Treadstone Associates
Guide

A database clean-up project, start to finish

A contact database does not go bad all at once — it ages out quietly, one expired implied-consent window at a time, until a list that felt safe two years ago is mostly unsendable. This is the audit method: date-stamp everything, apply the actual clocks, and act on what the dates tell you.

Treadstone Associates · Updated 2026

Key takeaways

  • • CASL's implied consent from a past transaction lasts two years from the purchase or lease; implied consent from a mere inquiry lasts only six months — different windows, both real.
  • • The National Do Not Call List runs a separate clock — an 18-month purchase window and a 6-month inquiry window — for telemarketing calls specifically, not the same clock as CASL's email consent.
  • • Express consent does not expire on its own, but the recipient can withdraw it at any time — an express-consent contact is evergreen only until they say otherwise.
  • • Direct mail to a farm area sits outside CASL entirely — the whole email/text consent framework does not apply to postal mail.

STEP 01 OF 10

Export the full database with a last-transaction or last-inquiry date on every row

Before applying any rule, get the raw data right: export every contact with the date of their last transaction, last inquiry, or last express opt-in — whichever applies. This date is what every subsequent step in this audit runs against, so a contact with no reliable date attached cannot be properly segmented and should be flagged as its own category rather than defaulted into either bucket.

If your CRM does not track this date cleanly today, fixing that tracking gap is itself the first real output of this project — every future audit depends on it being accurate going forward.

STEP 02 OF 10

Apply CASL's two-year purchase window

Under CASL s.10(10), implied consent arises from “the purchase or lease of a product, goods, a service, land or an interest or right in land, within the two-year period immediately before the day on which the message was sent.” A past client whose last transaction with you closed more than two years ago has dropped out of implied consent for commercial electronic messages — they need express consent to keep receiving CEMs, or they need to come off the CEM list.

Run this as a straightforward date filter: today's date minus two years. Anyone with a last-transaction date before that cutoff moves to the “needs express consent or drops” bucket, regardless of how engaged they otherwise seem.

STEP 03 OF 10

Apply the separate, shorter six-month inquiry window

A contact who only ever made an inquiry — never a completed purchase or lease — falls under a different, shorter clock: “an inquiry or application, within the six-month period immediately before the day on which the message was sent.” A lead who inquired eight months ago and never transacted has already dropped out of implied consent, even though two years feels like the more familiar number from the transaction rule.

Do not apply the two-year window to an inquiry-only contact by habit — check which relationship type actually applies to each row before filtering.

STEP 04 OF 10

Flag express-consent contacts as a separate, evergreen category

Per the CRTC's own FAQ, express consent “does not expire, but the recipient has the right to withdraw their consent at any time.” A contact who explicitly opted in through a form, a signed intake sheet, or another documented express action does not need to be re-permissioned on the same clock as an implied-consent contact — keep them in a clearly labelled express-consent segment, distinct from the implied-consent ones being audited against the date rules above.

The distinction matters practically: your implied-consent segment shrinks every day as contacts age past their window; your express-consent segment does not, until someone actively withdraws.

STEP 05 OF 10

Check the National DNCL clock separately if you also cold-call from this list

If any part of this database is used for telemarketing calls rather than just email, apply the National DNCL's own existing-business-relationship exemption: 18 months from a purchase or lease, or 6 months from an inquiry or application — genuinely different numbers from CASL's 2-year and 6-month windows, sharing only the inquiry figure by coincidence. Do not assume a contact who is still inside CASL's 2-year window is automatically callable — the DNCL's 18-month purchase window is shorter, and can expire first.

There is no real-estate-specific exemption in the National DNCL rules beyond the general existing-business-relationship exemption — do not assume the profession carries any special carve-out.

STEP 06 OF 10

Purge or re-permission anything that has aged out — do not just leave it

Once a contact has aged past their applicable window with no express consent on file, either actively seek express consent (a genuine re-permission ask, not a disguised newsletter) or remove them from CEM sends entirely. Leaving a stale, expired-consent contact in the active send list is the single most common way a database audit accomplishes nothing — the segmentation work in steps two and three is wasted if nobody acts on what it finds.

A re-permission ask is itself a CEM in most forms it might take, so make sure the ask itself either fits an exemption (see the referral and business-card exemptions in the sibling nurture guide) or is sent through a channel outside CASL's scope, such as a phone call or postal mail.

STEP 07 OF 10

Build the unsubscribe mechanism to the legal minimum, and check it actually works

CASL s.11 requires an unsubscribe mechanism that works “at no cost” to the recipient and stays “valid for a minimum of 60 days” after the message is sent, and per the CRTC's guidance, requests must be honoured “without delay, and no later than 10 business days.” Test your own unsubscribe link or process personally — click it, submit it, confirm it actually removes the contact — rather than assuming it works because it was set up correctly once.

A database clean-up project is the natural moment to also confirm this mechanism still functions, since a broken unsubscribe link compounds every other consent problem in the list.

STEP 08 OF 10

Separate farm-area postal contacts out of the CASL question entirely

CASL governs electronic messages only. A geographic farm mailing list — postal addresses you send physical mail to — is entirely outside CASL's framework and does not need to be run through any of the date filters in this guide. Keep your farm mailing list as a genuinely separate list from your CEM database, so the consent audit does not accidentally sweep in contacts that were never subject to it, or conversely, exclude a postal-only contact from a mailing they were always eligible for.

This distinction is worth stating plainly to anyone else in your business handling the database — it is a common and understandable confusion given how much of the rest of this guide is date-driven.

