You have a list of leads, a campaign ready to go, and a launch date on the calendar. Before you hit send or pick up the phone, it is worth knowing that Australian direct marketing rules are not found in one place — they sit across at least three separate legal regimes, each triggered by a different channel or type of data use. Getting this wrong is not a theoretical risk: the Australian Communications and Media Authority (ACMA) issues infringement notices, accepts court-enforceable undertakings, and refers serious matters to the Federal Court.
Which laws actually apply to direct marketing
There is no single "Direct Marketing Act" in Australia. Instead, four overlapping frameworks tend to catch most campaigns:
- The Spam Act 2003 (Cth) — covers commercial electronic messages, primarily email and SMS.
- The Do Not Call Register Act 2006 (Cth) and the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 — govern outbound telemarketing calls.
- The Australian Consumer Law (ACL), in Schedule 2 of the Competition and Consumer Act 2010 (Cth) — applies to the content of any marketing communication.
- The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) — apply to how you collect, hold, use and disclose the personal information underpinning your campaigns.
The channel you use determines which regime leads, but all four can operate at the same time. A single SMS campaign, for instance, can engage the Spam Act (electronic message), APP 7 (use of personal information for direct marketing), and the ACL (claims made in the message).
Email and SMS — the Spam Act's three pillars
If your campaign uses email, SMS, or MMS, the Spam Act 2003 is typically the first compliance stop.
The Act rests on three requirements for every commercial electronic message:
Consent
You must have the recipient's consent before sending. Consent is either express (the person actively opted in — for example, ticking a box, submitting a sign-up form) or inferred (there is an existing relationship and the person would reasonably expect to receive marketing of this kind from you).
Express consent is almost always easier to defend. Inferred consent has a short shelf life: if the relationship ends or the marketing strays beyond what the person could reasonably have expected, the inference falls away. The common failure mode is purchasing or scraping a list and treating it as consented — it is not.
Identification
Every commercial message must clearly identify the sender. That means your business name and accurate contact details must appear in the message itself. A sender address that obscures who you are does not satisfy this requirement.
Unsubscribe
Every commercial message must include a functional unsubscribe mechanism. Under the Act:
- The unsubscribe facility must work for at least 30 days after the message is sent.
- Once someone uses it, you must honour the request within 5 business days — after which you cannot send them further commercial messages (even if they remain a customer), unless they later opt back in.
- The unsubscribe process must not require the person to log in, create an account, or provide more personal information than their email address or phone number.
Where businesses most often fall short: unsubscribe links that expire before 30 days, manual opt-out queues that drift past the 5-business-day window, and CRM fragmentation where one team processes the opt-out but another team's automated sequence keeps firing.
Enforcement context: The ACMA can issue infringement notices, accept enforceable undertakings, or refer matters to the Federal Court. For body corporates, court-ordered civil penalties can reach AUD 626,000 per day for a first-time breach, and AUD 3,130,000 per day for repeat offenders. These are not theoretical numbers — large businesses including banks and retailers have faced multi-million-dollar penalties.
Outbound calls — the Do Not Call Register and calling-hour rules
If your direct marketing includes phone calls to consumers or individual businesses, you need to check two things before your first dial: the Do Not Call Register, and the permitted calling times.
The Do Not Call Register
The Do Not Call Register Act 2006 prohibits making unsolicited telemarketing calls to a number that appears on the Register, unless a specific exception applies (for example, the person has given you consent, or the call falls within certain exempt categories such as calls by registered charities).
The practical implication: you need a process to screen your calling list against the Register before each campaign. Registration on the Register becomes effective 30 days after the number is added, so periodic re-screening is also necessary as lists age.
Permitted calling hours
Even for numbers not on the Register, the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 restricts when calls can be made. Telemarketing calls are only permitted:
- Weekdays: 9:00 am to 8:00 pm (local time of the recipient)
- Saturdays: 9:00 am to 5:00 pm (local time of the recipient)
- Sundays: not permitted
- National public holidays: not permitted
The time that counts is the recipient's local time, not yours. A business calling from Melbourne on a Saturday afternoon at 4:45 pm AEDT may be calling someone in Perth at 1:45 pm AWST — that is within hours. But the reverse scenario can easily produce an unlawful call.
