Your Unsubscribe Link Won't Save You Anymore — and Your Open-Tracking Pixels Could Be the Next Legal Liability
What happens when both the sender and the platform demand explicit consent before you even hit “send”? That’s the new reality for cold email marketers targeting Canadian prospects or relying on AWS SES for delivery. Canada’s anti-spam regulator has stopped treating non-compliance as a learning exercise. Amazon Web Services has added a send-time toggle for open and click tracking that forces you to honor individual tracking preferences. Two separate forces — one legal, one technical — are converging to kill every gray area around implied consent. The unsubscribe link you’ve been leaning on? That’s table stakes. The tracking pixel you drop without asking? That’s now a liability.
The old playbook said: “Send the email, include an unsubscribe link, and you’re compliant.” That was never true under Canada’s Anti-Spam Legislation (CASL), but enforcement was sporadic. Now it’s systematic. And AWS’s new tracking consent rule means you can’t even collect engagement data without proving you have the right to do so — at the moment of sending.
The CRTC Has Stopped Playing Nice: CASL Investigations Are Ramping Up
Canada’s telecommunications regulator, the CRTC, has told businesses to expect stronger enforcement. In its latest CASL enforcement snapshot, covering October 2025 to March 2026, the message is blunt: more than a decade after the law was introduced, the regulator is less inclined to treat non-compliance as a learning exercise. The data backs that up.
During that six-month period, Canada’s Spam Reporting Centre received 189,908 submissions — an average of 7,304 per week. Among the complaints that used the detailed reporting form, email accounted for 60% of reported spam, SMS for 34%. The primary reason? Lack of consent. That was cited in 93% of complaints. Failure to identify the sender came in at 48%, and deceptive marketing practices at 46%. The CRTC also highlighted broken unsubscribe links and processes that made opting out unnecessarily difficult.
Those aren’t just numbers. They’re the basis for investigations. The regulator issued 11 warning or information letters, 96 notices to produce, and two preservation demands during the period. The ratio of evidence-gathering notices to warning letters is telling. The CRTC isn’t sending out friendly reminders — it’s building cases. The report states that the commission intends to use stronger enforcement measures where appropriate, including administrative monetary penalties proportional to the seriousness of the violation. Businesses can face penalties up to C$10 million per violation.
CASL’s core requirements haven’t changed: for any commercial electronic message, you need valid consent, clear sender identification, and a working unsubscribe mechanism. The law is the same as it was in 2014. What’s different is the regulator’s patience. The snapshot makes it clear: “heightened expectation” of compliance. If you’re sending cold emails to Canadians and relying on implied consent from a business relationship or a vaguely worded checkbox, you’re gambling with a C$10 million fine.
AWS Puts Tracking Consent on the Sending Line — Not Just the Privacy Policy
While the CRTC is tightening the screws on consent for sending, Amazon Web Services is doing the same for consent to track. On August 21, AWS announced that SES can now switch open and click tracking on or off for individual sends through the SendEmail and SendBulkEmail APIs. It sounds like a minor API update. It’s actually another sign that email infrastructure is being rebuilt around recipient-level consent.
AWS explicitly connects the change to GDPR, France’s CNIL guidance, and the need to respect individual tracking preferences. But the implications go far beyond Europe. Canada’s CASL doesn’t directly regulate tracking pixels, but it requires consent for the collection of personal information through electronic means if that collection is part of a commercial activity. And Quebec’s privacy law (Law 25) already requires separate consent for tracking used for profiling. The EU’s ePrivacy Directive and national laws in France and Italy have moved against the assumption that permission to send an email automatically includes permission to track its opening.
France generally requires separate consent for non-exempt tracking pixels, and its transitional period for existing contacts expired on July 14. Italy’s Garante allows more flexibility but requires granular withdrawal — a recipient can stop being tracked without unsubscribing from email entirely. Both regimes create the same technical problem for senders: tracking can no longer be treated as a campaign-wide setting. One recipient may have consented to tracking. Another may have consented only to receiving email. A third may have withdrawn tracking consent while remaining subscribed.
AWS’s new API provides the missing switch. Your application can now determine the appropriate tracking setting at send time, based on the consent status you hold for that recipient. For bulk sending, that may mean separating recipients into requests according to their tracking preferences. AWS does not collect consent, decide which rules apply, or maintain your compliance records. It simply allows your application to act on those decisions. The feature does not make an SES account compliant by default. You still need to identify which messages contain tracking, record consent and objections, and ensure the correct override is applied.
But the important development is that granular tracking consent is moving out of privacy policies and into sending infrastructure. What looked like a legal question is becoming an API requirement.
