1. First, work out whether the Privacy Act covers your business
  2. APP 7: the default position is a ban
  3. Exception one: collected directly, and the customer would expect the marketing
  4. Exception two: third-party data, or marketing the customer did not expect
  5. Sensitive information and Commonwealth contracts
  6. The opt-out duty: simple, free and honoured
  7. Channel-specific laws stack on top of APP 7
  8. What happens if you get it wrong
  9. A practical compliance checklist
  10. When a privacy lawyer is worth the cost
  11. The opt-out you never tested

Direct marketing covers more everyday business activity than most owners realise. Emailing customers about a sale, texting past clients, posting catalogues to a mailing list, telemarketing and serving targeted ads to logged-in users all count. Each of those activities uses personal information to reach an individual directly, and in Australia that use is tightly regulated. The core rules sit in the Australian Privacy Principles (APPs) in Schedule 1 of the Privacy Act 1988 (Cth), and channel-specific laws add further duties on top: the Spam Act 2003 (Cth) for email and SMS, and the Do Not Call Register Act 2006 (Cth) for telephone calls. This article sets out who those obligations apply to, the exceptions that permit marketing, the opt-out duties you must honour and what is at stake if you get it wrong.

First, work out whether the Privacy Act covers your business

The APPs bind APP entities: mainly government agencies and private sector organisations. For a business, coverage turns largely on turnover. Under s 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover for the previous financial year was $3 million or less, and small business operators are generally exempt from the APPs. A business that has not traded for a full year is assessed against its current-year turnover. In practice:

  • Turnover over $3 million: you are an APP entity and must comply with the APPs, including APP 7 on direct marketing.
  • Turnover of $3 million or less: you are generally exempt, but the exemption is not automatic. Some small businesses are covered regardless of size, including health service providers and businesses that trade in personal information, and any small business can choose to opt in under s 6EA.
  • Whatever your size: the Spam Act and the Do Not Call Register Act contain no turnover threshold. A one-person business sending marketing emails is bound by them.

The exemption is the threshold that catches businesses by surprise. A business that grows past $3 million, or that buys a list and starts trading in personal information, can find itself inside the Privacy Act without realising it.

APP 7: the default position is a ban

APP 7 starts from a prohibition. Under APP 7.1, an organisation that holds personal information about an individual must not use or disclose that information for the purpose of direct marketing, unless one of the specific exceptions in the principle applies.

Direct marketing means using or disclosing personal information to communicate directly with an individual to promote goods or services, according to the OAIC's APP guidelines. It includes telephone calls, SMS, mail, email and online advertising where personal information selects or targets the recipient.

Not everything that looks like marketing is caught. The OAIC gives examples of activity that is not direct marketing because personal information is not used to target particular recipients: sending catalogues addressed to the householder to every address in an area, hand-delivering flyers, or serving advertisements without using personal information to choose who sees them.

If your activity is direct marketing, you need to fit an exception. There are four, and which one applies changes what you must do.

Exception one: collected directly, and the customer would expect the marketing

Under APP 7.2, you may use or disclose personal information, other than sensitive information, for direct marketing if all of these are true:

  • Direct collection: you collected the information from the individual, not from a third party.
  • Reasonable expectation: the individual would reasonably expect their information to be used for direct marketing.
  • Simple opt-out: you provide a simple means by which the individual can easily request not to receive direct marketing communications.
  • No request made: the individual has not made that request.

The reasonable expectation test is objective. The OAIC describes it as what a reasonable person, properly informed, would expect in the circumstances. Expectation is usually built at collection: if your collection notice tells a customer their details will be used for marketing, they are far more likely to expect it. Conversely, if you tell a customer their information will be used only for a specific purpose, such as security, you cannot later claim they expected marketing. You also cannot assume expectation just because a customer's profession or interests suggest they would welcome the pitch.

Exception two: third-party data, or marketing the customer did not expect

Where information was collected from a third party, or was collected from the individual but the individual would not reasonably expect it to be used for marketing, APP 7.3 imposes stricter conditions. You may use or disclose the information only if:

  • Consent or impracticability: the individual has consented to the use or disclosure, or it is impracticable to obtain consent.
  • Simple opt-out: you provide a simple means by which the individual can request not to receive direct marketing communications.
  • Prominent statement: each direct marketing communication includes a prominent statement, or otherwise draws attention to the fact, that the individual may opt out.
  • No request made: the individual has not asked to opt out.

This is the exception that governs purchased lists, lead-generation data and social media data. The prominent statement requirement matters: the opt-out must be in the message itself, not buried in a privacy policy.

There is a related disclosure duty. If you use personal information for direct marketing and the individual asks where you got it, APP 7.7 requires you to tell them the source, unless it is unreasonable or impracticable to do so. A business using a rented list needs to be able to answer that question.

Sensitive information and Commonwealth contracts

Two further exceptions complete the picture. Under APP 7.4, sensitive information, such as health information, political opinions or religious beliefs, may be used for direct marketing only with the individual's consent, and that consent must be current.

Under APP 7.5, a contracted service provider under a Commonwealth contract may use or disclose personal information, other than sensitive information, for direct marketing where the use or disclosure is necessary to meet its obligations under the contract.

