Running a direct marketing campaign without understanding the legal framework is one of the more reliable ways for an Australian business to attract regulator attention. The rules are not especially complicated, but they cover multiple layers of law at once — and a common misconception is that only large organisations need to take them seriously.
This article explains the four overlapping legal frameworks that apply when an Australian business contacts customers or prospects for marketing purposes: the Spam Act 2003 (Cth), the Privacy Act 1988 (Cth), the Do Not Call Register Act 2006 (Cth), and the Australian Consumer Law. It covers how consent works, where the lines sit for each channel, and the mistakes that most commonly attract enforcement action.
The Spam Act and commercial electronic messages
The Spam Act 2003 (Cth) is the primary federal statute governing marketing by email and SMS or MMS. It applies to "commercial electronic messages" — broadly, any electronic message with the purpose of offering, advertising or promoting the supply of goods, services or business opportunities.
The Act imposes three requirements on every commercial electronic message you send:
- Consent — you must have the recipient's consent before sending. Consent can be express (an affirmative opt-in) or inferred from the circumstances of an existing business relationship. Sending without demonstrable consent is the most common breach.
- Identification — the message must accurately state who sent it and provide a way to contact the sender. Your business name, ABN or ACN and a valid reply address or contact link should appear in every message.
- Unsubscribe — every message must include a functional unsubscribe facility. Under the Act, that facility must remain operational for at least 30 days after the message is sent, and opt-out requests must be actioned promptly. You cannot charge a fee or require an account login to process an unsubscribe.
The Act applies regardless of whether the recipient is a consumer or a business. A professional email address at a company is not a free pass — the same three requirements apply.
Express versus inferred consent
Express consent is a clear, affirmative indication from the recipient — a checkbox they have actively ticked, a form they have completed, a verbal or written agreement to receive a particular type of message. It is easy to prove and the safest basis for any campaign.
Inferred consent is narrower than most businesses assume. Under Schedule 2 of the Spam Act 2003 (Cth), consent may be inferred where there is an existing business relationship and the marketing is directly related to what the recipient would reasonably expect given that relationship — for example, a follow-up offer on a product category a customer recently purchased. Consent cannot simply be inferred from the fact that someone published their email address on a website or handed over a business card.
If you are unsure whether inferred consent applies to a particular list or segment, the practical answer is to seek express consent instead.
What happens when you get it wrong
The Australian Communications and Media Authority (ACMA) is the regulator responsible for enforcing the Spam Act 2003 (Cth). It can issue infringement notices, accept court-enforceable undertakings, and take matters to the Federal Court for civil penalties.
The consequences can be significant. In 2020, Woolworths paid a $1,003,800 infringement notice after the ACMA found more than five million breaches of the Act — the company had continued sending marketing emails to customers who had already unsubscribed, and its internal systems were not adequate to honour opt-outs reliably. Woolworths also agreed to a three-year court-enforceable undertaking.
In 2022, Latitude Finance Australia paid a $1.55 million infringement notice for over three million breaches, after the ACMA found it had sent commercial emails and text messages without any unsubscribe function, and continued to message customers who had attempted to opt out. Those examples are from large organisations, but the Act applies equally to smaller businesses — and ACMA has issued infringement notices against companies of all sizes.
The Privacy Act and Australian Privacy Principle 7
Marketing compliance is not only about the message itself. If you collect, store or use personal information as part of your marketing operations, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) also apply.
Australian Privacy Principle 7 (APP 7) deals specifically with direct marketing. Its core requirements for organisations covered by the Act are:
- You may only use or disclose personal information for direct marketing purposes where the individual has consented, or where certain conditions apply (such as collecting the information directly from the individual and the use being reasonably expected).
- You must provide a simple, free means for individuals to opt out of direct marketing at any time.
- You must give effect to an opt-out request within a reasonable period.
The Privacy Act 1988 (Cth) applies to most private sector organisations with an annual turnover above $3 million, as well as to smaller organisations in certain circumstances. If your business is covered, APP 7 obligations sit alongside — not instead of — your Spam Act obligations. Both must be satisfied.
A publicly accessible privacy policy that sets out how you handle personal information, and a collection notice at the point you gather data (such as on a sign-up form), are the foundational documents for demonstrating compliance.
The Do Not Call Register
If your marketing includes outbound telephone calls, the Do Not Call Register Act 2006 (Cth) adds another layer. The Do Not Call Register, managed by the ACMA, allows individuals and some organisations to register their telephone numbers to opt out of most unsolicited telemarketing calls.
