Marketing Consent: How to Comply With Australia’s Privacy and Spam Laws

Alex Solo
byAlex Solo10 min read

For startups and small businesses, marketing can feel like the fastest path to growth - a newsletter to nurture leads, a few SMS reminders to reduce no-shows, or a launch campaign to get early traction.

But marketing only works long-term if your customers trust you. In Australia, that trust is backed by law. If you send marketing messages without the right consent (or you don’t handle customer data properly), you can quickly find yourself dealing with complaints, reputational damage, or regulatory attention.

The good news is that getting marketing consent right isn’t complicated once you understand the rules and build them into your day-to-day processes. Below, we’ll walk you through what marketing consent means in Australia, how it works across email and SMS, and practical steps you can implement to keep your marketing compliant as you scale.

In Australia, “marketing consent” generally refers to having a lawful basis to send promotional messages to someone (such as emails or SMS) and collecting/using their personal information in a way that meets privacy obligations.

Two key legal frameworks often apply:

  • Spam laws (including the Spam Act 2003) - focused on when you can send commercial electronic messages, what you must include in them, and how people can opt out.
  • Privacy laws (including the Privacy Act 1988 and the Australian Privacy Principles (APPs)) - focused on how you collect, store, use and disclose personal information (including for marketing).

These laws overlap in real life. For example, if you collect an email address via a website form, you need to think about:

  • whether your customer has consented (or you can rely on another lawful basis under spam rules) to receive marketing emails; and
  • whether you have clearly explained what you’ll do with their personal information and handled it securely (privacy compliance).

One helpful mindset is to treat marketing consent as two layers:

  • Permission to message (spam compliance), and
  • Permission to collect and use data (privacy compliance).

Spam Law Basics: When Can You Send Marketing Emails Or SMS?

If you’re sending emails or SMS for business promotion, you’re usually sending a “commercial electronic message” - and Australia’s spam rules apply.

In most cases, you need:

  • Consent (express or inferred),
  • Identification (your business details must be clear), and
  • Unsubscribe (a functional opt-out).

Express consent is when a person clearly agrees to receive marketing messages.

Common examples include when someone:

  • ticks a checkbox saying “I agree to receive marketing emails”;
  • subscribes to your newsletter via a form; or
  • enters their phone number into a form that clearly says they’ll receive SMS offers or reminders.

Practical tip: if you rely on express consent, ensure the customer understands what they’re signing up for. If the checkbox is buried, vague, or bundled with unrelated terms, you can end up with consent that’s hard to defend.

Inferred consent can apply where the customer’s conduct and relationship with you suggests they would reasonably expect marketing messages.

This commonly comes up when:

  • someone is an existing customer; and
  • your marketing is directly relevant to what they purchased or requested.

Inferred consent isn’t a “free pass”. It’s context-based, and expectations matter. A customer who bought a one-off item two years ago may not reasonably expect ongoing weekly promotions - but a customer with an ongoing service relationship might.

If you’re not sure whether inferred consent applies, it’s often a good risk-management step to seek express consent going forward.

3) Identification And Unsubscribe Are Not Optional

Even if you have consent, your message must still:

  • clearly identify your business (so the recipient knows who is contacting them); and
  • include a working unsubscribe option (and you need to honour opt-outs promptly).

For SMS, this often means including your business name (or a recognisable short name) and providing a simple opt-out such as “Reply STOP to unsubscribe”.

Privacy Law Basics: What If You’re Collecting And Using Customer Data For Marketing?

Most startups and small businesses collect personal information as part of normal operations - names, emails, phone numbers, addresses, purchase history, and sometimes more sensitive information depending on your industry.

Privacy compliance matters because marketing consent is often collected at the same time as customer data. Even if you’re using a simple email marketing platform, you’re still “handling” personal information.

It’s also worth noting that some businesses may be covered by the Privacy Act and APPs, while others may be exempt (for example, some “small businesses” under the Privacy Act). Even if you’re exempt, you may still need to comply with the Spam Act for marketing messages, and strong privacy practices are usually still good for trust and risk management - especially if you work with larger partners or handle more sensitive information.

In practice, you should be thinking about:

  • Transparency: do you clearly tell people what you collect and why?
  • Use and disclosure: do you use data only for the purposes you’ve told people about?
  • Security: do you store data securely, limit staff access, and manage data breaches?
  • Third parties: do you share customer data with other businesses, service providers, or platforms?

For many small businesses, a well-drafted Privacy Policy is a key building block. It sets expectations with customers and helps you demonstrate that your data practices are thought through, not improvised.

Depending on your setup, you may also need a separate collection notice at the point of collection (for example, near your website sign-up form). A Privacy Collection Notice can be a practical way to ensure people understand what will happen with their information before they click “submit”.

If you want marketing consent to be a growth asset (rather than a legal risk), it helps to treat it like a process - not just a checkbox on your website.

Here are practical steps you can implement and scale as your business grows.

Step 1: Map Your Marketing Channels And Data Sources

Start by listing:

  • the channels you use (email, SMS, direct messages, app notifications);
  • where you collect details (website forms, checkout pages, lead magnets, events, in-store, phone enquiries); and
  • what data you collect (email, phone, name, preferences, purchase history).

This gives you a clear view of where consent needs to be captured, recorded, and managed. Keep in mind that spam law rules are designed around “commercial electronic messages” (like email and SMS), and some channels (such as certain in-app notifications or platform direct messages) may be regulated differently depending on how the message is sent and received - so it can help to check the rules for any non-standard channels you plan to rely on.

