Skip to main content
Canadian Privacy & Email Compliance

CASL & PIPEDA Compliance for Canadian Websites

I put this guide together for Canadian website owners who want a plain-language explanation of privacy and email marketing compliance. If your site has contact forms, a newsletter, analytics, checkout pages, or customer accounts, CASL and PIPEDA are the two laws you will run into first.

Updated for 2026, including the Bill C-36 privacy reform tabled in June. One quick note before we start: this is general information from a website owner's perspective, not legal advice.

CASL and PIPEDA compliance guide for Canadian websites and online businesses
01

Quick Answers Before the Deep Dive

If you only have two minutes, these are the facts I would want every Canadian site owner to walk away with. Everything below is explained in more detail further down the page.

PIPEDA is the privacy law

It governs how you collect, use, protect, and retain personal information in commercial activity. The Office of the Privacy Commissioner of Canada oversees it.

CASL is the anti-spam law

It governs marketing emails, texts, and other commercial electronic messages. The CRTC enforces it, and it is opt-in, not opt-out.

The penalties are serious

CASL penalties can reach $10 million per violation for a business. PIPEDA breach reporting offences carry fines up to $100,000.

Breach reporting is mandatory

Breaches that create a real risk of significant harm must be reported to the Privacy Commissioner, and you must keep records of every breach for 24 months.

Pre-checked boxes do not count

Express consent under CASL needs a positive action. An already-ticked newsletter box does not meet the standard.

Big changes are coming

Bill C-36, tabled in June 2026, would replace PIPEDA with a new law called the PPCDA. It is not law yet, but it is worth watching.

02

What Is PIPEDA?

PIPEDA is Canada's federal private-sector privacy law. It came into force in 2001 and was fully phased in by 2004.

In simple terms, it is about how organizations collect, use, disclose, protect, and retain personal information during commercial activity. There is no small business exemption, so a one-person shop with a contact form is covered just like a national retailer.

The law is built on 10 fair information principles, covering things like accountability, consent, limiting collection, safeguards, and openness. For a website owner, those principles show up in everyday places: contact forms, quote requests, newsletter signups, analytics, ecommerce checkout, support tickets, server logs, and backups.

What PIPEDA focuses on

  • Personal information and why it is collected
  • Meaningful consent and clear explanations
  • Privacy safeguards and reasonable protection
  • Retention limits, access requests, and breach handling

Why it matters

  • It helps build trust with Canadian visitors
  • It forces cleaner data handling practices
  • It reduces risk from weak policies and vague consent
  • It makes your website feel more credible and professional
A simple way I think about PIPEDA is this: if your website collects information about real people, you should be able to explain what you collect, why you collect it, how you protect it, and when you delete it.
03

What Is CASL?

CASL is Canada's anti-spam legislation, in force since July 1, 2014. It is widely considered one of the strictest anti-spam laws in the world.

CASL covers commercial electronic messages, usually shortened to CEMs. That means marketing emails and newsletters, but also promotional texts and even direct messages on social platforms if they encourage a commercial activity.

The single most important thing to understand is that CASL is an opt-in law. You need consent before you send, and if the CRTC ever asks, the burden of proving that consent falls on you, not the recipient. The government's CASL information site is a solid starting point if you want the official overview.

Every commercial message needs

  • Consent from the recipient, either express or implied
  • Clear identification of who is sending it, including a mailing address and contact method
  • A working unsubscribe mechanism that is easy to use

Key things site owners miss

  • CASL applies to texts and social DMs, not just email
  • It applies to B2B messages, not just consumer marketing
  • It applies based on where the recipient is, so senders outside Canada are still covered
  • Express consent never expires, but implied consent does
If a message would make a reasonable person think one of its purposes is to encourage a purchase or other commercial activity, treat it as a CEM and apply the three requirements above.
04

CASL vs PIPEDA: What's the Difference?

This is the point where a lot of website owners get confused, so here is the clean version. PIPEDA is mostly about privacy and personal information. CASL is mostly about commercial electronic messages, like marketing emails, newsletters, some sales outreach, and similar electronic promotions.

PIPEDA covers

How your website handles personal information during commercial activity.

  • Privacy policy and openness
  • Personal information collection
  • Consent for data handling
  • Safeguards and security practices
  • Access requests and corrections
  • Retention and deletion decisions
  • Breach records and notification duties

CASL covers

How your business sends commercial electronic messages to people.

  • Newsletter and email marketing consent
  • Commercial email content
  • Sender identification
  • Working unsubscribe links
  • Signup records and proof of consent
  • Promotional follow-up messages
  • Certain abandoned cart and automated message scenarios

Side by side comparison

  PIPEDA CASL
What it governs Collection, use, disclosure, protection, and retention of personal information Commercial electronic messages such as marketing emails, texts, and DMs
In force since 2001, fully phased in by 2004 July 1, 2014
Who enforces it Office of the Privacy Commissioner of Canada (OPC) CRTC, with roles for the OPC and Competition Bureau
Who it applies to Private-sector organizations handling personal information in commercial activity Anyone sending commercial electronic messages to recipients in Canada
Core duty Meaningful consent, reasonable safeguards, limited retention, accountability Prior consent, sender identification, and an unsubscribe option in every message
Top penalties Fines up to $100,000 per offence for breach reporting violations Up to $1 million per violation for individuals, $10 million for businesses
If you want the shortest answer: PIPEDA is about data. CASL is about messages. Most business websites end up touching both.
05

Consent Rules Explained

Consent is the backbone of both laws. Under PIPEDA, visitors should understand what information you are collecting, why you are collecting it, how it will be used, whether it will be shared, and how they can contact you about it.

Here is how that plays out in the three places most websites collect information.

πŸ“

Contact forms

Tell users why you need their name, email, phone number, or project details before they submit the form. The more direct the explanation is, the better.

πŸ“§

Newsletter forms

Separate marketing consent from general contact requests. I would not treat a general inquiry as automatic permission to send ongoing promotional emails.

πŸ“Š

Analytics and tracking

Be clear about analytics, advertising pixels, embedded tools, and third-party scripts that may process visitor information or behaviour data.

On the CASL side, consent comes in two flavours: express and implied. Express consent is a deliberate opt-in and never expires until the person withdraws it.

Implied consent comes from an existing relationship, and this is the part people get wrong: it has expiry dates. The CRTC's CASL FAQ covers the fine print, but the table below is the short version.

CASL consent types at a glance

Consent type How you get it How long it lasts
Express consent An active opt-in, like an unchecked box the user ticks or a dedicated signup form Does not expire until the person unsubscribes
Implied: business relationship The person bought something from you or entered a contract Generally 2 years from the last purchase or transaction
Implied: inquiry The person asked about your products or services 6 months from the date of the inquiry
Implied: published or shared address The address was conspicuously published, or given directly to you, with no statement declining messages Only while the message is relevant to the person's role or business
The practical takeaway: build your list on express consent wherever you can. It never expires, it is easy to defend, and it keeps your open rates healthier than a list padded with people who barely remember you.
06

What Counts as Personal Information on a Website?

Many site owners assume they only handle personal information if they run a large ecommerce store. In reality, even a simple service business website can collect more than it realizes.

πŸ“

Contact form submissions

Name, email, phone number, project details, and any notes a visitor shares with you.

πŸ“§

Newsletter signups

Email addresses, consent records, source pages, and signup timestamps.

πŸ“Š

Website analytics

Analytics data, user behaviour, and tracking data from tools such as Google Analytics or similar platforms.

πŸ›’

Ecommerce checkout details

Billing details, shipping details, order history, account activity, and transaction records.

πŸ‘€

Customer accounts

Login data, saved preferences, profile information, and support history.

πŸ’¬

Support tickets and chat

Messages, attachments, troubleshooting notes, and customer follow-up records.

🧩

Embedded scripts or widgets

Third-party forms, pixels, chat tools, and plugins that process visitor data behind the scenes.

πŸ—„οΈ

Backups and hosting logs

Server logs, security logs, backups, and administrative records stored by your site or host.

07

Penalties and Who Enforces What

The headline numbers get quoted a lot, so let me put them in one place. These are statutory maximums per violation, not typical outcomes.

$10M

Max CASL penalty per violation for a business

$1M

Max CASL penalty per violation for an individual

$100K

Max PIPEDA fine per offence for breach reporting violations

$25M

Max penal fine under Quebec Law 25, or 4% of worldwide turnover

Real-world penalties are usually far below the maximums. The CRTC scales penalties based on the nature of the violation, cooperation, self-correction, and ability to pay.

In one early case, a $1.1 million notice of violation was ultimately set at $200,000 after review. The other cost people forget is the investigation itself, because a notice to produce means handing over consent records and email logs whether or not a fine ever lands.

CRTC

  • Enforces CASL's message and software installation rules
  • Can investigate, demand records, and issue notices of violation with penalties
  • Also accepts undertakings, which are negotiated settlements with compliance conditions

Privacy Commissioner (OPC)

  • Oversees PIPEDA, investigates complaints, and publishes findings
  • Handles CASL's address harvesting provisions
  • Can refer offences, like breach reporting failures, for prosecution

Competition Bureau

  • Handles false or misleading representations in electronic messages
  • Covers deceptive subject lines, sender info, and message content
  • Operates under the Competition Act alongside CASL

Provincial regulators

  • Quebec's CAI enforces Law 25 with GDPR-scale penalties
  • Alberta and BC commissioners enforce their provincial PIPA laws
  • More on the provincial layer in section 12
Directors and officers can be personally liable under CASL, and individuals have been fined directly. Small does not mean invisible, since most investigations start from complaints filed by ordinary recipients.
08

Data Breach Rules Under PIPEDA

Since November 1, 2018, breach reporting under PIPEDA has been mandatory, not optional. The trigger is a breach of security safeguards that creates a real risk of significant harm to an individual, which the guidance shortens to RROSH.

