← The Org Report

CASL for chambers: what your membership software should be doing automatically

CASL for chambers: what your membership software should be doing automatically

No software makes your organization CASL-compliant. That is worth saying first, because a platform that implies otherwise is selling you a false sense of security about a law with real penalties.

What a platform can do is carry the mechanical parts reliably, so the only things left are the ones that genuinely need a human decision. Here is where that line falls.

This is a practical summary rather than legal advice. If your organization has a lawyer, the consent-record question below is the one worth asking them.

What CASL asks of a membership organization

Canada's anti-spam legislation governs commercial electronic messages. Four obligations matter most for a chamber.

Consent, of one of two kinds. Express consent is someone actively agreeing, and it does not expire. Implied consent can arise from an existing business relationship, and it is time-limited. For a membership organization, the membership itself generally supports implied consent, which means it has an end date tied to the relationship rather than lasting forever.

Identification. Every commercial message identifies who is sending it, with contact information that stays valid.

A working unsubscribe. Present in the message, functional after the send, and actioned promptly. The commonly cited standard is ten business days.

Records. You have to be able to show consent existed. In practice this means knowing when it was given, how, and what the person was told at the time.

The fourth is where organizations are most often exposed, and it is the least visible, because nothing goes wrong until someone asks.

What a platform should handle without you thinking about it

Five things are mechanical and should never depend on staff remembering.

Suppression that actually suppresses. One list covering voluntary unsubscribes, hard bounces and spam complaints, checked before every send, with no way to send around it. The failure mode worth asking about is whether a campaign tool can bypass the check. If it can, the list is advisory.

Unsubscribe processing. The link works, the action is recorded immediately, and the person stops receiving marketing without anyone processing a request by hand.

Consent timestamps per person. When consent was given, through what surface, and what the wording said at the time. That last part matters: consent to a notice you have since rewritten is evidence of agreeing to different words.

Sender identification on every message. Enforced by the platform rather than remembered by whoever wrote the email.

The transactional and marketing split. A renewal invoice, a receipt and an event confirmation are not marketing. A newsletter and an event promotion are. The platform should treat them as different categories, so that unsubscribing from marketing does not stop a member receiving their invoice, and so a promotion cannot be tucked inside a receipt to reach people who opted out.

That last one is a design decision more than a feature, and it is the one to probe in a demo. Ask what happens to a member's receipts when they unsubscribe. If the answer is vague, the two categories are not really separate.

What no platform can do for you

Four things stay yours, and a vendor implying otherwise is the warning sign.

Deciding what is commercial. Some messages are obviously marketing and some are obviously transactional. A newsletter that mentions a sponsor sits between, and that judgement is yours.

Getting consent honestly. Software records what happened at the signup form. It cannot make a pre-ticked box into meaningful agreement.

Keeping the relationship real. Implied consent depends on a relationship that actually exists. A platform can time it; it cannot tell you whether the person still considers themselves connected to you.

Answering a complaint. If someone complains to the regulator, your organization answers, using records the platform holds. The platform is where the evidence lives, not who provides it.

What to ask a vendor

Four questions, and the answers should be specific.

Can anything send without checking suppression? Ask about campaigns specifically, and about any bulk or import-driven send. One bypass makes the list decorative.

What exactly is recorded when consent is captured? Timestamp and source is the minimum. Ask whether the wording shown at the time is stored, and what happens to old records when you change that wording.

Can we export the consent records? If you ever need to demonstrate consent, you need the evidence in a form you can hand over, not a screen you can look at.

How are transactional and marketing separated? And specifically, can a marketing message be sent through the transactional path.

How we handle it

Every marketing send passes a consent and suppression gate that the campaign tools cannot bypass; it is one door, and that is enforced in the code rather than by convention. Suppression covers unsubscribes, bounces and complaints together. Consent is written append-only with a timestamp, the source, and a hash of the exact notice text shown at the time, so a later rewording cannot quietly re-describe what someone agreed to. Transactional and marketing are separate paths, and unsubscribing from one never stops the other.

Consent records export with everything else, in JSON, CSV or SQL, at any time.

What we do not do is tell you your organization is compliant. We hold the evidence and enforce the mechanics. The judgement calls above stay with you, and any vendor claiming otherwise is describing a product that does not exist.

More on the practical side of building a sending calendar around this is in how to build a 12-month membership communications calendar.

The Org Report

Get our weekly writing on running a member organization.

One thoughtful post per Tuesday. No spam, unsubscribe any time.