; consent cannot be bundled or pre-checked.

Artefacts an auditor will ask for
  • express opt-in consent records with date, method and the wording presented
  • evidence the purpose and identity were disclosed at point of consent
  • no pre-checked boxes / bundled consent
Where this commonly fails
  • consent assumed from inaction
  • purpose or identity not disclosed at opt-in
  • consent wording not retained
CASL-3
Implied Consent

s.10(9): implied consent may exist through an existing business relationship or existing non-business relationship (within defined time limits), conspicuous publication, or disclosure of the address without a do-not-contact notice. Transitional implied consent provisions also apply.

Artefacts an auditor will ask for
  • records substantiating the existing business/non-business relationship and its date
  • tracking of the implied-consent expiry windows (e.g. 2 years from transaction, 6 months from inquiry)
  • basis for conspicuous-publication implied consent
Where this commonly fails
  • implied consent relied on past its time limit
  • no record of the qualifying relationship
  • conspicuous-publication basis not relevant to the message topic

CASL: Enforcement and Compliance

CASL-19
Complaint Handling

Handling of complaints and reports (including via the Spam Reporting Centre) as part of the CRTC enforcement regime and a documented compliance program.

Artefacts an auditor will ask for
  • process for receiving and actioning CASL complaints
  • monitoring of the Spam Reporting Centre referrals
  • remediation records
Where this commonly fails
  • no complaint-handling process
  • complaints not tracked or remediated
CASL-20
Due Diligence Defence

s.33: a person is not to be found to have contravened ss.6-9 if they establish that they exercised due diligence to prevent the contravention - in practice, a documented compliance program.

Artefacts an auditor will ask for
  • documented CASL compliance program (policies, procedures, training, monitoring, records)
  • evidence the program is maintained and effective
Where this commonly fails
  • no documented compliance program
  • program exists on paper but not operated
CASL-21
Training and Awareness

CRTC compliance guidance: a credible due-diligence defence includes staff training and awareness on CASL obligations.

Artefacts an auditor will ask for
  • CASL training materials and completion records for relevant staff
  • awareness of consent, unsubscribe and record-keeping obligations
Where this commonly fails
  • staff sending CEMs untrained on CASL
  • no completion tracking
CASL-22
Penalties and Enforcement

s.20: administrative monetary penalties (up to $1,000,000 for an individual and $10,000,000 for any other person) enforced by the CRTC; ss.13-46 cover investigations, notices of violation and undertakings.

Artefacts an auditor will ask for
  • awareness of AMP exposure and CRTC enforcement powers
  • process for responding to a notice of violation or undertaking
Where this commonly fails
  • no process for responding to CRTC enforcement
  • officers/directors unaware of personal liability (s.31)
CASL-8
Record Keeping of Consent

s.13 places the onus of proving consent on the person who alleges it. Maintain records of consent (express and implied) sufficient to discharge this burden.

Artefacts an auditor will ask for
  • retained consent records (who, when, how, wording) for express consent
  • records evidencing implied-consent relationships and dates
  • retention aligned to limitation periods
Where this commonly fails
  • no system of record for consent
  • records insufficient to prove consent if challenged
CASL-9
Transaction and Compliance Records

Records supporting the due-diligence defence (s.33) and demonstrating ongoing compliance: message logs, consent logs, unsubscribe handling, and complaint records.

Artefacts an auditor will ask for
  • CEM sending logs and unsubscribe-handling logs
  • documented compliance program records
  • evidence retained to support a due-diligence defence
Where this commonly fails
  • no audit trail of CEM activity
  • compliance program undocumented

CASL: Installation of Computer Programs (s.8)

CASL-14
Installation of Computer Programs - Consent

s.8: it is prohibited to install or cause to be installed a computer program on another person device in the course of a commercial activity without express consent.

Artefacts an auditor will ask for
  • express consent records before installing software on user devices
  • disclosure of program purpose at install
Where this commonly fails
  • software installed without express consent
  • consent not obtained before installation
CASL-15
Disclosure of Material Software Functions

s.10(3)-(5): for programs that perform specified functions (e.g. collecting personal information, changing settings, interfering with control), enhanced, separate disclosure of the function, purpose and impact is required before consent.

Artefacts an auditor will ask for
  • enhanced disclosure documents for programs performing specified functions
  • separate acknowledgement of material functions before install
Where this commonly fails
  • material functions buried in a general EULA
  • no separate disclosure for specified functions
CASL-16
Updates and Upgrades

s.10(6)-(8): consent for updates and upgrades to a previously consented program, including conditions for relying on prior consent.

Artefacts an auditor will ask for
  • consent basis for software updates/upgrades
  • records of update consent or reliance on prior consent conditions
Where this commonly fails
  • updates pushed without a valid consent basis

CASL: Unsubscribe Mechanism (s.11)

CASL-7
Form and Function of Unsubscribe

s.11: the unsubscribe mechanism must be able to be readily performed at no cost, specify an electronic address or web link valid for 60 days, and the request must be given effect without delay and in any event within 10 business days.

Artefacts an auditor will ask for
  • evidence unsubscribe is free and easy to use
  • records that unsubscribe requests are actioned within 10 business days
  • the unsubscribe address/link valid for at least 60 days
Where this commonly fails
  • unsubscribe requires login or fee
  • requests not honoured within 10 business days
  • unsubscribe link expires too soon
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.