Australia — Spam Act 2003 and ACMA Enforcement
Australia's opt-in regime: express/inferred consent, sender ID and unsubscribe rules (5 business days, 30 days, no login), ACMA penalties incl. Commonwealth Bank's record AU$3.55M, plus OAIC APP 7 and tracking-pixel guidance.
Australia is an opt-in jurisdiction with one of the most actively enforcing regulators in the world. The Spam Act 2003 (Cth) and the Spam Regulations govern commercial electronic messages (email, SMS, MMS, instant messages); the Australian Communications and Media Authority (ACMA) enforces it, routinely issuing seven-figure infringement notices against mainstream brands — most often for unsubscribe failures (including requiring login to unsubscribe), a direct design constraint on ESP unsubscribe flows.
Provenance: the Act's text below is from the consolidated compilation C2012C00030 (retrieved via the Internet Archive; legislation.gov.au serves the current compilation via a JS application). ACMA pages were also retrieved via the Internet Archive (2026 snapshots) because acma.gov.au blocks non-browser clients.
Scope
- A message is commercial if it offers, advertises or promotes goods or services (or land, business/investment opportunities) — even if only part of the message is commercial (ACMA fact sheet). Purely factual messages are exempt (Schedule 1, see below).
- The Act applies to messages with an Australian link (s 7): sent from, to, or accessed in Australia — so foreign senders mailing Australian recipients are covered.
- The Act extends extraterritorially (acts outside Australia) and is enforced through civil penalty provisions, not criminal law (s 27).
- Defences: the sender did not know and could not with reasonable diligence have ascertained the Australian link, or the message was sent by mistake — the sender bears the evidential burden (ss 16(3)–(5)).
The three obligations
1. Consent (s 16 + Schedule 2)
A commercial electronic message with an Australian link must not be sent without the consent of the relevant electronic account-holder. Consent means (Sch 2 cl 2):
- Express consent — best practice per ACMA. Can be given by form, website checkbox, phone, or face to face. You cannot send an electronic message to ask for consent — that request is itself a marketing message. Keep records of who consented, when, and how: the sender bears the burden of proving consent.
- Inferred consent — reasonably inferred from the conduct and business/other relationships of the recipient. ACMA reads this narrowly: a provable, ongoing relationship where the marketing is directly related to that relationship (e.g., a savings bank telling a customer about another savings account — but not cross-selling insurance to that same customer). A one-off purchase does not create inferred consent.
- Conspicuous publication (Sch 2 cl 4) — consent may be inferred for a work-related electronic address (employee, director, officer, partner, office-holder, self-employed individual, or role/position address) that has been conspicuously published, where publication reasonably appears to be with the person's/organisation's agreement, unless the publication is accompanied by a statement that unsolicited commercial messages are not wanted — and only for messages relevant to the work-related business, functions or duties of the addressee. Mere publication of an address is otherwise not consent (Sch 2 cl 4(1)). This is Australia's only "B2B allowance": business addresses are otherwise under the same consent rules as consumer addresses.
- Withdrawal of consent takes effect at the end of 5 business days from the day an unsubscribe message is sent (Sch 2 cl 6) — business days determined by the recipient's location.
- Purchased/rented lists: the advertiser remains responsible for proving consent for every address used.
2. Sender identification (s 17)
Every commercial electronic message (including "designated" exempt messages) must:
- clearly and accurately identify the individual or organisation who authorised the sending (use the legal business name, or name plus ABN);
- include accurate contact information; and
- that information must be reasonably likely to be valid for at least 30 days after sending.
If a third party (agency, ESP) sends on a brand's behalf, the message must still identify the authorising business, and that business remains liable ("you cannot outsource your risk" — ACMA fact sheet).
3. Functional unsubscribe (s 18 + ACMA 2024 fact sheet)
Every commercial message (except designated ones) must contain a clear and conspicuous unsubscribe statement and a facility that:
| Requirement | Detail |
|---|---|
| Clear instructions | Presented in a clear and conspicuous manner (s 18(1)(d)) |
| Functional ≥ 30 days | The unsubscribe address must be able to receive the recipient's message — and a reasonable number of similar messages from other recipients — for at least 30 days after sending (s 18(1)(e)) |
| Actioned within 5 working days | ACMA fact sheet; matches Sch 2 cl 6 withdrawal timing |
| No fee | Must not require payment; must not cost more than the usual cost of using the address (e.g., a standard SMS charge) |
| No login / no account / no extra personal information | The recipient must not be required to log in to, or create, an account, or provide additional personal information, to unsubscribe |
| Legitimately obtained address | The unsubscribe address itself must be legitimately obtained (s 18(1)(f)) |
The no-login rule is the one large brands keep breaking (see enforcement below) — an ESP's unsubscribe flow for Australian recipients must complete without authentication.
