Consent Guidance Updates: Recent Regulator Positions to Track
A running digest of recent consent guidance and enforcement the KB should track — NZ DIA spam case studies (real outcomes), ACMA's 2024 statement on what 'consent' now requires in Australia, and CNIL's rules for sharing B2C data with marketing partners — each with the operational lesson.
Reference7 min read
Who it is for Compliance teams, Senders
Applies to senders on any platform
ContentsOn this page — 4 sections
If you collect consent for email marketing, what regulators accept changes more often through their published interpretations than through new laws. Below are recent guidance and enforcement outcomes that clarify what consent requires in practice, each with the lesson for your operations.
These positions come after, or sharpen, the laws themselves. For the underlying law, see Australia Spam Act, France CNIL and, for New Zealand, APAC Email Laws. That material is not repeated here.
Not legal advice. See compliance/README.md.
New Zealand: DIA spam case studies
The Department of Internal Affairs (DIA) publishes worked case studies under the Unsolicited Electronic Messages Act 2007 (for the details of the law, see APAC Email Laws). They are useful because they show the low end of the enforcement ladder, formal warnings and infringement notices, which is where most real situations involving ESP customers end up, rather than the headline penalties.
| Case | Conduct | Finding | Outcome |
|---|---|---|---|
| Purchased database | The sender bought a database from a broker and mailed it, and could not show that the recipients had consented. The addresses were not "conspicuously published," and the messages were not relevant to the recipients' business roles. | 11 breaches of the Act. Buying the database did not establish consent: the burden of proof is on the sender. | Written formal warning (the lowest end of the range, with no financial penalty) |
| Broken unsubscribe | The sender kept sending a substantial amount of commercial email with no working unsubscribe facility (s 11), even after a formal warning in 2010 for breaches of s 9 and s 11. | A continuing failure under s 11 despite the earlier warning. | Civil infringement notice (Sept 2011), escalated because the warning was ignored |
| Assumed inferred consent | The sender relied on consent inferred from a Trade Me transaction and sent marketing months after the transaction. | "Inferred consent did not exist in this instance, as a business relationship did not exist." | Formal warning (May 2011) |
Lessons for an ESP:
- A purchased list is not consent, even under New Zealand's relatively permissive regime. The sender must be able to prove consent for each address. Screen customers who arrive with bought databases (see Address Acquisition Integrity and Customer Vetting).
- The DIA escalates when conduct is repeated: an ignored warning becomes an infringement notice. When a customer has a first spike in complaints, respond on the assumption that the regulator will treat a second one far more harshly.
- Inferred consent fades. A single past transaction, followed by marketing months later, is not an "ongoing business relationship". Australia applies the same narrow reading (below).
Australia — ACMA's 2024 statement on consent expectations
On 1 July 2024, the Australian Communications and Media Authority (ACMA) issued "Consumer consent: expectations for businesses conducting telemarketing and e-marketing". The statement focuses on outcomes and clarifies what the ACMA will accept as valid consent under the Spam Act 2003. It does not change the law. It tells senders how the regulator reads "express" and "inferred" consent in practice.
Express consent (the ACMA's strong preference) is "a clear and unambiguous decision by a customer to receive direct marketing," given through a form, a checkbox on a website, by phone or face to face. For the consent to be valid, its terms must be accessible at the point of collection and must state four things:
- what the marketing is for,
- who will use the consent (which businesses),
- how long it will be relied on, and
- how the customer can withdraw it.
Explicit prohibitions and cautions:
- No pre-ticked boxes.
- Consent must not be buried in fine print or long privacy policies. It has to be transparent at the time of collection.
- Rely only on current consent, and refresh it periodically. The ACMA states that telemarketing consent goes "stale" after 3 months unless the terms specify a longer period. This is a useful indication of how the regulator thinks about the freshness of consent in general, even though it did not set a fixed figure for email.
Inferred consent (use with caution) is allowed only where there is a clear, current or ongoing relationship and the product or service marketed is directly related to that relationship. If either answer is "no", do not rely on inferred consent. A one-off purchase does not create inferred consent, which is consistent with the ACMA's long-standing narrow reading and with the New Zealand Trade Me case above.
Record-keeping. The sender must keep reliable records of the method of consent, its terms, and the date and time it was obtained. Outsourcing to a marketing provider or an ESP does not transfer this responsibility: "you remain responsible for ensuring... your outsourced service provider" keeps those records too. This reinforces the Spam Act principle that you cannot outsource your risk (australia-spam-act.md).
