The short answer
Only for a limited time, unless they opted in. Under Canada's anti-spam law, someone who makes an inquiry through your form gives you implied consent for six months. Someone who buys from you gives you two years. Express consent, gathered with a clear unchecked box, does not expire at all.
The most common email mistake Canadian small businesses make is not spamming strangers. It is assuming that because someone once contacted them, that permission lasts forever. Canada's Anti-Spam Legislation is unusually specific about how long permission lasts, and the answer is almost always shorter than the list you are still emailing.
Two kinds of consent, only one of which expires
CASL recognizes express consent and implied consent, and treating them as interchangeable is where lists go wrong.
Express consent is someone actively agreeing to receive commercial messages from you. It has no expiry date. Once properly obtained, it lasts until the person withdraws it. This makes it enormously more valuable than implied consent, and it is why the checkbox on your signup form is worth designing carefully rather than burying.
Implied consent arises from a relationship rather than a decision, and it comes with a hard deadline built into the statute [1]. The distinction is set out in the Act itself rather than in guidance, which means it is not a matter of interpretation or industry convention [2].
The two clocks: two years and six months
CASL defines an existing business relationship precisely, and the timelines are worth memorizing because they are the whole game [1]:
- Two years from the purchase or lease of a product, goods, a service, land, or an interest in land [1]. The same two-year window applies to accepting a business, investment or gaming opportunity, and to bartering [1].
- Two years from the expiry of a written contract, or for as long as the contract remains in existence [1].
- Six months from an inquiry or application made to you in respect of any of those things [1].
That six-month figure is the one that matters most for websites, because an inquiry is exactly what a contact form produces. Someone asking "do you do bathroom renovations in Moncton?" has made an inquiry. You have six months of implied consent from that date, and then it lapses - silently, with no notification from anywhere.
The practical consequence: a list built from three years of contact form submissions is mostly expired. The people who bought from you within two years are fine. The people who only ever asked a question are not, unless they separately opted in.
Publicly listed addresses are a narrower exception than people think
CASL permits sending to an electronic address that the recipient has conspicuously published, but attaches two conditions: the publication must not be accompanied by a statement that the person does not wish to receive unsolicited commercial messages, and the message must be relevant to the person's business, role, functions or duties [1].
That relevance requirement does real work. A published address on a law firm's contact page is not permission to send them a landscaping promotion. It is arguably permission to send them something a law firm would plausibly want in that capacity. Business-to-business outreach built on scraped address lists usually fails the relevance test long before it fails anything else.
What every commercial message must contain
Consent is only half of compliance. The message itself has mandatory contents [1]:
- Identification of the sender, and of anyone on whose behalf the message is sent if that differs.
- Contact information that remains valid for at least 60 days after the message is sent [1]. A one-off campaign address that dies the following week does not satisfy this.
- An unsubscribe mechanism, which must let the recipient opt out at no cost to them, using the same electronic means the message arrived by, or another practicable electronic means [1].
The unsubscribe deadline is specific: the request must be given effect within 10 business days, without any further action required from the person who made it [1]. "Further action required" rules out reply-to-confirm flows and login-to-manage-preferences walls. If someone has to authenticate to stop hearing from you, the mechanism is not doing what section 11 requires.
The penalties, in proportion
The maximum administrative monetary penalty under CASL is $1,000,000 for an individual and $10,000,000 for any other person [1]. Those ceilings describe sustained, deliberate campaigns rather than a small business with a stale mailing list, and the official guidance is aimed at helping organizations comply rather than at maximizing penalties [3].
The realistic risk for a small business is different in shape: enforcement is complaint-driven. One irritated recipient who cannot find an unsubscribe link is the usual starting point. That means the practical defence is not legal sophistication, it is a working unsubscribe link and an accurate sender line.
Where privacy law overlaps
CASL governs whether you may send the message. Privacy law governs whether you may hold the address at all, and the two are frequently confused.
PIPEDA requires that the purposes for collecting personal information be identified at or before the time of collection [4]. So a form labelled "Request a quote" has collected an address for quoting. Repurposing that address for a monthly newsletter is a second purpose that was never identified, which is a privacy problem independent of anything CASL says about timing [5]. The Privacy Commissioner's consent guidance reinforces that consent has to be specific enough for people to understand what they are agreeing to [6].
PIPEDA's limiting collection principle points the same way: collect only what is necessary for the identified purposes, and do not collect indiscriminately [4].
How to build a form that ages well
The fix is small and belongs at the point of collection, where it costs nothing.
Put one unchecked box under your form: Also send me occasional updates and offers by email. Make it optional, keep it separate from the submit action, and store the date it was ticked along with the submission. That box converts a six-month implied window into express consent with no expiry [1].
Uptake will not be universal, and that is fine. A list of four hundred people who genuinely opted in outperforms two thousand addresses harvested from expired inquiries, and it is the only one of the two you can still legally use in three years.
The record-keeping nobody sets up in advance
If a complaint ever lands, the question will be what consent you had and when you got it. That is a records question, and it is far easier to answer if the records were created at the time rather than reconstructed afterwards from an inbox.
Storing three fields alongside every submission covers it: the date, the exact wording of the consent language shown on the form that day, and which boxes were ticked. The middle one is the one people skip and later regret, because form copy changes over the years and "we have always said that" is not evidence. A dated snapshot of the wording is.
An audit worth an hour
Export your list and add a column for where each address came from and when. Purchases inside two years are covered. Inquiries inside six months are covered. Express opt-ins are covered indefinitely. Anything else needs either a re-permission campaign now, while implied consent may still be running, or removal.
The re-permission email is itself a commercial electronic message, so it needs the sender identification, the durable contact information, and the unsubscribe mechanism [1]. Send it while the clock is still running, not after.
