Treadstone Associates
Guide · 8 min read

Keeping CASL consent records straight in your CRM

Canada’s Anti-Spam Legislation does not care how good your campaign is. It cares whether the person consented, whether you identified yourself, and whether you made it easy to stop. Here is how to hold that record in your CRM so a send is never a guess.

Treadstone Associates · Updated 2026

Key takeaways

  • • CASL applies to commercial electronic messages sent to Canadian recipients, and is enforced by the CRTC.
  • • Consent is either express or implied, and implied consent expires — two years after an existing business relationship such as a purchase, six months after an enquiry.
  • • Every message needs sender identification, valid contact information, and an unsubscribe mechanism valid for at least 60 days and actioned no later than 10 business days.
  • • The practical fix is to store consent type, source and date as fields in the CRM, not as folklore.

What CASL actually requires

A commercial electronic message sent to a Canadian recipient needs three things: consent, clear identification of who is sending it and on whose behalf, and a working unsubscribe mechanism. The CRTC, which enforces CASL, states the contact information and the unsubscribe mechanism must remain valid for at least 60 days after the message is sent, and that an unsubscribe request must be actioned without delay and no later than 10 business days.

None of that is difficult. What trips businesses up is the consent half, because consent is not a single state and it does not last forever.

Express versus implied consent

Express consent is someone actively agreeing to receive your messages, and it does not expire until they withdraw it. Implied consent is narrower and it does expire. Under CASL, an existing business relationship — a purchase or contract, for example — gives implied consent for two years from that event, and an enquiry or application gives six months.

That means a list built from enquiries three years ago is not a list you can lawfully email on implied consent, however warm it feels. If you cannot say which category a contact falls into and when the clock started, you do not have a record; you have a hope.

Store consent as data, not as memory

The fix is unglamorous: consent type, the source that produced it, and the date it was given become fields on the contact record in HubSpot, Zoho, Mailchimp or whatever holds your list. Every form, import and point-of-sale integration writes those fields at the moment the contact is created.

Once consent is data, automation can act on it. Implied consent that is about to expire can be flagged for a re-permission approach while it is still valid. Contacts whose implied consent has lapsed can be excluded from a send automatically rather than by someone remembering.

Automating the boring half

Unsubscribes should be written back to every system that could send, not just the one the recipient clicked in. That is where multi-tool stacks fail: someone opts out of the Mailchimp newsletter and still receives the GoHighLevel sequence because the two lists never spoke.

A consent automation reconciles those systems on a schedule, applies suppressions everywhere, and keeps an audit trail of when consent was captured, from where, and when it was withdrawn. That trail is what you would need if a complaint ever arrives.

What automation must never do

Automation increases volume, and volume applied to a shaky consent record is how a marketing problem becomes a regulatory one. No automated system we build sends to a contact whose consent state does not permit it, and none of them are designed to obscure who is sending the message.

If you are unsure how CASL applies to a specific list or campaign, that is a question for your own legal advisor. What we can do is make sure the record your advisor would ask for actually exists and is current.

See where AI pays off first in your business.

A 30-minute call is enough to tell you whether AI pays for itself here.