
Rules
Hotel and restaurant guest engagement rules in Canada versus the US
Canada and the US split on guest engagement: CASL consent, Quebec language duties, PIPEDA and Law 25 against state privacy laws, plus loyalty and WiFi data rules.
What to take away
- Canadian guest engagement starts with consent. CASL requires express or implied permission before a commercial email is sent, while CAN-SPAM lets a US sender go first and honor opt-outs.
- Quebec adds French language obligations for advertising and public commercial documents that no US state matches.
- Guest data sits under PIPEDA and Quebec Law 25 in Canada, and under a growing set of state privacy laws in the US.
- Loyalty points, WiFi logins and delivery platform data pull engagement into tax, security and record-keeping rules.
Consent comes first in Canada and last in the United States
Canada's Anti-Spam Legislation, in force since July 1, 2014, covers any commercial electronic message sent from Canada or accessed in Canada. A hotel or restaurant needs consent before the first send.
Consent can be express or implied. An existing business relationship gives implied consent for 24 months after a purchase and 6 months after an inquiry.
Every message needs sender identification, a mailing address, and a working unsubscribe link honored within 10 business days. The CRTC enforces CASL, with the Competition Bureau and the Privacy Commissioner of Canada alongside it.
The United States works the other way. CAN-SPAM, enforced by the Federal Trade Commission, allows sending without prior consent.
It still requires accurate routing information, a non-deceptive subject line, a clear ad identifier, a valid postal address, and opt-out handling within 10 business days. Penalties apply per message and are adjusted for inflation.
Consent comes first in Canada
Canada (CASL)
- Consent
- Express or implied before sending
- Implied consent window
- 24 months after purchase, 6 months after inquiry
- Unsubscribe deadline
- 10 business days
- Postal address
- Required
- Lead enforcer
- CRTC
- Maximum business penalty
- CAD 10 million
United States (CAN-SPAM)
- Consent
- Not required
- Implied consent window
- No equivalent
- Unsubscribe deadline
- 10 business days
- Postal address
- Required
- Lead enforcer
- Federal Trade Commission
- Maximum business penalty
- Per-message civil penalties, adjusted annually
A workable consent checklist:
Consent comes first in Canada
- Name the consent basis for every listexpress, purchase, or inquiry.
- Record the source and date against each address.
- Put the postal address and unsubscribe link in every template.
- Set a review date before the 24 month implied consent window closes.
Quebec adds language duties on top of consent
The Charter of the French Language, amended by Bill 96 in 2022, requires commercial advertising and public commercial documents in French. Where another language appears, French must be markedly predominant.
That reaches menus, websites, loyalty offers and email templates aimed at Quebec guests. No US state imposes a comparable requirement.
Privacy runs on two different clocks
PIPEDA is Canada's federal private-sector privacy law. British Columbia, Alberta and Quebec have laws deemed substantially similar, so the provincial rule usually governs.
Quebec's Law 25 modernized that provincial law in phases from September 2022. It adds privacy officer duties, breach reporting, consent requirements for certain uses, and portability rights.
The United States has no single federal privacy law covering hotels. California's CCPA and CPRA, plus laws in Virginia, Colorado, Connecticut and Texas, grant rights to know, delete, correct and opt out of targeted advertising.
Managing those overlapping duties is a risk program, not a legal memo. The NIST Privacy Framework gives a structure for managing privacy risk across both countries.
Loyalty points, WiFi and delivery data carry their own rules
In Canada, the Canada Revenue Agency sets out how GST/HST applies to loyalty programs and rewards. Points redeemed for a room night or a meal are not automatically outside the tax net.
Guest WiFi marketing collects device identifiers and email addresses. The FTC data security guidance applies once that guest data is stored.
Delivery adds another layer. Restaurant guest engagement through Uber Eats, DoorDash or SkipTheDishes runs on platform terms, not the property's own consent list.
Example: a Montreal hotel emailing a guest in Illinois
Say a Montreal hotel collects an email at check-in from a guest who lives in Illinois, then sends a loyalty offer the next month.
Montreal hotel emailing a guest in Illinois
- Confirm the consent basis before the message leaves the country. A message sent from Canada is caught by CASL even when the reader sits in Chicago.
- Check whether the same campaign reaches Quebec addresses, which triggers French language duties.
- Verify the loyalty point value against GST/HST guidance.
- Store the consent record, source and timestamp beside the guest profile.
Where the property sets the ceiling
Compliance work is only half of the job. The operational side runs from the first estimate to final handoff, where consent records sit beside booking notes and complaint logs.
A hospitality marketing strategy that treats Canada and the US as one list will underfund the consent record and the language review.
The building itself caps what any program can promise. Hospitality property turns on two things the landlord does not control: whether the licenses will issue, and whether the building can carry a kitchen.