Caller identification
Telemarketers must not block or withhold their calling number. The recipient must be able to identify who called and be able to call back.
Internal do-not-call lists
Separately from the Register, if someone asks you to stop calling them, you must maintain an internal do-not-call record and honour it — even if their number is not on the public Register.
Marketing content — the Australian Consumer Law
Whatever channel you use, the content of your marketing communication is subject to the ACL. Section 18 of the ACL prohibits conduct that is misleading or deceptive, or likely to mislead or deceive. The standard is objective — it turns on the impression a reasonable person in your audience would form, not on what you intended to say.
Common pressure points in direct marketing content:
Pricing and discount claims. "Was/now" pricing must be based on a genuine prior price held for a reasonable period. "From $X" claims need to reflect a price that applies in realistic circumstances, not edge cases. Mandatory fees or charges cannot be left out of the headline price.
Urgency and scarcity. "Only 3 left", "offer ends tonight", and "limited spots" are only lawful if they are true. Artificial countdown timers or fictional stock levels can constitute misleading conduct.
Testimonials and performance claims. Testimonials must reflect genuine experiences. Claims like "guaranteed results" or "the best in Australia" need a factual basis — unqualified superlatives can mislead if they imply a verified superiority you cannot demonstrate.
The ACL risk in SMS campaigns is particularly acute because character limits encourage compressing claims. A 160-character message can still mislead, and the brevity is not a defence.
Privacy — when the Privacy Act applies and what APP 7 requires
Direct marketing is data-intensive. Every campaign list is a collection of personal information — names, email addresses, phone numbers, browsing history, purchase data. That makes privacy compliance unavoidable at some threshold.
Who is covered
Under the Privacy Act 1988, businesses with an annual turnover of more than AUD 3 million are covered by the Act and the APPs. So are some smaller businesses regardless of turnover — including private sector health service providers, businesses that trade in personal information, and businesses that have opted in or are otherwise brought within the Act's scope by contract or regulation.
If your turnover is AUD 3 million or less and none of the special categories apply, you are likely outside the Act — but that does not mean you have no privacy obligations. Contractual requirements from enterprise clients, platform terms (such as Meta's or Google's custom-audience policies), and general community expectations all operate whether or not the Privacy Act applies.
APP 7 — direct marketing
For businesses that are covered, Australian Privacy Principle 7 specifically addresses direct marketing. The general rule is that you must not use or disclose personal information for direct marketing unless an exception applies. The main exceptions are:
- you collected the information directly from the individual, the person would reasonably expect you to use it for direct marketing, and you provide a simple way to opt out; or
- you have the individual's consent.
APP 7 also requires that whenever you send direct marketing, you must include a clear opt-out mechanism — and honour any opt-out request.
Common privacy failure points in direct marketing
- Collecting email addresses and phone numbers without a privacy collection notice at the point of collection, so individuals do not know their details will be used for marketing.
- Sharing customer lists with partner businesses or uploading them to advertising platforms to build lookalike audiences, without adequate transparency and consent.
- Using customer data collected for one purpose (for example, processing an order) to contact them for an unrelated commercial purpose they would not expect.
- Retaining data well past the point when it is needed or the person has opted out.
The OAIC's direct marketing guidance sets out the regulator's expectations in practical terms and is worth reading alongside the Act itself.
Consent — the concept that cuts across all three regimes
Consent appears in the Spam Act, the DNCR framework, and APP 7. While the technical definition varies slightly across each, the underlying expectations are consistent:
- It must be voluntary and informed. Pre-ticked boxes, consent buried in terms and conditions, and vague phrases like "we may contact you with updates" do not meet the standard where express consent is required.
- It must be specific enough. Consent to receive service-related messages does not automatically extend to promotional campaigns.
- It must be recorded. If a complaint is made, you need to be able to demonstrate when and how you obtained consent. "We think they opted in" is not a record.
- It expires or can be withdrawn. Consent obtained in 2019 from a customer who has had no contact with your business since then is not indefinitely valid. Treat old lists with caution.
