TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Corporate
№ 341 Case Study — Corporate

A purchased contact list nearly went out before anyone checked the consent

A Thunder Bay clinic founder had already run one email campaign off advice he found online when a complaint letter arrived, and a second, larger list sat ready to go out until we looked at where it actually came from.

Corporate8 min readThunder Bay, OntarioElectronic marketing consent
All Corporate case studies
ClientDante, founder of a multi-clinic physiotherapy company
The issueA purchased contact list for commercial email marketing had not been properly consented, and one earlier campaign had already drawn a complaint
ServiceThe existing campaign reviewed, the complaint resolved, and the purchased list rejected before a second mailing went out
ResolutionThe complaint was settled on negotiated terms and the risky list was pulled before use, though the earlier mistake could not be fully undone

The situation

The letter that reached Dante's desk was two pages, formal in tone, and cited a piece of electronic marketing legislation Dante had never heard of before that morning. It came from a hospital's internal compliance office on behalf of Faisal, a department manager there, objecting to an unsolicited promotional email his company had sent a few weeks earlier without any prior contact between the two of them. Dante read it twice before calling us, mostly because he genuinely could not understand how a routine marketing email had turned into a compliance matter serious enough to warrant a formal letter from a hospital's own office.

Dante had trained and worked as a physiotherapist for several years before building that clinical experience into a company that now ran several clinics and had grown into a business generating somewhere in the five to twenty million dollar range, largely through referral relationships with hospitals and other healthcare providers across the region. Growing the referral network further meant reaching the people who actually made referral decisions, department managers like Faisal among them, and Dante had decided the fastest way to reach that specific audience was a direct email campaign introducing his clinics to healthcare administrators he had never personally met.

Before running it, Dante had spent an evening researching the rules himself rather than asking anyone with legal training. What he found online, on a forum thread he could no longer locate when we later asked him to send it over, suggested that professional contact information exchanged in a business context, including information available through a purchased professional directory, counted as implied consent for a single introductory email, in roughly the same way handing someone a business card at a conference might. On the strength of that reading alone, he purchased a list of healthcare administrator contacts from a data broker named Adnan and sent an initial campaign to a few hundred recipients, Faisal among them, without further checking.

The complaint letter arrived within three weeks of that first campaign going out. By the time Dante called us, Adnan had already delivered a second, larger list of contacts, and Dante's marketing coordinator was ready to schedule a follow-up campaign for the following Monday, entirely unaware that a complaint about the first one had just landed. Dante wanted two things from that first call: a straight answer on how serious the complaint actually was, and a fast decision on whether the second, larger campaign could still safely go out as planned.

The gap nobody had noticed

The forum-thread reasoning Dante had relied on was not correct, and the gap it left in his understanding was significant rather than minor. Canadian rules governing commercial electronic messages generally require consent before sending marketing email to an individual, and the exceptions to that requirement are considerably narrower than the business-card comparison Dante had read suggested. An existing business relationship can support an exception in some circumstances, but a purchased contact list assembled cold by a third-party broker, with no prior relationship or direct interaction of any kind between Dante's company and the recipient, does not fit that exception no matter how professional or business-oriented the context looks on paper.

The purchase agreement with Adnan described the list as 'verified professional contacts' but said nothing at all about how consent to receive third-party marketing had actually been obtained from the people named on it. When we asked Dante's team to produce any consent record for Faisal specifically, none existed anywhere in the company's files. That absence was the real gap underneath the complaint: Dante had assumed that because Adnan's list was marketed as professional and business-oriented, it must already account for consent somewhere upstream, when in fact the legal burden to establish valid consent sits squarely with the sender of the message, not with the list vendor who sold it.

The second campaign, already scheduled for the following Monday, would have compounded the problem rather than resolved anything. It used the same broker relationship, the same complete absence of consent records, and a considerably larger recipient list, which meant a much larger population of people who could each, individually, raise the exact same objection Faisal already had. Running it while a complaint about the first campaign sat open would also have made it far harder later to present the company as having taken that first complaint seriously at all.

There was a narrower, second issue buried inside the complaint letter as well, one Dante had not even noticed on his own first read. Faisal's objection was not only about consent; it also noted that the email lacked any functioning way to opt out of future messages, a separate requirement layered on top of, and independent from, the consent question itself. Dante's marketing platform did technically have an unsubscribe link, but it routed to a generic company contact form rather than processing removal automatically, which meant it likely did not satisfy the requirement even for a message that had otherwise been properly consented and sent.

