emailmarketing.net

Australia — Spam Act 2003 and ACMA Enforcement

Australia's opt-in regime: express/inferred consent, sender ID and unsubscribe rules (5 business days, 30 days, no login), ACMA penalties incl. Commonwealth Bank's record AU$3.55M, plus OAIC APP 7 and tracking-pixel guidance.

Reference10 min read

Who it is for Compliance teams, Senders

Applies to senders on any platform

If you send marketing email to people in Australia, you need their consent, you must identify yourself, and your unsubscribe must work without a login. Australia is an opt-in jurisdiction, and its regulator is one of the most active enforcers in the world.

The Spam Act 2003 (Cth) and the Spam Regulations govern commercial electronic messages (email, SMS, MMS, instant messages). The Australian Communications and Media Authority (ACMA) enforces them, and it routinely issues infringement notices of seven figures against mainstream brands. The most common reason is an unsubscribe failure, including requiring a login to unsubscribe, which directly constrains how an email service provider (ESP) designs its unsubscribe flows.

Sources: the text of the Act below comes from the consolidated compilation C2012C00030, retrieved through the Internet Archive, because legislation.gov.au serves the current compilation through a JavaScript application. ACMA pages were also retrieved through the Internet Archive (2026 snapshots), because acma.gov.au blocks clients that are not browsers.

Scope

  • A message is commercial if it offers, advertises or promotes goods or services (or land, or business or investment opportunities), even if only part of the message is commercial (ACMA fact sheet). Messages that are purely factual are exempt (Schedule 1, see below).
  • The Act applies to messages with an Australian link (s 7): messages sent from Australia, sent to it, or accessed in it. Foreign senders who mail Australian recipients are therefore covered.
  • The Act applies outside Australia (to acts done outside Australia) and is enforced through civil penalty provisions, not criminal law (s 27).
  • Defences: the sender did not know, and could not have found out with reasonable diligence, that the message had an Australian link; or the message was sent by mistake. The sender bears the evidential burden (ss 16(3)–(5)).

The three obligations

A commercial electronic message with an Australian link must not be sent without the consent of the relevant electronic account-holder. Consent means (Sch 2 cl 2):

  • Express consent. ACMA considers it best practice. It can be given through a form, a checkbox on a website, by phone, or face to face. You cannot send an electronic message to ask for consent, because that request is itself a marketing message. Keep records of who consented, when and how, because the sender must prove consent.
  • Inferred consent. Consent reasonably inferred from the conduct and the business or other relationships of the recipient. ACMA reads this narrowly. It requires a provable, ongoing relationship, and the marketing must be directly related to that relationship. A bank may tell a savings customer about another savings account, but may not use that relationship to sell insurance to the same customer. A single purchase does not create inferred consent.
  • Conspicuous publication (Sch 2 cl 4). Consent may be inferred for a work-related electronic address that has been conspicuously published: the address of an employee, director, officer, partner, office-holder or self-employed individual, or the address of a role or position. The publication must reasonably appear to have the agreement of the person or organisation. This does not apply if the publication comes with a statement that unsolicited commercial messages are not wanted, and it covers only messages relevant to the work-related business, functions or duties of the addressee. Otherwise, publishing an address is not consent (Sch 2 cl 4(1)). This is Australia's only allowance for B2B mail; otherwise, business addresses follow the same consent rules as consumer addresses.
  • Withdrawal of consent takes effect at the end of 5 business days from the day the unsubscribe message is sent (Sch 2 cl 6). Business days are counted according to where the recipient is.
  • Purchased or rented lists: the advertiser is still responsible for proving consent for every address used.

2. Sender identification (s 17)

Every commercial electronic message, including exempt ("designated") messages, must:

  • clearly and accurately identify the individual or organisation that authorised the sending (use the legal business name, or the name and the Australian Business Number (ABN));
  • include accurate contact information; and
  • that information must be reasonably likely to be valid for at least 30 days after sending.

If a third party, such as an agency or an ESP, sends on a brand's behalf, the message must still identify the authorising business, and that business remains liable ("you cannot outsource your risk", ACMA fact sheet).

