Preparing for CASL


Published on

The presentation is about preparing for the upcoming Canadian Anti-Spam Legislation. Learn what CASL is, the timing of it’s implementation and how it will apply to commercial email. We will review specific case studies to better define consent requirements and exceptions to those requirements.

Published in: Business, Technology
  • Be the first to comment

No Downloads
Total Views
On Slideshare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide
  • Electronic Messages include
    An email account
    A telephone message or text
    An instant messaging account
    Any similar account
  • Has to be commercial – broader than CAN SPAM, no primary purpose

    Electronic Messages include
    An email account
    A telephone account; text messages (voice messages are excluded)
    An instant messaging account
    Any similar account

    Non-exhaustive list

    Sent to or from a computer system located in Canada.
    Exclusion for messages sent from Canada to another country with belief it will comply with another countries anti-spam legislation. Ex. The US.
  • Enforcement is done by Industry Canada and the CRTC.

    Broad investigative powers
    Administrative monetary penalties.
    Up to $10 Million per violation

    Competition Bureau (CB)
    Amends the Competition Act to include violations respecting:
    • Misleading and deceptive practices/ representations, including false headers, subject lines, etc...
  • Consent must be auditable. You must be able to prove where your leads gave consent when called upon.
  • Requires an action by the recipient.
    No check boxes.
    Never expires but can be revoked through an unsubscribe action.

    Clearly and conspicuously state purpose for obtaining consent.
    Clearly identify who is being given consent. If you are getting consent for a business partner you must state that business partner’s name .
    Provide contact information on behalf of who is getting consent.
    Inform individual that they can unsubscribe

    Image posted on CRTC website.
    Don’t NEED a check box. Check boxes are relevant where you may already have their email address.
  • Existing Business Relationship
    ‒  Recipient purchased, leased or engaged in bartering of virtually anything from the sender within the past 2 years
    ‒  Recipient accepted a business, investment or gaming opportunity offered by the sender within the past 2 years
    ‒  Recipient and the sender entered into a written contract in respect of any of the above and the contract is either currently in existence or expired within the past 2 years

    Existing Non-Business Relationship
    ‒  The sender is a club, association or voluntary organization and the recipient is or was a member in the past two years
    Less relevant for business senders

    A conspicuously published address.
    Provided to the sender
    Has to be relevant to the person in their professional business capacity – relevant in a B2B

    May be looser than Terms of Service of some service providers.
    May not want to continue sending to inactives – even if it is still OK under the law
  • A business has six months where there is permission to send commercial email after an inquiry, which is converted to a two-year period of implied consent if the sender closes business with that recipient.
  • • Data management will be key to compliance.
    Review existing data and groups consents:
    •  Explicit *
    •  Implied

    •  Third party
    •  Unknown
    •  None

    • Identify gaps in your database fields or the information you are tracking:
    •  Consent date
    •  Consent level
    •  Consent source
    o Website
    o IP address
    •  Last implied date
    •  Last contact date
  • Use this as a Marketing Opportunity! Show that you respect your recipients.
  • a pre-checked box would be considered "opt-out"

    Maintain image of the form that was filled out. Online or offline.

  • a pre-checked box would be considered "opt-out"

    Onerous requirements.
    CRTC backed off and these are “suggestions”

    Date, time, method, agent on the phone – whatever records you can maintain.
  • Where an existing business relationship or non-business relationship exists as of July 1, 2014, regardless of when the relationship began, implied consent is automatically refreshed until July 1, 2017

    To rely on the provision, there must have been prior communication of CEMs between sender and recipient
  • List Rental situations

    Must be relevant to original business where consent was given.

  • CASL only applies to Commercial Electronic Messages

    CASL does not apply to messages that are sent:
    1.  Within or between business, where there’s an ongoing relationship;
    2.  In response to a request;
    3.  To enforce a legal right or obligation;
    4.  Via closed messaging systems;
    a)  Proprietary system
    b)  Messaging systems where ID and unsubscribe included on
    5.  To a foreign jurisdiction in compliance with their spam law; (see Schedule 1 in the ECPR)
    6.  By registered charities raising funds
    7.  By political candidates or organizations, soliciting political contributions

    Personal email – ma protect the Forward to a Friend functions.
  • “CASL puts a legal framework around engagement, and defines what have been best practices for years.”

    Common sense approach

    Knowingly, Intentionally, Repeatedly violate rules

  • Shaun is from an Ottawa based law firm
    1. A particular slide catching your eye?

      Clipping is a handy way to collect important slides you want to go back to later.