
CASL Text Message Rules for Canadian Service Businesses
Last updated: 2026-08-22 · Legal references verified against the Act (laws-lois.justice.gc.ca) and CRTC guidance. This is operator research, not legal advice.
Yes, your business can text customers in Canada - CASL allows it, with two conditions. Status texts about a job the customer already booked ("your part arrived", "ready for pickup") are exempt transactional messages under section 6(6) of the Act. Marketing texts (promotions, seasonal reminders, win-back offers) are commercial electronic messages, and those need consent, sender identification, and a working unsubscribe. The whole game is knowing which of your messages sits on which side of that line, so this guide classifies them one by one.
Most of what ranks for this topic is either the government's own FAQ or a law firm writing for corporate counsel. Neither tells a plumber in Barrie whether "your water heater is in, we can install Thursday" needs an unsubscribe link. (It does not.) So here is the version for people who fix things for a living.
Does CASL even apply to text messages?
It does. CASL is technology neutral - it covers any commercial electronic message sent to an "electronic address", and the Act's definition explicitly includes a telephone account. The CRTC's FAQ spells out that messages sent over a text messaging service are subject to CASL, and ISED's guidance on texting says it plainly: you must obtain consent to send commercial electronic messages, including text messages.
And the regulator is watching the channel. In the CRTC's most recent enforcement report (April to September 2025), the Spam Reporting Centre logged 152,603 complaints, and 24% of the online-form complaints were about SMS - roughly one in four. Text spam is no longer a blind spot.
What counts as a commercial electronic message?
A commercial electronic message (CEM) is any message where it would be reasonable to conclude that one of its purposes is to encourage participation in a commercial activity. One purpose is enough - a text that is 90% status update and 10% upsell is a CEM. And in a detail that surprises most owners, a message asking for consent is itself a CEM under the Act, so you cannot text a cold list to ask permission to text them.
The three obligations on every CEM, from section 6 of the Act:
- Consent - express or implied (more on the difference below)
- Identification - who is sending it, and a valid mailing address plus contact info, kept valid for 60 days after the send
- Unsubscribe - a mechanism the customer can use at no cost, honoured within 10 business days. For SMS, the CRTC's own example is a reply keyword: "text STOP to unsubscribe"
The transactional exemption most guides skip
Here is the part that matters most for a service business, and the part almost nothing ranking on this topic explains. Section 6(6) of CASL lists message types that are exempt from the consent and unsubscribe requirements (identification is still required). The list includes messages that:
- Facilitate, complete or confirm a transaction the recipient previously agreed to enter into
- Provide warranty, recall, safety or security information
- Give factual information about the ongoing use or purchase of a product or service
- Deliver a product or service the recipient is entitled to receive
That carve-out is the legal home of nearly every text a job-tracking workflow sends: booking confirmations, "the technician is on the way", stage updates, "ready for pickup", invoice delivery. The customer agreed to the transaction when they booked the job, and these messages facilitate or complete it. While the exemption is broad, it is also strict about purpose - the moment a message adds promotional content, it stops being exempt and becomes a full CEM.
Which of your texts is which? A message-by-message guide
| The text you send | CASL status | What you need |
|---|---|---|
| "Booked for Thursday 9am, reply to reschedule" | Exempt (confirms the transaction) | Identify your business |
| "Part arrived, your repair starts today" | Exempt (factual, ongoing purchase) | Identify your business |
| "Your furnace is fixed, invoice attached" | Exempt (completes the transaction) | Identify your business |
| "How did we do? Leave us a Google review" | Grey zone, treated as a CEM by cautious operators (it promotes your business) | Consent + ID + unsubscribe |
| "Time for your annual furnace tune-up, book here" | CEM | Consent + ID + unsubscribe |
| "Spring special: 10% off duct cleaning" | CEM | Consent + ID + unsubscribe |
| "We miss you! It's been a year since your last visit" | CEM | Consent + ID + unsubscribe |
The review-request row deserves a note. A plain "how was the service?" feedback ask is arguably factual follow-up on the purchase, but a message whose purpose is to generate public reviews promotes your business, and one commercial purpose is enough. The safe pattern (and the one we built into FixyFlow) is to treat review asks like CEMs: send them to customers you have a real relationship with, identify yourself, and honour opt-outs. Our guide on when to send review request texts covers the timing side.
Express vs implied consent: the two-year clock
CASL recognises two kinds of consent, and the difference is where most owners get tripped up.
