CASL & PIPEDA Compliance for Canadian Websites
I put this guide together for Canadian website owners who want a plain-language explanation of privacy and email marketing compliance. If your site has contact forms, a newsletter, analytics, checkout pages, or customer accounts, CASL and PIPEDA are the two laws you will run into first.
Updated for 2026, including the Bill C-36 privacy reform tabled in June. One quick note before we start: this is general information from a website owner's perspective, not legal advice.
Quick Answers Before the Deep Dive
If you only have two minutes, these are the facts I would want every Canadian site owner to walk away with. Everything below is explained in more detail further down the page.
PIPEDA is the privacy law
It governs how you collect, use, protect, and retain personal information in commercial activity. The Office of the Privacy Commissioner of Canada oversees it.
CASL is the anti-spam law
It governs marketing emails, texts, and other commercial electronic messages. The CRTC enforces it, and it is opt-in, not opt-out.
The penalties are serious
CASL penalties can reach $10 million per violation for a business. PIPEDA breach reporting offences carry fines up to $100,000.
Breach reporting is mandatory
Breaches that create a real risk of significant harm must be reported to the Privacy Commissioner, and you must keep records of every breach for 24 months.
Pre-checked boxes do not count
Express consent under CASL needs a positive action. An already-ticked newsletter box does not meet the standard.
Big changes are coming
Bill C-36, tabled in June 2026, would replace PIPEDA with a new law called the PPCDA. It is not law yet, but it is worth watching.
What Is PIPEDA?
PIPEDA is Canada's federal private-sector privacy law. It came into force in 2001 and was fully phased in by 2004.
In simple terms, it is about how organizations collect, use, disclose, protect, and retain personal information during commercial activity. There is no small business exemption, so a one-person shop with a contact form is covered just like a national retailer.
The law is built on 10 fair information principles, covering things like accountability, consent, limiting collection, safeguards, and openness. For a website owner, those principles show up in everyday places: contact forms, quote requests, newsletter signups, analytics, ecommerce checkout, support tickets, server logs, and backups.
What PIPEDA focuses on
- Personal information and why it is collected
- Meaningful consent and clear explanations
- Privacy safeguards and reasonable protection
- Retention limits, access requests, and breach handling
Why it matters
- It helps build trust with Canadian visitors
- It forces cleaner data handling practices
- It reduces risk from weak policies and vague consent
- It makes your website feel more credible and professional
What Is CASL?
CASL is Canada's anti-spam legislation, in force since July 1, 2014. It is widely considered one of the strictest anti-spam laws in the world.
CASL covers commercial electronic messages, usually shortened to CEMs. That means marketing emails and newsletters, but also promotional texts and even direct messages on social platforms if they encourage a commercial activity.
The single most important thing to understand is that CASL is an opt-in law. You need consent before you send, and if the CRTC ever asks, the burden of proving that consent falls on you, not the recipient. The government's CASL information site is a solid starting point if you want the official overview.
Every commercial message needs
- Consent from the recipient, either express or implied
- Clear identification of who is sending it, including a mailing address and contact method
- A working unsubscribe mechanism that is easy to use
Key things site owners miss
- CASL applies to texts and social DMs, not just email
- It applies to B2B messages, not just consumer marketing
- It applies based on where the recipient is, so senders outside Canada are still covered
- Express consent never expires, but implied consent does
CASL vs PIPEDA: What's the Difference?
This is the point where a lot of website owners get confused, so here is the clean version. PIPEDA is mostly about privacy and personal information. CASL is mostly about commercial electronic messages, like marketing emails, newsletters, some sales outreach, and similar electronic promotions.
PIPEDA covers
How your website handles personal information during commercial activity.
- Privacy policy and openness
- Personal information collection
- Consent for data handling
- Safeguards and security practices
- Access requests and corrections
- Retention and deletion decisions
- Breach records and notification duties
CASL covers
How your business sends commercial electronic messages to people.
- Newsletter and email marketing consent
- Commercial email content
- Sender identification
- Working unsubscribe links
- Signup records and proof of consent
- Promotional follow-up messages
- Certain abandoned cart and automated message scenarios
Side by side comparison
| PIPEDA | CASL | |
|---|---|---|
| What it governs | Collection, use, disclosure, protection, and retention of personal information | Commercial electronic messages such as marketing emails, texts, and DMs |
| In force since | 2001, fully phased in by 2004 | July 1, 2014 |
| Who enforces it | Office of the Privacy Commissioner of Canada (OPC) | CRTC, with roles for the OPC and Competition Bureau |
| Who it applies to | Private-sector organizations handling personal information in commercial activity | Anyone sending commercial electronic messages to recipients in Canada |
| Core duty | Meaningful consent, reasonable safeguards, limited retention, accountability | Prior consent, sender identification, and an unsubscribe option in every message |
| Top penalties | Fines up to $100,000 per offence for breach reporting violations | Up to $1 million per violation for individuals, $10 million for businesses |
Consent Rules Explained
Consent is the backbone of both laws. Under PIPEDA, visitors should understand what information you are collecting, why you are collecting it, how it will be used, whether it will be shared, and how they can contact you about it.
Here is how that plays out in the three places most websites collect information.
Contact forms
Tell users why you need their name, email, phone number, or project details before they submit the form. The more direct the explanation is, the better.
Newsletter forms
Separate marketing consent from general contact requests. I would not treat a general inquiry as automatic permission to send ongoing promotional emails.
Analytics and tracking
Be clear about analytics, advertising pixels, embedded tools, and third-party scripts that may process visitor information or behaviour data.
On the CASL side, consent comes in two flavours: express and implied. Express consent is a deliberate opt-in and never expires until the person withdraws it.
Implied consent comes from an existing relationship, and this is the part people get wrong: it has expiry dates. The CRTC's CASL FAQ covers the fine print, but the table below is the short version.
CASL consent types at a glance
| Consent type | How you get it | How long it lasts |
|---|---|---|
| Express consent | An active opt-in, like an unchecked box the user ticks or a dedicated signup form | Does not expire until the person unsubscribes |
| Implied: business relationship | The person bought something from you or entered a contract | Generally 2 years from the last purchase or transaction |
| Implied: inquiry | The person asked about your products or services | 6 months from the date of the inquiry |
| Implied: published or shared address | The address was conspicuously published, or given directly to you, with no statement declining messages | Only while the message is relevant to the person's role or business |
What Counts as Personal Information on a Website?
Many site owners assume they only handle personal information if they run a large ecommerce store. In reality, even a simple service business website can collect more than it realizes.
Contact form submissions
Name, email, phone number, project details, and any notes a visitor shares with you.
Newsletter signups
Email addresses, consent records, source pages, and signup timestamps.
Website analytics
Analytics data, user behaviour, and tracking data from tools such as Google Analytics or similar platforms.
Ecommerce checkout details
Billing details, shipping details, order history, account activity, and transaction records.
Customer accounts
Login data, saved preferences, profile information, and support history.
Support tickets and chat
Messages, attachments, troubleshooting notes, and customer follow-up records.
Embedded scripts or widgets
Third-party forms, pixels, chat tools, and plugins that process visitor data behind the scenes.
Backups and hosting logs
Server logs, security logs, backups, and administrative records stored by your site or host.
Penalties and Who Enforces What
The headline numbers get quoted a lot, so let me put them in one place. These are statutory maximums per violation, not typical outcomes.
Max CASL penalty per violation for a business
Max CASL penalty per violation for an individual
Max PIPEDA fine per offence for breach reporting violations
Max penal fine under Quebec Law 25, or 4% of worldwide turnover
Real-world penalties are usually far below the maximums. The CRTC scales penalties based on the nature of the violation, cooperation, self-correction, and ability to pay.
In one early case, a $1.1 million notice of violation was ultimately set at $200,000 after review. The other cost people forget is the investigation itself, because a notice to produce means handing over consent records and email logs whether or not a fine ever lands.
CRTC
- Enforces CASL's message and software installation rules
- Can investigate, demand records, and issue notices of violation with penalties
- Also accepts undertakings, which are negotiated settlements with compliance conditions
Privacy Commissioner (OPC)
- Oversees PIPEDA, investigates complaints, and publishes findings
- Handles CASL's address harvesting provisions
- Can refer offences, like breach reporting failures, for prosecution
Competition Bureau
- Handles false or misleading representations in electronic messages
- Covers deceptive subject lines, sender info, and message content
- Operates under the Competition Act alongside CASL
Provincial regulators
- Quebec's CAI enforces Law 25 with GDPR-scale penalties
- Alberta and BC commissioners enforce their provincial PIPA laws
- More on the provincial layer in section 12
Data Breach Rules Under PIPEDA
Since November 1, 2018, breach reporting under PIPEDA has been mandatory, not optional. The trigger is a breach of security safeguards that creates a real risk of significant harm to an individual, which the guidance shortens to RROSH.
Significant harm is defined broadly. It includes financial loss, identity theft, humiliation, damage to reputation or relationships, and negative effects on a credit record. The OPC's breach guidance walks through the full assessment, but here is the sequence every site owner should know.
Contain and assess
Stop the exposure, figure out what personal information was involved, and assess the risk. The test weighs how sensitive the information is against how likely it is to be misused.
Report to the Privacy Commissioner
If there is a real risk of significant harm, report the breach to the OPC as soon as feasible. It does not matter whether one person or a million people were affected.
Notify affected people
Notification must be direct and conspicuous. Explain what happened, what information was involved, what you are doing about it, and who they can contact.
Notify anyone who can reduce the harm
That includes other organizations and government institutions, like a payment processor or law enforcement, if telling them could mitigate the damage.
Record every breach
Keep a record of every breach of security safeguards, even the minor ones that never get reported, for at least 24 months. The OPC can ask to see these records at any time.
Fix the gap
Review what failed, update your safeguards, and document the change. A repeat of the same breach looks much worse than the original incident.
