Canada s Anti-Spam Legislation and Its Impact on US Businesses

From this document you will learn the answers to the following questions:

What does CASL stand for?

What type of property is protected by CASL?

What type of message is protected from CASL?

Similar documents
Crawford Chondon &Partners LLP. Is your Business Ready for Canada s Anti Spam Law?

AN OVERVIEW OF CANADA S ANTI-SPAM LEGISLATION

Canada s New Anti-Spam Regime: Guidance for Your Organization

OHA BACKGROUNDER Canada s Anti-Spam Legislation (CASL)

Managing the message Canada s new anti-spam law sets a high bar

CANADA S ANTI-SPAM LEGISLATION EXCEPTIONS TO ANTI-SPAM RULES

Canada s New Anti-Spam Legislation: Overview and Implications for Businesses

Miller Thomson Legal Alert on Canada s Upcoming Anti-Spam Legislation. Canada s Anti-Spam Legislation (CASL) Are You Ready?

Canada Anti-Spam Legislation: Obligations and Opportunity. Presenters: Matthew Wansink Chris Bakker

CASL Canada s Anti-Spam Law. Webinar One - Consent

Anti-Spam Toolkit February 2014

CASL Compliance: A Primer on Canada's Anti-Spam Legislation. Whitepaper by David O. Klein, Esq.

Privacy Bulletin. Key Differences between US and Canadian Anti-Spam Laws

Guidance on Canada s Anti-Spam Legislation (CASL) for REALTOR Members

B2B Business Relations and Consent Requirements under the New Canadian Anti-Spam Law

Managing the message. Businesses brace for new digital marketing compliance requirements

Preparing for Canada s Anti-Spam Legislation (CASL)

Do It In Durham is a celebration of Global Entrepreneurship Week. 40 events to celebrate, inspire and grow entrepreneurship allowing businesses to

The Canadian Anti-Spam Law (PIPA) andCharity Organizations

Canada s Anti-Spam Legislation What You Need to Know Before July 1. June 19, 2014

Mailworks Anti-Spam Policy

Office of Legal Counsel

Compliance and Enforcement Information Bulletin CRTC

Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance

New Rules for Telemarketing and the National Do Not Call List Telecom Decision Important Implications for IIAC Members

ANTI-SPAM LAWS IN WESTERN COUNTRIES: A COMPARISON

Voter Contact Registry

Marketing: CAN- SPAM Act Compliance David J. Ervin and Christopher M. Loeffler, Kelley Drye and Warren LLP

A SIMPLIFIED EXPLANATION OF CANADA S NEW LAW ON SPAM

Marketing: CAN- SPAM Act Compliance

CANADA S ANTI-SPAM LEGISLATION THIRD PARTY CONTRACTS

CAN-SPAM Policy & Data Verification Guide

Unsolicited Electronic Messages Act 2007

BBB Wise Giving Alliance & The International Committee of Fundraising Organizations Advancing Trust in the Charitable Sector Federal Trade

NATIONAL DO NOT CALL LIST

THE ANTI-SPAM REGULATORY POLICY FRAMEWORK FOR THE KINGDOM OF SAUDI ARABIA

DISCLAIMER. Included on the following pages are questions marketers should be thinking about relative to CASL: Determining if you are affected

PRIVACY, ANTI-SPAM AND YOUR BUSINESS: WHERE DO WE STAND? Presented by: Cameron Mitchell B.A., LL.B.

Advertising & Marketing

AN INTRO TO. Privacy Laws. An introductory guide to Canadian Privacy Laws and how to be in compliance. Laura Brown

Privacy, Data Collection and Information Management Practice Team November 13, 2003

and Text Message Campaigns. Justine Young Gottshall Partner, InfoLawGroup

Election messages communicated over the Internet during the writ period are election advertising only if they have a placement cost.

SERVICES ADDENDUM TO EULA

We ask that you contact our Privacy Officer in the event you have any questions or concerns regarding this Code or its implementation.

Marketing and Canada s Anti-Spam Law

Frequently Asked Questions (FAQ) on Anti-Spam Legislation. What is the definition of a commercial electronic mail message?

Terms and Conditions

CANADIAN PRODUCT LIABILITY LAW

Canada s Anti Spam Legislation (CASL): FAQ

Quick help guide on upcoming antispam legislation and your parish

Arthur Rotatori, McGlinchey Stafford, PLLC Jason Romrell, LeadsMarket.com Dustin Alonzo, McGlinchey Stafford, PLLC. #LEND360 LEND360.