Significant harm is defined broadly. It includes financial loss, identity theft, humiliation, damage to reputation or relationships, and negative effects on a credit record. The OPC's breach guidance walks through the full assessment, but here is the sequence every site owner should know.

Knowingly failing to report, notify, or keep breach records is an offence under PIPEDA with fines up to $100,000. If a processor or host holds your data when a breach happens, you are still accountable for it, which is a good reason to know exactly where your website data lives.
09

Common CASL & PIPEDA Mistakes Website Owners Make

This is one of the most useful sections to audit against because most compliance problems do not start with dramatic breaches. They start with small, sloppy habits that nobody ever cleaned up.

Using one form submission as permission to send marketing emails

A contact form inquiry and a newsletter signup are not the same thing. Separate those consent paths clearly.

Buying or renting email lists

You cannot inherit express consent. The burden of proving every recipient opted in falls on you, and a purchased list can never carry that proof.

Assuming CASL is email-only or consumer-only

CASL covers texts and social media DMs too, and it applies to messages sent to business addresses, not just personal inboxes.

Hiding consent language in vague terms

If a visitor has to guess what they are agreeing to, the wording is not doing its job.

Using a copied privacy policy that does not match the actual website

Your policy should reflect your real forms, tools, scripts, analytics, email practices, and retention habits.

Collecting more information than needed

If a form only needs a name and email, asking for extra fields just in case creates unnecessary privacy risk.

Keeping form submissions forever

Retention should have a reason and a review schedule. Unlimited storage is rarely a good default.

Not knowing where backups or logs are stored

Backup locations, server logs, and third-party platforms are all part of your privacy picture.

Forgetting to include a working unsubscribe link

Commercial email without a proper unsubscribe option is one of the easiest CASL mistakes to avoid.

Not keeping records of email marketing consent

If you cannot show how someone joined your list, when they joined, and what they agreed to, your signup process needs tightening.

10

A Practical Website Privacy Checklist

If I were auditing a small Canadian website for better privacy hygiene, these are the blocks I would review first. This is not legal advice, but it is a strong practical checklist.

Privacy policy

  • Explain what data is collected
  • Explain why it is collected
  • List major tools or categories of tools being used
  • Provide a contact method for privacy questions

Consent and forms

  • Use clear form labels and consent language
  • Separate newsletter consent from general inquiries
  • Avoid pre-checked marketing boxes
  • Keep the wording consistent with what really happens

Retention and deletion

  • Set a retention window for form submissions
  • Review stale lead data on a schedule
  • Know what gets backed up and for how long
  • Delete information you no longer need

Hosting and infrastructure

  • Know where your website data and backups live
  • Review access to hosting panels and admin accounts
  • Use HTTPS, strong passwords, and 2FA where possible
  • Keep CMS, plugins, and server software updated

Analytics and tracking

  • Review analytics tools and pixels in use
  • Document them in your privacy practices
  • Remove tools you no longer need
  • Be clear about what third parties may process

Breach readiness

  • Have a clear contact for privacy requests
  • Keep a simple breach log, even for minor incidents
  • Document who does what if a breach happens
  • Review the site periodically instead of once and forgetting it
On retention specifically, I would rather see a simple documented rule than no rule at all. Even a small business can decide, for example, that stale contact submissions are reviewed and purged after a defined period unless there is an active customer relationship or a legal reason to keep them.
11

CASL Email Marketing Checklist

CASL is where many newsletter and email marketing issues show up. The easiest way to stay cleaner is to make your signup flow more explicit and your records more organized.

12

Provincial Laws and What's Changing in 2026

PIPEDA is the federal baseline, but it is not the whole picture. Three provinces run their own private-sector privacy laws, and the federal law itself is now up for replacement.

⚜️

Quebec Law 25

The strictest privacy law in Canada, phased in between 2022 and 2024. It applies to any business serving people in Quebec, requires a designated privacy officer and breach reporting to the CAI, and expects tracking technology that can identify or profile a person to be off by default. Penal fines can reach $25 million or 4% of worldwide turnover, with administrative penalties up to $10 million or 2%.

πŸ”οΈ

Alberta and BC PIPA

Both provinces have their own Personal Information Protection Acts that are considered substantially similar to PIPEDA and apply to activity within the province. Alberta has required breach reporting since 2010, years before the federal rules. PIPEDA still covers interprovincial and international data flows for businesses in these provinces.

