Networking events are one of the cheapest ways to find customers, and the business cards in your pocket look like a ready-made contact list. But a card is not a licence to start emailing. The Spam Act 2003 (Cth) (the Act) regulates every commercial electronic message sent with an Australian link, and it applies just as much to a follow-up email to someone you met once at an event as it does to a national email campaign. Get it wrong and each email can be a separate contravention carrying a civil penalty, enforced by the Australian Communications and Media Authority (ACMA).
The good news is that the Act's requirements are few and mechanical. Before you email a business card contact you need their consent, you need to identify yourself accurately, and you need to provide a working unsubscribe facility. This article explains who the Act applies to, what each of those three duties involves, what happens if you breach them, and a checklist you can work through before your next campaign.
Who does the Spam Act apply to?
The Act applies to any individual or business that sends a commercial electronic message with an Australian link. In broad terms, a message has an Australian link if it is sent to, or accessed by, a recipient in Australia, or sent from an Australian source. There is no turnover threshold and no minimum volume: a solo consultant sending one follow-up email to a networking contact is just as much within the Act as a retailer running a 100,000-recipient campaign.
The key threshold question is whether your message is a commercial electronic message under s 6 of the Act. The test is one of purpose, judged by the content of the message, the way it is presented, and what any links in it lead to. A message is commercial if its purpose, or one of its purposes, is to offer to supply, or to advertise or promote, goods, services, land, or a business or investment opportunity. One commercial purpose is enough, so a "quick catch-up" email that ends with an invitation to buy your services is a commercial electronic message just as much as a brochure blast. The Act also catches other electronic messages such as text messages, so the same rules apply if you message the mobile number on a card.
A small group of senders is exempt. Messages sent by government bodies, registered political parties, registered charities and educational institutions are "designated commercial electronic messages" and largely fall outside the consent and unsubscribe rules. For a typical small-to-medium business, none of this applies, and the full regime applies to you.
Run this quick self-assessment before any campaign:
- Commercial purpose: Does the message offer, advertise or promote your goods or services, even as a secondary purpose?
- Australian link: Will the recipient read or access it in Australia?
- Consent: Do you have express consent, or a defensible basis for inferred consent, from each recipient?
If the first two answers are yes, the Act applies, and consent is the question that decides whether you can send at all.
Duty one: obtain consent before you send
S 16 of the Act sets the core rule. A person must not send, or cause to be sent, a commercial electronic message with an Australian link unless the recipient's account-holder consented to receiving it. The burden of showing consent sits with you, the sender.
The Act defines consent in Schedule 2 as either express consent, or consent that can reasonably be inferred from the conduct and the business and other relationships of the individual or organisation concerned. Both routes matter to a business card contact.
Express consent
Express consent is the safest option and the easiest to prove. It does not need to be in writing, but it needs to be clear and informed, and you should be able to show it later. A "would you like me to email you our pricing sheet?" at the end of a conversation, with a yes, is express consent. So are a tick box on a sign-up sheet, an entry form that records permission, or a reply to your introductory message confirming interest. Record it: note the date, the person, and what they agreed to.
Inferred consent and the business card
A business card, on its own, is not consent. Clause 4 of Schedule 2 states that consent may not be inferred from the mere fact that an electronic address has been published, and handing over a card is, in effect, a publication of an address. What can support an inference is the surrounding conduct and the relationship between you and the recipient. In practice, the factors that matter are:
- Context: Did they hand you the card during a genuine conversation about your products or services, or was it swapped in a speed-networking round with twenty other people?
- Bilateral contact: Have you actually communicated before, such as a meeting, a call, or an exchange of documents, or is the card the only link between you?
- The address itself: Is the email one the person clearly uses for business contact, such as a work address rather than a personal one?
- Relevance: Is what you want to email about connected to why you met, or is it an unrelated pitch?
There is a limited exception for conspicuous publication. If someone conspicuously publishes a business email address for business purposes, such as on the contact page of their website, consent can be inferred for messages relevant to their business. A card handed to you across a networking table is not publication to the world, so the exception rarely helps in this context.
What the Clarity1 case teaches
The leading case on inferred consent is Australian Communications and Media Authority v Clarity1 Pty Ltd [2006] FCA 410. Clarity1 ran business seminar businesses and, through its sole director Wayne Mansfield, sent more than 213 million commercial electronic messages to almost 5.7 million unique addresses, much of it from lists compiled with address-harvesting software.
Clarity1 argued that recipients had consented because the messages contained an unsubscribe facility and nobody used it. The Court rejected that argument: the Act obliges senders to include an unsubscribe facility, but a recipient's failure to use it does not amount to consent. Clarity1 also argued that consent could be inferred from a business relationship with recipients. The Court found there was no such relationship where the communication was entirely one-way, and that an inference of consent was not open from unilateral broadcasts to people Clarity1 had never dealt with. Significantly, however, the Court accepted that an inference could be drawn for the 182 addresses belonging to people who had actually purchased goods or services from Clarity1. Those were genuine customers, and the dealings between the parties supported an inference of consent.