The Double Squeeze: Why Both CASL and AWS Target the Same Gap
Cold email marketers who target Canadian prospects or rely on AWS SES for sending are facing a double squeeze. On one side, CASL enforcement demands explicit opt-in for the message itself. On the other, AWS now demands you distinguish between consent to send and consent to track — at the point of sending. The common thread is that implied consent, once the foundation of many cold email strategies, is no longer acceptable for either the message or the engagement data.
Think about what most cold email campaigns look like today. You buy or scrape a list of emails. You send an initial outreach with an unsubscribe link. If the recipient doesn’t unsubscribe, you consider their continued silence as implied consent to keep sending. And you track opens — often without any mention of the pixel — to score leads and time follow-ups. That entire approach is now legally vulnerable in Canada and technically impossible to do cleanly on AWS if you want to honor tracking preferences.
The convergence is not accidental. Regulators in Canada and Europe are zeroing in on the same bad behavior: using tracking as a surveillance tool without consent. Platforms like AWS are responding because they face their own liability if they enable that behavior. The result is a permission-first architecture for both message delivery and engagement data. You need explicit, documented consent to send the email. And you need separate, documented consent to track what happens after it lands in the inbox.
What Cold Email Campaigns Need to Do Now: A Practical Checklist
1. Audit Your Consent Basis for Every Canadian Prospect
CASL recognizes three types of consent: express (explicit opt-in), implied from an existing business relationship (purchase, contract, inquiry within the last two years), and implied from a non-business relationship (e.g., you’re a member of the same association). Implied consent expires. If you’re relying on it, track the expiry dates. For cold outreach without any prior relationship, express consent is required. That means a clear, affirmative action — not a pre-checked box, not a vague “I agree to receive communications.” Document the time, date, and method of consent.
2. Separate Consent to Send from Consent to Track
Under French and Italian guidance — and increasingly under Canadian privacy laws like Quebec’s Law 25 — you cannot assume that permission to receive email includes permission to load a tracking pixel. You need to collect tracking consent separately, ideally at the point of subscription. Offer recipients the option to receive your emails with or without open and click tracking. If you have existing contacts, send a re-permission campaign that makes the distinction clear. Allow recipients to continue receiving messages without being tracked.
3. Build Send-Time Consent Logic into Your Email Platform
AWS’s new API override means you can — and should — check a recipient’s tracking consent at the moment of sending. If you’re using SES, update your sending code to query your consent database for each recipient and set the tracking override accordingly. For bulk sends, group recipients by tracking preference and send separate API calls. This is not optional if you want to comply with European regulations and avoid AWS enforcement actions. And while CASL doesn’t directly mandate this, using tracking without consent can be considered a violation of Section 6 (altering transmission data) or Section 8 (installing a computer program without consent — yes, pixels can fall under that).
4. Implement True Granular Withdrawal for Tracking
Don’t force a recipient to unsubscribe from your list entirely just to stop being tracked. Provide a preference center or a simple link that disables tracking while keeping them subscribed. This is required by the Italian Garante and is best practice everywhere. It also improves the quality of your engagement data — you’re only tracking people who genuinely want to be tracked.
5. Review Your Unsubscribe Mechanism for Compliance
The CRTC specifically called out broken unsubscribe links and processes that made opting out difficult. Test your unsubscribe flow regularly. Ensure it works on mobile. The unsubscribe request must be processed within 10 business days. And it must be free — no login required, no CAPTCHA that takes three attempts. If you’re sending to Canadians, track the date of each unsubscribe request and maintain a permanent suppression list.
The Unresolved Tension: Will the Industry Adapt Fast Enough?
Here’s the problem that keeps email operations people up at night: most cold email marketers still think an unsubscribe link is enough. They haven’t read the CRTC snapshot. They don’t know about France’s July 14 deadline or Italy’s October compliance date. They think AWS’s update is just a new API endpoint, not a signal that consent infrastructure is becoming mandatory. The gap between what the law and platforms require and what practitioners actually do is enormous.
That gap creates risk. A single CASL violation can cost up to C$10 million per violation. A series of compliance failures on AWS can lead to account suspension or termination. And if you’re using open tracking to score leads and your tracking data includes recipients who never consented to be tracked, you’re building decisions on legally questionable data. The foundation of your lead scoring model could collapse under regulatory scrutiny.
The question isn’t whether to adopt a permission-first architecture. The question is: how fast can you rebuild your systems, retrain your teams, and reconsent your lists before the next enforcement action or platform policy change lands? The regulator has signaled it’s moving from warnings to penalties. AWS has shown it expects granular consent at send time. What happens when a major email infrastructure provider makes tracking consent a mandatory field instead of an optional override?