What we did

  1. Pulled the second campaign before it went out, the same day as our first call, since sending a larger mailing off the same non-compliant list while a complaint was already pending would have materially and needlessly worsened the company's position with almost no time left to reconsider once the emails were actually sent, and no amount of subsequent apology could undo several hundred more people receiving the same defective message.
  2. Reviewed the purchase agreement with Adnan line by line to determine what, if any, consent representation the broker had actually made about the people on the list, and found the agreement offered no meaningful warranty the company could rely on if a recipient later challenged how their information had been obtained in the first place, leaving the company with no paper trail to point to if the question was ever pressed further.
  3. Assessed Dante's actual exposure from the first campaign, treating it as a single completed mailing to a defined and countable list rather than an ongoing practice, which mattered because the company's response could then focus on resolving one contained incident rather than defending a broader, harder-to-bound pattern of conduct that a regulator could treat as evidence of habitual disregard for the rules.
  4. Drafted a response to the hospital's compliance office acknowledging the consent gap plainly and without hedging, describing the corrective steps already taken, including pulling the second campaign, and proposing a resolution rather than disputing the underlying complaint, which set a cooperative tone from the very first exchange, and deliberately avoided any language that could read as minimizing Faisal's specific complaint, since a response that felt evasive on the individual case would have undercut the broader message that the company took the gap seriously.
  5. Negotiated the terms of that resolution directly with the hospital's compliance office over several calls, working toward an outcome both sides could accept without escalating to a formal regulatory complaint, since an early, direct resolution served Dante's ongoing referral relationship with the hospital far better than a prolonged, public dispute would have, balancing Faisal's reasonable insistence on a written commitment against Dante's concern that anything too formal would read, to other hospitals watching, as an admission bigger than the actual mistake.
  6. Fixed the unsubscribe mechanism on the company's email marketing platform so it processed opt-out requests automatically and immediately rather than routing through a generic contact form, closing the second, smaller compliance gap that the complaint letter had specifically and separately flagged alongside the consent issue, and tested it personally on Dante's own account before calling the fix complete, since a marketing platform's default settings had already misled the company once and a second unverified assumption was not a risk worth taking again.
  7. Advised against using any purchased list going forward, and outlined in practical terms what a properly consented contact-gathering process would actually look like, built on the company's own existing referral relationships rather than a third-party broker's unverifiable assurances about a list it did not build transparently, including a simple standard the marketing coordinator could apply herself before any future list purchase: if the company could not show, in writing, how and when each person on it had actually agreed to be contacted, the list did not go out.
  8. Reviewed the company's other marketing channels, including a separate print newsletter list and a patient referral email list, to confirm no similar consent gap existed elsewhere in the business, since a single overlooked channel could reopen the same problem months later, before closing out the engagement and reporting back to Dante in writing, finding both of those channels properly consented and no further action needed there.

The outcome

The matter with the hospital resolved on negotiated terms rather than escalating into a formal regulatory complaint. Faisal's compliance office accepted the company's written acknowledgment of the error, confirmation that the second campaign had been withdrawn before it ever went out, and a written commitment not to use purchased contact lists going forward, in exchange for closing the matter without further action. Dante's referral relationship with that hospital continued afterward, though he was candid that the letter had cost him some standing with people he had hoped to reach as prospective referral partners, not gained him any, and that the relationship needed active rebuilding rather than simply resuming where it left off.

The second campaign, which would have gone out to a larger and equally non-compliant list, never ran. That was the clearest win in the engagement: a much larger problem, touching hundreds more recipients, was avoided entirely rather than managed after the fact once it had already landed. The purchased list itself was discarded rather than archived for later use, and the business relationship with Adnan's brokerage ended, with no further lists purchased from that source or any similar one since.

Dante's company did not walk away from the episode without cost. The first campaign's damage to at least one referral relationship could not be reversed, only managed and partly repaired over time, and the company spent real time and a modest amount of legal and administrative cost correcting its marketing process rather than expanding it during that period. Dante has since rebuilt his outreach around consent gathered directly through existing patient and provider relationships, a slower and more deliberate approach than a purchased list ever was, but one that does not carry the same risk the first campaign did, and one he now checks against before any new channel launches.

What you can learn from this

  • A purchased contact list is not a shortcut around consent requirements; the burden to show valid consent sits with the business sending the message, not the list vendor.
  • General advice found online about marketing and privacy rules, especially informal comparisons like the business-card exception, is often wrong in ways that only surface after a complaint.
  • An unsubscribe link that does not actually process removal automatically may not satisfy the requirement even if one technically exists on the message.
  • When a compliance gap is caught before a second, larger mailing goes out, the damage is contained to one incident instead of compounding across a bigger recipient list.
  • Responding to a consent complaint with acknowledgment and corrective steps, rather than disputing it, tends to preserve the underlying business relationship better than a defensive posture.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a corporate problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →