emailmarketing.net

Australia — Spam Act 2003 and ACMA Enforcement

Australia's opt-in regime: express/inferred consent, sender ID and unsubscribe rules (5 business days, 30 days, no login), ACMA penalties incl. Commonwealth Bank's record AU$3.55M, plus OAIC APP 7 and tracking-pixel guidance.

Referencecompliancesender

Australia is an opt-in jurisdiction with one of the most actively enforcing regulators in the world. The Spam Act 2003 (Cth) and the Spam Regulations govern commercial electronic messages (email, SMS, MMS, instant messages); the Australian Communications and Media Authority (ACMA) enforces it, routinely issuing seven-figure infringement notices against mainstream brands — most often for unsubscribe failures (including requiring login to unsubscribe), a direct design constraint on ESP unsubscribe flows.

Provenance: the Act's text below is from the consolidated compilation C2012C00030 (retrieved via the Internet Archive; legislation.gov.au serves the current compilation via a JS application). ACMA pages were also retrieved via the Internet Archive (2026 snapshots) because acma.gov.au blocks non-browser clients.

Scope

  • A message is commercial if it offers, advertises or promotes goods or services (or land, business/investment opportunities) — even if only part of the message is commercial (ACMA fact sheet). Purely factual messages are exempt (Schedule 1, see below).
  • The Act applies to messages with an Australian link (s 7): sent from, to, or accessed in Australia — so foreign senders mailing Australian recipients are covered.
  • The Act extends extraterritorially (acts outside Australia) and is enforced through civil penalty provisions, not criminal law (s 27).
  • Defences: the sender did not know and could not with reasonable diligence have ascertained the Australian link, or the message was sent by mistake — the sender bears the evidential burden (ss 16(3)–(5)).

The three obligations

1. Consent (s 16 + Schedule 2)

A commercial electronic message with an Australian link must not be sent without the consent of the relevant electronic account-holder. Consent means (Sch 2 cl 2):

  • Express consent — best practice per ACMA. Can be given by form, website checkbox, phone, or face to face. You cannot send an electronic message to ask for consent — that request is itself a marketing message. Keep records of who consented, when, and how: the sender bears the burden of proving consent.
  • Inferred consent — reasonably inferred from the conduct and business/other relationships of the recipient. ACMA reads this narrowly: a provable, ongoing relationship where the marketing is directly related to that relationship (e.g., a savings bank telling a customer about another savings account — but not cross-selling insurance to that same customer). A one-off purchase does not create inferred consent.
  • Conspicuous publication (Sch 2 cl 4) — consent may be inferred for a work-related electronic address (employee, director, officer, partner, office-holder, self-employed individual, or role/position address) that has been conspicuously published, where publication reasonably appears to be with the person's/organisation's agreement, unless the publication is accompanied by a statement that unsolicited commercial messages are not wanted — and only for messages relevant to the work-related business, functions or duties of the addressee. Mere publication of an address is otherwise not consent (Sch 2 cl 4(1)). This is Australia's only "B2B allowance": business addresses are otherwise under the same consent rules as consumer addresses.
  • Withdrawal of consent takes effect at the end of 5 business days from the day an unsubscribe message is sent (Sch 2 cl 6) — business days determined by the recipient's location.
  • Purchased/rented lists: the advertiser remains responsible for proving consent for every address used.

2. Sender identification (s 17)

Every commercial electronic message (including "designated" exempt messages) must:

  • clearly and accurately identify the individual or organisation who authorised the sending (use the legal business name, or name plus ABN);
  • include accurate contact information; and
  • that information must be reasonably likely to be valid for at least 30 days after sending.

If a third party (agency, ESP) sends on a brand's behalf, the message must still identify the authorising business, and that business remains liable ("you cannot outsource your risk" — ACMA fact sheet).

