ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Consent for Text Messaging

Who needs to comply with CASL?

Back to InsightsWho needs to comply with CASL?

Who needs to comply with CASL?

Key Facts

  • CASL applies to anyone sending commercial electronic messages — including texts — with penalties up to $10 million per violation for organizations, per Bloomberg Law.
  • Compu.Finder paid a $1.1 million CASL penalty in 2015 for messages sent without consent and a broken unsubscribe mechanism, according to an enforcement roundup.
  • CASL covers text messages explicitly because they're transmitted to an electronic address, per the CRTC's FAQ.
  • Even a single Canadian lead triggers CASL — messages received in Canada must comply regardless of where they're sent from, per Robins Kaplan.
  • Unsubscribe requests must be honored within 10 business days, and the sender bears the burden of proving consent, per CRTC guidance.
  • Plentyoffish paid a $48,000 CASL penalty simply because its unsubscribe feature wasn't clearly presented, per Legal500.
  • Canadians filed 167,939 spam complaints in just six months — over 6,400 per week, per the Government of Canada.

The Short Answer: If You Send Commercial Messages, CASL Applies to You

Most people assume anti-spam laws target spammers — giant botnets blasting millions of emails. Canada's Anti-Spam Legislation takes a different approach entirely: it looks at what you do, not who you are.

CASL is activity-based, not entity-based. There is no official list of "who must comply." Instead, the trigger is simply sending a commercial electronic message (CEM) — any message that encourages participation in a commercial activity, whether or not you expect to profit. According to the Government of Canada's own guidance, that covers businesses, organizations, and individuals alike.

And yes, that includes text messages. The CRTC's FAQ is explicit: commercial messages sent over a text messaging service are subject to CASL because they're transmitted to an electronic address. The same goes for instant messages and social media messaging systems like Facebook Messenger.

So if you're texting leads — missed-call text-backs, appointment reminders, follow-up sequences — you're sending CEMs. That means every message needs three things:

  • Prior consent, either express or implied
  • Identification and contact information for the sender
  • A working unsubscribe mechanism, honored within 10 business days

The stakes are real. Legal analysts have called CASL's penalties "arguably the most severe of any consumer protection statute in Canada" — up to $10 million per violation for organizations, with officers and directors personally liable. Enforcement isn't theoretical either: Compu.Finder drew a $1.1 million penalty in 2015, and Plentyoffish paid $48,000 for an unsubscribe feature that wasn't clearly presented.

Here's the part that catches US businesses off guard: CASL applies regardless of where the message originates. Messages sent to recipients in Canada from other countries must comply, per the CRTC. A US legal analysis from Robins Kaplan puts it plainly: CASL regulates messages received in Canada no matter where the communication is initiated.

So a plumbing company in Dallas texting a lead can't assume Canadian law doesn't touch them. If that lead has a Canadian phone number, or your texting platform routes through Canada, CASL comes into play. And the burden of proving consent falls on the sender — even when using lists provided by third parties.

This is exactly why CallMyLeads, a Halifax-based company serving US businesses, treats consent handling as a core feature rather than an afterthought — collecting explicit consent in the booking flow and honoring opt-outs immediately and automatically, well inside the legal window.

Yes, US Businesses Are Covered: CASL's Cross-Border Reach

Here's the trap most US companies walk straight into: CASL doesn't care where your business is located. It cares where the message lands and where it's sent from. If your text, email, or instant message reaches a recipient in Canada, CASL applies — full stop.

According to the CRTC's official guidance, commercial electronic messages sent from other countries to recipients in Canada must comply with CASL. The same rule runs in reverse: messages sent from Canada must comply even when they're addressed to recipients abroad, with only limited exemptions.

Legal analysts at Robins Kaplan put it plainly for American firms: CASL regulates businesses sending commercial messages received in Canada, regardless of where the communication is initiated. Their conclusion is blunt — because noncompliance carries serious repercussions, US businesses must review their marketing practices to conform.

