CASL, Canada’s Anti-Spam Legislation, has been in force since 2014. Most Canadian contractors have heard of it. Most don’t know exactly what it covers or how it applies to reaching out to GCs after finding their permit on a city database.
This isn’t legal advice. It’s a plain-language read of what the law says, how it applies to B2B outreach in construction, and what to do to stay clean.
What CASL actually covers
CASL applies to “commercial electronic messages”, emails, text messages, and some social media messages sent for a commercial purpose. Calling a GC on the phone is not covered. Sending a LinkedIn connection request typically is not treated as a CEM under CASL, though the content and intent of the message matter. Email and SMS are.
The law requires that you have consent before sending a CEM, that every message identifies the sender, and that every message contains an easy way to unsubscribe.
The consent categories
Express consent is when someone explicitly opts in, fills out a form, checks a box, replies “yes, contact me.” This is the cleanest form of consent and it doesn’t expire (though it can be revoked).
Implied consent is more relevant for cold outreach. CASL recognizes several categories of implied consent:
- An existing business relationship (you’ve worked with this GC before)
- An existing non-business relationship
- The recipient has published their contact information and hasn’t indicated they don’t want to receive commercial messages related to their business role
That third category is the one that matters most for using permit data to reach GCs.
The published contact information exemption
Under CASL, if a person has published their electronic address and hasn’t indicated they don’t want to receive commercial messages, you can contact them, provided the message is relevant to their business role.
A GC whose email is on their company website or listed on a business directory has published their contact information. If you email them about a construction project related to their work as a GC, you’re operating within the implied consent framework.
This exemption has limits. It doesn’t apply if:
- The contact information is published with a statement that they don’t want commercial messages
- The message isn’t related to their professional role or business
A cold email that says “I saw you pulled a permit for [address] and we do mechanical work in that area” is clearly related to their professional role. A promotional email selling something unrelated is not.
What your emails need to include
Regardless of consent basis, every commercial email you send must:
-
Identify you. Your name, your company name, and contact information where you can actually be reached.
-
Make it easy to unsubscribe. This doesn’t need to be a formal unsubscribe mechanism for manual outreach. “Reply to this email and I’ll stop contacting you” works. What doesn’t work is ignoring unsubscribe requests, once someone asks to be removed, the legislation requires you to honour that within 10 business days.
-
Not be deceptive. The subject line has to reflect what’s in the email. No fake RE: or FWD: headers.
What this means for permit-based outreach
If your outreach looks like this, you’re in reasonable shape:
- You found the GC’s email on their company website or a business directory
- You’re emailing them about a specific project where they hold the permit
- Your email identifies you and your company
- If they ask to stop, you stop
Where contractors run into trouble is bulk email to purchased or scraped lists, or sending commercial messages to personal email addresses found through means other than the person’s own publishing.
A GC whose gmail address you found on a Facebook group hasn’t published that for commercial contact. Their company email on their website has been.
The practical approach
Three rules that keep you clean:
Use publicly listed business emails only. Company websites, contractor associations, the permit data itself when the contractor name is listed and their website is findable. Not personal emails, not social media accounts.
Stay relevant. Every email should be about a specific project or a specific service they’d plausibly need given their work. Generic promotional emails are higher risk than targeted, specific ones.
Honour opt-outs immediately. The moment someone asks to stop, they stop. Keep a simple list. This is also just good practice, someone who doesn’t want your emails isn’t going to hire you anyway.
A note on scale
CASL’s enforcement has focused on large-scale spam operations, not individual contractors sending targeted outreach to GCs. That doesn’t mean the law doesn’t apply, it does. It means the risk profile of sending 20 targeted emails a week to GCs you found through permit data is very different from buying a list of 10,000 emails and blasting them.
The law is designed to stop spam. Targeted, relevant outreach to a business contact who has published their information isn’t what the legislators had in mind. That said, understand the rules and follow them.
This post is for general information only. For specific situations, talk to a Canadian lawyer familiar with CASL.
SiteWire finds the GCs holding permits in your area. What you do with that information is up to you.