The opt-out duty: simple, free and honoured

Every exception carries the same underlying duty: the individual must be able to stop the marketing, and you must stop. Under APP 7.6 and 7.7, an individual may request not to receive direct marketing communications, and you must give effect to that request within a reasonable period, free of charge. Once they opt out, you must not use or disclose their information for direct marketing, which includes not passing it on so another business can market to them.

The OAIC's guidance on what makes an opt-out simple is a useful compliance benchmark. A simple means:

  • Plain and visible: gives a visible, clear explanation written in plain English, in a font size that is easy to read.
  • Low effort: takes minimal time and effort to use.
  • Free: costs nothing, or no more than a nominal amount.
  • Same channel: works through a straightforward channel, ideally the same channel the marketing came through.
  • Findable: is easy to discover, including in each communication.

Two practical notes. First, honouring an opt-out is a systems task, not a policy one: if your marketing database and your unsubscribe list are separate, a customer can opt out and keep receiving messages. Second, record the request and the date, because the OAIC's guidance puts the responsibility on the organisation to be able to justify its conduct.

Channel-specific laws stack on top of APP 7

APP 7 does not operate in a vacuum. Under APP 7.8, it does not apply to the extent the Do Not Call Register Act or the Spam Act applies. For email, SMS and phone calls, the channel-specific laws therefore do most of the work, and they bind businesses of every size.

Under the Spam Act, a commercial electronic message with an Australian link, such as an email or SMS, must meet three requirements:

  • Consent: under s 16 you must not send an unsolicited commercial electronic message unless the recipient consented, whether expressly or by inference from their conduct and relationship with you.
  • Identification: under s 17 the message must clearly and accurately identify who authorised it and include accurate contact details that remain valid for at least 30 days.
  • Unsubscribe: under s 18 the message must include a functional unsubscribe facility, presented clearly and conspicuously, that works for at least 30 days.

Telemarketing calls are governed by the Do Not Call Register Act. Numbers listed on the register generally must not be called for marketing purposes, subject to limited exemptions such as calls by charities and government bodies, and separate industry standards restrict calling hours and caller identification. The ACMA administers these regimes alongside the Spam Act.

Postal marketing sits outside both channel laws, so APP 7 is the primary control on addressed mail and catalogues.

What happens if you get it wrong

Breaching an APP is an interference with privacy, and the penalties are now substantial. Under s 13G of the Privacy Act 1988 (Cth), a serious interference with privacy can attract a civil penalty for a body corporate of up to the greater of $50 million, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach period. Penalties for individuals reach $2.5 million. Lower penalties apply to interferences that are not serious.

The OAIC also has a faster tool. Under s 13K, it can issue infringement notices for breaches of specific APP provisions without going to court, and the list includes the opt-out obligations: providing a simple means to opt out under APP 7.2(c) and 7.3(c), drawing attention to the ability to opt out under 7.3(d), and giving effect to a request within a reasonable period under 7.7.

Spam Act breaches are enforced by the ACMA, which has pursued marketing conduct aggressively in recent years:

A repeat corporate offender can also face civil penalties of up to 10,000 penalty units a day under the Spam Act, about $3.3 million at the current unit value of $330. And if a privacy breach is serious enough to be likely to result in serious harm, the notifiable data breaches scheme can require you to notify the OAIC and affected individuals.

The pattern in those ACMA cases is worth noting: the penalties were mostly about broken opt-outs and consent failures, not about the fact of marketing itself.

A practical compliance checklist

Before you run another campaign, work through this list:

  • Confirm coverage: document whether the Privacy Act covers you, so a turnover change or a shift into trading in personal information does not catch you out.
  • Set expectations: make sure your collection notice states that information may be used for direct marketing, so expectations are set at the point of collection.
  • Keep consent records: note when and how each recipient consented to email and SMS marketing.
  • Check every message: it identifies the sender, includes working contact details, and carries a clear, functional unsubscribe.
  • Test the opt-out: run a test message on each channel at least once a quarter, and confirm opting out removes the person from future campaigns promptly and free.
  • Know your lists: find out where your data came from, and make sure any supplier warrants that it collected the information lawfully.
  • Publish a privacy policy: keep an up-to-date APP privacy policy that is easy to find, as required by APP 1.3 and 1.4.
  • Train your staff: make sure the people who handle customer data pass opt-outs, access requests and complaints to the right person.

When a privacy lawyer is worth the cost

For a small business, the day-to-day compliance here is manageable. A lawyer adds value at the edges: drafting or updating your APP privacy policy, reviewing agreements with data suppliers, marketing agencies and list brokers, building consent and opt-out processes that survive a regulator's scrutiny, and representing you if the OAIC or the ACMA opens an investigation or issues a notice. If you are unsure whether the small business exemption applies to you, or you are buying personal information from a third party, a short advice session is cheaper than the alternative.

The opt-out you never tested

The most expensive direct marketing mistake is not starting to market. It is marketing at scale with an opt-out that does not work. Read the ACMA penalty notices again: millions of dollars for unsubscribe failures, faulty consent records and messages sent after people asked to be left alone. Regulators treat the machinery of opting out as the heart of the law, not an administrative afterthought.

So this week, send yourself a test message on every channel you use. Click the unsubscribe link. Check that it is free, that it works, and that your database drops you immediately. Then ask the person who bought your last list where it came from. Those two checks answer most of what the law asks of you.