The distinction between express and inferred consent matters practically. Inferred consent under the Spam Act applies where: you have a prior commercial relationship with the person; the message relates to the subject matter of that relationship; and it is reasonable in the circumstances. If you are building a growth campaign on inferred consent alone, you are building on shaky ground as the list ages and the relationship thins.
Where third parties fit in
Many businesses outsource campaign execution to marketing agencies, lead generation providers, outbound calling contractors, or email and SMS platform providers. Outsourcing the execution does not outsource the legal responsibility.
Under the Spam Act, the business whose brand appears in the message is generally responsible for compliance — not just the agency that sent it. Under APP 7, if you direct a third party to use personal information you hold, you remain accountable for how it is used.
Practical protections when working with third parties:
- Data processing agreements that specify who holds personal information, how it can be used, what security standards apply, and what happens if there is a breach.
- Consent documentation — written assurances (ideally contractually binding) that any list a lead provider supplies was obtained with consent for your specific type of marketing.
- Brand and message approval processes so that what goes out under your name has been reviewed against your compliance standards.
- Audit rights or at least periodic reporting, so you are not relying on assumptions about a third party's practices.
If you switch providers, the question of who owns the consent records — and whether they transfer — is one of the more consequential things to resolve before the relationship ends.
Where an Artificer Legal practitioner can help
The rules across these four regimes are clear enough in principle but genuinely complex in practice — particularly once a business is running multiple channels, relying on third parties, or scaling quickly. There are several points where legal judgement is not optional:
Consent architecture. Whether your existing sign-up flows, checkout processes, and lead-magnet landing pages produce lawful consent under the Spam Act and APP 7 requires a specific review. Getting this wrong produces a non-compliant list that cannot safely be used.
Privacy collection notices and privacy policies. If you are covered by the Privacy Act, your privacy policy and collection notices need to accurately describe your marketing practices. Standard template policies often do not reflect what businesses actually do.
Third-party agreements. Data processing agreements, marketing services agreements, and lead generation contracts need to allocate compliance responsibility, set consent standards, and address breach scenarios. These agreements are often absent or inadequate when disputes arise.
Campaign-specific documents. Competition terms and conditions, referral offer terms, and promotion mechanics all need to comply with the ACL and, where applicable, state-specific trade promotion laws.
An Artificer Legal practitioner can review your campaign workflows, draft or update the documents you need, and advise on the specific judgement calls the rules leave open — including what "inferred consent" can and cannot support in your particular customer journey.
The most important thing to get right from the start
The single biggest compliance mistake in direct marketing is treating list quality as a logistics problem rather than a legal one. A list is not just a file of contacts — it is a record of what each person agreed to. If you cannot answer the questions "when did this person consent?", "what did they consent to?", and "have they since opted out?" for every contact on your list, you do not have a compliant list. Buying a list from a third party, scraping contacts, or inheriting a database from an acquisition does not give you consent — it gives you contact details. The consent must be verified or the contacts must be re-permissioned before the campaign launches.
Summary of key points:
- Email and SMS campaigns must satisfy the Spam Act 2003: obtain consent, clearly identify your business in the message, include a functional unsubscribe mechanism that remains active for 30 days, and honour opt-out requests within 5 business days.
- Outbound telemarketing requires screening against the Do Not Call Register and calling only within permitted hours (weekdays 9:00 am–8:00 pm, Saturdays 9:00 am–5:00 pm; no calls Sundays or public holidays).
- All marketing content is subject to the ACL — pricing claims, urgency tactics, testimonials, and performance representations must be accurate and not create a misleading overall impression.
- The Privacy Act and APP 7 apply once your turnover exceeds AUD 3 million (and in some cases below that threshold). APP 7 restricts when personal information can be used for direct marketing and requires an easy opt-out.
- Consent is the common thread across all regimes — it must be voluntary, informed, specific, and recorded. Inferred consent is narrower than most businesses assume.
- Outsourcing campaigns does not outsource compliance. Written agreements with third parties, clear consent documentation, and data processing terms are essential risk management tools.