On December 15, 2010, Canada passed Canada's Anti-Spam Legislation ("CASL"), one of the world's most stringent anti-spam laws.1 On January 15, 2015, the provisions set forth in Section 8 of CASL relating to the installation of computer programs came into effect.2 Section 8 prohibits the installation of a computer program, including any mobile application, as well as upgrades and updates ("Updates") to a computer program (each a "Computer Program") on another person's device in the course of commercial activity without the express consent of the device owner or authorized user.3 Another person's device can include any laptop, smartphone, desktop, gaming console, or other connected device (each a "Computer System").

Failure to comply with CASL could result in substantial liability. The Canadian Radio-Television and Telecommunications Commission ("CRTC") is authorized to impose administrative monetary penalties of up to C$1 million per violation of CASL for individuals and C$10 million for businesses.4 Officers, directors, and agents may be personally liable if they acquiesced in a violation of the law.5 However, because CASL takes into account "honest mistakes," a company that has undertaken good faith efforts to comply with the law has an affirmative defense in the event the CRTC initiates action based on a violation of CASL.6

Because CASL requires installation of a Computer Program on another person's Computer System, Section 8 does not apply when a user self-installs a Computer Program on her own Computer System, such as in the case of a user-installed mobile application. However, an automatically downloaded and installed Update to a self-installed Computer Program would be considered an installation of a Computer Program on another person's Computer System.7 Thus, automatic Updates require consent.8

The consent required by Section 8 applies to U.S. and other non-Canadian companies because the law applies to Computer Programs installed on Computer Systems located in Canada even if the installation originated elsewhere.9Consequently, companies located outside of Canada, including U.S. companies, need to obtain the required consent if they are automatically installing any Computer Programs, including Updates, on Computer Systems in Canada.10

Recommendations

In order to reduce exposure to liability, you should consider the following steps to ensure that your company complies with Section 8 of CASL if you have determined that your company is automatically installing any Computer Programs, including Updates, on Computer Systems located in Canada.

1. Determine if you have implied or deemed consent to automatically install any Computer Programs, including Updates.

Section 8 provides that you will be deemed to have received consent to automatically install the following types of Computer Programs as long as the user's conduct does not indicate that she does not provide consent (e.g. if a user disables cookies in her browser, then you cannot install cookies in that person's computer):11

  • Cookies;
  • HTML;
  • JavaScript;
  • Operating systems;
  • Other Computer Programs that are executable only through another Computer Program for which the person has already provided express consent to the Computer Program's installation or use;
  • Computer Programs installed solely to correct a failure in a Computer System (e.g. bug fixes); and
  • Computer Programs installed by telecommunications service providers if such Computer Programs are being installed to protect the security of all or part of the provider's network from a current and identifiable threat or to update or upgrade all or part of the provider's network.

In addition, Section 8 provides that you will be considered to have received implied consent to upgrade or update any Computer Programs installed prior to January 15, 2015. Such implied consent will be considered valid until January 15, 2018, unless the user notifies you that she no longer consents to the installation of future Updates.12

2. If you do not have implied or deemed consent, you must obtain express consent from the owner or authorized user of a Computer System before you automatically install any Computer Programs, including Updates. Terms for express consent must be clearly and simply set out and cannot be incorporated into an agreement or bundled with requests for consents for other purposes.

Consent must be obtained from the owner or authorized user of the Computer System.13 The following are examples of owners and authorized users:14

  1. In an employment relationship, the employer is the owner and the employee is the authorized user.
  2. If an individual owns a Computer System but provides it to his child, spouse, or other relative for his or her sole use, the individual is the owner and the child, spouse, or other relative is the authorized user.
  3. If an individual leases a Computer System to a third party, the lessor is the owner of the Computer System for the purposes of CASL and the lessee is the authorized user.
  4. If a Computer System is sent out for repair, the person conducting the repair is an authorized user under CASL, but only to the extent that she is performing agreed-upon repairs to the Computer System.

In order to provide valid express consent, the owner or authorized user must take an active step to "opt in," such as by checking a previously unchecked box.15 Express consent cannot be included in or bundled with requests for consents for other purposes.16 For example, checking a single box cannot provide consent to automatic installation of a Computer Program in addition to consent to a license agreement or terms of use.17

A request for express consent must clearly and simply set out:18

  • A description in general terms of the functions and purpose of the Computer Program for which you are seeking consent to install;
  • The reason for seeking consent;
  • Who is seeking consent (e.g. name of company, or if consent is being sought for another person, that person's name);
  • If consent is sought on behalf of another person, a statement indicating the person who is seeking consent and the person on whose behalf the consent is being sought;
  • Mailing address and one other piece of contact information (i.e. phone number, email, website address); and
  • A statement that the person whose consent is being sought may withdraw their consent at any time.

Even if a user consented to the initial installation of the Computer Program (or initial consent was not required because the user installed the Computer Program), you must obtain consent for automatic installation of Updates.19 One important note: to avoid having to get consents for Updates in the future, you can request consent from the user to install Updates at the time of the initial installation of the Computer Program.20

You will want to maintain a record of the consents that you receive from users, as the burden of proving that you have obtained consent rests with the company that automatically installs the Computer Program or causes the Computer Program to be installed.21

3. If you know and intend that your Computer Program will cause the user's Computer System to operate in manner contrary to the reasonable expectations of the user and your Computer Program performs certain functions, such as collecting personal information stored on the Computer System, you must comply with additional heightened consent requirements.

A Computer Program that performs any of the following types of functions contrary to the reasonable expectation of a user triggers the heightened consent requirement:22

  • Collects personal information stored on the Computer System;
  • Interferes with the owner's or an authorized user's control of the Computer System;
  • Changes or interferes with settings, preferences, or commands already installed or stored on the Computer System without the knowledge of the owner or an authorized user of the Computer System;
  • Changes or interferes with data that is stored on the Computer System in a manner that obstructs, interrupts, or interferes with lawful access to or use of that data by the owner or an authorized user of the Computer System;
  • Causes the Computer System to communicate with another Computer System without the authorization of the owner or an authorized user of the Computer System; or
  • Installs a Computer Program that may be activated by a third party without the knowledge of the owner or an authorized user of the Computer System.

For example, if a user installs a mobile game application that also collects personal information from the user's mobile device for advertising purposes—a function that would not be reasonably expected by the user—the heightened consent requirements apply.

The heightened information requirements set out above do not apply to Computer Programs that only collect, use, or communicate transmission data.23

If your Computer Program is subject to the heightened consent requirements, prior to the installation of the Computer Program you must clearly and prominently (and separately from a license agreement):24

  • Describe the Computer Program's material elements that perform the unanticipated function or functions, including the nature and purpose of those elements and their reasonably foreseeable impact on the operation of the Computer System;
  • Bring those elements to the attention of the user separate from other information provided in a request for consent; and
  • Obtain the user's written acknowledgment that the user understands and agrees that the Computer Program performs the specified functions. An example of an acceptable means of obtaining consent in writing includes having the user check another previously unchecked box to indicate consent to the heightened consent requirements, where a record of the date, time, purpose, and manner of that consent is stored in a database.25

In addition to the heightened consent requirements, for a period of one year after installation, you must ensure that that the person who provided consent is provided with an electronic address to which she may send a request to remove or disable the Computer Program in the event that she believes that the function, purpose, or impact of the Computer Program installed under the consent was not accurately described when the consent was requested.26

If the consent was based on an inaccurate description of the material elements of the function or functions described under the heightened requirements, on receipt within that one-year period of a request to remove or disable that Computer Program, you must assist that person in removing or disabling the Computer Program as soon as feasible, without cost.27