Skip to content

← All articles

CASL and transactional email: what the exception really covers

"Transactional emails are exempt from the anti-spam law." You read it everywhere, and it is only half true. To know what you may send, and what each message must contain, you have to read what the statute says. Here is what Canada's Anti-Spam Legislation (CASL) says, section by section.

This article is general information, not legal advice. If your situation is unclear or the stakes are high, talk to a lawyer.

What the law targets: the "commercial electronic message"

The prohibition in section 6 does not cover every email. It covers the commercial electronic message (CEM), which subsection 1(2) defines as a message that, having regard to its content, the hyperlinks it contains or its contact information, it would be reasonable to conclude has as its purpose, or one of its purposes, to encourage participation in a commercial activity. Offering or promoting a product or a service is part of that.

Two practical consequences:

  • an email with no commercial purpose at all (for example, the link to reset a password) is not a commercial electronic message and is not covered by section 6;
  • an email with one commercial purpose among others is. The words "one of its purposes" are the source of most surprises (see below).

The basic rule (section 6)

Subsection 6(1) prohibits sending a commercial electronic message, or causing or permitting one to be sent, unless two conditions are met:

  1. the person it is sent to has consented, expressly or by implication, to receiving it;
  2. the message complies with subsection 6(2): it identifies the person who sends it (and the person on whose behalf it is sent), it sets out information enabling the recipient to contact them, and it sets out an unsubscribe mechanism.

Subsection 6(3) adds that the contact information must remain valid for at least 60 days after the message is sent. And under section 11, an unsubscribe request must be given effect without delay, and no later than 10 business days after it was sent.

The exception in subsection 6(6)

This is the passage everyone talks about. Subsection 6(6) says that paragraph 6(1)(a), the consent requirement, does not apply to a commercial electronic message that solely:

  • provides a quote or estimate requested by the person;
  • facilitates, completes or confirms a commercial transaction the person previously agreed to enter into (order confirmation, receipt, invoice);
  • provides warranty, product recall, or safety or security information about a product or service the person uses or has purchased;
  • provides notification of factual information about the ongoing use or purchase of a product or service offered under a subscription, membership, account, loan or similar relationship, or about that relationship itself (renewal notice, statement, change to account terms);
  • provides information directly related to an employment relationship or a related benefit plan;
  • delivers a product or service, including an update or upgrade, that the person is entitled to receive under a transaction they have already entered into.

Keep two words from that list in mind.

"Solely". The message must be only one of those things. As soon as it also does something else (a promotion, an offer, an invitation to buy), the exception no longer applies to it.

What the exception removes. It removes the consent requirement, nothing else. The text does not remove the requirements of subsection 6(2): identification, contact information, unsubscribe mechanism. In other words, on a literal reading of the statute, even a message covered by 6(6) should contain that information. Many people remember "no consent needed, so nothing to do", which is broader than what the text says.

In practice, some messages on that list (a receipt, a renewal notice) are also messages with no commercial purpose at all. Deciding which ones are genuine commercial electronic messages, and therefore subject to 6(2), is a question of interpretation. If it matters to you, get advice.

The classic traps

  • Promotion inside the receipt. A receipt that ends with "Discover our new products" or a banner of featured products now has one more commercial purpose. The message is no longer "solely" a transaction confirmation: consent is required again for that message.
  • The disguised reminder. "You forgot something in your cart" is not the confirmation of a transaction the person agreed to: it is a solicitation.
  • The sign-up message that takes advantage. A sign-up confirmation can be transactional; the same confirmation with a welcome offer added is not.
  • The link that changes everything. Subsection 1(2) takes into account the content, hyperlinks to a website and contact information. A footer pointing to an online store can weigh in the analysis.

Who is responsible?

Subsection 6(1) targets whoever sends, but also whoever causes or permits the sending. Section 9 also prohibits aiding, inducing or procuring an act contrary to sections 6 to 8. That is not a detail: a sending platform is not protected simply because it did not write the content. It is one of the reasons a serious transactional service prohibits newsletters and promotions by default, as Duva does in its terms of use.

The penalties are real: subsection 20(4) sets the maximum penalty at $1,000,000 for an individual and $10,000,000 for any other person, per violation.

CASL is not the privacy law

The consent CASL talks about is consent to receive commercial electronic messages. It does not settle what you may do with the addresses and information you hold: that falls under privacy laws (in Québec, the private sector Act as modernized by Law 25; elsewhere, PIPEDA or a provincial law). The two regimes add up.

PIPEDA also contains a rule that bears directly on address lists: its section 7.1 removes the consent exceptions for the collection of an electronic address by means of a computer program designed or marketed primarily for generating, searching for and collecting electronic addresses, and for the use of an address collected that way. A list of addresses "harvested" automatically is therefore a problem on both sides: you cannot send it commercial messages without consent (CASL), and collecting it is restricted by PIPEDA.

A checklist

For each type of email your application sends:

  1. What is its purpose? If it has only one and it is not commercial (login code, security alert), you are outside section 6.
  2. If it is commercial, does it fit a category of subsection 6(6), and only that category? If not, you need consent.
  3. Who sends it, and who can be reached? Put the company name and valid contact information in all your emails, even the non-commercial ones.
  4. Can you prove consent? Keep the date, the source and the wording of the consent request.
  5. Does unsubscribing work? Process requests without delay, within 10 business days at most, and never ignore them.
  6. Separate your streams. Do not send your promotions with your transactional emails: their risks are not the same.

Sources