That means a US company has CASL exposure if any of the following are true:

  • A lead fills out your web form with a Canadian phone number or email address
  • Your ad campaign or referral network pulls in prospects north of the border
  • Your follow-up texts or nurture emails reach someone who lives in or travels to Canada
  • A vendor or service provider sends messages on your behalf from Canadian soil

Even one Canadian lead in your pipeline is enough to trigger the rules. And the stakes are not theoretical. Under CASL, administrative monetary penalties reach up to $10 million per violation for organizations and $1 million for individuals, with officers and directors personally liable. Enforcement has already produced real fines — Compu.Finder paid $1.1 million in 2015 for messages sent without consent and a broken unsubscribe mechanism.

There's a second wrinkle US senders rarely consider. If you outsource your lead response — your text-backs, reminders, and nurture follow-ups — to a third party, where that provider operates matters too. A Canadian-based service sending messages for you sits squarely inside CASL's "sent from Canada" rule, even when every recipient is American.

This is exactly the intersection where CallMyLeads operates. Based in Halifax, Nova Scotia, and serving businesses across the United States, it handles lead response under both rule sets at once: US carrier registration (A2P 10DLC) on one side, CASL's consent requirements on the other. Its booking flow collects explicit consent, opt-outs are honored immediately and automatically — well inside the 10-business-day window the CRTC requires — and every lead is tracked from source to result, which matters because the sender bears the burden of proving consent.

The practical takeaway for any US business: geography is no defense. If a message touches Canada in either direction, CASL's consent, identification, and unsubscribe rules apply — and "we didn't know" is not a compliance strategy.

The Three Things Every Message Must Have (and What Violations Cost)

Send one text without consent, and the fine can reach $1.1 million. That's not a scare tactic — it's what happened to Compu.Finder in March 2015, and it's exactly why understanding CASL's three core requirements matters before you send your next message.

Every commercial electronic message needs consent before you hit send, and consent comes in two forms. Express consent means the recipient actively opted in — no pre-checked boxes allowed — and it doesn't expire until withdrawn. Implied consent exists when you have an existing business relationship: someone purchased from you within the last 2 years, or made an inquiry within the past 6 months, according to CRTC guidance.

Here's the part that catches most businesses off guard: the sender bears the burden of proving consent. The CRTC states plainly that under CASL, the onus is on you — even if a third party supplied the list. No records, no defense.

Every message must clearly identify who's sending it and provide a way to reach you. If a lead gets a text and can't tell which company it came from or how to respond, that message is non-compliant. Transparency isn't optional — it's built into the law.

Every message needs a clear, functional unsubscribe option, honored within 10 business days per CRTC rules. This is where regulators struck first: Plentyoffish paid a $48,000 penalty because its unsubscribe mechanism wasn't clearly and prominently set out. Porter Airlines ($150,000) and Rogers Media ($200,000) both entered undertakings over unsubscribe failures.

  • Compu.Finder: a $1.1 million penalty for messages sent without consent and an ineffective unsubscribe mechanism
  • Organizations face administrative monetary penalties up to $10 million per violation; individuals up to $1 million
  • Officers and directors can be held personally liable
  • Enforcement actions can reach back three years under the statute of limitations

Legal analysts at Baker & McKenzie have called CASL's penalties arguably the most severe of any Canadian consumer protection statute, and the law has earned a reputation as one of the strictest anti-spam regimes in the world.

The practical takeaway for any business texting leads: build consent capture, clear identification, and instant opt-out handling into your follow-up process from the start. CallMyLeads, for example, collects explicit consent during the booking flow and honors opt-outs immediately and automatically — faster than the 10-business-day window requires — so every lead conversation stays on the right side of the line. When speed-to-lead is measured in seconds, compliance can't be the thing that slows you down.

How to Stay Compliant Without Slowing Down Your Lead Response

Compliance and speed are not enemies — the businesses that get burned are the ones treating consent as paperwork instead of plumbing. Build these practices into your lead response workflow once, and every message after that runs clean.

Collect express consent at first contact. CASL requires a proactive opt-in — pre-checked boxes are prohibited — and express consent does not expire until the person withdraws it, according to CRTC guidance. That makes the first interaction your best opportunity. When a lead fills out a form or books an appointment, ask for permission to text them right there, in plain language. CallMyLeads builds this directly into its booking flow, so consent is captured explicitly before the first follow-up text ever goes out.

