CASL applies to commercial electronic messages — broadly, any electronic message that encourages participation in a commercial activity, whether or not there's an expectation of direct profit from that specific message. For a mortgage broker, this covers the obvious cases (a rate promotion, a newsletter promoting your services) and the less obvious ones too: a renewal reminder, a rate-hold follow-up, or a “thinking of you at tax time” email all count if they're reasonably read as encouraging the recipient to engage commercially with you, even when the tone is friendly rather than sales-y.
Before sending any of these, CASL generally requires three things to be in place: consent from the recipient, clear identification of who's sending the message and how to contact them, and a functioning mechanism for the recipient to unsubscribe. Missing any one of the three is a compliance gap, regardless of how good the other two look.
Express consent is the clean case: a recipient affirmatively opted in — checked a box, replied to a request, signed up through a form — before you sent them anything. It doesn't expire on its own the way implied consent does, though it can be withdrawn at any time. Implied consent, by contrast, arises from an existing relationship rather than an explicit opt-in, and it comes with a built-in expiry date that catches a lot of brokers off guard.
An existing business relationship — a client who's actually done a transaction with you — supports implied consent for two years from the date of that transaction. A weaker relationship, where someone made an inquiry but the transaction never happened, supports implied consent for only six months from the inquiry. Once either window closes, sending a commercial message on the strength of that old relationship is no longer covered — you need either fresh express consent or a new qualifying transaction to keep the relationship active for CASL purposes.
A detail that surprises a lot of brokers: the burden of proving consent existed, whether express or implied, sits entirely with the sender, not the recipient. If a client complains about an unwanted message and the broker can't produce a record showing when and how consent was obtained, or when the qualifying transaction occurred that supports an implied-consent claim, the broker is in a weak position regardless of whether consent genuinely existed at the time.
This makes record-keeping around consent a real, practical necessity rather than a formality — a CRM note capturing when a lead opted in, or the closing date of a past transaction that anchors an implied-consent window, is what actually protects a broker if a consent claim is ever challenged. Sending on the honest belief that consent exists, without a record to back it up, leaves the broker exposed even when they were right.
Every commercial electronic message needs to clearly identify who sent it and how the recipient can get in touch — a message that's hard to trace back to a specific, identifiable sender fails this requirement even if consent was otherwise in order. Alongside that, every message needs a working unsubscribe mechanism that's genuinely easy to use: no login requirement, no reply-to-confirm step, nothing that adds friction beyond what it took to receive the message in the first place. The unsubscribe link or address also has to stay functional for a meaningful period after the message is sent, not just at the moment it's delivered.
Once a recipient uses that mechanism — or otherwise clearly asks to stop — the sender has 10 business days to actually stop sending. There's no grace period beyond that window, and CRTC enforcement has repeatedly cited slow or broken unsubscribe processes as the basis for real penalties, not just a warning. A broker whose CRM keeps sending automated drip messages for two weeks after an unsubscribe request, because nobody manually updated the list in time, is exposed under this rule even if the delay was a technical oversight rather than an intentional choice.
CASL and PIPEDA cover adjacent but distinct territory, and it's worth being clear about the boundary. PIPEDA governs how a client's contact information was collected and what you're allowed to do with it generally; CASL governs the specific act of sending them a commercial electronic message once you have that information. A broker can be fully PIPEDA-compliant in how they collected a lead's email address and still violate CASL by emailing that lead without consent or without a working unsubscribe option — the two regimes ask different questions about the same piece of contact information.
In practice, a compliant marketing process satisfies both at once: information collected with meaningful consent under PIPEDA, and messages sent only within the boundaries — express consent, or implied consent still inside its window — that CASL requires, with clear identification and a working unsubscribe on every message.
A broker closed a mortgage for a client 30 months ago and never obtained express marketing consent. The broker wants to send that client a rate-update newsletter today. Is this covered by implied consent?
Implied consent from an actual transaction lasts two years, not indefinitely — at 30 months, that window has already closed, and sending on the strength of the old relationship without fresh consent is exactly the gap this module warns about. There's no mortgage-industry exemption from CASL's timing rules, and the two-year window specifically applies to completed transactions; it's the shorter six-month window that applies to inquiries that never became a transaction, not the other way around.
The intro and first module are free to read. Add your name and email once and the rest of this course opens — along with every other course on the site. No card, no trial.
Already unlocked on another device?