Cold email under CASL: how implied consent actually works for B2B outreach
CASL is opt-in by default, but implied consent covers real B2B outreach. Here's the existing-business-relationship window, the conspicuous-publication test, and required message content.
By Gabriel Lara, Developer Relations, Norbelys
Founder-reviewed ·How we research and correct articles
Canada’s Anti-Spam Legislation — CASL, formally the Fighting Internet and Wireless Spam Act — has a reputation as the strictest commercial-email law in North America, and the reputation is earned. Unlike CAN-SPAM in the U.S., CASL is opt-in: you generally need consent before you send a commercial electronic message, not just an unsubscribe link after the fact.
That said, “opt-in” doesn’t mean “consent has to be a signed form.” CASL recognizes implied consent, and its two main categories cover a meaningful amount of real B2B outreach. Here’s how the mechanics actually work.
Consent comes first, and it’s opt-in
CASL prohibits sending a commercial electronic message (CEM) — broadly, any message that has the promotion of a product, service, or business as one of its purposes — without consent. Consent is either:
- Express consent — the recipient affirmatively agreed to receive messages from you, ideally with a record of when and how they agreed.
- Implied consent — consent the law recognizes exists because of an existing relationship or circumstance, without the recipient having explicitly opted in.
For cold B2B outreach, implied consent is the mechanism that matters, and CRTC guidance sets out two categories relevant here.
Implied consent, category one: the existing business relationship
If someone bought from you, entered into a contract with you, or made an inquiry, CASL treats that as grounds for implied consent to email them — but only within a defined window, and only while that relationship stays current. The categories the CRTC describes include purchases, contracts, and inquiries, each with its own applicable time window measured from the triggering event. Consent implied this way isn’t permanent: it lapses, and once it does you’re back to needing express consent or another valid basis.
This is the category most relevant to warm-ish B2B outreach — following up with someone who requested a demo, inquired about pricing, or had an active contract with you recently — but it does not, by itself, cover a purchased or scraped list of people who have never interacted with your business.
Implied consent, category two: conspicuous publication
The second implied-consent category is the one most relevant to genuinely cold B2B prospecting, and it has three conditions that all have to be true at once, per the CRTC’s guidance:
- The recipient has conspicuously published their electronic address — for example, listed publicly on a company website, a professional directory, or a similar public-facing source, not harvested from a private or scraped source.
- The publication isn’t accompanied by a statement that they don’t wish to receive unsolicited commercial messages at that address — if the page says “no unsolicited emails,” conspicuous publication doesn’t apply.
- The message is relevant to the recipient’s business, role, functions, or duties — a pitch to a person in a role plausibly connected to what you’re selling, not a mismatched blast to whoever’s address happened to be findable.
All three conditions matter, and the burden of proving they were met sits with the sender, not the recipient. A publicly listed sales-role email address, contacted about a sales tool, with no stated objection to unsolicited contact, is the textbook case this category was built for. A publicly listed HR contact, emailed about an unrelated engineering product, is not.
What every commercial electronic message must include — regardless of consent type
Consent gets you permission to send. It doesn’t excuse you from what ISED’s official CASL guidance requires be in the message itself. Every CEM — implied consent, express consent, doesn’t matter — has to include:
- Sender identification — who’s actually sending the message, including the name of the person or organization on whose behalf it’s sent, if different.
- Contact information — a way to reach the sender, valid for at least 60 days after the message is sent.
- A functional unsubscribe mechanism — one that works, is easy to find and use, and that the sender actually honors.
Missing any one of these three elements is a violation on its own, even if you had valid consent to send in the first place. This is the part of CASL most cold-email tools get right by default, because it overlaps heavily with basic deliverability hygiene — see built on U.S. anti-spam law for how the same category of requirement (identify yourself, give a working opt-out, honor it) shows up under CAN-SPAM south of the border, and DMARC monitoring for keeping the sending domain behind that identification honest.
The penalty structure, and why lawsuits aren’t the enforcement path
CASL’s civil enforcement runs through administrative monetary penalties (AMPs), issued by the CRTC. Per the CRTC’s own published FAQ, the maximum AMP is $1 million per violation for an individual and $10 million per violation for a business — figures that get repeated often precisely because they’re real, and they’re a meaningful multiple of CAN-SPAM’s per-email civil penalty in the U.S. These are statutory ceilings, not typical outcomes; the CRTC assesses actual penalties case by case.
One detail that surprises people who’ve heard CASL described as having “private lawsuits over spam”: it doesn’t, in practice. CASL originally included a private right of action that would have let individuals and businesses sue directly over violations, scheduled to take effect July 1, 2017. The federal government suspended that provision indefinitely just before it took effect, after concerns that it would be used to extract settlements over minor technical violations rather than genuine harm. Enforcement today runs through the CRTC, the Competition Bureau, and the Office of the Privacy Commissioner of Canada — not through a private lawsuit from whoever received your email.
What this looks like in practice
A CASL-aware B2B cold-email program generally means:
- Knowing which implied-consent category you’re relying on for each segment — existing relationship, conspicuous publication, or neither (meaning you need express consent instead) — rather than treating “we found the email publicly” as automatically sufficient.
- Tracking the relationship window so implied consent from an old inquiry or expired contract isn’t quietly relied on past its shelf life.
- Keeping the message relevant to the recipient’s actual role, since relevance is a load-bearing condition of the conspicuous-publication category, not just a copywriting nicety.
- Sender identification, contact info, and a working unsubscribe on every message, unconditionally.
Compared with GDPR’s legitimate-interest balancing test — a documented, case-by-case assessment — CASL’s implied-consent categories are more rule-based and mechanical, but the rules are also narrower. For a side-by-side view of how CASL, GDPR, and CAN-SPAM actually differ, see CAN-SPAM vs. GDPR vs. CASL compared. If you’re sending across the border too, the CAN-SPAM specifics live in built on U.S. anti-spam law.
Frequently asked questions
Is CASL opt-in or opt-out?
CASL is opt-in: you generally need express or implied consent before sending a commercial electronic message, unlike CAN-SPAM in the U.S., which is opt-out. Implied consent under an existing business relationship or conspicuous publication of an address can satisfy this without a formal opt-in step, but it is narrower and time-limited compared to express consent.
What counts as an existing business relationship under CASL?
The CRTC's guidance describes categories including a purchase, a contract, or an inquiry from the recipient, each carrying its own applicable time window during which implied consent based on that relationship remains valid. Once the relevant window lapses, that basis for implied consent no longer applies.
Can I cold email a publicly listed business email address under CASL?
Potentially, under the conspicuous-publication category of implied consent, but only if three conditions are all met: the address was conspicuously published (not scraped or purchased from a private source), the publication carries no statement declining unsolicited messages, and the message is relevant to the recipient's business role or duties.
What are the penalties for violating CASL?
The CRTC's published maximum administrative monetary penalty is $1 million per violation for an individual and $10 million per violation for a business. These are statutory ceilings, not typical fines — actual penalties are assessed case by case. CASL's private right of action, which would have allowed direct lawsuits, was suspended indefinitely by the federal government in 2017 before it took effect.