emailmarketing.net

Consent Guidance Updates: Recent Regulator Positions to Track

A running digest of recent consent guidance and enforcement the KB should track — NZ DIA spam case studies (real outcomes), ACMA's 2024 statement on what 'consent' now requires in Australia, and CNIL's rules for sharing B2C data with marketing partners — each with the operational lesson.

Referencecompliancesender

Consent law changes less through new statutes than through regulators publishing how they interpret the existing ones. This article collects recent interpretive guidance and enforcement outcomes that refine what "consent" operationally requires — material that post-dates or sharpens the base statute articles. It complements, and does not restate, the substantive law in Australia Spam Act, France CNIL, and APAC Email Laws (New Zealand). Each item below is the guidance/case plus the operational lesson.

Not legal advice — see compliance/README.md.

New Zealand — DIA spam case studies

The Department of Internal Affairs publishes worked case studies under the Unsolicited Electronic Messages Act 2007 (statute detail: APAC Email Laws). They are useful precisely because they show the low end of the enforcement ladder — formal warnings and infringement notices — where most real ESP-customer situations land, not the headline penalties.

Case Conduct Finding Outcome
Purchased database Sender bought a database from a broker and mailed it; could not demonstrate recipients consented. Addresses were not "conspicuously published," and the messages were not relevant to recipients' business roles. 11 breaches of the Act. Buying the database did not establish consent — the burden of proof sits with the sender. Written formal warning (lowest end of the spectrum; no financial penalty)
Broken unsubscribe Sender kept sending substantial commercial email with no functional unsubscribe facility (s 11), after a prior formal warning in 2010 for s 9/s 11 breaches. Ongoing s 11 failure despite prior warning. Civil infringement notice (Sept 2011) — escalated because the warning was ignored
Assumed inferred consent Sender relied on inferred consent from a Trade Me transaction and mailed marketing months after the transaction. "Inferred consent did not exist in this instance, as a business relationship did not exist." Formal warning (May 2011)

Operational lessons for an ESP:

  • A purchased list is not consent even in NZ's relatively permissive regime; the sender must be able to prove consent per address. Screen customers who onboard with bought databases (see Address Acquisition Integrity and Customer Vetting).
  • The DIA escalates on repeat conduct: a warning ignored becomes an infringement notice. An ESP's response to a customer's first complaint spike should assume the regulator will treat a second one far more harshly.
  • Inferred consent decays. A single past transaction, mailed against months later, is not an "ongoing business relationship" — the same narrow reading Australia applies (below).

Australia — ACMA's 2024 statement on consent expectations

On 1 July 2024 the ACMA issued "Consumer consent: expectations for businesses conducting telemarketing and e-marketing" — an outcome-focused statement clarifying what it will accept as valid consent under the Spam Act 2003. It does not change the statute; it tells senders how the regulator reads "express" and "inferred" consent in practice.

Express consent (ACMA's strong preference) — "a clear and unambiguous decision by a customer to receive direct marketing," given via form, website checkbox, phone, or face-to-face. To be valid, the consent terms must be accessible at the point of collection and must state four things:

  1. what the marketing is for,
  2. who will use the consent (which businesses),
  3. how long it will be relied on, and
  4. how the customer can withdraw it.

Explicit prohibitions and cautions:

  • No pre-ticked boxes.
  • Consent must not be buried in fine print or long privacy policies — it has to be transparent at collection time.
  • Rely only on current consent; refresh it periodically. (ACMA states telemarketing consent goes "stale" after 3 months unless the terms specify a longer period — a useful benchmark for how the regulator thinks about consent freshness generally, even though it did not set a fixed email figure.)

Inferred consent (use with caution) — permissible only where there is a clear, current or ongoing relationship and the product/service marketed is directly related to that relationship. If either answer is "no," do not rely on inferred consent. A one-off purchase does not create inferred consent — consistent with the ACMA's long-standing narrow reading and with the NZ Trade Me case above.

Record-keeping — the sender must keep reliable records of the method of consent, its terms, and the date/time obtained. Outsourcing to a marketing/ESP provider does not transfer responsibility: "you remain responsible for ensuring... your outsourced service provider" keeps those records too. (Reinforces the Spam Act's "you cannot outsource your risk" principle — australia-spam-act.md.)

Operational lessons for an ESP:

  • Consent-capture forms for Australian traffic should surface the four required disclosures at the checkbox, not link out to a policy — the design constraint ACMA is signalling.
  • Build for consent expiry: treat old consents as stale and re-permission rather than mailing indefinitely. The 3-month telemarketing figure is the clearest number ACMA has put on freshness — but it is specific to telemarketing consent in Australia, not a universal benchmark. Consent-freshness cadence is jurisdiction- and channel-specific (ICO ~2 years, CNIL ~6 months, ACMA ~3 months); see the reconciled comparison in Consent Record-Keeping.
  • Store consent metadata (method/terms/timestamp) in a form the customer can produce to ACMA — the ESP holds records on the customer's behalf but the customer stays liable. Pairs with the acquisition metadata in Address Acquisition Integrity.

France — CNIL rules for sharing B2C data with partners

CNIL guidance on transmitting consumer personal data to partners for their own marketing fills a gap the base France CNIL article notes but doesn't detail: how, and whether, a French company may hand a subscriber's data to third parties. The rule splits by the channel the partner will use, because the legal basis differs.

Partner will use postal mail → legitimate interest

Data may be shared for a partner's postal marketing on the transmitting company's legitimate interest, provided:

  • individuals were informed at collection of the transmission, its objectives, and the categories of partners; and
  • a simple, free opt-out is offered both at collection and at any time afterwards.

Best practice CNIL recommends: give an exhaustive, up-to-date list of the partners by identity, with links to their privacy policies (activity sector, contact types, approximate number of partners at minimum).

Partner will use email / SMS / automated calls → prior consent

Because electronic prospecting is opt-in (Art. L.34-5 CPCE), sharing data for a partner's electronic marketing requires prior explicit consent. Two structures are allowed:

Scenario 1 — the collecting company gathers consent for the partners' marketing up front. The individual must clearly know which partners will contact them: an exhaustive partner list is provided at the moment of consent. A single checkbox can cover both the data transmission and the partners' prospecting, e.g. — "I accept that my email address be shared with the partners [link] of company X for commercial prospecting."

Scenario 2 — the company transmits data without collecting prospecting consent. Then each partner must obtain its own consent before prospecting. The partner's first contact may rely on legitimate interest only if the individual had received sufficient prior information about the scope of solicitation and the categories of partners, and the partner limits frequency to avoid nuisance.

Two hard limits:

  • No cascading consent. Consent obtained by one partner does not extend to that partner's partners; each actor must independently collect consent for its own downstream sharing. (This is the address-acquisition "consent is not transferable" principle stated as a chain rule.)
  • Receiving partner must inform the individual within one month of first contact, including the identity of the source company and the individual's rights to consent/object (GDPR Art. 14 transparency).

Operational lessons for an ESP:

  • "Shared with our partners" language is only valid for electronic marketing if the partner list is exhaustive and presented at consent — the affiliate/co-reg pattern condemned in Consent Methods is exactly what CNIL is fencing in.
  • An ESP onboarding a French list built from partner-shared data should verify which scenario produced it: Scenario-1 consent evidence, or a Scenario-2 chain where this sender collected its own consent. A generic "partner consent" claim without an exhaustive-list-at-collection record is not defensible.
  • The one-month source-disclosure duty on the receiving partner is a concrete task the ESP's welcome/first-contact flow must satisfy for partner-sourced French contacts.

Related

#compliance#consent#enforcement#acma#cnil#new-zealand#dia#partner-data#direct-marketing