In December, the Canadian government announced [1] that its new anti-spam law [2] (CASL) will go into effect July 1, 2014.  Where the US CAN-SPAM law focuses only on e-mail spam, CASL covers all “commercial electronic messages” (CEMs), regardless of the type of organizations sending them.  CASL takes a technology-neutral approach and applies to any electronic message sent to an electronic address.  This means any means of telecommunication, including text, sound, voice, or image, via e-mail, instant messaging, telephone, or any similar account (which could include Facebook and Twitter postings), delivered in connection with a commercial activity.  The new law will also apply to any CEM either sent from, or accessed on, a computer system in Canada.

Under CASL, “commercial activity” is defined as any transaction, act, or conduct that is of a commercial character, whether or not the person who carries it out does so with the expectation of profit.  CASL also creates an “opt-in” system, requiring permission from the recipient before sending a CEM, though consent can be express or implied.  In certain circumstances, implied consent can include existing business or non-business relationships, as well as where the recipient has disclosed to the sender, or conspicuously published, their electronic address, without an accompanying statement that they do not wish to receive unsolicited messages.  The message must also be relevant to their business, role, functions, or duties in a business or official capacity.  All CEMs must also include information regarding both the actual and beneficial sender of the message, a sender’s contact information, and an effective and timely unsubscribe mechanism.

CASL will also prohibit the installation of any computer program on another person’s PC, smartphone or other computer-based device in the course of a commercial activity unless express consent has been given, regardless of whether it is installed for a malicious purpose.  “Computer program” will be defined very broadly to mean “data representing instructions or statements that, when executed in a computer system, causes the computer system to perform a function.”  Additionally, like the new US Telephone Consumer Protection Act regulations, valid consent cannot be obtained using pre-checked boxes or other forms of opt-out consent (see Insights, New Telemarketing Regulations Could Cost Companies Millions [3], October 22, 2013).  Consent will also not be allowed to be bundled with requests to confirm agreement with a license or other consumer agreement such as privacy policies or general terms and conditions of sale.

Violating CASL’s provisions can lead to significant penalties ranging from up to C$1 million for individuals and C$10 million for businesses, as well as damages and statutory damages, per incident.  Further, officers and directors can be held liable if they directed, authorized, acquiesced in or participated in the offending conduct.

Outsell 200Todd Haiken, Director & Lead Analyst of Outsell Inc. writes:  “CASL has serious implications for any company doing business in or that has customers residing or working in Canada.  B2B and B2C marketers may need to devote significant attention to their procedures for electronic communications and ensure proper consent.  Companies that have only been complying with the US CAN-SPAM law will need to change their practices and obtain express “opt-in” consent if they want to continue to send messages to or through Canada.  Companies that have been following the European Union [4] or United Kingdom’s [5] respective spam laws will be in much better shape.  If a company is using one of the popular third-party e-mail services like MailChimp, VerticalResponse, or Constant Contact to manage their e-mail campaigns, they are also probably in good shape.  If they’re not, it’s something to strongly consider.

Though most of CASL goes into effect in less than six months, companies still have time to get consent from their existing prospect database and advertising subscribers.  If they have a monthly newsletter, explain that their company respects the recipient’s privacy and that if they want to continue to receive the newsletter, they can click a link provided to give express consent.  For companies that do not have a newsletter or regular e-mail marketing, it would be a good idea to start now.

Though it’s hard to think about the summer when we’re right in the thick of the winter, July is only a few short months away.  It is imperative that companies that send CEMs or that provide software budget, plan, finalize, and implement compliance programs before CASL goes into effect.

Links contained in this article:

[1] http://fightspam.gc.ca/eic/site/030.nsf/eng/00272.html”

[2] http://fightspam.gc.ca/eic/site/030.nsf/eng/h_00211.html”

[3] http://www.outsellinc.net/Insights.aspx?ID=12211”

[4] http://europa.eu/legislation_summaries/information_society/legislative_framework/l24120_en.htm”

[5] http://www.opsi.gov.uk/si/si2003/20032426.htm”

Source:  Outsell Inc., A Co-founder of BIIA