Two recent CRTC enforcement actions provide another reminder that CASL compliance does not end when someone clicks an unsubscribe link.

On October 1, 2026, PH Canada Company, doing business as Pizza Hut, entered into an undertaking with the CRTC that included a $500,000 monetary payment. Less than two months earlier, Indeed Canada Corp. entered into a separate undertaking involving a $200,000 payment.

The timing is notable. Before the Indeed undertaking, the last significant CASL enforcement action involving a monetary consequence listed by the CRTC was a $50,000 Notice of Violation issued to Jimmy Genesse on August 13, 2025. Almost a year passed before the Indeed undertaking was announced.

Now, within roughly seven weeks, the CRTC has announced two CASL compliance undertakings representing $700,000 in payments.

That does not mean CASL enforcement stopped during the intervening year. Public enforcement announcements only provide part of the picture. The CRTC’s latest published CASL enforcement dashboard shows continued compliance and enforcement activity, including warning letters, notices to produce, preservation demands, and other investigative work. Still, the timing and size of these two undertakings are worth paying attention to.

More importantly for email marketers, both cases involve fundamental requirements that have existed under CASL for years: consent, functional unsubscribe mechanisms, and actually honouring unsubscribe requests.

The Pizza Hut undertaking is particularly notable. At $500,000, it appears to be the largest monetary payment associated with a CASL undertaking published by the CRTC to date.

Pizza Hut: $500,000 CASL undertaking

On October 1, 2026, PH Canada Company, doing business as Pizza Hut, entered into an undertaking with the CRTC concerning alleged CASL violations occurring between January 1, 2025, and February 12, 2026.

According to the CRTC, the alleged violations covered three important areas.

  • First, commercial electronic messages (CEMs) were allegedly sent, caused, or permitted to be sent to Canadian consumers without the required express or implied consent. This concerned paragraph 6(1)(a) of CASL.
  • Second, the CRTC alleged that unsubscribe requests were not given effect within the required 10 business days. This concerned subsection 11(3).
  • Third, some CEMs were allegedly sent without an unsubscribe mechanism. This concerned paragraph 6(2)(c) and subsection 11(1).

The resulting undertaking requires PH Canada Company to make a $500,000 payment to the Receiver General for Canada. The company also agreed to review and, where necessary, enhance its CASL compliance program.

Importantly, those commitments include ensuring that third parties authorized to send CEMs on its behalf comply with CASL and the applicable regulations.

Indeed Canada: $200,000 CASL undertaking

The August 10 undertaking involving Indeed Canada Corp. covers somewhat narrower allegations, but there is considerable overlap.

The CRTC alleged that between February 1, 2025, and February 1, 2026, Indeed sent or caused CEMs to be sent to Canadian consumers who had already withdrawn their consent.

The CRTC also alleged that messages did not consistently contain an unsubscribe mechanism that could be readily performed. The undertaking cites alleged contraventions of paragraph 6(1)(a), subsection 11(3), and subsection 3(2) of the CRTC’s Electronic Commerce Protection Regulations.

Indeed agreed to make a $200,000 monetary payment to the Receiver General for Canada. It also agreed to review and, where necessary, enhance its compliance program.

As with the Pizza Hut undertaking, Indeed committed to ensuring third parties authorized to send CEMs on its behalf comply with CASL and the applicable regulations.

The common thread: unsubscribing must actually work

CASL requires more than placing an unsubscribe link somewhere near the bottom of an email.

The unsubscribe mechanism must allow recipients to indicate that they no longer want CEMs. Once a recipient withdraws consent, that request must be given effect without delay and, in any event, no later than 10 business days. That distinction matters operationally.

A perfectly functional unsubscribe link does not solve the compliance problem if the suppression never reaches another ESP, CRM, franchise system, business unit, or agency. Likewise, a central suppression database provides little protection if a local marketing platform can continue sending independently.

The Pizza Hut undertaking is especially relevant for organizations with distributed marketing operations. The CRTC alleges that PH Canada Company “sent or caused or permitted to be sent” the CEMs. Its undertaking also specifically addresses third parties authorized to send CEMs on the company’s behalf.

Indeed’s undertaking contains a similar third-party compliance commitment.

Outsourcing the sending does not outsource the compliance responsibility.

Organizations impacted

These cases should be relevant to Canadian senders, international brands messaging Canadians, franchises, agencies, ESP customers, and organizations using several marketing platforms or local operators.

Franchise and distributed marketing models deserve particular attention. A recipient may believe they unsubscribed from a brand, while the organization’s systems interpret that request as applying only to one location, list, campaign, or platform.

The same problem can occur when marketing teams operate several ESPs or when sales, transactional, and marketing platforms maintain separate contact records. An unsubscribe that stays trapped inside one system may not accomplish what the recipient requested.

That difference can become a compliance problem very quickly.

Actions to consider

Organizations should review the complete unsubscribe path, rather than simply testing whether the link in an email works.

That review should include:

  • Consent evidence attached to each address and sending purpose
  • Suppression propagation across ESPs, CRMs, franchises, and agencies
  • Processing times measured from the recipient’s request
  • Templates or systems capable of omitting unsubscribe functionality
  • Contracts, controls, and audit evidence for third-party senders

Testing should follow an unsubscribe from the recipient’s click through every system capable of initiating another CEM. If one forgotten platform can still send, the suppression process is not complete.

CASL allows up to 10 business days to give effect to an unsubscribe request, but organizations should not treat that period as their operational target. Immediate or same-day suppression should be the goal wherever practical.

Ten business days is a legal ceiling, not a service-level ambition.

Organizations should also be able to demonstrate that the process worked. Logs showing when the request was received, when suppression occurred, and which systems received the update can become valuable compliance evidence.

A useful CASL compliance warning

Neither case introduces a new CASL requirement. Consent and unsubscribe obligations have been part of the legislation for years.

What these undertakings demonstrate is the operational risk created when compliance rules do not survive contact with real marketing infrastructure. Multiple platforms, third-party senders, franchises, legacy databases, and disconnected suppression lists can turn a simple unsubscribe request into a surprisingly complicated workflow.

That complexity does not make the requirement disappear.

The enforcement timeline is also worth watching. After almost a year without a publicly listed CASL enforcement action involving a monetary consequence, the CRTC announced two substantial undertakings within roughly seven weeks.

That alone does not establish a change in enforcement strategy. However, $700,000 in payments across two cases should be enough to get the attention of organizations that have allowed their consent and unsubscribe processes to run on autopilot.

For organizations operating several sending systems, this is a good time to test the process from the recipient’s perspective.

Subscribe. Unsubscribe. Then determine whether every system actually got the message.

The unsubscribe link is only the beginning of that test.

This article discusses CASL from an email marketing and compliance operations perspective. It is not legal advice. Organizations with questions about their specific obligations should consult qualified legal counsel.