Express consent is a real opt-in: the customer checked an unchecked box, signed a form, or said yes on a recorded call. It never expires, and pre-checked boxes do not count. Implied consent comes mostly from an "existing business relationship": a purchase or lease within the last two years, or an inquiry within the last six months, measured back from the day you send each message.
A Shopify merchant in Canada put the operational headache well in a thread on consent record-keeping:
"Implied consent after a business transaction is limited to a two year window... We would have no way of knowing to unsubscribe these people."
That is the real problem: not understanding the rule, but tracking it per customer. A one-truck HVAC outfit with 600 past customers has 600 individual two-year clocks, each restarting on every new job. (In the same thread, another commenter confidently explained that past business counts as express consent. It does not - it creates implied consent with an expiry date. Peer advice on CASL is frequently wrong, which is partly why this article cites the Act directly.)
What actually happens if you get it wrong?
The maximum penalties are the numbers that make headlines: up to $1 million per violation for an individual and $10 million for a corporation. The enforcement record tells a more proportionate story:
- Compu-Finder (2015) - the first CASL penalty, $1.1 million for unsolicited training-course emails, reduced to $200,000 on review
- Sami Medouni (2023) - $40,000 for a high-volume phishing text campaign, the clearest SMS-specific CASL penalty to date
- Gap Inc. (2021) and DavidsTea (2023) - undertakings of $200,000 and $40,000 respectively, both with mandatory compliance programs
- Hudson's Bay (2024) - a $120,000 undertaking after messages kept flowing to people who had unsubscribed
Two honest observations from that list. First, nobody is fining a plumber $10 million; enforcement has focused on volume senders and bad actors, and the private right of action (which would have let individuals sue for $200 per message) has been suspended since 2017. Second, the pattern in the retail cases is instructive: the violations were mostly process failures - unsubscribes not honoured, consent records missing - not villainy. A $40,000 undertaking would be a very bad year for most shops, and the customer on the receiving end reports you in seconds. One Edmonton resident described doing exactly that to a dealership that kept texting after a STOP reply: "So now I am reporting them every time at Fight Spam."
CASL is not 10DLC (and you may need both)
If you text through a US-based platform, you have probably met A2P 10DLC registration - the US carrier system that registers business traffic so it gets delivered. It is easy to assume that passing 10DLC review means you are compliant in Canada. It does not. 10DLC is carrier infrastructure; CASL is law. One decides whether your message gets delivered, the other decides whether you were allowed to send it at all. A Canadian shop can be fully 10DLC-registered and still offside CASL on every marketing blast it sends. (The reverse is also true - CASL-clean consent records do nothing for US deliverability.) For the broader list of ways shops get their numbers suspended, see our piece on SMS compliance mistakes.
The consent-record habit that makes this easy
The CRTC's 2016 enforcement advisory says the quiet part: under section 13 of the Act the burden of proving consent is on the sender, and businesses investigated by the CRTC are "frequently unable" to prove the consent they claim. The fix is boring and cheap:
- Put an unchecked opt-in box on your intake form ("Send me service reminders and offers by text") - our intake form generator includes one
- Log the date, time and wording of every opt-in, and keep the record as long as you use the consent
- Keep your unsubscribe log, and honour STOP replies within 10 business days (in practice: immediately and automatically)
- Identify your business name in the message and keep a valid contact address on your site
Where FixyFlow sits in this: the texts FixyFlow sends for you are the section 6(6) kind - booking confirmations, stage updates, "ready for pickup", invoice links - tied to a job the customer booked, sent from an identified business. Review asks go only to your actual customers, and opt-outs are handled automatically.
Every message is logged against the job, so "when did this customer consent and what did we send them" is a lookup, not an archaeology project. Plans start free (5 jobs/month) - see pricing.
The bottom line for Canadian service businesses
Text your customers. The data on why is unambiguous - vendor benchmarks consistently put SMS open rates near 98% against roughly 20-28% for email - and CASL was never meant to stop a business from telling a customer their furnace is fixed. The rules reduce to three habits: keep status texts factual, get a real opt-in before marketing texts, and keep the records that prove it. Do that and you are more compliant than most of the businesses texting you.
Sources: CASL (S.C. 2010, c. 23), ss. 1, 6, 10, 13; CRTC CASL FAQ; CRTC enforcement report, Sep 2025; CRTC Decision 2017-368 (Compu-Finder); CRTC enforcement actions; ISED: Texting and good client relations; CRTC enforcement advisory on consent records. This article is general information, not legal advice - for a specific situation, talk to a lawyer who works in Canadian communications law.
- Lasse / Built FixyFlow in Collingwood