- Which businesses do these laws apply to
- Duty 1: Obtain and record consent before you email anyone
- Duty 2: Identify yourself and make unsubscribing easy
- Duty 3: Protect the personal information behind your list
- Duty 4: Keep every claim, price and promise accurate
- What happens if you get it wrong
- A practical compliance checklist
- Where a lawyer can help
- Start with your consent records
Email marketing remains one of the cheapest and most effective ways for an Australian business to reach customers, but the legal framework around it is easy to underestimate. If you send promotional emails, often called EDMs (electronic direct mail), three bodies of law can apply at once: the Spam Act 2003 (Cth) (the Spam Act), the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Consumer Law (the ACL), which is Schedule 2 of the Competition and Consumer Act 2010 (Cth).
Each law imposes a different set of duties. The Spam Act controls who you can email and how every message must look. The Privacy Act, where it applies, controls how you collect, use and protect the personal information behind your list. The ACL keeps your claims and prices honest. This guide sets out who each law applies to, the specific duties it creates and the practical steps you can take to stay on the right side of the regulators.
Which businesses do these laws apply to
The reach of each law depends on your size, your industry and what you send. The three regimes apply like this:
- Spam Act: Every business that sends a commercial electronic message with an Australian link is in scope, regardless of size. That covers messages sent from Australia, or to an Australian email address, that advertise or promote a product or service. There is no small business exemption, so if you send promotional emails at all, this Act applies to you.
- Privacy Act: The Australian Privacy Principles (the APPs) bind organisations with an annual turnover above $3 million. Businesses at or below that threshold are generally exempt, but exceptions catch many SMEs anyway: health service providers, businesses that trade in personal information, and bodies corporate related to a larger organisation. Even where the Act does not apply, a larger customer or platform partner may contractually require APP-level compliance.
- ACL: The consumer law applies to conduct in trade or commerce in Australia. If you market goods or services to Australian consumers, your promotional emails fall within it.
Duty 1: Obtain and record consent before you email anyone
The starting point of the Spam Act is section 16: you must not send an unsolicited commercial electronic message. "Unsolicited" means the recipient has not consented, and the Act defines consent as either express or inferred.
Express consent is the gold standard. A person gives it when they tick an opt-in box, complete a sign-up form, or otherwise clearly ask to receive your emails. Under the ACMA's guidance, you should keep a record of every consent you receive: who gave it, when, and how. If the regulator ever asks, the burden of proving consent sits with you, not with the recipient.
Inferred consent is narrower than most businesses assume. The Act allows consent to be inferred only where it is reasonable from the person's conduct and their business or other relationship with you. ACMA's guidance is that this usually requires a provable, ongoing relationship where the marketing is directly related to that relationship: a bank telling a savings customer about another savings product, for example, but not about insurance. A single purchase does not create inferred consent, and publishing an email address on a website does not, on its own, amount to consent.
This is where bought lists cause most of the trouble. If you purchase a list of addresses, you carry the burden of proving valid consent for every contact, and that the consent covers your specific marketing. If you cannot prove it, do not send to it. The same logic applies when an agency or platform sends on your behalf: you are still responsible for the consent behind every address.
Duty 2: Identify yourself and make unsubscribing easy
Every commercial message must do two things regardless of consent.
First, identify the sender. Section 17 of the Spam Act requires each message to include accurate information about the business that authorised it, together with current contact details. ACMA adds that this information must stay correct for at least 30 days after the message goes out. A trading name the recipient cannot connect to you, or a reply address that bounces, is a breach even if the content itself is fine.
Second, provide a functional unsubscribe. Every message must carry a clear and conspicuous way to opt out, and the mechanism must keep working for at least 30 days after sending. ACMA's requirements for honouring requests are strict: you must action an unsubscribe within five business days, you cannot charge a fee, and you cannot require the person to log in, create an account, or supply personal information beyond an email address. Keep a suppression list and sync it across every tool you send from, because one forgotten database can undo an otherwise compliant program.
Duty 3: Protect the personal information behind your list
If the Privacy Act applies to you, the APPs add a second layer of duties over the same data. Four principles matter most for an EDM program.
APP 7 is the direct marketing principle. You cannot use or disclose personal information for direct marketing unless you collected it from the individual, they would reasonably expect that use, and you provide a simple way to opt out that you honour promptly. Using sensitive information, such as health details, for marketing requires consent.
The transparency principles matter too. APP 1 requires a clearly expressed privacy policy, and APP 5 requires a collection notice at the point you gather an address, telling people what you collect, why, and how to complain. APP 6 limits you to using the information for the purposes you disclosed. If you start sending a new type of marketing your subscribers did not sign up for, you need to update your notice and usually obtain fresh consent.
