Can I Email Marketing to Customers Without Consent Under CASL?

The short answer Federally, under Canada's Anti-Spam Legislation (CASL), you generally cannot send marketing emails to customers without their consent, either express or implied. Even with consent, messages must identify the sender, provide contact information, and include a working unsubscribe mechanism. Narrow exemptions exist, such as messages to secure limited-access accounts or fundraising messages from registered charities.

Verdict

Usually no. Federally, under Canada’s Anti-Spam Legislation (CASL, SC 2010, c 23), sending a marketing email (a “commercial electronic message”) to a customer is prohibited unless that customer has consented, whether expressly or by implication. This is a purely federal rule: it applies the same way whether the business is in Ontario, Alberta, or anywhere else in Canada, so there is no separate provincial layer to check.

Section 6(1)(a) of CASL sets the baseline rule: it is prohibited to send, or cause to be sent, a commercial electronic message to an electronic address unless the recipient has consented, “whether the consent is express or implied.” Marketing emails fall squarely within this rule. Absent one of the two forms of consent, or a specific regulatory exemption, sending the message is a breach of the Act.

The statute does not treat all consent as interchangeable for every purpose. A separate, stricter rule applies to installing software: under section 8(1), installing a computer program (for example, a tracking script or app component) on someone else’s device in the course of a commercial activity requires the express consent of the device’s owner or authorized user. Implied consent is not enough for that specific act, even where it might be enough to justify the email itself.

Having consent does not end the compliance obligation. Section 6(2) requires that a compliant commercial electronic message:

  1. Identify the person who sent it (and the person on whose behalf it was sent, if different)
  2. Provide information letting the recipient readily contact the sender
  3. Include a working unsubscribe mechanism

These content requirements apply on top of the consent requirement, not instead of it. A business that has valid consent but omits sender identification, contact details, or an unsubscribe option is still non-compliant.

Liability beyond the sender

CASL’s reach extends past whoever presses send. Section 9 makes it prohibited to aid, induce, procure, or cause another person to do anything contrary to the consent, installation, or content rules in sections 6 to 8. A business that directs a marketing agency, contractor, or affiliate to send non-compliant messages on its behalf can be exposed under this provision, not just the party that transmitted the message.

Limited exemptions

The Electronic Commerce Protection Regulations (SOR/2013-221) carve out narrow situations where the consent requirement in section 6 does not apply:

ExemptionWhat it covers
Secure, limited-access accountsMessages sent to an account that is limited-access and confidential, where only the account provider can send messages to it
Registered charity fundraisingMessages sent by or on behalf of a registered charity, as defined under subsection 248(1) of the Income Tax Act, for the purpose of raising funds

These exemptions are narrow and fact-specific. A business that assumes it qualifies without checking the regulation’s precise wording risks relying on an exemption that does not actually cover its messages.

Why this matters day to day

For a small business sending marketing emails, the practical consequence is that a customer list built without tracking how consent was obtained is a compliance risk, regardless of how the list was assembled or how long the business has operated. The Act’s prohibition in section 6(1)(a) is the default; consent (in one of its two recognized forms) or a specific regulatory exemption is what removes a given message from that default. Because the statute treats the message content requirements (sender ID, contact information, unsubscribe mechanism) as independent of the consent question, a business needs to satisfy both, not just one.

Frequently asked questions

Does CASL apply across all of Canada, or just Ontario and Alberta?

CASL is federal legislation, so it applies the same way in every province, including Ontario and Alberta. There is no separate provincial email-marketing consent regime layered on top of it.

What counts as consent under CASL?

The Act allows either express consent (the recipient affirmatively agreed) or implied consent, without further qualification in the statute's general prohibition. Because the specific categories of implied consent involve detailed conditions, a business relying on implied consent should confirm its situation fits the Act's definitions before sending.

Do I need special consent to install tracking software, like a marketing pixel, on a customer's device?

Yes, federally. Installing a computer program on someone else's device in the course of a commercial activity requires the express consent of the device owner or authorized user, a stricter standard than the express-or-implied rule for the message itself.

Can I get in trouble for a marketing email sent by a contractor or agency on my behalf?

Federally, yes. CASL prohibits aiding, inducing, or causing another person to send a message that violates the consent, sender-identification, or unsubscribe rules, so liability is not limited to whoever hits send.

Sources

  1. Canada's Anti-Spam Legislation (CASL) , SC 2010, c 23, ss 6(1)(a), 6(2), 8(1), 9 (retrieved July 17, 2026)
  2. Electronic Commerce Protection Regulations , SOR/2013-221, s 3 (retrieved July 17, 2026)