Other prohibited conduct
- Address-harvesting software and harvested-address lists must not be supplied, acquired or used in connection with sending in breach of s 16 (ss 20–22).
- Ancillary liability: aiding, abetting, inducing, being knowingly concerned in, or conspiring in a contravention is itself a contravention (ss 16(9), 17(5), 18(6)) — relevant to platforms and agencies. Merely supplying a carriage service is excluded.
- Messages must not be sent to addresses the sender has no reason to believe exist (s 16(6)).
Exemptions — designated commercial electronic messages (Schedule 1)
Exempt from the consent (s 16) and unsubscribe (s 18) rules — but still subject to sender identification (s 17):
| Category | Conditions |
|---|---|
| Factual information messages | No more than factual information plus directly-related comment and permitted identifying information (name/logo/contact details of author, employer, sponsor); would not be commercial without that added info (Sch 1 cl 2) |
| Government bodies, registered political parties, religious organisations, charities | Message relates to goods/services and the body is the supplier (Sch 1 cl 3) |
| Educational institutions | Recipient (or household member) is or was enrolled; institution supplies the goods/services (Sch 1 cl 4) |
Penalties and enforcement
Statutory maxima (ss 24–25)
Penalties are expressed in penalty units, per contravention, imposed by the Federal Court; each day's sending can comprise many contraventions:
| Person | No prior record — per contravention / per-day cap | Prior record — per contravention / per-day cap |
|---|---|---|
| Body corporate, s 16 breach | 100 units / 2,000 units | 500 units / 10,000 units |
| Body corporate, other civil penalty provisions | 50 units / 1,000 units | 250 units / 5,000 units |
| Individual, s 16 breach | 20 units / 400 units | 100 units / 2,000 units |
| Individual, other provisions | 10 units / 200 units | 50 units / 1,000 units |
The Court may additionally order compensation to victims and disgorgement of financial benefits (ss 28–29); actions may be brought up to 6 years after the contravention (s 26). ACMA can also issue infringement notices (Schedule 3 — payable within 28 days, given within 12 months of the alleged contraventions), formal warnings, and accept court-enforceable undertakings. (A Commonwealth penalty unit is periodically indexed — AU$330 as of late 2024 — so the 10,000-unit repeat-corporate daily cap exceeds AU$3M per day.)
Enforcement practice — the record
ACMA publishes every investigation outcome. Unsubscribe failures and sending without consent dominate. Selected email-relevant actions:
| Company | Breach | Outcome | Date |
|---|---|---|---|
| Commonwealth Bank of Australia | 61M+ emails requiring login to unsubscribe; 4M+ without functioning unsubscribe; 5,000+ sent after unsubscribe | AU$3,552,000 infringement notice + 3-year enforceable undertaking (then the largest ever) | Jun 2023 |
| Commonwealth Bank of Australia (again) | Email/SMS without consent, non-functional unsubscribe | AU$7,502,610 infringement notice + EU | Aug 2024 |
| Tabcorp (TAB) | SMS/WhatsApp: inadequate sender info, no functional unsubscribe, no consent | AU$4,003,270 + EU | Apr 2025 |
| Pizza Hut Australia | Emails without consent, contact details, or functional unsubscribe | AU$2,502,500 + EU | May 2024 |
| Sportsbet | Email/SMS without consent or unsubscribe | AU$2,508,600 + EU | Mar 2022 |
| DoorDash | Email/SMS without consent or unsubscribe | AU$2,011,320 + EU | Aug 2023 |
| Binance Australia | Emails without consent or unsubscribe | AU$2,000,220 + EU | Oct 2022 |
| Latitude Finance | Email/SMS without consent or unsubscribe | AU$1,549,560 + EU | Jul 2022 |
| Luxottica | Emails without consent or unsubscribe | AU$1,512,500 + EU | Apr 2024 |
| Kmart | Emails without consent | AU$1,303,500 + EU | Sep 2023 |
| Woolworths | Emails after consent withdrawn and without unsubscribe | AU$1,003,800 + EU | Jun 2020 |
| Lululemon Australia | 370,000+ emails with commercial content and no unsubscribe | AU$702,900 | Mar 2026 |
| Betfair | Emails/SMS to VIP customers without consent/unsubscribe | AU$871,660 + EU | May/Jul 2025 |
| Telstra | SMS without consent/unsubscribe | AU$626,000 + EU | Dec 2024 |
| Ticketek | Email/SMS without consent | AU$515,040 + EU | Oct 2023 |
| Uber Australia | Emails without consent or unsubscribe | AU$412,500 | Sep 2023 |
| Kogan | Emails without a functional unsubscribe | AU$310,800 + EU | Jan 2021 |
In the 18 months to mid-2023 alone, businesses paid AU$11M in spam/telemarketing penalties, with 12 court-enforceable undertakings and 1 formal warning. Patterns an ESP should engineer against: unsubscribe links that require login (CBA), "transactional" messages containing promotional content without an unsubscribe (Lululemon, Kogan), continuing sends after withdrawal (Woolworths, Optus, Ticketek), and treating VIP/loyalty segments as consent-exempt (Betfair).