3. Functional unsubscribe (s 18 and ACMA 2024 fact sheet)

Every commercial message, except designated ones, must contain a clear and conspicuous unsubscribe statement and a facility that meets these requirements:

Requirement Detail
Clear instructions Presented in a clear and conspicuous way (s 18(1)(d))
Working for ≥ 30 days The unsubscribe address must be able to receive the recipient's message, and a reasonable number of similar messages from other recipients, for at least 30 days after sending (s 18(1)(e))
Acted on within 5 working days ACMA fact sheet; the same period as the withdrawal of consent in Sch 2 cl 6
No fee Must not require payment, and must not cost more than the usual cost of using the address (for example, a standard SMS charge)
No login, no account and no extra personal information The recipient must not have to log in to an account, create one, or provide more personal information in order to unsubscribe
Legitimately obtained address The unsubscribe address itself must have been obtained legitimately (s 18(1)(f))

Large brands keep breaking the no-login rule (see enforcement below). An ESP's unsubscribe flow for Australian recipients must work without any authentication.

Other prohibited conduct

  • Address-harvesting software and lists of harvested addresses must not be supplied, acquired or used in connection with sending in breach of s 16 (ss 20–22).
  • Ancillary liability. Aiding, abetting or inducing a contravention, being knowingly involved in one, or conspiring to commit one is itself a contravention (ss 16(9), 17(5), 18(6)). This matters for platforms and agencies. Merely supplying a carriage service is excluded.
  • Messages must not be sent to addresses that the sender has no reason to believe exist (s 16(6)).

Exemptions: designated commercial electronic messages (Schedule 1)

These messages are exempt from the consent (s 16) and unsubscribe (s 18) rules, but they are still subject to sender identification (s 17):

Category Conditions
Factual information messages Contain no more than factual information, with directly related comment and permitted identifying information (the name, logo and contact details of the author, employer or sponsor). The message would not be commercial without that added information (Sch 1 cl 2)
Government bodies, registered political parties, religious organisations, charities The message relates to goods or services, and the body is the supplier (Sch 1 cl 3)
Educational institutions The recipient, or a member of their household, is or was enrolled, and the institution supplies the goods or services (Sch 1 cl 4)

Penalties and enforcement

Statutory maxima (ss 24–25)

Penalties are expressed in penalty units for each contravention, and the Federal Court imposes them. A single day's sending can contain many contraventions:

Person No prior record: for each contravention / daily cap Prior record: for each contravention / daily cap
Body corporate, breach of s 16 100 units / 2,000 units 500 units / 10,000 units
Body corporate, other civil penalty provisions 50 units / 1,000 units 250 units / 5,000 units
Individual, breach of s 16 20 units / 400 units 100 units / 2,000 units
Individual, other provisions 10 units / 200 units 50 units / 1,000 units

The Court may also order compensation for victims and the surrender of financial benefits (ss 28–29). Actions may be brought up to 6 years after the contravention (s 26). ACMA can also issue infringement notices (Schedule 3: payable within 28 days, and given within 12 months of the alleged contraventions), give formal warnings, and accept undertakings that courts can enforce.

A Commonwealth penalty unit is indexed from time to time. It was AU$330 in late 2024, so the daily cap of 10,000 units for a repeat corporate offender is more than AU$3M per day.

Enforcement practice: the record

ACMA publishes the outcome of every investigation. Unsubscribe failures and sending without consent account for most of them. Selected actions that involve email:

Company Breach Outcome Date
Commonwealth Bank of Australia 61M+ emails that required a login to unsubscribe; 4M+ without a working unsubscribe; 5,000+ sent after an unsubscribe AU$3,552,000 infringement notice and a 3-year enforceable undertaking (the largest ever at the time) Jun 2023
Commonwealth Bank of Australia (again) Email and SMS without consent, unsubscribe not working AU$7,502,610 infringement notice and an enforceable undertaking (EU) Aug 2024
Tabcorp (TAB) SMS and WhatsApp: inadequate sender information, no working unsubscribe, no consent AU$4,003,270 + EU Apr 2025
Pizza Hut Australia Emails without consent, contact details or a working unsubscribe AU$2,502,500 + EU May 2024
Sportsbet Email and SMS without consent or unsubscribe AU$2,508,600 + EU Mar 2022
DoorDash Email and SMS without consent or unsubscribe AU$2,011,320 + EU Aug 2023
Binance Australia Emails without consent or unsubscribe AU$2,000,220 + EU Oct 2022
Latitude Finance Email and SMS without consent or unsubscribe AU$1,549,560 + EU Jul 2022
Luxottica Emails without consent or unsubscribe AU$1,512,500 + EU Apr 2024
Kmart Emails without consent AU$1,303,500 + EU Sep 2023
Woolworths Emails after consent was withdrawn and without unsubscribe AU$1,003,800 + EU Jun 2020
Lululemon Australia 370,000+ emails with commercial content and no unsubscribe AU$702,900 Mar 2026
Betfair Emails and SMS to VIP customers without consent or unsubscribe AU$871,660 + EU May and Jul 2025
Telstra SMS without consent or unsubscribe AU$626,000 + EU Dec 2024
Singtel Optus Marketing emails and SMS after consent was withdrawn and without unsubscribe AU$504,000 + EU Jan 2020
Ticketek Email and SMS without consent AU$515,040 + EU Oct 2023
Uber Australia Emails without consent or unsubscribe AU$412,500 Sep 2023
Kogan Emails without a working unsubscribe AU$310,800 + EU Jan 2021