For each channel and list, decide whether you’re relying on:

  • express consent (often best practice for email newsletters and promotional SMS); or
  • inferred consent (often relevant for existing customers in specific contexts).

Where possible, design your customer journey so consent is express. It’s cleaner, easier to document, and reduces disputes later.

If your sign-up form includes multiple agreements, keep marketing opt-in separate from other terms.

As a general rule:

  • use plain language (“Send me product updates and offers”);
  • avoid pre-ticked boxes; and
  • don’t make marketing consent a condition of buying unless you have a genuine reason and you’re transparent about it.

This also aligns with broader consumer expectations - and helps reduce complaints about being “signed up without knowing”.

If someone complains, your best defence is being able to show when and how you got consent.

For each contact, try to keep:

  • date and time of sign-up;
  • source (which form, which page, in-store sign-up);
  • the wording used at the time (what they agreed to); and
  • whether it was express or inferred consent (and your reasoning for inferred).

Many email marketing tools and CRMs store some of this automatically. If you’re collecting consent offline (like at a market stall), make sure you have a simple system to transfer and store those records.

Step 5: Make Unsubscribing Easy (And Operationally Enforced)

A working unsubscribe link is not enough if your internal processes don’t support it.

Make sure that:

  • unsubscribe requests are automatically applied wherever possible;
  • your staff know not to re-add someone who has opted out; and
  • your systems don’t accidentally keep messaging a person through a different list or channel.

As your business grows, this is often where things go wrong - multiple systems, multiple lists, and no single source of truth.

Step 6: Align Your Marketing With What You Promised In Your Privacy Documents

If your Privacy Policy says you use customer information for account management and service delivery only, but you’re also sending promotional campaigns, that mismatch can create privacy risk (and customer trust issues).

This is where it helps to ensure your privacy documents reflect what you actually do day-to-day, and what you plan to do as you scale.

Most marketing consent issues don’t come from bad intentions. They come from moving fast and building systems later.

Here are a few common pitfalls to watch for.

Using Purchased Or Scraped Lists

Buying or scraping email lists is high risk. Even if it looks like a shortcut, you may not have valid consent from those individuals for your business to contact them - and it can damage deliverability and brand trust fast.

If someone gives you a business card at an event, that doesn’t automatically mean they want marketing emails. They might be open to a follow-up about the specific conversation you had, but ongoing promotions are a different thing.

If you want to add them to a newsletter list, a simple follow-up asking them to opt in is usually the safer route.

Sending SMS Marketing Without A Clear Opt-In

SMS feels more direct (and it is), which is why customer expectations are often stricter. If you plan to send promotional SMS, it’s usually best to capture express consent with clear wording.

Forgetting Privacy When You’re Focused On Growth

Marketing consent is often gathered alongside personal information collection. If you’re scaling quickly, you might also be sharing data with new platforms, contractors, and service providers.

If your team is collecting and storing IDs or other sensitive details as part of onboarding, privacy obligations can become more complex. It’s worth being across your broader privacy handling, including areas like drivers licence collection, which can raise additional risk if not handled carefully.

Even a great policy can fail if your team doesn’t understand it.

For example:

  • a salesperson manually exporting contacts and uploading them into a new email list;
  • a contractor messaging customers from a personal phone; or
  • a staff member re-adding an opted-out contact because “they’re a good lead”.

Consent needs to be part of your internal processes, not just your website forms.

For most startups and small businesses, compliance is easier when it’s “built in” to your customer journey and documents - instead of being an afterthought.

Here are some key documents and terms that often support marketing and privacy compliance:

  • Privacy Policy: explains what personal information you collect, how you use it (including marketing), and how customers can contact you about privacy concerns.
  • Privacy Collection Notice: a short notice shown at the point you collect information (like a sign-up form), helping you be transparent from the start.
  • Website Terms: can help set expectations about how your website is used and how accounts, content, and communications work (especially if you have member sign-ups or online ordering).
  • Customer Terms And Conditions: if you sell online or provide ongoing services, your terms can clarify service communications versus marketing communications (and reduce disputes about what customers “signed up for”).
  • Internal policies and training: if team members or contractors are sending messages or handling lists, written internal guidance and basic training can help prevent accidental non-compliance (for example, re-adding opted-out contacts or using personal devices).
  • Data breach and security processes: while not strictly a “marketing consent” item, strong security supports compliance and customer trust. If your marketing database is compromised, that can become a serious business issue quickly.

If you’re building or buying a marketing database as part of a broader business acquisition (or you’re selling your business later), consent and privacy compliance can also affect the value of that customer list. That’s one reason these foundations matter early.

Key Takeaways

  • Marketing consent in Australia commonly requires you to think about both spam laws (permission to message) and privacy laws (lawful collection and use of customer data).
  • For spam compliance, focus on the essentials: consent (express or inferred), identification, and a working unsubscribe function that you actually honour operationally.
  • For privacy compliance, consider whether the Privacy Act applies to your business (including whether any small business exemption is relevant), and make sure you’re transparent about what you collect and why, and that your handling of personal information matches what you tell customers in your documents.
  • Set up consent as a system: clear opt-ins, good record-keeping, easy opt-outs, and staff processes that prevent accidental re-subscribing or cross-list messaging.
  • A tailored Privacy Policy and a clear Privacy Collection Notice are practical tools that can reduce risk and build customer trust as you scale.
  • If you’re unsure whether you can rely on inferred consent, or you’re building more complex marketing journeys (SMS + email + CRM), it’s worth getting advice early to avoid costly fixes later.

If you’d like help setting up compliant marketing consent processes, privacy documents, or customer terms for your startup, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo

Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.