Direct Marketing Consent Reviews for Australian Businesses

Alex Solo
byAlex Solo12 min read

Many Australian businesses collect email addresses, mobile numbers and customer details long before they stop to ask a basic legal question: do we actually have the right consent to market to these people? This is where founders often get caught. Common mistakes include relying on pre-ticked boxes, sending promotions to contacts gathered for another purpose, and assuming one sign-up form covers email, SMS and retargeting forever. Those shortcuts can create privacy issues, spam compliance problems and customer complaints at the exact point you are trying to grow.

A direct marketing consent review helps you test whether your sign-up flows, privacy wording, CRM records and campaign practices line up with Australian law and with what people were actually told. It also helps you spot weak points before you spend money on ads, automation or a major sales push. If your business sends newsletters, promotional SMS, product updates, event invites or personalised offers, this guide explains what to review, when the issue usually arises, and the practical fixes that reduce risk.

Overview

A direct marketing consent review is a legal and operational check of how your business collects, records, manages and uses consent for promotional communications. For Australian businesses, the main focus is usually whether your direct marketing practices match your privacy disclosures, whether your messages comply with spam rules, and whether you can prove the permission you say you have.

  • What customers were told at the point their details were collected
  • Whether consent was voluntary, informed, current and specific enough for the relevant channel
  • How email, SMS and other marketing permissions are recorded in your systems
  • Whether unsubscribe functions and opt-out processes actually work
  • How your privacy policy, collection notices and campaign wording fit together
  • Whether purchased lists, referrals, competition entries or old databases are being used lawfully
  • How staff, agencies and software tools are handling customer contact data
  • What evidence your business can produce if a complaint is made

A direct marketing consent review means checking the legal basis and practical record behind every promotional message your business sends. It is not just a paperwork exercise. It tests whether the customer journey, the wording on your forms and the way your team actually markets are aligned.

In Australia, direct marketing usually intersects with two main legal areas: privacy obligations and spam rules. Privacy law can affect how personal information is collected, disclosed and used for marketing. Spam rules are especially relevant for commercial electronic messages such as emails, SMS and some instant messages.

For many startups and SMEs, this review sits alongside broader setup issues such as company setup, customer terms, selling online terms and trade mark strategy. You might already have your ABN or company registration sorted, your website live, and your brand protected, but your marketing consent process can still be the weakest point if no one has checked it closely.

What counts as direct marketing?

Direct marketing generally means promoting goods, services, events, donations or business opportunities directly to an individual using their contact details. In a business setting, that often includes:

  • email newsletters
  • promotional SMS campaigns
  • discount codes and abandoned cart messages with a marketing purpose
  • new product announcements
  • event invitations
  • cross-sell and upsell campaigns
  • personalised advertising based on customer profiles or behaviour

Not every message is purely marketing. Some communications are transactional, such as order confirmations, password resets or service notices. The problem usually arises when businesses blend operational and promotional content and assume the whole message is exempt from marketing rules. If a message has a commercial purpose, it should be reviewed carefully.

Consent is not just a box to tick. The main risk is that your business may think it has consent when it really has a vague, bundled or outdated record that would be hard to defend if challenged.

For example, a customer who gave an email address to download a guide may not have clearly agreed to ongoing SMS promotions. A person who entered a giveaway two years ago may not expect weekly sales emails now. A contact imported from an old spreadsheet may have no reliable consent history at all.

Consent quality matters because a weak sign-up process often creates problems in several places at once:

  • complaints from customers who say they never signed up
  • poor unsubscribe experiences that frustrate leads and existing customers
  • difficulty proving consent when regulators or service providers ask questions
  • higher risk when using marketing automation or segmented campaigns
  • brand damage from appearing pushy or careless with personal information

What a review usually covers

A proper review looks at more than your privacy policy. It usually covers the whole path from collection to campaign delivery.

That may include your website pop-ups, checkout pages, app sign-up forms, event registration pages, lead ads, referral programs, competition terms, CRM settings, agency instructions, email platform configuration and unsubscribe workflows. It can also include internal processes, such as who can upload lists, whether old contacts are cleaned out, and what happens when a customer opts out through customer support instead of through an automated link.

The aim is simple: make sure your business can say what consent was requested, when it was given, what it covered, and how a person can withdraw it.

