A contact database does not go bad all at once — it ages out quietly, one expired implied-consent window at a time, until a list that felt safe two years ago is mostly unsendable. This is the audit method: date-stamp everything, apply the actual clocks, and act on what the dates tell you.
Key takeaways
STEP 01 OF 10
Before applying any rule, get the raw data right: export every contact with the date of their last transaction, last inquiry, or last express opt-in — whichever applies. This date is what every subsequent step in this audit runs against, so a contact with no reliable date attached cannot be properly segmented and should be flagged as its own category rather than defaulted into either bucket.
If your CRM does not track this date cleanly today, fixing that tracking gap is itself the first real output of this project — every future audit depends on it being accurate going forward.
STEP 02 OF 10
Under CASL s.10(10), implied consent arises from “the purchase or lease of a product, goods, a service, land or an interest or right in land, within the two-year period immediately before the day on which the message was sent.” A past client whose last transaction with you closed more than two years ago has dropped out of implied consent for commercial electronic messages — they need express consent to keep receiving CEMs, or they need to come off the CEM list.
Run this as a straightforward date filter: today's date minus two years. Anyone with a last-transaction date before that cutoff moves to the “needs express consent or drops” bucket, regardless of how engaged they otherwise seem.
STEP 03 OF 10
A contact who only ever made an inquiry — never a completed purchase or lease — falls under a different, shorter clock: “an inquiry or application, within the six-month period immediately before the day on which the message was sent.” A lead who inquired eight months ago and never transacted has already dropped out of implied consent, even though two years feels like the more familiar number from the transaction rule.
Do not apply the two-year window to an inquiry-only contact by habit — check which relationship type actually applies to each row before filtering.
STEP 04 OF 10
Per the CRTC's own FAQ, express consent “does not expire, but the recipient has the right to withdraw their consent at any time.” A contact who explicitly opted in through a form, a signed intake sheet, or another documented express action does not need to be re-permissioned on the same clock as an implied-consent contact — keep them in a clearly labelled express-consent segment, distinct from the implied-consent ones being audited against the date rules above.
The distinction matters practically: your implied-consent segment shrinks every day as contacts age past their window; your express-consent segment does not, until someone actively withdraws.
STEP 05 OF 10
If any part of this database is used for telemarketing calls rather than just email, apply the National DNCL's own existing-business-relationship exemption: 18 months from a purchase or lease, or 6 months from an inquiry or application — genuinely different numbers from CASL's 2-year and 6-month windows, sharing only the inquiry figure by coincidence. Do not assume a contact who is still inside CASL's 2-year window is automatically callable — the DNCL's 18-month purchase window is shorter, and can expire first.
There is no real-estate-specific exemption in the National DNCL rules beyond the general existing-business-relationship exemption — do not assume the profession carries any special carve-out.
STEP 06 OF 10
Once a contact has aged past their applicable window with no express consent on file, either actively seek express consent (a genuine re-permission ask, not a disguised newsletter) or remove them from CEM sends entirely. Leaving a stale, expired-consent contact in the active send list is the single most common way a database audit accomplishes nothing — the segmentation work in steps two and three is wasted if nobody acts on what it finds.
A re-permission ask is itself a CEM in most forms it might take, so make sure the ask itself either fits an exemption (see the referral and business-card exemptions in the sibling nurture guide) or is sent through a channel outside CASL's scope, such as a phone call or postal mail.
STEP 07 OF 10
CASL s.11 requires an unsubscribe mechanism that works “at no cost” to the recipient and stays “valid for a minimum of 60 days” after the message is sent, and per the CRTC's guidance, requests must be honoured “without delay, and no later than 10 business days.” Test your own unsubscribe link or process personally — click it, submit it, confirm it actually removes the contact — rather than assuming it works because it was set up correctly once.
A database clean-up project is the natural moment to also confirm this mechanism still functions, since a broken unsubscribe link compounds every other consent problem in the list.
STEP 08 OF 10
CASL governs electronic messages only. A geographic farm mailing list — postal addresses you send physical mail to — is entirely outside CASL's framework and does not need to be run through any of the date filters in this guide. Keep your farm mailing list as a genuinely separate list from your CEM database, so the consent audit does not accidentally sweep in contacts that were never subject to it, or conversely, exclude a postal-only contact from a mailing they were always eligible for.
This distinction is worth stating plainly to anyone else in your business handling the database — it is a common and understandable confusion given how much of the rest of this guide is date-driven.