Security and access complete the picture. APP 11 requires reasonable steps to protect the information you hold, and APPs 12 and 13 let individuals request access to their data and ask for corrections. There is currently no general right under the Privacy Act to demand deletion from a marketing list, though you must destroy or de-identify information you no longer need. Under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, a breach that is likely to result in serious harm must be reported to the Office of the Australian Information Commissioner and to affected individuals.
Duty 4: Keep every claim, price and promise accurate
The ACL applies to the content of your emails even when the Spam Act and Privacy Act are fully satisfied. Section 18 of the ACL prohibits misleading or deceptive conduct in trade or commerce, which catches a subject line that overpromises or an email that implies an endorsement that does not exist. Section 29 separately prohibits false or misleading representations about goods and services, including pricing, quality and benefits.
Pricing claims attract particular scrutiny. The ACL's single price rule (section 47) requires the total price to be stated prominently where a component price is advertised, and the component pricing rule (section 48) treats a prominent component price as misleading if the total is not also stated. "50 per cent off" must be a genuine discount from your usual price, and "limited time" must be true. If you promote refunds, warranties or consumer guarantees, you must be able to honour them.
What happens if you get it wrong
Each law has its own regulator and penalty regime.
The Spam Act is enforced by the ACMA. It can issue formal warnings and infringement notices, accept enforceable undertakings, and take businesses to court for civil penalties. Penalties are calculated in penalty units, which are indexed and currently set at $330 each, so a large campaign can attract penalties running into the hundreds of thousands or millions of dollars. ACMA has made spam compliance an enforcement priority in recent years and has secured significant outcomes, including $3.7 million in penalties and refunds from Sportsbet in 2022 and $1.55 million from Latitude Finance the same year.
The Privacy Act is enforced by the OAIC. A serious interference with privacy exposes a body corporate to a penalty of up to the greatest of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover (section 13G), and individuals to up to $2.5 million. Less serious interferences carry penalties of up to 2,000 penalty units, currently about $660,000 for a corporation.
The ACCC and state and territory fair trading agencies enforce the ACL. False or misleading representations expose a corporation to penalties of up to the greatest of $100 million, three times the benefit, or 30 per cent of adjusted turnover (section 224 of the ACL). Misleading or deceptive conduct under section 18 can attract injunctions, damages and corrective orders even though it is not itself a pecuniary penalty provision.
There is also a commercial consequence that needs no regulator at all. Recipients who feel spammed report the sender, and enough complaints push a domain into junk folders across the major email providers. A campaign that ignores the rules dies quietly in the spam filter.
A practical compliance checklist
Work through each item before you launch a campaign:
- Consent: capture consent with unticked opt-in boxes and plain language about what the subscriber will receive and how often.
- Records: log the source, date and method of every consent so you can prove it later.
- Lists: do not buy lists unless you can verify consent for each address and that it covers your marketing.
- Templates: include accurate sender identification, current contact details and a visible unsubscribe in every message.
- Unsubscribe: action opt-outs within five business days and keep suppression lists synced across all tools.
- Privacy: publish a privacy policy, display a collection notice at sign-up, and limit the use of data to the purposes you disclosed.
- Security: protect the database with access controls and multi-factor authentication, and put a data processing agreement in place with your email platform.
- Claims: check every discount, price and promise against the ACL before it sends.
- Incidents: have a plan for data breaches and a documented procedure for handling complaints.
Where a lawyer can help
A lawyer can first tell you which parts of this framework actually apply to your business, which is the question most SMEs get wrong. Beyond that, a practitioner can audit your consent records and list acquisition practices, draft or update your privacy policy and collection notices, negotiate a data processing agreement with your email platform, review your promotional claims and pricing against the ACL, and step in if the ACMA, OAIC or ACCC comes knocking. If you run competitions or giveaways to grow your list, a lawyer can also prepare the terms and conditions and check whether your state or territory requires a trade promotion permit.
Start with your consent records
If there is one part of this framework that catches Australian businesses by surprise, it is the burden of proof. Under the Spam Act you, the sender, must be able to show consent for every address you email, and regulators ask for that evidence when something goes wrong. A list built through unticked opt-ins, with the date and source of each consent logged, is a list you can defend. A list assembled from bought data or a haphazard sign-up form is a liability that grows with every campaign. Before you design your next email, audit where each address came from. If you cannot prove consent, you do not have it, and that is the first thing to fix this week.