(1) The term automatic telephone dialing system means equipment which has the capacity

Data, Privacy, Cookies and the FTC in Kevin Stark - ExactTarget Maltie Maraj - ExactTarget Nicholas Merker - Ice Miller

Marketing Workshop

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN

COMMENTARY. Hong Kong Strengthens Its Personal Data. on Direct Marketing JONES DAY

Claims Management Regulation. Marketing and Advertising Guidance Note

Privacy Policy and Terms of Use

Our Commitment to You Privacy Statement

The Do Not Call Register Act 2006 and The Spam Act 2003

Spam Act 2003: A practical guide for business

Anti-SPAM Policy v

LAW SOCIETY OF SASKATCHEWAN

HIPAA Privacy and Security Changes in the American Recovery and Reinvestment Act

Messaging Service (SMS) Terms and Conditions

Congress Passes New Anti-Spam Legislation

Electronic Security Association, Inc. Code of Ethics and Standards of Conduct Amended May 14, 2010 by Executive Committee

How To Comply With The Can-Spam Act

Wrong Number: Hot Topics In TCPA Compliance & Litigation

Hibbett Sports Messaging Service (SMS) Terms and Conditions

Navigating the Canadian Anti Spam Legislation. Presented by Marie Wiese September 30, 2014

CASL Survival Guide - CAMP

Privacy Law in Canada

Telemarketing, , and Text Message Marketing: Tips to Avoid Lawsuits

EMERGING ISSUES THE CANADIAN ANTI-SPAM LEGISLATION. BDO Connections - The Canadian Anti-Spam Legislation Page 1

Comparison of Newly Adopted Rhode Island Rules of Professional Conduct with ABA Model Rules RHODE ISLAND

SUMMARY OF PUBLIC LAW THE CAN-SPAM ACT OF 2003

MISLEADING ADVERTISING GUIDE

Broadband Acceptable Use Policy

THE NATIONAL DO-NOT-CALL LIST. Information for REALTOR members

1. The Telephone Consumer Protection Act

Standard of Electronic Fundraising Practice

13-25a-101. Title. This chapter is known as the "Telephone and Facsimile Solicitation Act."

Evolution of HB 300. HIPAA passed in 1996 Originally, HIPAA only directly impacted certain covered entities :

The DMA s Analysis of Can Spam Act of 2003

MODEL POLICY CONCERNING SOLICITATIONS SENT BY

What personal information do we collect from the people that visit our blog, website or app?

Senate. File No Approved by the Legislative Commissioner May 3, 2014

Immigration Assistance Services

Avoiding Internet Advertising and Recruitment Pitfalls

SOFTWARE LICENSE AND NON-DISCLOSURE AGREEMENT

Section 28 Marketing by Means of Telemarketing 1. Generally

SPAM AND PRIVACY ISSUES. Spam for Breakfast, Lunch and Dinner: What will the Unsolicited Electronic Messages Bill do for Privacy?

The Marketing Landscape since CASL: One Year Later

Regulatory Policy. Unsolicited Electronic Communications

Putting Consumers First. Code of Practice The Professional Financial Claims Association. All rights reserved.

SalesPro CRM SUBSCRIPTION AGREEMENT & TERMS USE

THE NATIONAL DO-NOT-CALL LIST. Information for REALTORS

HIPAA and HITECH Compliance Under the New HIPAA Final Rule. HIPAA Final Omnibus Rule ( Final Rule )

Transcription:

(Actual image used will be more applicable to the webinar subject matter) Canada s Anti-Spam Legislation and Its Impact on US Businesses September 4, 2014 Presenters: Jillian Swartz, Blake, Cassels & Graydon LLP Melissa Krasnow, Dorsey & Whitney LLP and Certified Information Privacy Professional/US Erica Kitaev, Practical Law Intellectual Property & Technology (Moderator)

Disclaimer This presentation was created by Blake Cassels & Graydon LLP and Dorsey & Whitney LLP. These slides are intended for general information purposes only and should not be construed as legal advice or legal opinions on any specific facts or circumstances. An attorney-client relationship is not created or continued by sending and/or receiving this presentation. Members of Blake Cassels & Graydon LLP and Dorsey & Whitney LLP will be pleased to provide further information regarding the matters discussed in this presentation. The contact information for the speakers is contained on slide 35. 2

Agenda Overview of Canada s Anti-Spam Legislation (CASL) Application of CASL to US Businesses Anti-spam Provisions Enforcement and Penalties Best Practices and Compliance Strategies Key Issues for M&A and Commercial Agreements Comparing CASL to US Law 3

