Anonymised, illustrative composite. A Calgary associate bought a 3,000-name “homeowner leads” file from a data broker and ran a five-email drip campaign through it, on the theory that paying for a list is the same thing as having consent to email it. Under CASL, it is not — and the gap between the two is exactly where the complaint came from.
At a glance
The associate had just taken on a second listing area and wanted a running start on buyer inquiries before the spring market opened. A data broker offered a 3,000-record file of “homeowners actively researching a move,” priced per thousand records, with a landing page describing the names as “100% opt-in, permission-based.” The associate imported the file into a CRM, built a five-email drip — market update, home-value teaser, listing showcase, testimonial, booking link — and scheduled it to go out over three weeks.
No one on the list had ever contacted the associate's brokerage, requested a valuation, or handed over a business card at an event. The entire relationship, on the associate's side, was the invoice for the list.
CASL's core prohibition is blunt: it is “prohibited to send or cause or permit to be sent to an electronic address a commercial electronic message unless… the person to whom the message is sent has consented to receiving it, whether the consent is express or implied” — Section 6(1). The obligation sits with the sender, and it attaches to the specific recipient's consent, not to a data file's provenance.
A vendor's “opt-in” label describes, at best, consent to be added to that vendor's own list — it says nothing about whether the recipient agreed to hear from every downstream buyer of that list. CASL does not recognize a transferable, list-wide consent; consent runs to a sender, and this associate had never been named to any of the 3,000 people on it.
Implied consent under Section 10 would have covered a past client (a purchase or lease within the prior two years) or a recent inquiry (within six months) — the two Existing Business Relationship windows the Act actually recognizes. None of the 3,000 names fit either window with this associate, because none of them had ever dealt with this associate at all.
The campaign ran three of its five scheduled sends before the complaint arrived: 340 messages delivered across the first email and the start of the second. The list itself cost a flat per-thousand fee, budgeted as a normal marketing line item alongside signage and open-house printing.
One recipient forwarded the third message to the CRTC's spam-reporting channel rather than unsubscribing. Under Section 11, an unsubscribe mechanism has to work — at no cost, honoured without delay and no later than 10 business days — but this recipient never used it, going straight to a formal complaint instead.
The associate's defence, raised with the brokerage's compliance contact, was that the list had been paid for and marketed as compliant. That argument does not engage the actual test. CASL asks one question of every message: does this specific recipient's consent exist for this specific sender? A purchase receipt from a data broker answers a different question — whether the broker was paid — and is silent on the one that matters.
The narrow exemptions in the Act did not help here either. The business-card exemption requires the associate to actually hold the recipient's card and confine the message to their business role; nothing like that existed for a purchased file. The referral exemption covers one first message following a genuine referral where the referrer has a relationship with both sides — a data broker selling a bulk file is not a referrer in that sense, and the exemption in any case only ever covers a single message, not a five-part drip.
The brokerage's broker of record ordered the campaign stopped after the complaint, and the remaining 2,660 unsent records were deleted rather than requeued. The associate rebuilt the campaign against a genuinely consented list: past clients inside the two-year purchase window, recent inquiries inside the six-month window, and a small number of business-card contacts confined to business-relevant content, exactly as Section 10 and the CRTC's exemption guidance define them.
No penalty was assessed on this file — a single complaint typically triggers review, not enforcement action. But the exposure the associate had been carrying was real: CASL's administrative monetary penalties under Section 20(4) run up to $1,000,000 for an individual and $10,000,000 for a corporation per violation, a ceiling that applies per contravention, not per campaign.
For the two clocks that actually define implied consent under CASL, see the implied-consent glossary entry and how the unsubscribe mechanism itself has to work.
The tell was in the vendor's own language: “opt-in” described consent to the list, not consent to this associate. Any lead source that cannot name the specific business the recipient agreed to hear from is describing a marketing asset, not a compliance one. The fix is not a better-sounding list — it is building the pipeline from people who have actually dealt with this brokerage, and treating a bought file as, at most, a mail-merge target for physical mail, which CASL does not govern at all.
A short call is enough to see how AI-assisted follow-up works inside real consent, not around it.