Interaction with the Privacy Act — OAIC APP 7 (direct marketing)
Australian Privacy Principle 7 restricts using personal information for direct marketing, but APP 7 does not apply to the extent the Spam Act (or Do Not Call Register Act) applies — so for email/SMS/MMS marketing the Spam Act governs, and APP 7 covers the rest (mail, door-to-door, targeted online advertising, in-app marketing) and applies where an organisation is exempt from those Acts. Still relevant to email programs:
- APP 7.2 — information collected directly from the individual may be used for direct marketing if the individual would reasonably expect it (objective test), a simple means of opting out is provided, and they haven't opted out.
- APP 7.3 — information from third parties, or where there is no reasonable expectation: requires consent (unless impracticable to obtain), a simple opt-out, and a prominent opt-out statement in each communication (plain English, prominent placement, readable font).
- APP 7.4 — sensitive information may only be used for direct marketing with explicit consent (no impracticability exception).
- On request, an organisation must tell the individual where it got their personal information (unless unreasonable/impracticable), within about 30 days, and must honour opt-outs of list "facilitation" (providing data for others' marketing).
- "Simple means" of opting out: clear instructions, minimal effort, free or nominal cost, available through the channel the marketing used.
OAIC guidance on tracking pixels
The OAIC's tracking-pixels guidance targets third-party pixels (it focuses on website pixels while noting pixels are also used in emails and apps). Key positions relevant to open-tracking and click-tracking:
- Data such as IP addresses, URLs, or hashed email addresses can be personal information when linkable with a third-party platform's data — individuals need not be directly identified. OAIC advises organisations to "err on the side of caution."
- Obligations engaged: APP 1 (privacy policy must disclose third-party pixel use), APP 3 (collection must be reasonably necessary; configure pixels for data minimisation; sensitive information requires express opt-in consent and should generally be blocked from pixel disclosure), APP 5 (notify at or before collection, including third-party recipients and overseas transfers), APP 6 (disclosure to the pixel provider must match the collection purpose or a valid secondary-use basis), APP 7 (simple opt-out from pixel-driven targeted marketing), APP 8 (reasonable steps for overseas disclosure).
- Before deployment: due diligence on how the pixel works, review provider terms, run a Privacy Impact Assessment, configure to prevent sensitive-data collection, and review regularly. The deploying organisation is responsible for compliant configuration.
ESP checklist for Australian traffic
- One-click, unauthenticated unsubscribe (List-Unsubscribe / RFC 8058) satisfies the no-login rule; suppress within 5 business days (immediate is best practice).
- Keep the unsubscribe endpoint live ≥ 30 days after each campaign; keep sender contact info valid ≥ 30 days.
- Store consent evidence (who/when/how) — the sender must produce it if ACMA asks.
- Identify the authorising customer (legal name/ABN) in every message sent on their behalf; the customer is liable but ancillary liability can reach those knowingly concerned.
- Treat "the recipient once bought something" as insufficient — inferred consent needs an ongoing, directly-related relationship. See Consent Methods for the quality spectrum.
- Never accept lists built with harvesting software; supplying or using them is a separate contravention.
Not legal advice — see compliance/README.md.
Sources
- https://www.legislation.gov.au/Details/C2012C00030
- https://www.acma.gov.au/avoid-sending-spam
- https://www.acma.gov.au/investigations-spam-and-telemarketing
- https://www.acma.gov.au/telemarketing-and-spam-compliance-and-investigations
- https://www.acma.gov.au/sites/default/files/2024-05/Fact%20sheet%20-%20email%20and%20SMS%20unsubscribe%20rules.pdf
- https://www.acma.gov.au/articles/2023-06/commonwealth-bank-penalised-355-million-spam-breaches
- https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-7-app-7-direct-marketing
- https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/direct-marketing
- https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/tracking-pixels-and-privacy-obligations