Keep consent records like your defense depends on it — because it does. Under CASL, the sender bears the onus of proving consent, even when using lists provided by third parties. If a complaint lands, "we're pretty sure they opted in" is not a defense. Your records should capture:

  • When and how consent was given (form, booking flow, oral confirmation)
  • The exact wording of the consent request
  • The lead source tied to each contact
  • Every opt-out and the timestamp it was processed

This is where source-to-booking tracking quietly does double duty. The same system that shows which ad or form produced a booked appointment also documents the consent trail behind every message — a due-diligence record you never had to build separately.

Honor opt-outs instantly, not eventually. CASL gives senders up to 10 business days to process an unsubscribe request, but early enforcement shows regulators have little patience for broken unsubscribe mechanisms. Plentyoffish paid a $48,000 penalty because its unsubscribe wasn't clearly set out, and Compu.Finder was fined $1.1 million in part for an unsubscribe that didn't work, per an enforcement roundup of early CASL cases. Automatic, immediate opt-out handling — the kind CallMyLeads applies the moment a lead says stop — beats the legal deadline by days and removes the human error that causes these fines.

Register your business texting properly. For US messaging, A2P 10DLC registration with carriers is the baseline for legitimate business texting, and it pairs naturally with CASL's identification requirement — every commercial message must identify the sender and provide contact information under the CRTC's regulatory framework.

The stakes justify the setup. Penalties reach up to $10 million per violation for organizations, with officers and directors personally liable, according to a Bloomberg Law analysis. None of this requires slowing down. Consent captured at booking, instant opt-outs, and automatic record-keeping let you respond in seconds while staying on the right side of one of the world's strictest anti-spam laws.

Frequently Asked Questions

Does CASL apply to my US business if I text a lead with a Canadian phone number?
Yes — CASL applies to commercial electronic messages received in Canada regardless of where they originate, so a US business texting a Canadian number must comply with consent, identification, and unsubscribe requirements.
Do text messages count as commercial electronic messages under CASL?
The CRTC explicitly states that commercial messages sent over a text messaging service are subject to CASL because they are transmitted to an electronic address, and the same rule covers instant messages and social media messaging systems like Facebook Messenger.
What's the difference between express and implied consent under CASL, and which one should I use?
Express consent requires a proactive opt-in with no pre-checked boxes and does not expire until withdrawn, while implied consent covers existing business relationships — purchases within 2 years or inquiries within 6 months — making express consent the stronger, longer-lasting option for lead follow-up.
Who's responsible for proving consent if a complaint is filed — me or my texting provider?
The sender bears the onus of proving consent under CASL, even when using lists or services provided by third parties, so you need your own records of when and how each lead gave permission.
How fast do I need to honor an opt-out request under CASL?
CASL requires unsubscribe requests to be honored within 10 business days, but early enforcement cases like Plentyoffish's $48,000 penalty show regulators expect the mechanism to be clear and functional immediately.
What are the actual penalties for violating CASL, and have they been enforced?
Organizations face administrative monetary penalties up to $10 million per violation with officers and directors personally liable, and enforcement is real — Compu.Finder was fined $1.1 million in 2015 for sending messages without consent and a broken unsubscribe mechanism.

If You Text Leads, CASL Already Applies to You

CASL doesn't care what kind of business you run — it cares what you send. If a commercial text, email, or message leaves your system, you need prior consent, clear identification, and a working unsubscribe mechanism. And if you're a US business, geography won't save you: a single Canadian lead in your pipeline, or a Canadian-based provider texting on your behalf, is enough to trigger the rules. With penalties reaching up to $10 million per violation for organizations — and directors personally liable — "we didn't know" is not a strategy. The good news: compliance doesn't have to slow you down. Capture express consent at first contact, keep records that prove it, and honor opt-outs instantly. That's exactly how CallMyLeads runs its lead response — consent collected in the booking flow, opt-outs processed automatically, every lead tracked from source to booked appointment. Stop paying for leads you never get to talk to — book a free scoping call and see how fast, compliant follow-up actually works.

Build My Lead Response Plan

Get lead response tips that actually work