STEP 09 OF 10

Document a retention and cross-border storage note for the cleaned list

Most cloud CRMs host in, or route data through, the United States — which likely triggers PIPEDA's application to the data regardless of your own province, because the data crosses a border. Note this plainly in whatever privacy disclosure you give contacts, and be aware that specific breach-reporting mechanics — what counts as a reportable breach, the notification timeline — could not be confirmed from current guidance for this project; consult the Office of the Privacy Commissioner's current published material directly if a breach question ever arises, rather than relying on general PIPEDA reputation.

This is an honest gap to flag rather than paper over: the general principles here are solid, but the specific breach mechanics need a fresh check against current guidance if the question ever becomes live.

STEP 10 OF 10

Put the whole audit back on a fixed calendar

A one-time clean-up solves today's problem and guarantees a new one in six months, because contacts keep aging past their windows continuously. Put the whole process — export, segment, purge or re-permission, test the unsubscribe mechanism — on a recurring calendar entry, quarterly at minimum given the six-month inquiry window is the shortest clock in play. See the time-blocking guide for where this fits into a weekly and quarterly schedule generally.

Pair this recurring audit with the past-client nurture programme, which is built around converting contacts to express consent before they age out in the first place — the two guides are two sides of the same clock.

Common mistakes

Applying the two-year window to an inquiry-only contact. Inquiries run on a six-month clock, not two years. Check which relationship type applies before filtering by date.

Treating CASL's windows and the National DNCL's windows as the same rule. CASL runs 2 years/6 months for email; the DNCL runs 18 months/6 months for calls. A contact can be inside one window and outside the other.

Leaving aged-out contacts in the active send list after the audit. Segmentation without action changes nothing. Purge or actively re-permission every contact that ages out — do not just identify them and move on.

Running farm-area postal contacts through the CASL date filters. Direct mail is outside CASL's scope entirely. Keep the postal farm list separate from the CEM consent audit.

Assuming the unsubscribe link works without testing it. Click it, submit it, confirm the contact is actually removed. A broken unsubscribe mechanism compounds every other consent problem in the list.

A 400-contact database, segmented

A worked scenario showing how a database actually splits once the real CASL and DNCL clocks are applied — the contact counts are illustrative, but the method and the arithmetic are exactly what a real audit produces.

The starting list. 400 total contacts: 180 past transaction clients, 150 inquiry-only leads who never transacted, 70 express-consent newsletter subscribers.

Applying the two-year and six-month windows. Of the 180 past clients, dated by last-transaction, 110 transacted within the last two years (still implied-consent, CEM-eligible) and 70 transacted more than two years ago (aged out). Of the 150 inquiry-only leads, dated by last inquiry, 40 inquired within the last six months (still implied-consent) and 110 inquired more than six months ago (aged out).

The totals after segmentation. Still CEM-eligible on implied consent: 110 (recent past clients) + 40 (recent inquiries) = 150. Plus the 70 express-consent subscribers, who are evergreen regardless of date: 150 + 70 = 220 contacts still legally sendable. Aged out and needing express consent or removal: 70 (old past clients) + 110 (old inquiries) = 180 contacts — using every one of the original 400: 220 + 180 = 400.

Nearly half this hypothetical list — 180 of 400 contacts — has aged out of implied consent by the time of the audit, which is a realistic outcome, not an extreme one: a database that has not been audited in two or three years routinely looks like this. The 180 in the aged-out bucket are exactly the population the past-client nurture guide's express-consent conversion step is built to shrink before the next audit finds them here again.

PIPEDA versus the provincial equivalents

The consent rules above are federal and identical everywhere, but which privacy statute actually governs the data itself depends on where your business operates.

  • Alberta, British Columbia and Quebec: each has its own private-sector privacy statute “deemed substantially similar to PIPEDA,” which applies in place of PIPEDA for a business operating wholly within that province.
  • Every other province and territory: PIPEDA governs directly — Ontario, Manitoba, Saskatchewan, the Atlantic provinces, and the territories have no general substantially-similar private-sector law of their own.
  • The cross-border trigger overrides all of this: any organization whose personal-information handling crosses a provincial or national border — which most cloud CRM use does — falls under PIPEDA regardless of home province, including a BC or Alberta agent using a US-hosted CRM.
  • CASL itself does not vary by province — the two-year and six-month windows in this guide are federal and identical everywhere in Canada.

For most agents using a mainstream cloud CRM, the practical answer is PIPEDA applies regardless of province, because of the cross-border trigger — but confirm your specific CRM's hosting location if the question ever becomes material to a client dispute.

Frequently asked

Does deleting a contact's data satisfy the consent problem?

It removes the CASL question for that contact by removing them entirely, but check your own record-retention obligations before deleting a file connected to a past transaction — a commission or tax record retention duty may require keeping some underlying records even if you stop sending CEMs.

Can I ask an aged-out contact for express consent by email?

That request is itself a CEM in most forms, so it needs to fit an exemption (such as the referral or business-card exemptions) or be sent through a channel outside CASL's scope — a phone call or postal mail, for instance.

What if a contact both transacted with me and later just made an inquiry?

Use whichever event is more recent to set the applicable clock — a more recent inquiry does not reset a two-year purchase window backward, but a more recent transaction would extend it forward under the transaction rule.

How often should this audit actually run?

Quarterly at minimum, since the six-month inquiry window is the shortest clock in play — a list only checked annually can carry contacts that aged out and were sent CEMs anyway for most of a year.

Want this audit built into your own CRM?

A short call is enough to map the segmentation logic onto your actual database fields.