3. Functional unsubscribe (s 18 + ACMA 2024 fact sheet)

Every commercial message (except designated ones) must contain a clear and conspicuous unsubscribe statement and a facility that:

Requirement Detail
Clear instructions Presented in a clear and conspicuous manner (s 18(1)(d))
Functional ≥ 30 days The unsubscribe address must be able to receive the recipient's message — and a reasonable number of similar messages from other recipients — for at least 30 days after sending (s 18(1)(e))
Actioned within 5 working days ACMA fact sheet; matches Sch 2 cl 6 withdrawal timing
No fee Must not require payment; must not cost more than the usual cost of using the address (e.g., a standard SMS charge)
No login / no account / no extra personal information The recipient must not be required to log in to, or create, an account, or provide additional personal information, to unsubscribe
Legitimately obtained address The unsubscribe address itself must be legitimately obtained (s 18(1)(f))

The no-login rule is the one large brands keep breaking (see enforcement below) — an ESP's unsubscribe flow for Australian recipients must complete without authentication.

Other prohibited conduct

  • Address-harvesting software and harvested-address lists must not be supplied, acquired or used in connection with sending in breach of s 16 (ss 20–22).
  • Ancillary liability: aiding, abetting, inducing, being knowingly concerned in, or conspiring in a contravention is itself a contravention (ss 16(9), 17(5), 18(6)) — relevant to platforms and agencies. Merely supplying a carriage service is excluded.
  • Messages must not be sent to addresses the sender has no reason to believe exist (s 16(6)).

Exemptions — designated commercial electronic messages (Schedule 1)

Exempt from the consent (s 16) and unsubscribe (s 18) rules — but still subject to sender identification (s 17):

Category Conditions
Factual information messages No more than factual information plus directly-related comment and permitted identifying information (name/logo/contact details of author, employer, sponsor); would not be commercial without that added info (Sch 1 cl 2)
Government bodies, registered political parties, religious organisations, charities Message relates to goods/services and the body is the supplier (Sch 1 cl 3)
Educational institutions Recipient (or household member) is or was enrolled; institution supplies the goods/services (Sch 1 cl 4)

Penalties and enforcement

Statutory maxima (ss 24–25)

Penalties are expressed in penalty units, per contravention, imposed by the Federal Court; each day's sending can comprise many contraventions:

Person No prior record — per contravention / per-day cap Prior record — per contravention / per-day cap
Body corporate, s 16 breach 100 units / 2,000 units 500 units / 10,000 units
Body corporate, other civil penalty provisions 50 units / 1,000 units 250 units / 5,000 units
Individual, s 16 breach 20 units / 400 units 100 units / 2,000 units
Individual, other provisions 10 units / 200 units 50 units / 1,000 units

The Court may additionally order compensation to victims and disgorgement of financial benefits (ss 28–29); actions may be brought up to 6 years after the contravention (s 26). ACMA can also issue infringement notices (Schedule 3 — payable within 28 days, given within 12 months of the alleged contraventions), formal warnings, and accept court-enforceable undertakings. (A Commonwealth penalty unit is periodically indexed — AU$330 as of late 2024 — so the 10,000-unit repeat-corporate daily cap exceeds AU$3M per day.)

Enforcement practice — the record

ACMA publishes every investigation outcome. Unsubscribe failures and sending without consent dominate. Selected email-relevant actions:

Company Breach Outcome Date
Commonwealth Bank of Australia 61M+ emails requiring login to unsubscribe; 4M+ without functioning unsubscribe; 5,000+ sent after unsubscribe AU$3,552,000 infringement notice + 3-year enforceable undertaking (then the largest ever) Jun 2023
Commonwealth Bank of Australia (again) Email/SMS without consent, non-functional unsubscribe AU$7,502,610 infringement notice + EU Aug 2024
Tabcorp (TAB) SMS/WhatsApp: inadequate sender info, no functional unsubscribe, no consent AU$4,003,270 + EU Apr 2025
Pizza Hut Australia Emails without consent, contact details, or functional unsubscribe AU$2,502,500 + EU May 2024
Sportsbet Email/SMS without consent or unsubscribe AU$2,508,600 + EU Mar 2022
DoorDash Email/SMS without consent or unsubscribe AU$2,011,320 + EU Aug 2023
Binance Australia Emails without consent or unsubscribe AU$2,000,220 + EU Oct 2022
Latitude Finance Email/SMS without consent or unsubscribe AU$1,549,560 + EU Jul 2022
Luxottica Emails without consent or unsubscribe AU$1,512,500 + EU Apr 2024
Kmart Emails without consent AU$1,303,500 + EU Sep 2023
Woolworths Emails after consent withdrawn and without unsubscribe AU$1,003,800 + EU Jun 2020
Lululemon Australia 370,000+ emails with commercial content and no unsubscribe AU$702,900 Mar 2026
Betfair Emails/SMS to VIP customers without consent/unsubscribe AU$871,660 + EU May/Jul 2025
Telstra SMS without consent/unsubscribe AU$626,000 + EU Dec 2024
Ticketek Email/SMS without consent AU$515,040 + EU Oct 2023
Uber Australia Emails without consent or unsubscribe AU$412,500 Sep 2023
Kogan Emails without a functional unsubscribe AU$310,800 + EU Jan 2021

