North America Data privacy

Canada Expands Blocking Rules

This matters for CPaaS providers, carrier-partnership teams, and compliance owners delivering OTP, account alerts, customer care messages, and multi-channel notifications into Canada because anti-phishing controls are now tied more directly to telecom delivery infrastructure. On June 18, 2026, the CRTC expanded its network-level blocking framework to permit additional blocking methods against malware and phishing, while imposing a five-business-day complaint resolution expectation and more explicit disclosure duties around privacy, third-party providers, and blocking operations.

Published:08/18/2026 Updated:08/18/2026

1. Regulatory focus

In Decision 2026-140, effective June 18, 2026, the CRTC moved beyond a narrower botnet blocklist model and allowed Canadian carriers to use any approved network-level blocking method, provided it meets the principles of necessity, accuracy, and consumer privacy. The framework expressly covers malware, phishing, and related cyber threats, requires a carrier process for false-positive and over-blocking complaints with resolution within five business days, and mandates a dedicated “cyber security blocking” disclosure on carrier websites describing the blocking approach, third-party support including providers located outside Canada, and relevant privacy information.

2. Business impact

For aggregators, brands, and notification programs that rely on shortened links or redirected domains, the compliance risk is no longer limited to content being tagged as spam. Delivery can now be affected by infrastructure-level indicators of compromise, domain reputation, vendor practices, and how quickly blocking complaints are resolved. The CRTC’s latest CASL enforcement update also shows why this matters operationally: between October 1, 2025 and March 31, 2026, the Spam Reporting Centre received 189,908 submissions, and SMS represented 34% of reports filed through the online form. That makes phishing-style text traffic a live enforcement concern, especially where brands depend on third-party sending, external anti-fraud tooling, or offshore support providers.

3. Operating recommendations

For traffic terminating in Canada, teams should expand message governance into an infrastructure compliance package: inventory sending domains, landing pages, link-shortening services, sender-to-brand mappings, anti-fraud vendors, and any processing nodes outside Canada. On the remediation side, prepare evidence that can be assembled within five business days, including timestamps for blocked traffic, message purpose, redirect destinations, IOC review logs, and responsibility boundaries across carriers and vendors. Also treat blocking-derived data carefully: do not repurpose it for profiling, remarketing, or scoring models unless you can point to a separate lawful basis, consent path, or other explicit authorization.

Frequently Asked Questions

If Canadian users stop receiving notification texts with links, should teams review content first or the delivery chain first?
Start with the delivery chain. The framework now explicitly connects phishing, IOCs, and third-party blocking methods to traffic handling, so shortened links, redirect domains, landing-page reputation, DNS anomalies, and vendor controls can all trigger blocking. Content review still matters, but the first pass should focus on infrastructure evidence before message copy.
What evidence should a brand prepare when challenging suspected over-blocking in Canada?
Prepare at least five items: the sending time window, the exact template and its use case, the destination URL and redirect chain, the affected number range or volume, and a vendor map showing who handled which part of delivery. IOC review notes, proof of domain ownership, and the user-trigger context materially improve the quality of a five-business-day escalation.
Can traffic and risk data collected during blocking be reused for marketing or model training?
Not by default. The CRTC framework says collection, use, and disclosure of personal information in blocking operations must stay limited to what is necessary for that purpose and for no longer than needed. Secondary use requires a separate legal basis, consent path, or other explicit authorization. A generic vendor clause about “security purposes” is usually not enough to support marketing reuse.
This article is for informational purposes only and does not constitute legal advice.

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch