Australia’s anti-spam law is the Spam Act 2003 (Cth), enforced by the Australian Communications and Media Authority. Like New Zealand’s later Act, it reduces to three obligations: consent, identify, unsubscribe.
But the thing worth understanding about Australia is not the rules. It is what ACMA actually fines people for — and it is almost never what marketers expect.
The enforcement pattern nobody tells you about
ACMA’s significant penalties in recent years — against Optus, Commonwealth Bank, DoorDash and Pizza Hut among others — have overwhelmingly not been for cold spam or bought lists.
They have been for failing to honour unsubscribe requests on lists the company lawfully owned. Broken opt-out pipelines. Requests logged in one system that never propagated to the sending platform. Customers who unsubscribed and kept receiving mail because two databases did not talk to each other.
That reframes the compliance job entirely. The risk is not your acquisition practices; it is your unsubscribe plumbing. If you do one thing after reading this, test that an opt-out on your website actually stops mail from every system you send from.
Does the Act apply to you?
It covers commercial electronic messages with an Australian link — sent from Australia, or sent to an address accessed in Australia. Overseas senders emailing Australian recipients are in scope.
It applies to email, SMS, MMS and instant messaging. It does not cover voice calls.
Consent — express or inferred
Express consent
The person actively agreed — a ticked box, a form, a verbal yes with a record kept.
Inferred consent
Australia recognises two routes, and the second one surprises people:
- An existing business relationship where the recipient would reasonably expect to hear from you.
- A conspicuously published work address — if a business address is published without a statement refusing unsolicited messages, and your message is relevant to that person’s role, functions or duties, consent can be inferred.
That second route means B2B email to published business addresses is often lawful in Australia without prior opt-in — provided relevance holds. Emailing a published procurement address about procurement software is likely fine. Emailing the same address about an unrelated consumer offer is not.
This is close to New Zealand’s deemed consent and considerably more permissive than Canada’s CASL, which requires express or narrowly-defined implied consent with expiry dates. See CASL explained.
Identify — and the detail people miss
Every message must clearly identify the sender and include accurate contact details. The requirement is that the information remains accurate and reachable for a reasonable period after sending — a contact address that stops working a month later does not satisfy it.
Unsubscribe — five business days, thirty days live
Two separate numbers, and they are frequently confused:
- Honour the request within five business days. This sits in Schedule 2, clause 6 of the Act — not section 16, which is where many secondary guides mis-cite it.
- Keep the unsubscribe facility functional for at least 30 days after the message was sent (s18(1)(e)). A campaign whose links die after a week is non-compliant even if you honoured every request you received.
Note the Act says business days, not working days or calendar days. Over Christmas and Easter that difference is material.
The facility must also be free, functional, and must not require the recipient to log in, create an account or provide information beyond identifying themselves.
Transactional and factual messages
Purely factual messages — and messages that facilitate or confirm a transaction the recipient agreed to — sit outside the consent requirement, though sender identification rules still apply. Receipts, delivery notifications and account notices are not commercial electronic messages.
As always, a “transactional” email dominated by promotion is a marketing email wearing a receipt’s clothing. See transactional vs marketing email.
Penalties — and why most figures you will read are wrong
Spam Act penalties are expressed in penalty units, and the unit value changes. For conduct on or after 1 July 2026 the penalty unit is A$364. A great many guides still quote A$313 or A$330, which produces figures that are simply out of date.
The unit value that applies is the one in force on the date of the contravention, not the date of judgment.
Under s25(5), repeated contraventions by a body corporate with a prior record are capped at 10,000 penalty units per day — A$3.64 million per day at the current unit value.
Separately, the Privacy Act 1988 governs how you collect and store the personal information behind your list, and its serious-interference penalty is far larger: under s13G, the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover for the relevant period. The OAIC enforces that one, not ACMA.
Two regulators, two regimes
It is worth being clear which body does what, because the obligations differ:
- ACMA enforces the Spam Act — consent, identification, unsubscribe. This is the sending rulebook.
- OAIC enforces the Privacy Act — how you collect, store, secure and dispose of the data. This is the holding rulebook.
You can be fully Spam Act compliant and still breach the Privacy Act, and vice versa.
A practical compliance checklist
- Test your unsubscribe pipeline end to end, across every system that can send. This is where the fines actually come from.
- Record consent source, timestamp and method against every address
- Keep unsubscribe links working for at least 30 days after each send
- Action opt-outs within five business days
- For B2B inferred consent, document why the message was relevant to that person’s role
- Suppress across systems, not just within the sending platform
- If you also send to New Zealand, the rules are close enough to run one standard — see New Zealand spam law explained
Frequently asked questions
How long do I have to honour an unsubscribe in Australia?
Five business days from the request. Separately, the unsubscribe facility itself must remain functional for at least 30 days after the message was sent.
Is B2B email legal in Australia without consent?
Often, under inferred consent — if the business address was conspicuously published without a refusal statement and your message is relevant to that person’s role. It is not a blanket B2B exemption, and relevance is the test.
What is the maximum Spam Act penalty?
For a body corporate with a prior record, contraventions are capped at 10,000 penalty units per day — A$3.64 million per day at the A$364 unit in force from 1 July 2026. Figures based on older penalty units understate this.
Does the Spam Act apply to overseas companies?
Yes, where the message has an Australian link — sent from Australia or to an address accessed in Australia.
Do I need consent to send order confirmations?
No. Messages that facilitate or confirm a transaction the recipient agreed to are not commercial electronic messages. Sender identification still applies.
Related reading
- Best email marketing software in Australia — platforms and AUD billing
- Newsletter platforms for Australia
- Email marketing rules by country
- New Zealand spam law explained — the Act this one inspired
- Email list cleaning — suppression done properly
Verified against the Spam Act 2003 (Cth), ACMA guidance and current penalty unit values, September 2026. General information, not legal advice.
Bluey Email handles suppression globally across marketing and transactional sending, so an unsubscribe stops every stream — the failure mode ACMA actually fines. Start free.