In the 18 months to mid-2023 alone, businesses paid AU$11M in spam/telemarketing penalties, with 12 court-enforceable undertakings and 1 formal warning. Patterns an ESP should engineer against: unsubscribe links that require login (CBA), "transactional" messages containing promotional content without an unsubscribe (Lululemon, Kogan), continuing sends after withdrawal (Woolworths, Optus, Ticketek), and treating VIP/loyalty segments as consent-exempt (Betfair).

Interaction with the Privacy Act — OAIC APP 7 (direct marketing)

Australian Privacy Principle 7 restricts using personal information for direct marketing, but APP 7 does not apply to the extent the Spam Act (or Do Not Call Register Act) applies — so for email/SMS/MMS marketing the Spam Act governs, and APP 7 covers the rest (mail, door-to-door, targeted online advertising, in-app marketing) and applies where an organisation is exempt from those Acts. Still relevant to email programs:

  • APP 7.2 — information collected directly from the individual may be used for direct marketing if the individual would reasonably expect it (objective test), a simple means of opting out is provided, and they haven't opted out.
  • APP 7.3 — information from third parties, or where there is no reasonable expectation: requires consent (unless impracticable to obtain), a simple opt-out, and a prominent opt-out statement in each communication (plain English, prominent placement, readable font).
  • APP 7.4sensitive information may only be used for direct marketing with explicit consent (no impracticability exception).
  • On request, an organisation must tell the individual where it got their personal information (unless unreasonable/impracticable), within about 30 days, and must honour opt-outs of list "facilitation" (providing data for others' marketing).
  • "Simple means" of opting out: clear instructions, minimal effort, free or nominal cost, available through the channel the marketing used.

OAIC guidance on tracking pixels

The OAIC's tracking-pixels guidance targets third-party pixels (it focuses on website pixels while noting pixels are also used in emails and apps). Key positions relevant to open-tracking and click-tracking:

  • Data such as IP addresses, URLs, or hashed email addresses can be personal information when linkable with a third-party platform's data — individuals need not be directly identified. OAIC advises organisations to "err on the side of caution."
  • Obligations engaged: APP 1 (privacy policy must disclose third-party pixel use), APP 3 (collection must be reasonably necessary; configure pixels for data minimisation; sensitive information requires express opt-in consent and should generally be blocked from pixel disclosure), APP 5 (notify at or before collection, including third-party recipients and overseas transfers), APP 6 (disclosure to the pixel provider must match the collection purpose or a valid secondary-use basis), APP 7 (simple opt-out from pixel-driven targeted marketing), APP 8 (reasonable steps for overseas disclosure).
  • Before deployment: due diligence on how the pixel works, review provider terms, run a Privacy Impact Assessment, configure to prevent sensitive-data collection, and review regularly. The deploying organisation is responsible for compliant configuration.

ESP checklist for Australian traffic

  • One-click, unauthenticated unsubscribe (List-Unsubscribe / RFC 8058) satisfies the no-login rule; suppress within 5 business days (immediate is best practice).
  • Keep the unsubscribe endpoint live ≥ 30 days after each campaign; keep sender contact info valid ≥ 30 days.
  • Store consent evidence (who/when/how) — the sender must produce it if ACMA asks.
  • Identify the authorising customer (legal name/ABN) in every message sent on their behalf; the customer is liable but ancillary liability can reach those knowingly concerned.
  • Treat "the recipient once bought something" as insufficient — inferred consent needs an ongoing, directly-related relationship. See Consent Methods for the quality spectrum.
  • Never accept lists built with harvesting software; supplying or using them is a separate contravention.

Not legal advice — see compliance/README.md.

#compliance#legal#australia#spam-act#acma#oaic#consent#opt-in#unsubscribe