Before making outbound sales or promotional calls, businesses must "wash" their calling lists against the Register — that is, remove any numbers that appear on it. Calling a registered number without consent is a breach of the Act. The Register is free for individuals to use and registration is permanent.
The Act also imposes identification requirements: callers must identify themselves and their organisation at the start of the call, and must end the call if the recipient requests it.
Australian Consumer Law: the content of the message
Even if you have consent, accurately identify yourself and include an unsubscribe mechanism, the content of your marketing message must comply with the Australian Consumer Law (ACL), which is found in Schedule 2 of the Competition and Consumer Act 2010 (Cth).
Section 18 of the ACL prohibits conduct in trade or commerce that is misleading or deceptive, or likely to mislead or deceive. This applies to marketing content regardless of channel. Practical examples in a direct marketing context include:
- Claiming a price reduction when you do not have accurate records of the previous price
- Describing a product's features or results in a way that overstates what most customers will experience
- Presenting conditions, limitations or recurring charges in fine print that contradicts the headline of the offer
- Using "was/now" pricing without substantiation
The ACL test focuses on the overall impression your communication creates, not your intention. A well-intentioned campaign can still breach s 18 if its content would cause an ordinary recipient in the target audience to form a false impression.
Where businesses typically go wrong
Understanding the framework is one thing; the harder part is maintaining compliant systems as your business scales. These are the patterns that most often lead to enforcement action or complaints:
No consent records. Many businesses collect consent but do not log when it was given, via which form version, or through which channel. When complaints arise — or an ACMA investigation starts — the absence of records makes it very difficult to demonstrate compliance. Your CRM or email platform should capture the date, source and form of each consent.
Treating inferred consent as a general licence. An existing customer relationship does not automatically authorise you to send marketing messages across all channels or about any product. The connection between the relationship and the message content must be direct and reasonably expected by the recipient.
Buying or scraping contact lists. Consent obtained by a third party for a different purpose is not transferable to your marketing. Lists purchased from a data broker, or scraped from websites and social media, almost never come with consent that satisfies the Spam Act or APP 7.
Slow or incomplete opt-out processing. The unsubscribe facility must remain functional for at least 30 days and requests must be actioned promptly. Continuing to send messages after an opt-out request has been received — even because of a systems lag — is a breach of s 18 of the Spam Act 2003 (Cth). The Woolworths enforcement action was driven precisely by this failure.
Assuming B2B means no consent needed. The Spam Act 2003 (Cth) applies to business email addresses just as it does to personal addresses. "They're a business contact" is not a basis for inferred consent if there is no genuine prior business relationship.
Channel assumptions. Consent for one channel does not carry across to another. Express consent to receive email newsletters does not authorise SMS marketing unless the original consent statement covered both.
How Artificer Legal can help
Spam Act compliance is straightforward in principle but easy to get wrong in practice, particularly when your marketing technology, sales processes and data handling systems evolve faster than your legal documentation. If you are unsure whether your current setup is defensible, a review with Artificer Legal typically covers:
- Auditing your consent capture, consent records and unsubscribe workflows against the requirements of the Spam Act 2003 (Cth) and APP 7
- Reviewing your privacy policy and collection notices for accuracy and accessibility
- Checking marketing content for ACL risk, including pricing claims and offer descriptions
- Assessing whether your outbound call process complies with Do Not Call Register obligations
- Drafting or updating the internal policies and documentation your team needs to maintain compliance as you scale
Getting the legal foundations in order before you run a large campaign is considerably less expensive than responding to an ACMA investigation or infringement notice after one.
Conclusion
Australia's direct marketing rules draw from four separate statutes — the Spam Act 2003 (Cth), the Privacy Act 1988 (Cth), the Do Not Call Register Act 2006 (Cth), and the Australian Consumer Law — and the obligations under each apply at the same time, not in the alternative. The single most important thing to understand is that the rules apply to B2B marketing and small businesses, not only to consumer-facing campaigns by large organisations.
Key points from this article:
- Every commercial electronic message must satisfy three conditions: consent, accurate identification, and a functional 30-day unsubscribe facility.
- Consent must be demonstrable — inferred consent is narrow, and purchased or scraped lists almost never satisfy it.
- APP 7 of the Privacy Act 1988 (Cth) adds a separate requirement to offer a free opt-out from direct marketing use of personal information.
- Outbound telephone calls require checking against the Do Not Call Register before dialling.
- Marketing content must not mislead or deceive, regardless of whether consent and identification requirements are otherwise met.
- Consent records, opt-out logs and an accurate privacy policy are the documents that protect you if a complaint or investigation arises.