When This Issue Comes Up

This issue usually comes up when a business is growing faster than its compliance processes. Founders often discover consent gaps when they launch a new campaign, switch systems, or receive a complaint.

You are launching or refreshing your marketing

A review is worth doing before you spend money on setup for a bigger campaign. If your team is about to roll out a newsletter, automate SMS offers, start selling online, or invest in a customer data platform, check consent settings first.

This is especially relevant where your business is expanding from one channel to another. Consent for email does not automatically mean consent for SMS. Consent gathered in person at an event may not cover retargeting or profile-based marketing unless that was properly disclosed.

You are importing or cleaning up a database

Old databases are a common problem. Businesses often merge spreadsheets, migrate CRMs or inherit contacts from a previous operator without checking where those contacts came from.

Before you sign a contract with a new platform or agency, consider a contract review and confirm what evidence of consent you can carry across. If your records only show a name and email address with no date, source or wording, the database may need a careful re-permission or suppression strategy instead of a broad campaign.

You collected details for one reason and now want to market

This issue also appears when customer data was first collected for service delivery, support, quoting, checkout or account registration. A business may then want to use those contacts for offers and promotions.

That shift needs review because the original purpose of collection matters. If the person was not clearly told about direct marketing at the point of collection, using their details later for promotions may create risk.

You use agencies, contractors or multiple tools

Marketing operations often involve several moving parts. A lead capture plugin feeds a CRM, which syncs to an email platform, which sends segmented campaigns drafted by an agency. If one part of that setup is wrong, the whole consent chain can break.

This is also where contracts matter. If external providers handle your customer data, your service agreements should address data use, confidentiality, responsibilities for compliance and what happens if a complaint arises.

You received a complaint or unsubscribe problem surfaced

A direct marketing consent review should not wait until there is a formal issue, but complaints are often the trigger. A customer might say they never subscribed, cannot unsubscribe, or keep receiving messages after opting out.

When that happens, your business needs records, a clear internal process and consistent wording across your forms, privacy policy and collection notices. If you cannot trace the person’s consent path quickly, that is a strong sign your systems need work.

Practical Steps And Common Mistakes

The best approach is to map your real customer journey and test your consent records against it. Most problems are practical, not theoretical: unclear wording, missing records, mixed-purpose messages and old contact lists.

Step 1: Map every collection point

Start with where customer details enter the business. Most businesses have more collection points than they first think.

  • website forms
  • checkout pages
  • account sign-up screens
  • lead magnet downloads
  • competition entries
  • event registration forms
  • point of sale systems
  • customer support interactions
  • social media lead ads
  • referral programs

For each collection point, identify what the person was told, what boxes or buttons they clicked, whether any fields were mandatory, and where that record is stored.

Common mistake: the form says one thing, the privacy policy says another, and the CRM tags the person as consenting to everything.

Consent wording should be clear about what the person is agreeing to. Vague statements such as “stay in touch” or “hear from us” may not be enough if you are planning regular promotional campaigns across several channels.

Good review questions include:

  • Does the form clearly mention marketing or promotional content?
  • Does it identify the channel, such as email or SMS?
  • Is consent optional where it should be optional?
  • Is the wording separate from acceptance of core service terms?
  • Is any third party involvement disclosed if relevant?
  • Does the language match what happens in practice?

Common mistake: bundling marketing consent into terms acceptance so that a customer cannot complete a purchase or enquiry without agreeing to promotions that are not necessary for the transaction.

Step 3: Check your evidence trail

If your business says a person consented, you should be able to show a usable record. That usually means more than a contact sitting in a list.

A stronger record may include:

  • date and time of sign-up
  • source of collection
  • specific form or campaign used
  • wording shown at the time
  • channel consented to
  • IP address or system log where relevant
  • changes to consent status over time

Common mistake: relying on an imported mailing list with no source notes, then discovering later that half the contacts came from a networking event, an old quote form or a prior business owner.

Step 4: Test unsubscribe and opt-out systems

An unsubscribe process must not exist only on paper. Test it. Send a message to yourself, click the unsubscribe link, try replying STOP to SMS, and check how long it takes for your systems to suppress future marketing.

Then test the manual path. If a customer emails support asking to stop promotions, does your team know what to do? Is that request logged and actioned across every relevant platform?

Common mistake: a customer is removed from one tool but not another, so they keep receiving SMS or event invites after opting out.

