1. Who the spam and privacy rules apply to
  2. Get consent before you send
  3. Identify your business in every message
  4. Give every recipient a working unsubscribe
  5. Handle subscriber data under the Privacy Act
  6. Keep campaign claims honest
  7. What happens if you get it wrong
  8. A practical compliance checklist
  9. Where a lawyer can help
  10. Build the consent record first

Marketing email is one of the cheapest and most direct channels an Australian small business has. It is also one of the most heavily regulated. Every commercial message you send is governed by the Spam Act 2003 (Cth), which the Australian Communications and Media Authority (ACMA) enforces, and the personal information behind your list is protected by the Privacy Act 1988 (Cth). A campaign that overstates what you sell can also bring the Australian Consumer Law into play.

The core duties are simple to understand: get consent, identify yourself, provide a working unsubscribe, look after the personal information you hold, and keep your claims honest. This guide explains who those duties apply to, what each one requires in practice, and what a breach can cost you.

Who the spam and privacy rules apply to

The laws that govern marketing email do not apply uniformly. Before worrying about the detail, check which regimes bind your business:

  • Spam Act: applies to any person who sends, or causes to be sent, a commercial electronic message with an Australian link. There is no turnover threshold and no small business exemption. If you send emails, text messages or similar electronic messages that advertise or promote goods, services, land or investment opportunities, the Act applies to you.
  • Privacy Act: binds "organisations", which generally means businesses with an annual turnover above $3 million in the previous financial year. Businesses at or below that threshold are usually exempt under the small business exemption, unless an exception applies, for example where the business provides health services or discloses personal information for a benefit.
  • Australian Consumer Law: applies to conduct in trade or commerce, which covers virtually any marketing activity regardless of business size.

The asymmetry matters. The Spam Act reaches every business, but most of the Privacy Act's rules, including its direct marketing provisions, only bind businesses above the $3 million threshold. A business under the threshold still has to comply with the Spam Act in full, and the threshold is based on the previous financial year, so a business that grew quickly can find itself newly covered.

The Spam Act also has a specific content test. A message is commercial if its purpose, judged from its content and presentation, is to offer, advertise or promote goods, services, land or a business or investment opportunity. Purely transactional messages, such as a receipt or a password reset containing no promotional content, fall outside the definition, but the moment you add a marketing element, the full set of rules applies.

The central rule is in s 16 of the Spam Act 2003 (Cth): you must not send an unsolicited commercial electronic message with an Australian link. Consent is the defence that makes a message solicited, and under s 16(5) the sender bears the evidential burden of establishing it.

The Act defines consent in Schedule 2 as either express consent or consent that can reasonably be inferred from the recipient's conduct and from the business or other relationship between you. In practice:

  • Express consent: the person actively opts in, for example by ticking a box on a sign-up form or subscribing to a newsletter.
  • Inferred consent: based on an existing relationship, such as a customer who recently bought from you and gave you their email, where marketing would reasonably be expected.

Inferred consent is narrow. The Act is explicit that consent cannot be inferred merely because an email address has been published, so scraping addresses from a website or directory and emailing them is not consent. Buying a list from a data broker is high risk unless you can verify the consent attached to each address, because the consent travels with the person, not with the list.

Keep a record of when, how and why each person consented. A double opt-in, where the subscriber confirms their subscription by clicking a link in a confirmation email, creates the strongest audit trail and is the safest default for a small business. Pre-ticked boxes are not a genuine choice and leave you unable to show active consent.

Identify your business in every message

Under s 17 of the Spam Act 2003 (Cth), every commercial electronic message must clearly and accurately identify the individual or organisation that authorised the sending of the message, and include accurate information about how the recipient can readily contact them. That information must stay valid for at least 30 days after the message is sent.

In practical terms, use your real business name rather than a vague or misleading "from" name, and make sure the contact details in your footer are current. A recipient should never have to wonder who sent the email or how to reach you, and subject lines should match the content.

Give every recipient a working unsubscribe

Section 18 of the Spam Act 2003 (Cth) requires every commercial electronic message to include a statement, presented clearly and conspicuously, telling the recipient how to unsubscribe, with an electronic address that actually works for at least 30 days.

The unsubscribe must be honoured quickly. Under Schedule 2 of the Act, a withdrawal of consent takes effect at the end of five business days from when the recipient sends the unsubscribe message. Do not charge a fee for unsubscribing, and do not force the recipient to log in to an account to opt out. A one-click unsubscribe link is the industry standard, and it should feed a suppression list so the person is not emailed again through a different campaign.