The lesson for business card marketing is direct. If you have actually dealt with the person, such as where they bought from you, engaged you for a quote, or worked with you on something, inferred consent is arguable. If your only contact is that they handed you a card at an event, you are closer to the Clarity1 end of the spectrum: the relationship is thin, and the communication is effectively one-way. The courts have not decided precisely where a business card exchange sits, so the safest course is to ask for express consent while you are still standing in front of the person.
Duty two: identify yourself accurately
S 17 of the Act requires every commercial electronic message to clearly and accurately identify the individual or organisation who authorised the sending of the message, and to include accurate information about how the recipient can readily contact that person or organisation. That information must be reasonably likely to remain valid for at least 30 days after the message is sent.
In practical terms, send from a real identity: your business name, and a reply address or phone number that someone can actually use. A message that comes from "no-reply@yourbusiness.com.au" with no other contact details is close to a breach. This duty matters beyond the Act itself: it is also the practice that keeps your unsubscribe function workable, because recipients need a way to reach you.
Duty three: provide a working unsubscribe facility
S 18 of the Act requires every commercial electronic message to include a statement, presented in a clear and conspicuous manner, that the recipient can send an unsubscribe message to an electronic address set out in the message. That address must be reasonably likely to be capable of receiving unsubscribe messages for at least 30 days after the message is sent. In plain terms:
- State clearly that the recipient can opt out, and make the statement easy to see.
- Give an address that actually receives unsubscribe requests, and check it regularly.
- Honour every request: stop sending commercial messages to anyone who opts out, and keep a suppression list so they are not picked up by a later campaign.
There is also an ancillary rule: it is a contravention to be knowingly concerned in someone else's breach, and directors and managers can be personally liable for their involvement. Mansfield was ordered to pay a penalty in his own name, not just the company's, so treat compliance as a personal responsibility, not an IT matter.
What happens if you breach the Act
ACMA is the regulator and enforces the Act through infringement notices and civil penalty proceedings in the Federal Court. Penalties are expressed in penalty units, and the current value of a penalty unit is $330 under s 4AA of the Crimes Act 1914 (Cth). Under s 25 of the Spam Act, the maximums are:
- Company, no prior record: 100 penalty units (about $33,000) per contravention, capped at 2,000 penalty units (about $660,000) where multiple contraventions occur on the same day.
- Company, prior record: 500 penalty units (about $165,000) per contravention, capped at 10,000 penalty units (about $3.3 million) per day.
- Individual, no prior record: 20 penalty units (about $6,600) per contravention, capped at 400 penalty units (about $132,000) per day.
- Individual, prior record: 100 penalty units (about $33,000) per contravention, capped at 2,000 penalty units (about $660,000) per day.
Because each email is a separate contravention, the numbers climb quickly. A list of a few thousand contacts sent to without consent can produce six-figure exposure before anyone notices. The penalties in Clarity1 show the stakes: the company was ordered to pay $4.5 million and Mansfield $1 million personally in Australian Communications and Media Authority v Clarity1 Pty Ltd [2006] FCA 1399, and injunctions and public enforcement action can follow.
A compliance checklist before you press send
Work through this before every campaign to business card contacts:
- Record consent: Note how you obtained consent for each address, whether an express opt-in or the dealings you rely on for an inference.
- Keep the evidence: The conversation notes, the sign-up form, the email thread, the purchase record.
- Identify yourself: Use your real business name and accurate, working contact details.
- Provide an unsubscribe: Make the statement clear and conspicuous, and keep the address working for at least 30 days.
- Honour opt-outs: Process every unsubscribe request promptly and maintain a suppression list.
- Never buy or scrape lists: Using harvested address lists is itself a separate contravention, and it poisons any argument about inferred consent.
- Check the Australian link: It almost certainly exists, so assume the Act applies.
- Link your privacy policy: Telling people how you collect, store and use their details, and linking your privacy policy in your emails, is best practice that supports the trust a consent-based list depends on.
Where a lawyer can help
Most of this is straightforward, but two situations justify advice. The first is a list built up over years without express consent, where you want to know whether inferred consent is defensible. A lawyer can review the dealings, the relationships and the context, and tell you which addresses carry real risk. The second is contact from ACMA, whether a complaint, an investigation or an infringement notice, because penalties escalate once you have a prior record and the way you respond matters. A lawyer can also draft your consent capture, such as the wording for event sign-up sheets and email footers, so the mechanics of the Act are built into your systems from the start.
The card is the record of a meeting, not a record of consent
The mistake that costs businesses most under the Act is treating the business card as permission to email. It is not. A card tells you a conversation happened and gives you a way to follow up, but the Act looks for consent: express, or reasonably inferred from conduct and relationships. The Clarity1 case drew the line firmly: no consent from a silent unsubscribe, and no relationship from one-way communication, but a genuine customer relationship can justify an inference. If you have been emailing cards you collected without asking, make this week your audit week. Go through the list, mark which contacts gave you something approaching consent, and add a one-line opt-in question to the way you collect cards at your next event. A marketing list built on that record is worth far more than one built on cards alone.