Step 5: Compare privacy documents with actual practice

Your privacy policy and collection notices should reflect what your business really does with personal information. If your policy says you may send marketing emails but your business also sends SMS, builds customer profiles for targeted promotions, or shares data with external marketing providers, the wording may need review.

This is a frequent issue for businesses that move quickly. The website legal documents stay static while the marketing stack changes.

Common mistake: copying a generic privacy policy during company setup and never updating it after new campaigns, new platforms or new sales channels are added.

Step 6: Review third party data sources and purchased lists carefully

Purchased lists and informal lead-sharing arrangements create obvious risk. Even where a supplier claims the contacts opted in, your business still needs to ask whether the consent was valid for your specific marketing use.

Questions worth asking include:

  • Who collected the data?
  • What exactly were people told?
  • Did they agree to hear from your business specifically, or only from the original collector?
  • Can the supplier provide records of consent?
  • Do your contracts allocate responsibility if the consent turns out to be defective?

Common mistake: treating any list with email addresses as usable because it was obtained through a “partner campaign” or industry database.

Step 7: Align teams, agencies and contracts

Consent problems often come from internal confusion. Sales may upload leads from a trade show. Customer service may add support contacts to a newsletter. An external agency may create a new pop-up with wording no one in legal or management reviewed.

Set practical rules for who can collect contacts, upload lists, create forms and approve campaigns. Then make sure your supplier agreements with agencies and software providers support those rules.

For startups and growing SMEs, this sits alongside your other legal building blocks, such as customer terms, supplier agreements, privacy documents, website terms and brand protection. If you are planning to scale, sort this out before you print flyers, launch the next promo cycle or sign a new marketing retainer.

Step 8: Decide what to do with risky legacy contacts

Not every old contact should stay on your active list. Some businesses need a re-consent campaign. Others should suppress contacts where the consent record is too weak. The right approach depends on what records exist, what was originally communicated, and how the contacts have been used.

Common mistake: sending a broad re-engagement campaign to every old contact without first checking whether the business has a lawful basis to send that message in the first place.

Founder examples

These are the moments where a direct marketing consent review usually proves its value:

  • A retail brand launches online and wants to use checkout data for weekly promotions and cart reminders.
  • A SaaS startup collects leads through webinars and then adds them to product update and sales sequences.
  • A professional services firm downloads business cards from an expo app and plans a follow-up email campaign.
  • A health or wellness business moves from studio bookings to SMS offers and app-based promotions.
  • An e-commerce business changes platforms and realises unsubscribe settings did not transfer properly.

Each scenario looks commercially normal. The legal question is whether the consent path, the messaging and the records support what the business now wants to do.

FAQs

Not always in the same way, but many electronic marketing messages raise consent and compliance issues that should be reviewed carefully. The answer depends on the message type, the relationship with the recipient, the channel used and what the person was told when their details were collected.

Can we use customer details collected during a sale for future promotions?

Sometimes, but only if your collection wording, privacy disclosures and campaign use line up with what the customer would reasonably expect and what the law requires. A sale does not automatically mean unrestricted marketing permission.

No. An unsubscribe function is important, but it does not fix invalid or unclear consent. You still need a lawful basis to send the marketing message and a reliable process for recording and honouring opt-outs.

What if our business bought a mailing list from another company?

You should treat that as high risk until the consent trail is properly checked. The key issue is whether the individuals actually agreed to receive marketing from your business, not just from the seller or a generic partner group.

Review it whenever your collection methods, marketing channels, systems or campaign strategy change. It is also sensible to review after complaints, database migrations, new agency appointments or major website updates.

Key Takeaways

  • A direct marketing consent review checks whether your business can lawfully send promotional messages and prove the consent it relies on.
  • Australian businesses should review both privacy issues and electronic marketing compliance, especially for email and SMS campaigns.
  • The most common weak points are unclear sign-up wording, bundled consent, poor record keeping, broken unsubscribe systems and risky legacy databases.
  • Consent should be reviewed at each collection point, including websites, checkout pages, events, competitions, referrals and CRM imports.
  • Your privacy policy, collection notices, campaign practices, staff processes and provider contracts should all tell the same story.
  • Founders should sort this out before they sign with a new platform, spend money on setup, migrate a database or launch a larger campaign.

If your business is dealing with direct marketing consent review and wants help with privacy policy updates, marketing consent wording, database compliance checks, and agency or platform contracts, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.