Checklist of five CASL compliance records for Canadian email teams. 5 records Canadian email teams must log under CASL
Image: Productivity Software Reviews

Rules

5 records Canadian email teams must log under CASL

Business email and productivity software teams in Canada must log five CASL records: consent, unsubscribe, sender ID, unsubscribe mechanism and retention.

What to take away

  • For business email and productivity software teams in Canada, CASL record keeping comes down to five logs: consent, unsubscribe requests, sender identification, the unsubscribe mechanism you used, and retention.
  • Consent must be provable, not assumed. The CRTC reads the record, not your intentions, and the burden sits with the sender.
  • Unsubscribe requests need to be honoured within 10 days and the request itself has to be logged with a timestamp.
  • Retention settings in your email tool decide whether any of this survives an audit. Defaults are usually wrong for compliance.
  • Marketing platforms, CRMs and help desks each hold a piece of the record. If they do not reconcile, the gap is the finding.

What CASL counts as a commercial electronic message

CASL, the Canadian anti-spam law, covers any electronic message that encourages participation in a commercial activity. That is broader than most administrators expect. A newsletter, a product announcement, a webinar invitation, a request to connect on a professional network, and a transactional receipt with an upsell line all fall inside the definition.

The statute sits with the other consolidated federal acts published on the Justice Laws Website, so the version you cite should always be the current consolidation rather than a saved PDF from a past review. If you cannot find the right act quickly, the Justice Laws index lists federal statutes by title.

The CRTC enforces CASL. The Office of the Privacy Commissioner of Canada handles the personal information side, and the two overlap constantly: an email address is personal information under PIPEDA, and consent to use it for marketing has to satisfy both regimes.

Three message types matter for record keeping:

  • Commercial electronic messages, which need consent and a working unsubscribe mechanism.
  • Messages with a family, personal or charitable purpose, which sit outside the consent requirement.
  • Messages sent within an existing business relationship, which can rely on implied consent until the relationship lapses.

That third category is where most Canadian records go wrong. Implied consent from a purchase or an inquiry has a shelf life. Once it expires, the contact needs express consent or the next send is a violation.

The five records: consent, unsubscribe, sender ID, mechanism, retention

The CRTC does not publish a single prescribed form. It requires that you be able to demonstrate compliance, which in practice means five distinct records.

Five CASL records to keep

  • Consenttype, date, source, wording
  • Unsubscribetimestamp, address, channel, effective date
  • Sender IDname, mailing address, phone, email
  • Unsubscribe mechanismworking opt-out in every message
  • Retentionsettings that preserve all four records

1. The consent record

For every contact, you need the type of consent (express or implied), the date and time it was obtained, the source, and the wording the person agreed to. Express consent should be positive and unambiguous: a checkbox, a confirmed signup, a documented verbal agreement.

Implied consent needs its basis recorded. A purchase, a downloaded whitepaper, a trade show badge scan, or a published business address each carry different durations under the regulations. Store the basis, not just the flag.

This is where a consent log template earns its place. The template forces the fields you would otherwise skip.

2. The unsubscribe record

Every unsubscribe request needs a timestamp, the address it came from, the channel it arrived through, and the date the suppression took effect. The 10-day clock starts when the request is sent, not when someone on your team opens it.

Log requests that arrive by phone or in person too. A verbal unsubscribe recorded in a help desk ticket is still a record, and it still has to be honoured.

3. Sender identification

The message itself must identify the sender by name, include a physical mailing address, and provide a phone number, email address or web address. Keep a copy of the template that produces that footer, plus a dated note of when it changed.

If your footer is assembled dynamically by a marketing platform, capture a rendered example with the full headers. A screenshot of the template is weaker evidence than the actual message.

4. The unsubscribe mechanism record

You need to show that every commercial message carried a working unsubscribe mechanism, and that the mechanism stayed functional for at least 60 days after the message was sent. Record the link or reply address used, and the date it was retired.

A broken unsubscribe link is a standalone violation, separate from the consent question. If your marketing team rotates landing pages monthly, this record is the one that disappears first.

5. The retention record

This is the meta record: how long you keep the other four, and where. CASL does not set a fixed retention period in the statute. The practical frame comes from the CRTC's expectation that you can produce the record on request, and from the privacy principle that you keep personal information only as long as necessary.

The table below sets out what each record contains and the retention behaviour that fits.

The retention record

RecordCore fieldsRetention behaviour
ConsentType, date, source, wordingKeep for the life of the relationship plus your limitation period
UnsubscribeTimestamp, channel, effective dateKeep indefinitely as suppression evidence
Sender identificationFooter template, rendered example, change logKeep for each version in use
Unsubscribe mechanismLink or address, active datesKeep for 60 days past the send, longer if disputed
Retention policySchedule, owners, storage locationsReview annually

How CRTC enforcement decisions read the consent record

The pattern across enforcement outcomes is consistent: the record decides the case. Where a sender can produce a dated consent with the wording the recipient saw, the matter usually ends early. Where the sender can only say the address was on a list, the outcome is worse.

Canadian regulators publish their actions and decisions, and the privacy side offers a useful parallel for how consent and safeguards are assessed. The OPC actions and decisions collection shows how findings turn on documentation rather than on intent, which is the same logic CRTC decisions follow.