In the 18 months to mid-2023 alone, businesses paid AU$11M in penalties for spam and telemarketing, and gave 12 court-enforceable undertakings and received 1 formal warning.

The patterns an ESP should design against are unsubscribe links that require a login (CBA), "transactional" messages with promotional content and no unsubscribe (Lululemon, Kogan), sending after consent is withdrawn (Woolworths, Optus, Ticketek), and treating VIP or loyalty segments as exempt from consent (Betfair).

Interaction with the Privacy Act: OAIC APP 7 (direct marketing)

Australian Privacy Principle 7, overseen by the Office of the Australian Information Commissioner (OAIC), restricts the use of personal information for direct marketing. However, APP 7 does not apply to the extent that the Spam Act (or the Do Not Call Register Act) applies. For marketing by email, SMS or MMS, the Spam Act governs. APP 7 covers the other channels (mail, door-to-door, targeted online advertising, in-app marketing), and applies where an organisation is exempt from those Acts. It is still relevant to email programs:

  • APP 7.2. Information collected directly from the individual may be used for direct marketing if the individual would reasonably expect it (an objective test), a simple way to opt out is provided, and the individual has not opted out.
  • APP 7.3. For information from third parties, or where the individual would not reasonably expect the marketing, you need consent (unless it is impracticable to obtain), a simple opt-out, and a prominent opt-out statement in each communication (in plain English, placed prominently, in a readable font).
  • APP 7.4. Sensitive information may be used for direct marketing only with explicit consent, and there is no exception for impracticability.
  • On request, an organisation must tell the individual where it got their personal information (unless that is unreasonable or impracticable), within about 30 days. It must also honour requests to opt out of list "facilitation", which means providing data for other organisations' marketing.
  • A "simple means" of opting out has clear instructions, takes little effort, is free or costs very little, and is available through the channel the marketing used.

OAIC guidance on tracking pixels

The OAIC's guidance on tracking pixels is aimed at third-party pixels. It focuses on pixels on websites, while noting that pixels are also used in emails and apps. Its main positions relevant to open tracking and click tracking:

  • Data such as IP addresses, URLs or hashed email addresses can be personal information when it can be linked with a third-party platform's data, even if the individual is not directly identified. The OAIC advises organisations to "err on the side of caution."
  • The obligations involved are:
    • APP 1: the privacy policy must disclose the use of third-party pixels.
    • APP 3: collection must be reasonably necessary, and pixels should be configured for data minimisation. Sensitive information requires express opt-in consent and should generally be blocked from disclosure through pixels.
    • APP 5: notify people at or before collection, including about third-party recipients and transfers overseas.
    • APP 6: disclosure to the pixel provider must match the purpose of collection or have a valid basis for secondary use.
    • APP 7: a simple opt-out from targeted marketing driven by pixels.
    • APP 8: reasonable steps for disclosure overseas.
  • Before deployment, check how the pixel works, review the provider's terms, carry out a Privacy Impact Assessment, configure the pixel so that it cannot collect sensitive data, and review it regularly. The organisation that deploys the pixel is responsible for configuring it in a compliant way.

ESP checklist for Australian traffic

  • A one-click unsubscribe that needs no authentication (List-Unsubscribe and RFC 8058) satisfies the no-login rule. Suppress the address within 5 business days; doing it immediately is best practice.
  • Keep the unsubscribe endpoint working for ≥ 30 days after each campaign, and keep the sender's contact information valid for ≥ 30 days.
  • Store evidence of consent (who, when and how), because the sender must produce it if ACMA asks.
  • Identify the authorising customer (legal name or ABN) in every message sent on their behalf. The customer is liable, but ancillary liability can reach anyone knowingly involved.
  • Do not treat "the recipient once bought something" as enough. Inferred consent needs an ongoing, directly related relationship. See Consent Methods for how the quality of consent varies.
  • Never accept lists built with harvesting software. Supplying or using them is a separate contravention.

This is not legal advice. See the compliance notice.