Skip to content

compliance

CASL Compliance for Business SMS: What Canadian Businesses Must Know

compliance

Canada’s Anti-Spam Legislation (CASL) is one of the strictest commercial messaging laws in the world. Since it came into force in 2014, the CRTC has issued fines as high as $1.1 million to businesses that violated its provisions. If your business sends SMS messages to customers in Canada, CASL applies to you — regardless of where your company is headquartered.

This guide covers what you need to know to run a compliant business SMS program.

CASL applies to “commercial electronic messages” (CEMs) — any message that encourages participation in a commercial activity. For SMS, that means:

  • Promotional texts (sales, offers, discounts)
  • Appointment reminders that include upsell offers
  • Transactional messages with marketing content added
  • Win-back or re-engagement campaigns

Not covered: Pure transactional messages (e.g., “Your order has shipped”), messages between individuals, and certain B2B communications where there is an existing relationship.

1. Consent

You need explicit, documented consent before sending any CEM. There are two types:

  • Express consent: The recipient actively opted in — checked a box, signed a form, sent a keyword to your shortcode. This is the gold standard.
  • Implied consent: An existing business relationship exists (e.g., the person bought from you in the past two years). Implied consent is time-limited and narrower in scope.

Critically, consent cannot be buried in terms and conditions. It must be clear, specific, and documented. If you can’t prove consent, you don’t have it.

2. Identification

Every commercial SMS must clearly identify who is sending it. For SMS, this means including your business name in the message body, since sender IDs on text messages are not always displayed or trusted by recipients.

3. Unsubscribe Mechanism

Every message must include a simple, free way to opt out. Standard practice is including “Reply STOP to unsubscribe” in each message. Once a recipient opts out, you have 10 business days to honor the request and must never message them again for commercial purposes.

The CRTC can audit your consent records. For every contact in your SMS list, you should be able to document:

  • The date and method of consent
  • Exactly what the person agreed to receive
  • The specific language shown at the time of opt-in

Most compliant SMS platforms, including SIPSTACK Flare, maintain these records automatically with timestamps and opt-in source tracking.

  • Importing contact lists without verifying consent — Just because you have someone’s phone number doesn’t mean you have CASL consent to text them.
  • Letting implied consent expire — Implied consent from a transaction expires after two years. Many businesses fail to stop messaging contacts once this window closes.
  • Not honoring opt-outs promptly — The 10-business-day window is a maximum, not a target. Honor opt-outs immediately.
  • Confusing CASL and TCPA — If you’re messaging US numbers, the Telephone Consumer Protection Act (TCPA) applies separately and has its own requirements.

If you’re not sure your current SMS list is CASL-compliant, the safest approach is to run a re-consent campaign before sending any further commercial messages. Yes, your list will shrink. But the subscribers who actively re-opt-in are more engaged, and you’ll be on solid legal footing.

CASL compliance is not optional. The upside is that a clean, consented list consistently outperforms a large, non-consented one.