Lessons for an ESP:
- Consent forms for Australian traffic should show the four required disclosures at the checkbox, not in a linked policy. That is the design constraint the ACMA is pointing to.
- Build for consent expiry: treat old consents as stale, and ask for permission again rather than mailing indefinitely. The 3-month figure for telemarketing is the clearest number the ACMA has put on freshness, but it applies specifically to telemarketing consent in Australia and is not a universal benchmark. How often to refresh consent depends on the jurisdiction and the channel (ICO ~2 years, CNIL ~6 months, ACMA ~3 months). Consent Record-Keeping compares the figures.
- Store consent metadata (method, terms and timestamp) in a form the customer can produce for the ACMA. The ESP holds the records on the customer's behalf, but the customer remains liable. This goes with the acquisition metadata described in Address Acquisition Integrity.
France: CNIL rules for sharing B2C data with partners
The CNIL has published guidance on passing consumers' personal data to partners for the partners' own marketing. It answers a question that France CNIL raises but does not detail: whether and how a French company may give a subscriber's data to third parties. The rule depends on the channel the partner will use, because the legal basis differs.
Partner will use postal mail: legitimate interest
The transmitting company may share data for a partner's postal marketing on the basis of its legitimate interest, provided that:
- individuals were informed at collection of the transmission, its objectives and the categories of partners; and
- a simple, free opt-out is offered both at collection and at any time afterwards.
The CNIL recommends as best practice giving an exhaustive, up-to-date list of the partners by identity, with links to their privacy policies. At a minimum, give their sector of activity, the types of contact and the approximate number of partners.
Partner will use email, SMS or automated calls: prior consent
Electronic prospecting requires opt-in (Art. L.34-5 CPCE), so sharing data for a partner's electronic marketing requires prior explicit consent. Two structures are allowed.
Scenario 1: the collecting company obtains consent for the partners' marketing at the start. The individual must clearly know which partners will contact them, so an exhaustive list of partners is given at the moment of consent. A single checkbox can cover both the transmission of the data and the partners' prospecting, for example: "I accept that my email address be shared with the partners [link] of company X for commercial prospecting."
Scenario 2: the company transmits the data without collecting consent to prospecting. In this case, each partner must obtain its own consent before prospecting. The partner's first contact may rely on legitimate interest only if the individual had received enough information beforehand about the scope of the solicitation and the categories of partners, and the partner limits how often it makes contact to avoid being a nuisance.
Two hard limits:
- Consent does not cascade. Consent obtained by one partner does not extend to that partner's own partners. Each party must collect consent separately for any further sharing. This is the principle that "consent is not transferable", from address acquisition, applied to a chain.
- The receiving partner must inform the individual within one month of first contact, including the identity of the source company and the individual's rights to consent or object (the transparency requirement of GDPR Art. 14).
Lessons for an ESP:
- Wording such as "shared with our partners" is valid for electronic marketing only if the list of partners is exhaustive and shown at the moment of consent. The affiliate and co-registration pattern criticized in Consent Methods is exactly what the CNIL is restricting.
- An ESP onboarding a French list built from data shared by partners should check which scenario produced it: evidence of consent under Scenario-1, or a Scenario-2 chain in which this sender collected its own consent. A general claim of "partner consent", without a record that an exhaustive list was shown at collection, cannot be defended.
- The receiving partner's duty to disclose the source within one month is a concrete task that the ESP's welcome or first-contact flow must handle for French contacts that came from partners.
Related articles
- Australia Spam Act, including the unsubscribe rules and the ACMA's full penalty record
- France CNIL, including the rules for B2C and B2B prospecting and the 2026 recommendation on tracking pixels
- APAC Email Laws, on consent under New Zealand's Unsolicited Electronic Messages Act and its penalties
- Enforcement Cases, on enforcement of CASL and CAN-SPAM, the liability of intermediaries, and harvesting as an aggravated violation
- Address Acquisition Integrity
- Consent Methods and the List-Quality Spectrum
- Customer Vetting, on screening customers whose acquisition or consent practices are undocumented
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- CAN-SPAM Act (United States)
- CAN-SPAM Rulemaking (16 CFR Part 316)
- CASL — Canada's Anti-Spam Legislation
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail