Living with Canada’s Anti‐Spam Legislation Portfolio Management Association of Canada Toronto Compliance Forum
Adam Kardash Partner, Privacy and Data Management Osler, Hoskin & Harcourt LLP akardash@osler.com 416.862.4703
September 23, 2014
Living with Canadas Anti Spam Legislation Portfolio Management - - PowerPoint PPT Presentation
Living with Canadas Anti Spam Legislation Portfolio Management Association of Canada Toronto Compliance Forum Adam Kardash Partner, Privacy and Data Management Osler, Hoskin & Harcourt LLP akardash@osler.com 416.862.4703 September 23,
September 23, 2014
2
Applies to a broad range of messages (marketing, B2B,
3
Commercial Electronic Message provisions in force July 1, 2014 Computer programming provisions in force January 15, 2015 Private right of action in force July 1, 2017
CRTC Regulations finalized in March 2012. Industry Canada Regulations finalized in December 2013.
Guidelines on the Interpretation of the Electronic Commerce
Guidelines on the use of Toggling as a means of Obtaining
4
Up to $1 million per violation for individuals and $10
Statutory damages up to $200 for each violation of the
5
Any means of telecommunication, including text, sound, voice
Reasonable to conclude that, among its purposes, the message
emails text messages refer‐a‐friend emerging forms of messaging an email or text message that hyperlinks to content “aimed at
6
7
Messages to those with whom there is a personal or
Defined in Industry Canada Regulations Personal Relationship: Sender and recipient have had direct,
Messages that are sent to an individual engaged in
Messages sent between organizations or within
Messages sent in response to a request, inquiry
Messages sent to satisfy legal obligations.
8
Platforms: Messages sent or received on electronic
Information and unsubscribe mechanism required under the Act
Person consents to receive it either expressly or by implication
Closed Messaging Systems: Messages sent to a limited‐
Messages sent or caused or permitted to be sent by a
116 countries listed in the Industry Canada Regulations
9
Express consent may be obtained orally or in writing Positive or explicit indication of consent required (i.e. no
Requests for express consent must include notice about
The purpose for which consent is sought. The name of the person seeking consent. Certain prescribed contact information including the mailing address, and
either a telephone number, email address or web address of the sender.
A statement indicating that the person whose consent is sought can
withdraw their consent.
10
E.g. “[ ] Check here if you would like to receive offers
Unnamed third party (e.g. marketing partner) must
Recipients must be able to unsubscribe from all lists Centralized management of consents across unaffiliated
11
12
There is implied consent where the sender and recipient
Implied consent is time‐limited:
13
There is implied consent where the recipient has:
or where the recipient has:
14
For example, CEMs that solely:
Provide a quote or estimate Facilitate, complete or confirm a commercial transaction Provide warranty information, product recall information or
Provide notification of factual information Deliver a product, goods or service
15
A commercial electronic message may be sent the purpose of
The message must disclose the full name of the referral source
Only applies to the first message sent.
16
installs a computer program (no malware threshold) on
causes an electronic message to be sent from a
the computer system is located in Canada or the person
17
Same general rules as for CEMs
18
enumerated “invasive” function
knowledge and intent that computer will operate
19
20
Requires CASL compliant consent to installation or
Does not provide relief from enhanced
Specified categories of computer programs If conduct makes it reasonable to believe consent
21
22
Determine whether and what type of consent will be required Determine whether CASL’s identity, contact and unsubscribe rules
23
24
Inventory/review of all computer programs Inventory computer updates and upgrades, and “invasive
Review/revise all notices More broadly, consider steps to establish “due diligence”
Internal compliance policies and procedures