Activity Messenger Help Center
Personal information and electronic message laws in Canada and the USA
Choose your audience and message purpose with consent and privacy in mind. Activity Messenger provides communication controls and tools to collect personal information; your organization remains responsible for deciding whether a particular message and use of personal information are permitted.
Electronic message laws in Canada and the USA
- Canada's Anti-Spam Legislation (CASL): The CRTC publishes a FAQ to help you understand CASL. See the CRTC's CASL guidance.
- United States CAN-SPAM Act: The FTC publishes a compliance guide. See the FTC compliance guide.
Both laws generally require sender identification and an unsubscribe mechanism for commercial electronic messages, and CASL also requires consent. Exceptions and implied-consent conditions depend on the circumstances, and the FTC's email guidance is not a complete rulebook for SMS. Four considerations matter most.
1 - Intent of the message
The laws apply to commercial messages, meaning messages with a marketing intent. For example, promoting next season's program or announcing available spots at a day camp is commercial.
The laws generally do not apply to transactional or relationship messages, such as notifying participants that a class is cancelled or sending an account statement or receipt. The FTC distinguishes commercial from transactional or relationship content according to the message's primary purpose. A promotional offer does not become operational simply because it mentions a registration.
When you create a message, classify its actual content as Marketing or Non-marketing. Non-marketing messages can reach people who have unsubscribed from marketing messages, so use that type only for genuine reminders, cancellations, follow-ups and similar content. Non-marketing classification does not guarantee delivery or bypass every suppression. Follow unsubscribe management for the product workflow.
2 - Consent
It is your organization's responsibility to obtain and keep evidence of consent from your participants. If you use a registration platform such as Amilia, consent may already have been given when the participant registered for the activity or program, or subscribed to a membership or service. Registration or an imported address is not a blanket authorization for every future promotion.
Activity Messenger assumes that the participants you import and send messages to have given you consent. Import existing opt-outs when migrating lists.
3 - Identification information
Messages you send must identify your organization. Activity Messenger puts your address in the footer of emails, and the From name is always the name of your organization. SMS messages are signed with your organization's alias. Review your identifying information before sending. See Organization identity and branding for details.
4 - Unsubscribe mechanism
Both laws require clear and easy ways to unsubscribe. Activity Messenger provides several ways for participants to do that. See Emails and text messages from Activity Messenger for details, and consider the recipient's channel preferences before sending.
Ask qualified counsel about uncertain cases, jurisdiction-specific requirements and SMS obligations.
Personal information
Activity Messenger provides tools for you to collect personal information to conduct your business and operations. Collecting and storing that information must respect the law in your jurisdiction, which depends on your organization, activity and location. Collect only the information needed for the intended workflow, assign suitable staff access and establish your organization's retention and incident-response procedures. For Activity Messenger's current privacy, security and hosting statements, consult its Privacy policy and Security information.
Canada: PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. Provinces with substantially similar laws, such as Québec, may apply their own law instead for activity within the province, and cross-border information flows can also matter. Start with the Privacy Commissioner's applicability guidance and the PIPEDA overview.
Québec: Law 25
Law 25 modernizes Québec's Act respecting the protection of personal information in the private sector and offers residents stronger protection. It applies to private organizations that collect, hold or use the personal information of people in Québec, and its obligations were phased in between 2022 and 2024. The main points for an organization using Activity Messenger include:
- Accountability: designate a person in charge of the protection of personal information, by default the organization's highest authority, and publish their title and contact information.
- Policies and transparency: establish and publish clear governance policies and a privacy policy that explain how you collect, use, keep and protect personal information.
- Consent: obtain clear, free, informed consent that is specific to each purpose. The request must be presented separately from other information.
- Privacy impact assessments: assess the privacy impact of projects that involve personal information, and before communicating personal information outside Québec.
- Confidentiality incidents: keep a register of incidents, and report an incident that presents a risk of serious injury to the Commission d'accès à l'information and to the people concerned.
- Individual rights: respond to requests to access, correct or receive their information, and to stop its dissemination where the law provides for it.
Requirements depend on your organization's situation and can change, so confirm them with qualified counsel. Consult the Commission d'accès à l'information's guidance for private-sector businesses to understand your obligations.
Data breach
In the unlikely event of a data breach, defined as the loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a breach of an organization's security safeguards, Activity Messenger will take appropriate measures to:
- Take measures to resolve the data breach
- Contact the organization account owners to inform them of the data breach and the measures that were taken
Contact us at support@activitymessenger.com if you would like more information.