STEP 09 OF 10
Most cloud CRMs host in, or route data through, the United States — which likely triggers PIPEDA's application to the data regardless of your own province, because the data crosses a border. Note this plainly in whatever privacy disclosure you give contacts, and be aware that specific breach-reporting mechanics — what counts as a reportable breach, the notification timeline — could not be confirmed from current guidance for this project; consult the Office of the Privacy Commissioner's current published material directly if a breach question ever arises, rather than relying on general PIPEDA reputation.
This is an honest gap to flag rather than paper over: the general principles here are solid, but the specific breach mechanics need a fresh check against current guidance if the question ever becomes live.
STEP 10 OF 10
A one-time clean-up solves today's problem and guarantees a new one in six months, because contacts keep aging past their windows continuously. Put the whole process — export, segment, purge or re-permission, test the unsubscribe mechanism — on a recurring calendar entry, quarterly at minimum given the six-month inquiry window is the shortest clock in play. See the time-blocking guide for where this fits into a weekly and quarterly schedule generally.
Pair this recurring audit with the past-client nurture programme, which is built around converting contacts to express consent before they age out in the first place — the two guides are two sides of the same clock.
Applying the two-year window to an inquiry-only contact. Inquiries run on a six-month clock, not two years. Check which relationship type applies before filtering by date.
Treating CASL's windows and the National DNCL's windows as the same rule. CASL runs 2 years/6 months for email; the DNCL runs 18 months/6 months for calls. A contact can be inside one window and outside the other.
Leaving aged-out contacts in the active send list after the audit. Segmentation without action changes nothing. Purge or actively re-permission every contact that ages out — do not just identify them and move on.
Running farm-area postal contacts through the CASL date filters. Direct mail is outside CASL's scope entirely. Keep the postal farm list separate from the CEM consent audit.
Assuming the unsubscribe link works without testing it. Click it, submit it, confirm the contact is actually removed. A broken unsubscribe mechanism compounds every other consent problem in the list.
A worked scenario showing how a database actually splits once the real CASL and DNCL clocks are applied — the contact counts are illustrative, but the method and the arithmetic are exactly what a real audit produces.
The starting list. 400 total contacts: 180 past transaction clients, 150 inquiry-only leads who never transacted, 70 express-consent newsletter subscribers.
Applying the two-year and six-month windows. Of the 180 past clients, dated by last-transaction, 110 transacted within the last two years (still implied-consent, CEM-eligible) and 70 transacted more than two years ago (aged out). Of the 150 inquiry-only leads, dated by last inquiry, 40 inquired within the last six months (still implied-consent) and 110 inquired more than six months ago (aged out).
The totals after segmentation. Still CEM-eligible on implied consent: 110 (recent past clients) + 40 (recent inquiries) = 150. Plus the 70 express-consent subscribers, who are evergreen regardless of date: 150 + 70 = 220 contacts still legally sendable. Aged out and needing express consent or removal: 70 (old past clients) + 110 (old inquiries) = 180 contacts — using every one of the original 400: 220 + 180 = 400.
Nearly half this hypothetical list — 180 of 400 contacts — has aged out of implied consent by the time of the audit, which is a realistic outcome, not an extreme one: a database that has not been audited in two or three years routinely looks like this. The 180 in the aged-out bucket are exactly the population the past-client nurture guide's express-consent conversion step is built to shrink before the next audit finds them here again.
The consent rules above are federal and identical everywhere, but which privacy statute actually governs the data itself depends on where your business operates.
For most agents using a mainstream cloud CRM, the practical answer is PIPEDA applies regardless of province, because of the cross-border trigger — but confirm your specific CRM's hosting location if the question ever becomes material to a client dispute.
It removes the CASL question for that contact by removing them entirely, but check your own record-retention obligations before deleting a file connected to a past transaction — a commission or tax record retention duty may require keeping some underlying records even if you stop sending CEMs.
That request is itself a CEM in most forms, so it needs to fit an exemption (such as the referral or business-card exemptions) or be sent through a channel outside CASL's scope — a phone call or postal mail, for instance.
Use whichever event is more recent to set the applicable clock — a more recent inquiry does not reset a two-year purchase window backward, but a more recent transaction would extend it forward under the transaction rule.
Quarterly at minimum, since the six-month inquiry window is the shortest clock in play — a list only checked annually can carry contacts that aged out and were sent CEMs anyway for most of a year.
A short call is enough to map the segmentation logic onto your actual database fields.