- Who the Spam Act applies to
- Your second duty: identify yourself in every message
- Your third duty: give every message a working unsubscribe
- What else the Act bans
- What happens if you breach the Act
- A compliance checklist for your marketing
- When you need a lawyer
- Start with your message classification
If your business sends emails, text messages or instant messages to promote what you sell, the Spam Act 2003 (Cth) (the Act) sets the rules you must follow. In short, you need consent from each recipient, you need to identify who you are in every message, and you need to give recipients a way to unsubscribe that actually works. Those three duties sit at the centre of Australia's spam laws, and they apply to businesses of every size, including sole traders and small teams.
The Act is enforced by the Australian Communications and Media Authority (ACMA). Over the 18 months to October 2024, businesses paid more than $20 million in spam penalties, and the amounts since then have only grown. The good news is that compliance is mostly a matter of building the right systems: clear opt-in forms, honest message templates and a reliable unsubscribe process. This guide sets out who the Act catches, what each of the three core duties requires in practice, what the penalties look like, and the steps you can take this week to protect your business.
Who the Spam Act applies to
The Act regulates commercial electronic messages (CEMs). Under s 6 of the Act, a message is commercial if, looking at its content, the way it is presented and what its links or contact details lead to, its purpose is to offer, advertise or promote goods, services, land, or a business or investment opportunity, or to help someone carry on business.
That definition covers:
- Email: marketing emails of any kind, including newsletters with promotional content.
- SMS and MMS: text message campaigns, including shortcode and longcode sends.
- Instant messaging: messages sent through apps such as WhatsApp and iMessage. The ACMA's penalty against Tabcorp in April 2025 concerned SMS and WhatsApp messages to VIP customers.
It also captures less obvious messages. A "receipt" or "service update" that also promotes a product, or that links to marketing content, is a commercial message. The ACMA fined the Commonwealth Bank $7.5 million in October 2024 partly because 170 million emails were classified as non-commercial "service" messages when they in fact promoted the bank's insurance, credit and loan products. If a message includes marketing content, or direct links to marketing content, treat it as commercial.
A message is caught by the Act if it has an "Australian link". Under s 7 of the Act, that includes messages that originate in Australia, messages sent by a person physically in Australia or by an organisation managed and controlled here, and messages accessed by a device or account-holder in Australia. The practical effect is that overseas businesses marketing into Australia are also on the hook.
Some messages fall outside the main rules. Voice calls are not covered by the Spam Act; they are regulated separately under the Do Not Call Register Act 2006 (Cth). And a narrow category of designated commercial electronic messages, for example certain purely factual messages authorised by a government body, a registered charity or a registered political party, is exempt from the consent and unsubscribe rules, though the sender must still be identified.
One further point on scope: the Act catches messages you send or cause to be sent. If you engage a marketing agency, an affiliate or a list provider, you remain responsible for the messages they send on your behalf. A "forward to a friend" feature that your business encourages can also make you responsible for the forwarded message.
Your first duty: get consent before you send
Section 16 of the Act prohibits sending, or causing to be sent, an unsolicited CEM that has an Australian link. The exception is consent: if the recipient's account-holder consented to receiving the message, it is not unsolicited. Consent can be express or inferred, and it is the foundation of everything else, because the other two duties only matter once you are lawfully entitled to send at all.
Express consent
Express consent is a clear, informed "yes" to receiving marketing from you. It can be given through a tick box on a website form, a sign-up at checkout, a text-in keyword, or a verbal agreement that you record. For consent to be reliable, the person needs to know what they are agreeing to: which business will send, what channel (email, SMS or both), and roughly what kind of content. Pre-ticked boxes and vague wording create risk rather than consent, because they do not show that the person actually agreed to marketing.
Keep a record of each opt-in: when it happened, how it happened (form version, IP address, keyword, or in-person conversation), and exactly what the person was told at the time. If a complaint is made, or the ACMA asks, your records are what prove consent existed.
Inferred consent
Under Schedule 2 of the Act, consent may also be inferred from conduct and from the relationship between the parties. The classic example is an existing customer who has given you their details, has been told they will receive marketing, and has been given a clear opportunity to opt out. In that situation, consent can reasonably be inferred.
Inferred consent is narrower than most businesses assume, and it weakens over time. It rarely covers someone whose details you bought from a third party, and it does not survive a customer going quiet for years. If you are not confident consent exists, get express consent before you send. The ACMA's enforcement record shows that businesses regularly overestimate what can be inferred from a past purchase or a business card swap.
Withdrawal of consent
A recipient can withdraw consent at any time, usually by using your unsubscribe facility. Under Schedule 2 of the Act, the withdrawal takes effect at the end of five business days after the request is made. In practice that means you should action unsubscribe requests as soon as they arrive, and certainly within that five-business-day window, and never send another commercial message to that address unless the person opts back in.
Your second duty: identify yourself in every message
Section 17 of the Act requires every CEM to clearly and accurately identify the individual or organisation that authorised the sending of the message, and to include accurate information about how the recipient can contact that person or organisation. That contact information must be reasonably likely to remain valid for at least 30 days after the message is sent.
In practical terms, your message should name your business (and your trading name if it differs), and give a contact route that works: a physical address, a phone number or an email address monitored by someone who can respond. A footer disclaimer is not a substitute for this requirement; the identification information itself must be present and accurate. If the address or number in your footer goes dead within 30 days of sending, the message is non-compliant even though it was accurate on the day it went out.