Common CASL & PIPEDA Mistakes Website Owners Make
This is one of the most useful sections to audit against because most compliance problems do not start with dramatic breaches. They start with small, sloppy habits that nobody ever cleaned up.
Using one form submission as permission to send marketing emails
A contact form inquiry and a newsletter signup are not the same thing. Separate those consent paths clearly.
Buying or renting email lists
You cannot inherit express consent. The burden of proving every recipient opted in falls on you, and a purchased list can never carry that proof.
Assuming CASL is email-only or consumer-only
CASL covers texts and social media DMs too, and it applies to messages sent to business addresses, not just personal inboxes.
Hiding consent language in vague terms
If a visitor has to guess what they are agreeing to, the wording is not doing its job.
Using a copied privacy policy that does not match the actual website
Your policy should reflect your real forms, tools, scripts, analytics, email practices, and retention habits.
Collecting more information than needed
If a form only needs a name and email, asking for extra fields just in case creates unnecessary privacy risk.
Keeping form submissions forever
Retention should have a reason and a review schedule. Unlimited storage is rarely a good default.
Not knowing where backups or logs are stored
Backup locations, server logs, and third-party platforms are all part of your privacy picture.
Forgetting to include a working unsubscribe link
Commercial email without a proper unsubscribe option is one of the easiest CASL mistakes to avoid.
Not keeping records of email marketing consent
If you cannot show how someone joined your list, when they joined, and what they agreed to, your signup process needs tightening.
A Practical Website Privacy Checklist
If I were auditing a small Canadian website for better privacy hygiene, these are the blocks I would review first. This is not legal advice, but it is a strong practical checklist.
Privacy policy
- Explain what data is collected
- Explain why it is collected
- List major tools or categories of tools being used
- Provide a contact method for privacy questions
Consent and forms
- Use clear form labels and consent language
- Separate newsletter consent from general inquiries
- Avoid pre-checked marketing boxes
- Keep the wording consistent with what really happens
Retention and deletion
- Set a retention window for form submissions
- Review stale lead data on a schedule
- Know what gets backed up and for how long
- Delete information you no longer need
Hosting and infrastructure
- Know where your website data and backups live
- Review access to hosting panels and admin accounts
- Use HTTPS, strong passwords, and 2FA where possible
- Keep CMS, plugins, and server software updated
Analytics and tracking
- Review analytics tools and pixels in use
- Document them in your privacy practices
- Remove tools you no longer need
- Be clear about what third parties may process
Breach readiness
- Have a clear contact for privacy requests
- Keep a simple breach log, even for minor incidents
- Document who does what if a breach happens
- Review the site periodically instead of once and forgetting it
CASL Email Marketing Checklist
CASL is where many newsletter and email marketing issues show up. The easiest way to stay cleaner is to make your signup flow more explicit and your records more organized.
Use clear consent language
Tell people what they are signing up for, what kind of messages they can expect, and how often you may contact them.
Keep newsletter consent separate
Do not hide marketing consent inside a general contact form or a vague footer note.
Do not rely on pre-checked boxes
Express consent requires a positive action. An unchecked box that the user actively selects is the standard, and it is far easier to defend later.
Identify the sender clearly
Your commercial emails should clearly identify your brand or business, include a mailing address, and provide a real contact method.
Include a working unsubscribe link
The link has to keep working for at least 60 days after the message is sent, and unsubscribe requests must be honoured within 10 business days. Faster is better.
Keep signup records
Store who consented, when, from which page or form, and the exact wording they saw. This is the first thing the CRTC asks for in an investigation.
Track implied consent expiry
Purchases give you roughly 2 years and inquiries give you 6 months. Convert those contacts to express consent before the window closes, or stop mailing them.
Provincial Laws and What's Changing in 2026
PIPEDA is the federal baseline, but it is not the whole picture. Three provinces run their own private-sector privacy laws, and the federal law itself is now up for replacement.
Quebec Law 25
The strictest privacy law in Canada, phased in between 2022 and 2024. It applies to any business serving people in Quebec, requires a designated privacy officer and breach reporting to the CAI, and expects tracking technology that can identify or profile a person to be off by default. Penal fines can reach $25 million or 4% of worldwide turnover, with administrative penalties up to $10 million or 2%.
Alberta and BC PIPA
Both provinces have their own Personal Information Protection Acts that are considered substantially similar to PIPEDA and apply to activity within the province. Alberta has required breach reporting since 2010, years before the federal rules. PIPEDA still covers interprovincial and international data flows for businesses in these provinces.
Bill C-36 and the PPCDA
Tabled on June 15, 2026, Bill C-36 would replace PIPEDA's privacy provisions with the Protecting Privacy and Consumer Data Act. It proposes a new regulator, mandatory privacy management programs, a private right of action, and penalties up to the greater of $10 million or 3% of global revenue. It is the third reform attempt after two earlier bills died, and it is only at first reading.
Frequently Asked Questions
Build on Clearer Canadian Infrastructure
Privacy compliance gets easier when you understand your forms, your tools, your retention habits, and where your website data is stored. If you want to compare Canadian-friendly providers, start with the hosting directory.
Browse Canadian Hosts