Overview of CASL Key Prohibitions Sending unsolicited commercial electronic messages (CEMs) to an electronic address Altering transmission data without express consent Installing computer programs without express consent Making false and misleading representations Collecting e-addresses using computer programs without consent Collecting personal information through unauthorized access to a computer system 4

Application of CASL to US Businesses CASL applies to any individual or organization that sends, or causes or permits to be sent, a commercial electronic message if a computer system located in Canada is used to send or access the message, unless the message is subject to an exception specified in CASL. 5

Anti-spam Provisions: What Is Prohibited? CASL Prohibits: Sending a commercial electronic message to an electronic address, unless: Consent (express or implied) has been obtained and Form and content requirements are met 6

Anti-spam Provisions: Key Definitions What is a commercial electronic message (CEM)? A message sent by any means of telecommunication (e.g., text, sound, voice or image) that has as its purpose, or one of its purposes, to encourage participation in a commercial activity An electronic message that requests consent to send a CEM 7

Anti-spam Provisions: Key Definitions (cont d) What is commercial activity? Any transaction that is of commercial character whether or not for profit 8

Anti-spam Provisions: Key Definitions (cont d) What is an electronic address?: An email account @ An instant messaging account A telephone account Any similar account What about social media? Facebook or LinkedIn posts? "Inmails"? 9

Anti-spam Provisions: Express Consent How is express consent obtained? Requires active opt-in May be obtained orally or in writing Request for express consent must clearly and simply state: The purpose(s) for which consent is being sought Specific information about the person seeking consent and, if applicable, the person on whose behalf consent is being sought A statement that the person can withdraw their consent at any time 10

Anti-spam Provisions: Express Consent (cont d) Example used in Compliance and Enforcement Information Bulletin CRTC 2012-549 11

Anti-spam Provisions: Express Consent (cont d) 12

Anti-spam Provisions: Form and Content Requirements What information must be provided in a CEM? Specific information that identifies the sender or person on whose behalf the CEM is sent Statement indicating which person is sending the CEM and which person on whose behalf the message is being sent, if applicable A functional unsubscribe mechanism that meets prescribed requirements 13

Anti-spam Provisions: Form and Content Example 14

Exemptions: Full Exemption from CASL Where the sender reasonably believes the message will be accessed in a specified country and the message conforms to the anti-spam law of that country Personal and family relationships Inquiries sent to a person engaged in a commercial activity in relation to that activity 15

Exemptions: Full Exemption from CASL (cont d) Intra-business messages under certain circumstances Inter-business messages under certain circumstances Responses to requests, inquiries or complaints 16

Exemptions: Full Exemption from CASL (cont d) Messages sent and received on an electronic messaging service under certain circumstances Messages sent to a limited-access secure and confidential account where messages can only be sent by the person who provides the account Messages sent to satisfy certain legal obligations 17

Exemptions: Full Exemption from CASL (cont d) Messages sent by a registered charity for the primary purpose of fundraising Messages sent by a political party, organization or candidate for the primary purpose of soliciting a contribution 18

Exemptions: Exemption from Consent Requirement Certain messages are exempt from the requirement of obtaining consent if they solely: Provide a requested quote or estimate Facilitate or confirm a previously agreed-on commercial transaction Provide warranty/safety information Provide factual information about an ongoing subscription, membership, etc. Provide information related to an employment relationship, etc. Deliver a product, good or service under a prior transaction Form and content requirements still apply 19

Exemptions: Exemption from Consent Requirement (cont d) First messages sent through a third-party referral are exempt if certain conditions are met 20

Exemptions: Implied Consent An organization has implied consent to send CEMs to persons: With whom it has an existing business relationship for a prescribed period of time With whom it has an existing non-business relationship for a prescribed period of time Who voluntarily disclose their electronic address or who conspicuously publish their electronic address: Without indicating they do not wish to receive unsolicited CEMs; and The message is relevant to the person s business, role, functions or duties in a business/official capacity Form and content requirements still apply 21

Transition Period CASL contains a three-year transitional period that extends the period of implied consent if: The parties had an existing business relationship or existing non-business relationship on or before July 1, 2014 (without regard to the time limits that normally apply) The relationship has previously included communication by CEMs; and The recipient has not opted-out of receiving CEMs 22

Enforcement and Penalties Violation Penalty Private Right of Action Sending unsolicited CEMs without consent Failure to include a functional unsubscribe in the prescribed form Failure to effect unsubscribe/opt-out within 10 business days Maximum per breach: C$1-million for individuals C$10-million for corporations Maximum: C$200 per breach, not to exceed C$1-million per day Plus Actual damages suffered or expenses incurred 23