πŸ›οΈ

Bill C-36 and the PPCDA

Tabled on June 15, 2026, Bill C-36 would replace PIPEDA's privacy provisions with the Protecting Privacy and Consumer Data Act. It proposes a new regulator, mandatory privacy management programs, a private right of action, and penalties up to the greater of $10 million or 3% of global revenue. It is the third reform attempt after two earlier bills died, and it is only at first reading.

What should you do about C-36 right now? Nothing dramatic. PIPEDA is still the law, and the habits in this guide, meaning clear consent, honest policies, sensible retention, and a breach log, are exactly the foundation the new law would build on.
13

Frequently Asked Questions

What is the difference between CASL and PIPEDA?
PIPEDA governs how organizations collect, use, disclose, protect, and retain personal information during commercial activity. CASL governs commercial electronic messages such as marketing emails, newsletters, and promotional texts. PIPEDA is overseen by the Office of the Privacy Commissioner of Canada, while CASL's message rules are enforced by the CRTC. Most business websites touch both laws.
What are the penalties for violating CASL?
The maximum administrative monetary penalty under CASL is $1 million per violation for an individual and $10 million per violation for a business. Real penalties are usually much lower and scale with factors like the nature of the violation, cooperation, and ability to pay, but enforcement actions have still landed in the tens and hundreds of thousands of dollars.
Does PIPEDA apply to my small business?
Yes, if you collect, use, or disclose personal information during commercial activity. There is no small business exemption. In Alberta, British Columbia, and Quebec, substantially similar provincial laws cover activity within the province, but PIPEDA still applies to interprovincial and international data flows.
Does CASL apply to B2B emails?
Yes. CASL applies to commercial electronic messages sent to any electronic address, including business addresses. There are limited exemptions and implied consent categories for existing business relationships, but a work email address is not automatically fair game for marketing.
What counts as implied consent under CASL?
The most common categories are an existing business relationship, such as a purchase within the last 2 years, and an inquiry about your products or services within the last 6 months. A conspicuously published address, or one given directly to you, can also qualify if the message relates to the person's role. Implied consent expires, while express consent does not.
Do I need separate consent for newsletter signups?
Usually, yes. A person contacting you for information is not necessarily agreeing to receive ongoing marketing emails. The cleaner approach is to give newsletter signups their own unchecked checkbox or form with clear wording, and to keep a record of that consent.
Can I use a pre-checked newsletter box in Canada?
No, not for express consent. CRTC guidance treats express consent as requiring a positive action, so a box that is already ticked does not meet the standard. Use an unchecked box that the user actively selects, and keep proof of when and how they opted in.
Does CASL apply to abandoned cart emails?
It can. If the message encourages a purchase or contains promotional content, CASL is likely relevant. Review the purpose of the email, the consent you are relying on, and whether the message is truly transactional or partly promotional.
Does PIPEDA apply to Google Analytics or tracking pixels?
Potentially, yes. If analytics or tracking tools collect or help process information about identifiable individuals, they should be accounted for in your privacy practices and explained clearly to visitors. Quebec's Law 25 goes further and expects tracking technologies that can identify, locate, or profile a person to be off by default.
Do I have to report a data breach under PIPEDA?
Yes, if the breach creates a real risk of significant harm. You must report it to the Privacy Commissioner of Canada as soon as feasible, notify affected individuals, and notify any organization that could reduce the harm. You must also keep a record of every breach, even minor ones, for at least 24 months.
How long should I keep contact form submissions?
Only as long as needed for the purpose they were collected, plus any legitimate legal, accounting, security, or operational reasons. Keeping submissions forever is a poor default. A documented review and deletion schedule is much better than unlimited retention.
Does my website data have to be stored in Canada?
Generally no. PIPEDA does not prohibit storing personal information outside Canada, but you remain accountable for it, must ensure comparable protection through contracts, and should be transparent about foreign storage. Quebec adds stricter transfer assessment requirements. Many businesses still choose Canadian hosting for latency, trust, and simpler answers to those questions.
Does Canadian hosting make my site automatically PIPEDA compliant?
No. Hosting location can support a stronger privacy posture, but it does not replace the need for a real privacy policy, clear consent, good safeguards, reasonable retention practices, and a working breach response process.
Do small Canadian businesses need a privacy policy?
If your website collects personal information, even through a basic contact form, a privacy policy is strongly recommended and often expected. It should explain what you collect, why you collect it, how you use it, how long you keep it, and how someone can reach you with a privacy question.
Keep it practical

Build on Clearer Canadian Infrastructure

Privacy compliance gets easier when you understand your forms, your tools, your retention habits, and where your website data is stored. If you want to compare Canadian-friendly providers, start with the hosting directory.

Browse Canadian Hosts