Your third duty: give every message a working unsubscribe
Section 18 of the Act requires every CEM to include a statement that the recipient can use an electronic address in the message to send an unsubscribe request. The statement must be presented in a clear and conspicuous manner, and the address must be reasonably likely to accept unsubscribe messages for at least 30 days after the message is sent.
What works in practice:
- Email: a one-click unsubscribe link, or a reply address that is actually monitored. Do not require the recipient to log in, navigate multiple pages or answer questions before they can opt out.
- SMS: a reply "STOP" function, which is the standard and expected mechanism for text campaigns.
- Cost: the unsubscribe method should be free or low cost, such as a standard SMS reply. Charging for opting out is not acceptable.
Once a request arrives, add the address to your suppression list immediately and across every platform you use. A common failure is unsubscribing a customer from the email platform but continuing to text them, because the two systems were never connected. The Telstra penalty of $626,000 in March 2025, for close to 10.5 million text messages, arose from unsubscribe arrangements that did not comply with the Act.
What else the Act bans
Beyond the three core duties, the Act prohibits conduct that supports spam at scale:
- Address-harvesting: using or supplying software that collects electronic addresses from the internet, and using or supplying lists generated by that software, is prohibited. Never buy "harvested" lists, and check that any list you acquire was built from genuine opt-ins.
- Non-existent addresses: sending a CEM to a non-existent electronic address, where you had no reason to believe the address existed, is also a contravention. Sending to guessed or unverified addresses therefore carries its own risk.
What happens if you breach the Act
The ACMA investigates complaints and conducts its own surveillance of marketing activity. Its enforcement toolkit includes formal warnings, infringement notices, court-enforceable undertakings and proceedings in the Federal Court for civil penalties.
The maximum court penalty for a company with no prior record is $626,000 per day, rising to $3,130,000 per day for a company with a prior record, as the ACMA itself confirmed when announcing the Commonwealth Bank penalty. The Act calculates these amounts by reference to penalty units, so the dollar figures move each year, and separate contraventions can each attract penalties up to the daily cap.
Recent outcomes show the scale of enforcement:
- Commonwealth Bank: $7.5 million penalty in October 2024 after sending more than 170 million emails without a working unsubscribe, including 34.8 million to people who had not consented or had withdrawn consent. It also gave a three-year court-enforceable undertaking.
- Tabcorp: $4,003,270 in April 2025 for SMS and WhatsApp messages to VIP customers that lacked consent, accurate sender information or a functional unsubscribe, plus a three-year undertaking covering independent review, audits and staff training.
- Telstra: $626,000 in March 2025 for close to 10.5 million text messages with non-compliant unsubscribe arrangements.
- Betfair: $871,660 in July 2025 for messages sent to VIP customers who had not consented or had withdrawn consent.
Penalties are not the only cost. Court-enforceable undertakings routinely require independent consultants to review your systems, quarterly audits, staff training and reporting to the ACMA, which is expensive and disruptive for a small business. The Act also applies to individuals: a sole trader or director who sends, or causes to be sent, non-compliant messages can be penalised in their own right.
A compliance checklist for your marketing
Work through this list as a starting point for your program:
- Map your messages: list every automated and manual message your business sends, and classify each as commercial or non-commercial.
- Audit your opt-ins: check every form, checkout and event sign-up for clear, unbundled consent wording that names your business and the channel.
- Remove pre-ticked boxes: consent must be an active choice, not a default.
- Record consent: keep timestamps, form versions and source details for every opt-in.
- Check your templates: every commercial message must name your business, include contact details that stay valid for 30 days, and carry a clear, working unsubscribe.
- Test your unsubscribes: send yourself test messages and actually use the unsubscribe link or STOP reply at least every quarter.
- Connect your suppression lists: make sure an opt-out in one channel stops messages in every channel.
- Scrutinise third parties: require agencies, affiliates and list providers to evidence consent, and put the requirement in writing.
- Keep the transaction clean: do not bolt promotional content onto receipts or service messages unless you have consent and an unsubscribe in place.
When you need a lawyer
A lawyer's role in spam compliance is usually preventive, but it can become defensive quickly. On the preventive side, a practitioner can audit your message templates, forms and consent records against the Act, redraft opt-in wording and privacy materials, and review your agreements with marketing agencies and affiliates so that consent obligations are documented and enforceable.
Where it becomes defensive is if the ACMA comes knocking. If you receive a complaint notification, a formal warning, an infringement notice or a request for information, the way you respond shapes the outcome. A lawyer can help you respond to an investigation, negotiate the scope of any undertaking, and assess whether a penalty demand is legally correct before you pay it. Given that penalties are calculated per day and per contravention, a small factual error in a template can multiply into a very large figure, so early advice is almost always worth it.
Start with your message classification
The misstep that costs Australian businesses the most right now is message classification. The ACMA's stated compliance priority for 2024-25 is stopping commercial messages from being misleadingly sent as "service" or non-commercial messages, and its biggest penalties have come from exactly that mistake: the Commonwealth Bank's 170 million emails, and Tabcorp's VIP messages, were non-compliant in part because the businesses did not treat promotional content for what it was.
So the first task for your business this week is simple: list every email, SMS and instant message your business sends on a regular basis, including receipts, order confirmations and account updates, and decide honestly whether each one promotes anything. If it does, or if it links to anything promotional, it is a commercial message under the Act. Give it consent, sender identification and a working unsubscribe before it goes out again. That single classification exercise, done properly, will put your business ahead of most of the enforcement targets the ACMA is chasing.