- Who the law applies to: what counts as spam
- Duty 2: Identify yourself accurately in every message
- Duty 3: Make unsubscribing easy, and honour the request
- What non-compliance costs: enforcement and penalties
- A compliance checklist for your next campaign
- When to get a lawyer involved
- The consent trap most businesses miss
Every marketing email, text message or instant message your business sends is regulated by Commonwealth law, whether you send it yourself or an agency, platform or consultant sends it for you. The Spam Act 2003 (Cth) has been one of the most actively enforced laws in Australian marketing for two decades, and enforcement has only sharpened. The Australian Communications and Media Authority (ACMA) reported that businesses paid more than $20 million in spam penalties in the 18 months to October 2024 alone.
The law is built on three duties that apply to every commercial electronic message. You need the recipient's consent. You need to identify yourself accurately. And you need to provide a working unsubscribe facility and honour it. Miss any of the three and you expose the business to per-day penalties, infringement notices and regulator scrutiny. This article sets out who the law applies to, what each duty requires in practice, what non-compliance costs, and how to check your own campaigns before the next send.
Who the law applies to: what counts as spam
The Act regulates commercial electronic messages: emails, SMS and MMS texts and instant messages whose purpose, judged by their content, presentation and any links they contain, is to offer, advertise or promote goods, services, land or a business or investment opportunity. That test comes from section 6 of the Spam Act 2003 (Cth). It catches most marketing: newsletters, promotional offers, sale announcements, event invitations that push a product, and any message that links to marketing content.
A message only needs an Australian link to be covered. Under section 7, that includes a message that originates in Australia, is sent by someone physically present in Australia or by an organisation managed from Australia, is accessed using a computer, server or device in Australia, or is sent to a recipient in Australia. A Sydney business emailing customers in the United States is still regulated, because the message originates here.
Two points are easy to miss. First, you are the sender even when you outsource. Under section 8, a person who authorises the sending of a message is treated as having sent it, and ACMA's guidance is blunt that you must have consent for every recipient even when someone else runs the campaign for you. Second, the commercial test catches messages dressed up as service messages. ACMA has repeatedly found businesses misclassifying marketing as purely factual. DoorDash was penalised after treating texts to prospective delivery drivers as factual when they contained offers and incentives, and the Commonwealth Bank was penalised after classifying millions of promotional emails as non-commercial.
Not every message is caught. Purely factual messages that do not promote anything fall outside the definition, and messages sent by government bodies, registered political parties, registered charities and educational institutions to their students are exempt from the consent and unsubscribe rules as designated commercial electronic messages under Schedule 1, though they must still identify the sender accurately.
Duty 1: Get consent before you send
Section 16 prohibits sending unsolicited commercial electronic messages with an Australian link. The defence that matters commercially is consent: the recipient's consent is what makes the message solicited. The sender bears the burden of proving it, which is why record-keeping is not administrative overhead but the legal foundation of your campaign.
There are two ways to hold consent, and ACMA's guide to consumer consent is worth reading in full before you build a list.
Express consent
Express consent is an informed, active opt-in: the recipient fills in a form, ticks a box on your website, or agrees over the phone or face to face. Keep a record of who gave consent, when and how. There is a trap here: you cannot send an electronic message asking for consent, because the request itself is a marketing message. That makes re-consent campaigns for old lists legally fraught, and it is why many businesses turn to lawyers before trying to revive a dormant list.
Inferred consent
Inferred consent is narrower than most businesses assume. ACMA says you can only infer consent where the recipient has knowingly and directly given their address and it is reasonable to believe they would expect marketing from your business, usually because they have a provable, ongoing relationship with you and the marketing is directly related to that relationship. Someone with a savings account may expect to hear about a better savings product; they have not consented to insurance pitches. A one-off purchase does not create inferred consent, and an address scraped from a website or directory does not either.
Inferred consent also does not survive buying a list. If you buy, rent or inherit a marketing list, you remain responsible for proving consent for every address on it. Using address-harvesting software or harvested-address lists is separately prohibited under sections 20 to 22, so the cheapest list is the one most likely to end in an enforcement action.
Duty 2: Identify yourself accurately in every message
Section 17 requires every commercial electronic message to clearly and accurately identify the individual or organisation that authorised the sending of the message, and to include accurate contact information that is reasonably likely to remain valid for at least 30 days after the message is sent. ACMA's practical guidance is to use the correct legal name of the business, or your name and Australian Business Number. If someone else sends the messages on your behalf, the message must still identify your business as the one that authorised them, not the agency or platform that pressed send.
Duty 3: Make unsubscribing easy, and honour the request
Section 18 requires every commercial message to include a clear and conspicuous unsubscribe statement with an electronic address capable of receiving unsubscribe messages for at least 30 days after the message is sent. The Spam Regulations 2021 (Cth) and ACMA's guidance add the practical requirements: honour requests within five working days, charge no fee, do not require the recipient to give extra personal information, and do not force them to log in or create an account just to unsubscribe.
