CASL, Canada’s anti-spam legislation, is the most commonly broken marketing rule in Canadian dentistry, and it is broken mostly by practices following American advice in good faith. The US CAN-SPAM regime is built on opt-out: you may email people until they ask you to stop. Canada’s is built on consent: you may not email them until they have agreed, and if challenged, you must prove it.
It sits alongside, not inside, what your college permits in advertising. A message can be perfectly acceptable to your regulator and still breach the federal statute, because the two govern different things.
Does CASL apply to dental practices?
Yes. It applies to any commercial electronic message sent to an electronic address, and it does not carve out healthcare. The CRTC frames the test as a single question: “Is one of the purposes to encourage the recipient to participate in a commercial activity?”
That test, rather than any list of message types, is what determines whether a given message is caught. A newsletter promoting whitening is plainly commercial. A message that mixes a recall reminder with an offer is a harder question, and the mixed message is where most practices actually get into difficulty.
Do appointment reminders count as commercial messages?
Apply the test rather than assuming. A message whose purpose is to confirm an appointment the patient already booked is not obviously encouraging participation in a commercial activity. A message that reminds them of the appointment and also mentions a promotion looks materially different under the same test.
The practical rule that follows: keep transactional messages transactional. If a reminder carries a promotional line, you have arguably converted an operational message into a commercial one and pulled it inside the regime, including the consent requirement and the unsubscribe obligation. Splitting the two message streams costs nothing and removes the question entirely.
No healthcare exemption was found
Nothing in the published CRTC guidance carves dentistry or healthcare out of the anti-spam regime. If someone tells you patient communications are exempt, ask them which provision says so.
What is the difference between express and implied consent?
Express consent is consent the person actively gave. According to the CRTC, “express consent does not expire; however, the recipient has the right to withdraw their consent at any time.”
Implied consent is inferred from a relationship, and unlike express consent it runs out. This is the part practices consistently get wrong.
How long does implied consent last?
| Basis | Duration | Runs from |
|---|---|---|
| Existing business relationship | Two years | “the event that starts the relationship” |
| Enquiry or application | Six months | The enquiry, per paragraph 10(10)(e) |
| Express consent | Does not expire | Until withdrawn |
A patient seen three years ago, with no express consent on file and no qualifying event since, is not someone you can lawfully send a commercial message to. Most dental patient databases contain a very large number of those, and a reactivation campaign to the whole list is precisely the campaign that creates exposure.
Does CASL apply to text messages?
Yes. The CRTC states that “messages that are commercial in nature that are sent over a text messaging service…are subject to CASL”. It also treats direct messages sent through “a social media closed two-way direct messaging system” as messages to electronic addresses, so those are caught too.
Practices frequently assume SMS is outside the regime because it feels more like a phone call than an email. It is not.
What must every message contain?
Two obligations, both mechanical and both easy to satisfy.
- Identification. You must “identify yourself and the persons on whose behalf a commercial electronic message is sent”. If an agency sends on your behalf, both parties are identified.
- An unsubscribe mechanism in every commercial message, and when someone uses it, “you must process the request without delay, and no later than 10 business days after receiving it”.
Who has to prove consent, and what happens if you cannot?
You do. The CRTC is unambiguous: “the onus is on the person who claims that they have obtained consent to prove that they have such consent.”
That single sentence should change how a practice thinks about its patient database. Consent is not something you either have or do not have in the abstract. It is something you can evidence or cannot, and if you cannot, you are treated as not having it. A list imported from an old practice management system with no record of how any address was obtained is, for enforcement purposes, a list without consent.
What are the penalties, and who pays them?
The maximum administrative monetary penalties are, per the CRTC, “for an individual is $1 million. For a business, it is $10 million.”
More relevant to an owner-operated practice is who is exposed. The CRTC confirms that “directors, officers, agents and mandataries of a corporation can be liable, if they directed, authorized, assented to, acquiesced in, or participated in the commission of the violation.”
In a practice the owner is usually also the director, and usually the person who approved the email campaign. There is no meaningful corporate shield between the practice and the individual here. Combine that with the burden of proof sitting on the sender and the exposure is real, even though enforcement against dental practices specifically is not something we found any published record of.
Almost all of this is a systems problem rather than a writing problem, which means it is solved in the CRM and patient conversion layer rather than in the copy.
What should a Canadian dental practice actually do?
- Split transactional from commercial. Reminders, recalls and confirmations in one stream with no promotional content. Anything commercial in another.
- Capture express consent at every entry point, on the new patient form, the website form and at the front desk, and record when and how it was given.
- Store the evidence, not just the flag. The date, the method and the wording shown at the time. A boolean column marked “consented” is not proof.
- Age your list. Anything relying on implied consent needs a date attached and needs to fall out of the commercial stream when the window closes.
- Audit anything that sends on your behalf. Your CRM, your recall software, your agency. You are identified in the message and you carry the exposure.
None of this is difficult. It is simply a different starting assumption from the one most marketing advice is written on, which is why it is worth checking against what your college and the federal statutes permit before running any campaign. Whether you may lawfully use the patient information in the first place is a separate question with a separate answer, and privacy law handles it differently again, and the wider pattern of American advice failing in Canada is set out in this comparison.
One last thing worth sitting with. Every obligation above is discharged by a decision you make once, at the point a patient first gives you their email address. Practices that get that moment right never think about CASL again. Practices that get it wrong inherit a database they cannot lawfully use and usually do not discover it until they try. It is a five minute fix at the front desk and an unsolvable one three years later, which is why it appears so early in how we set a practice up.
This article describes advertising and privacy rules as they applied on the review date shown. Regulations change and vary by province. This is general information, not legal advice. Confirm anything you intend to rely on with your own regulatory college.