Enforcement and Penalties: Vicarious Liability An officer, director or other manager of a corporation can be held liable for a violation if he or she directed, authorized, assented to, acquiesced in or participated in the commission of the violation An organization can be held liable for a violation by its employee/agent who is acting within the scope of his or her employment/authority Due diligence is a defense 24

Best Practices and Compliance Strategies CATEGORIZE the electronic messages you send by type and recipient CONSIDER whether the electronic messages you send are exempt from CASL DETERMINE whether you have express or implied consent from the recipient ASSESS if the CEM complies with the form and content requirements 25

Best Practices and Compliance Strategies (cont d) MEET with your IT department to develop technology-based solutions to assist the organization to comply with CASL DEVELOP a CASL-compliant request for express consent and send it to your contact database if there is implied consent under CASL ESTABLISH AND ADOPT internal policies to require employees to comply with CASL CREATE a formal training program for all employees and keep track of attendance 26

Best Practices and Compliance Strategies (cont d) SCRUB your contacts database UPDATE contracts to address CASL compliance CREATE a compliance and audit program to ensure ongoing compliance 27

Key Issues for Transactional Lawyers where an M&A Target has a Connection to Canada Due diligence Questions What has been the target s approach to complying with CASL? Does it have a CASL policy? Has it done any employee training? Does the target purchase contact lists? Does the target maintain a central contact database? Is it up-todate? How does it track express and implied consent? Does the target s terms of service include CASL consent? Does the target use a prescribed format for all commercial electronic messages which it sends? 28

Key Issues for Transactional Lawyers where an M&A Target has a Connection to Canada (cont d) Acquisition Agreement Representations and warranties to address CASL CASL policy Status of consents Information about contacts database Status of CASL complaints, if any Transfer of consents Express consents should be transferred as a separate asset Implied consents move with the business by operation of law 29

What to Look for in Commercial Agreements Covenants Obligation to comply with CASL Other specific obligations Requests for consent to comply with CASL Send CEMs only to persons who have consented to receive them CEMs to comply with the form, content and other requirements CEMs include a functional unsubscribe mechanism Employee training Designated contact No false or misleading commercial representations No computer programs are installed on third party computer systems without consent 30

Comparing CASL to US Law Messages covered CASL CAN-SPAM Act TCPA Commercial electronic messages that encourage participation in commercial activity, including: Commercial email messages Text messages - Emails - Text messages - Instant messages - Direct messages through social media sites Scope Applies where one of the purposes of the message is commercial Applies where primary purpose of email is commercial Where an advertisement or constitutes telemarketing 31

Comparing CASL to US Law (cont d) Consent regime Identification requirements CASL CAN-SPAM Act TCPA Requires express opt-in consent (unless exemptions apply or there is implied consent) Sender Opt-out Sender s postal address Requires prior express written opt-in consent for advertisement or telemarketing (unless exemptions apply) Sender Person on whose behalf message is sent Prescribed contact information Unsubscribe requirements Valid for 60 days after message sent Valid for at least 30 days after message sent See Consent regime above Sender must give effect to unsubscribe mechanism within 10 business days Sender must give effect to optout within 10 business days Industry practice is to provide opt out 32

Comparing CASL to US Law (cont d) Penalties/enforcement Federal Regulator CASL CAN-SPAM Act TCPA Administrative monetary penalties of C$1 million for individuals and C$10 million for corporations Private right of action coming into effect July 1, 2017, with C$200 per breach up to C$1 million per day plus damages and expenses Employer liability Vicarious liability for directors and officers Canadian Radio-television and Telecommunications Commission Violation as unfair or deceptive act or practice under Federal Trade Commission Act: Injunctive relief Civil penalties up to US$16,000 per email in violation Other federal and state regulator enforcement Federal Trade Commission Forfeiture penalties, including up to US$16,000 per violation Private right of action: - Injunctive relief - US$500 per violation or US$1,500 for willful or knowing violation State regulator enforcement Federal Communications Commission Competition Bureau Office of the Privacy Commissioner of Canada 33

Related Practical Law Resources Article, Canada s Anti-Spam Legislation and its impact on US Businesses Practice Note, E-mail Marketing: CAN-SPAM Act Compliance Practice Note, Direct Marketing Relevant resources are available with a free, no-obligation trial to Practical Law. Visit Practicallaw.com and request your trial today. 34

Jillian M. Swartz Partner 416-863-3280 jillian.swartz@blakes.com Melissa J. Krasnow Partner 612-492-6106 krasnow.melissa@dorsey.com Questions 35