For SMS, a simple Reply STOP is the standard. There is a technical trap here: alphanumeric sender IDs generally cannot receive replies, so a campaign sent from an alphanumeric header without another unsubscribe route is non-compliant from the start.
The most common enforcement trigger is not a missing unsubscribe link but a broken one. Kmart paid a $1,303,500 infringement notice after sending 212,471 emails to customers who had already unsubscribed, which ACMA attributed to a combination of technology, system and procedural failures. Suppression lists that are not maintained, updated or applied across every campaign are how otherwise respectable marketing operations end up in ACMA's enforcement reports.
What non-compliance costs: enforcement and penalties
ACMA investigates spam complaints and has a graduated enforcement toolkit: formal warnings, directions to comply, infringement notices, court-enforceable undertakings and Federal Court proceedings for pecuniary penalties. The amounts are not trivial.
- Civil penalties: the Federal Court can order penalties for each contravention of section 16, capped per day. For a body corporate, the daily cap is 2,000 penalty units, about $660,000 at the current $330 penalty-unit value, for a first offence, and 10,000 penalty units, about $3.3 million, per day where the court has previously ordered a penalty for the same provision. The caps under section 25 are lower for individuals, and penalties accumulate for every day the conduct continues.
- Infringement notices: ACMA can issue a penalty notice without going to court. DoorDash paid a $2,011,320 infringement notice in August 2023 after sending more than 566,000 emails to customers who had unsubscribed and more than 515,000 texts without any unsubscribe facility to prospective drivers. Kmart's $1,303,500 notice followed in November 2023.
- Repeat exposure escalates: the Commonwealth Bank paid $3.55 million in May 2023 after sending 65 million emails without working unsubscribe arrangements, then $7.5 million in October 2024 after sending more than 170 million marketing emails without an unsubscribe facility, 34.8 million of them to people who had not consented or had withdrawn their consent.
- Undertakings: both DoorDash and CBA also gave three-year court-enforceable undertakings committing to independent compliance reviews, governance improvements and regular reporting to ACMA. These are ongoing, expensive obligations, not one-off costs.
The pattern is worth noting: each of these businesses had real marketing operations and real consent practices on paper. The failures were in execution, classification of messages, and suppression list hygiene. The enforcement figures are published by ACMA and are a reliable guide to what a mid-size Australian business can expect to pay.
A compliance checklist for your next campaign
Work through each item before you press send:
- Map your list: For every email address and mobile number, identify where it came from and which consent basis applies: express opt-in, or a knowingly and directly provided address tied to an ongoing relationship. If you cannot document it, do not send to it.
- Keep consent records: Who consented, when and how. The burden of proof is yours, and the record is the proof.
- Check the sender field: Correct legal name or ABN, and contact details valid for at least 30 days, even when an agency sends the campaign.
- Test the unsubscribe before sending: A clear and conspicuous link or Reply STOP route, functional for 30 days, with no login and no extra data required.
- Honour unsubscribes within five working days: Maintain one suppression list across all platforms, brands and agencies, and test it regularly.
- Do not relabel marketing as service messages: If the message promotes a product or service or links to marketing content, it is commercial and needs consent, identification and an unsubscribe facility.
- Review your platform and agency contracts: Responsibility for compliance sits with your business, so you need visibility of how your providers collect data, manage suppression and handle complaints.
When to get a lawyer involved
Most spam compliance is administrative, but a lawyer adds value at three points. Before you build or buy a list, a quick review of how addresses are collected and what records you keep can stop an expensive problem forming. When you inherit a list through an acquisition or a new agency, the consent position of every address should be assessed before the first send. And if ACMA comes knocking, whether through a complaint, an investigation or a proposed infringement notice or undertaking, advice early in the process materially changes the outcome. A lawyer can also help you navigate the overlap with privacy obligations under the Privacy Act 1988 (Cth), because a marketing database is usually a collection of personal information, and the OAIC and ACMA regimes are enforced separately but often bite on the same campaign.
The consent trap most businesses miss
The duty most often missed is the first one. Businesses routinely assume that a purchase, a business-card exchange or a website enquiry is consent to marketing. ACMA's position is that a one-off transaction does not create inferred consent, and a conspicuously published address is not an invitation to join a list. The businesses that end up in enforcement reports are rarely trying to spam anyone. They are sending to lists whose consent they assumed, without records, without checking the relationship, and without a working unsubscribe.
So before the next campaign, do one thing: list every source of email addresses and mobile numbers your business holds, and write down the consent basis for each. Where there is an express opt-in record, keep it. Where there is an ongoing relationship and a knowingly provided address, check that the marketing is directly related to that relationship. Where neither exists, take the address out of the list. That single audit is the difference between a campaign that grows your list and one that grows your liability.