Handle subscriber data under the Privacy Act

If your business is bound by the Privacy Act 1988 (Cth), direct marketing is regulated by Australian Privacy Principle (APP) 7. The starting point is that you must not use or disclose personal information for direct marketing, with two main exceptions:

  • Information collected from the individual: you may use it for direct marketing if the person would reasonably expect that use and you give them a simple way to opt out, which you must honour.
  • Information collected from a third party: you may only use it for direct marketing with the individual's consent.

Sensitive information, such as health information, can only be used for direct marketing with consent, and there are separate restrictions on using credit reporting information for direct marketing.

The wider APP framework also matters. When you collect an email address you should provide a collection notice explaining what you collect, why, and how it will be used, and your privacy policy should describe your direct marketing practices. If subscriber data is compromised, the Notifiable Data Breaches scheme in Part IIIC of the Act can require you to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where there are reasonable grounds to believe an eligible data breach has occurred and is likely to result in serious harm. The Commissioner can also direct you to notify.

Keep campaign claims honest

Separate from the spam rules, your marketing content must not mislead anyone. Section 18 of the Australian Consumer Law, which is Schedule 2 of the Competition and Consumer Act 2010 (Cth), prohibits conduct in trade or commerce that is misleading or deceptive or is likely to mislead or deceive.

That applies to your subject lines, pricing and discount claims, "only X left" scarcity statements, testimonials and comparisons. Any claim you make should be accurate and capable of being substantiated. The Australian Competition and Consumer Commission (ACCC) can take action on misleading marketing, and the Australian Consumer Law carries its own penalty regime on top of the spam rules.

What happens if you get it wrong

ACMA has a ladder of enforcement options under the Spam Act 2003 (Cth): formal warnings, infringement notices, enforceable undertakings, and applications to the Federal Court for civil penalties.

Civil penalties are calculated in penalty units, which have been worth $313 since 1 July 2023. For a body corporate that sends unsolicited commercial messages in breach of s 16, the cap is 2,000 penalty units per day for a first offence, or $626,000 per day, rising to 10,000 penalty units per day, or $3.13 million per day, where the company has a prior record. Breaching the identification or unsubscribe requirements carries up to 1,000 penalty units per day for a first-time body corporate, about $313,000 per day, and smaller caps apply to individuals.

These figures are not theoretical. In August 2023, ACMA reported that DoorDash paid a $2,011,320 infringement notice after sending more than one million texts and emails that breached the spam rules, and gave ACMA an enforceable undertaking covering its future conduct.

The Privacy Act penalties are steeper again for the businesses it covers. A serious interference with privacy can attract a penalty for a body corporate of up to the greatest of $50 million, three times the benefit obtained from the conduct, or 30% of adjusted turnover, with individuals facing up to $2.5 million. Compliance failures can also hurt in softer ways: spam complaints damage sender reputation, push your emails into junk folders, and shrink the deliverability of everything you send.

A practical compliance checklist

Use this checklist before every campaign and as part of your annual review:

  • Consent: use unticked opt-in boxes, state clearly what subscribers will receive, and store the source, date and wording of consent for every contact.
  • Unsubscribe: ensure every campaign includes a prominent unsubscribe link, and process opt-outs within five business days.
  • Identification: check that sender names, business names and footer contact details are accurate and current.
  • Privacy: publish a privacy policy and collection notice, restrict who can access your list, and secure your email platform accounts.
  • Claims: review subject lines, pricing and scarcity statements before sending, and keep evidence to substantiate them.
  • Breach response: know who is responsible for assessing a data breach and notifying the OAIC and affected individuals if required.
  • Reviews: audit your consent flows, templates and policies at least annually, and whenever you launch a new automation or referral program.

Where a lawyer can help

Most of the work here is practical, but a lawyer adds value at specific points. A practitioner can review your sign-up forms and consent records against the Spam Act and APP 7, draft or update your privacy policy and collection notices, and check the terms with your email platform or marketing agency so data processing obligations are covered. They can also sense-check high-risk campaigns before launch, particularly ones making strong claims or using third party data. If a complaint or an ACMA investigation does land, early legal advice can make the difference between a quick resolution and a costly one.

If you take one action this week, make it the consent record. The identification and unsubscribe duties can be checked against any message you send. Consent is the only one the regulator cannot verify by looking at the email itself, and s 16(5) puts the burden of proving it on you. When ACMA investigates, the central question is whether you can show when and how each recipient consented. A list built on inferred consent with no records collapses the moment it is questioned. Turn on double opt-in, timestamp every sign-up, and store the wording of the consent you asked for. Everything else in this guide becomes easier once you can prove that.