Three habits show up repeatedly in cases that go badly.

  • Consent is asserted but the signup wording cannot be produced.
  • Unsubscribe requests were honoured in practice but never logged, so the timeline cannot be shown.
  • Implied consent was relied on long after the relationship ended.

Penalties under CASL are not trivial, and they attach to officers and directors as well as to the corporation. That is the argument for treating the consent record as a governance document rather than a marketing spreadsheet.

If your email account is the key to almost every other account you hold, the compliance record built on top of it deserves the same protection as the account itself. Access control on the consent log matters as much as the log's contents.

Retention settings to enable in business email and productivity software

Default retention is built for storage cost, not for compliance. Most platforms delete or archive aggressively, and the deleted record is the one the CRTC asks for.

Start by deciding where the record lives. There are three realistic options: inside the email platform, inside a CRM or marketing tool, and in a separate compliance store. Choose one as the system of record and treat the others as copies.

Then work through the settings that matter:

Retention settings to enable

  1. Turn on litigation hold for compliance mailbox
  2. Set retention period to match policy
  3. Enable audit logging for access and exports
  4. Turn on export and takeout
  5. Disable auto-purge on unsubscribe folders

A business email comparison done on retention terms alone will eliminate several providers. Ask each vendor three questions: what the default retention period is, whether holds override deletion, and how records are exported.

Where the platform is admin-heavy, the settings sit behind roles. Make sure at least two people hold the compliance role, so a departure does not lock you out of your own record.

Business email security controls and retention controls should be configured together, because a compromised admin account can delete a consent log as easily as it can view it.

Cost matters here too. Long retention and audit logging are usually higher tiers, and business email pricing pages rarely spell out which tier includes hold. Confirm it in writing before you commit.

Where consent records live when marketing sits outside the inbox

In most Canadian organizations, the inbox is not where marketing happens. The consent record is split across a CRM, a marketing automation platform, an ecommerce system, a ticketing tool and, increasingly, a consent management platform.

The regulatory context for that sprawl is set out in the federal business guidance published on Business and industry - Canada.ca, which is the sensible starting point when you need to explain obligations to a non-specialist executive.

Practical reconciliation looks like this:

Consent record reconciliation

  • Name an owner for every email-sending system
  • Keep one authoritative consent log
  • Sync suppression lists one direction outward
  • Route outside unsubscribes within 10 days
  • Calculate implied consent expiry dates
  • Map CRM and platform consent fields
  • Sign a quarterly reconciliation note

The privacy side of this is not optional. Business guidance from the Office of the Privacy Commissioner of Canada covers consent and safeguards in terms that map closely onto CASL consent records, so a single well-built log can serve both.

Quebec adds a layer. Law 25, administered by the Commission d'accès à l'information, imposes its own consent and transparency requirements on organizations handling Quebec residents' data. If you market into Quebec, the consent wording and the record need to satisfy both regimes.

Provincial privacy commissioners in Ontario, British Columbia and Alberta oversee their own statutes for provincially regulated organizations. A national sender can end up answering to several regulators for one email programme, which is another argument for one clean log rather than five partial ones.

A records audit you can run in one afternoon

You do not need a project to find the gaps. Pick one send from each of the last four quarters and trace it end to end.

One-afternoon records audit

  1. Pick one send from each of last four quarters
  2. Pull ten random recipient addresses
  3. Find consent type, date and source for each
  4. Check unsubscribe history including phone and reply
  5. Retrieve sent message with headers and footer
  6. Confirm retention setting and no auto-purge
  7. Write down missing items as remediation list

Write down what you could not find. The missing items are your remediation list, and they are usually concentrated in one or two systems rather than spread evenly.

Repeat the exercise with a message sent from a sales tool rather than the marketing platform. Sales mail is where sender identification and unsubscribe mechanism records most often go missing, because the footer is generated by a template nobody owns.

Run the audit quarterly and keep the signed notes. A dated series of audit notes is itself evidence of a compliance programme, and it is far more persuasive than a reconstructed spreadsheet produced after a complaint.

Common questions

How long must CASL consent records be kept?
CASL does not set a fixed period. Keep consent for the life of the relationship plus your limitation period, and keep unsubscribe records indefinitely as suppression evidence.
Does an unsubscribe request by phone count?
Yes. Any unsubscribe request sent by the recipient triggers the 10-day clock, regardless of the channel it arrived through. Log it with a timestamp.
What happens if the unsubscribe link breaks after the send?
The mechanism must remain functional for at least 60 days. A broken link is a separate violation from any consent problem, so keep dated records of when links were active.
Do implied consent records need the same detail as express consent?
They need the basis and the date, because implied consent expires. Record whether it came from a purchase, an inquiry or a published address, and calculate the expiry.
Can a marketing platform be the system of record?
It can, provided retention settings, holds and exports are configured for compliance rather than storage savings. Confirm the vendor's default retention in writing.
How does Quebec's Law 25 affect a CASL consent log?
It adds consent and transparency requirements for Quebec residents. A log built to CASL standards usually needs extra fields to cover both regimes.

More in Rules

Latest from Reporting Desk