Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
If you run a business in Australia, chances are you rely on marketing to grow - email newsletters, SMS promotions, customer updates, and automated follow-ups are all common tools.
But there’s a legal line between “smart marketing” and spam. The Spam Act 2003 (Cth) sets the rules for commercial electronic messages, and it applies to businesses of all sizes (including small businesses and startups).
The good news is that compliance doesn’t have to be complicated. Once you understand the core requirements, you can put simple systems in place to reduce risk, avoid complaints, and build better trust with customers.
Below, we’ll walk you through what the Spam Act 2003 (Cth) is, when it applies, what you need to do to comply, and practical steps you can implement in your day-to-day marketing.
What Is The Spam Act 2003 (Cth) And Who Does It Apply To?
The Spam Act 2003 (Cth) is an Australian federal law that regulates commercial electronic messages. In plain terms, it’s designed to stop businesses (and individuals) from sending unsolicited marketing messages via certain digital channels.
It applies broadly - including to:
- sole traders, companies, and partnerships
- online businesses and eCommerce stores
- service providers (tradies, agencies, consultants, clinics)
- not-for-profits (where messages are “commercial” in nature)
- anyone using third-party marketing platforms or agencies
Importantly, you can still be responsible even if you outsource marketing. If an agency or contractor sends messages “for your business”, you should treat that as your compliance risk too (which is why it’s worth having clear contracts and processes in place).
What Counts As A “Commercial Electronic Message”?
A message is likely to be a commercial electronic message if it has one of these purposes:
- offering goods or services
- promoting a business opportunity
- advertising your business, brand, or supplier
- directing someone to a website or landing page with a promotional angle
This can include:
- marketing emails (newsletters, promo campaigns, abandoned cart emails)
- SMS marketing messages
- marketing messages sent through electronic messaging channels (for example, where a platform’s messaging function is used to send promotional content), depending on the circumstances
Some messages are more “transactional” (like receipts, delivery notifications, appointment reminders). These aren’t always treated the same way as marketing messages - but if you include promotional content, you may be sending a commercial electronic message (for example, adding a promotional banner and discount code).
The 3 Core Compliance Rules Under The Spam Act 2003 (Cth)
Most Spam Act compliance comes down to three practical rules. If you build your marketing processes around these, you’ll be in a much stronger position.
1. Consent (You Need Permission)
You generally need a customer’s consent before sending them commercial electronic messages.
Consent can be:
- Express consent: the person actively agrees (for example, ticking a sign-up box, entering their email in a newsletter form, or choosing to receive SMS offers).
- Inferred consent: consent is implied from the relationship and the person’s conduct (for example, an existing customer relationship where marketing messages are reasonably expected and relevant).
For small businesses, express consent is usually the safest and simplest approach - especially when you’re building email lists, running lead magnets, or collecting numbers at events.
Be careful with “inferred consent”. It can exist, but it’s not a blank cheque to market forever. You should still keep your messages relevant and give a clear unsubscribe option.
2. Identification (Be Clear About Who You Are)
Your message must clearly identify the business (or individual) who authorised sending it.
In practice, that means your marketing email or SMS should include accurate information like:
- your business name (the name customers recognise)
- ABN/ACN details where appropriate
- contact details (email, phone, physical address, or other appropriate business contact method)
This is not just a legal requirement - it also helps deliverability and trust. If people can’t tell who you are, they’re more likely to report your message as spam.
3. Unsubscribe (Make It Easy To Opt Out)
You must include a functional unsubscribe facility in your commercial electronic messages.
Your unsubscribe must be:
- clear (easy to find and understand)
- functional (it actually works)
- low friction (no unnecessary steps, no login required)
For emails, this is usually an unsubscribe link at the bottom of the message. For SMS, it might be “Reply STOP to unsubscribe” (or a similar clear instruction).
Once someone unsubscribes, you need to stop sending them marketing messages. Keeping good records matters here (especially if you use multiple platforms).
Common Spam Act Compliance Traps For Small Businesses
Many businesses breach the Spam Act 2003 (Cth) without intending to. It often happens when marketing processes grow faster than compliance systems.
Here are some of the most common traps we see.
Buying Or Scraping Email Lists
Purchased lists and scraped contacts are high-risk. Even if the list seller says it’s “compliant” or “opt-in”, that doesn’t automatically mean you have consent to message those people.
If you can’t show that each recipient consented to receive marketing from your business specifically (or at least that consent clearly covers your type of marketing), you’re taking on risk.
Pre-Ticked Boxes And “Bundled” Consent
Consent should be real and informed. If your sign-up form uses pre-ticked boxes or bundles marketing consent into something unrelated, you could end up with shaky consent evidence.
A safer approach is a clear opt-in statement at the point of collection (and a separate checkbox where appropriate), aligned with how you’ll actually use the data.
This is also where your privacy compliance should match your marketing practice - your Privacy Policy should accurately describe how you collect and use personal information, including marketing communications where relevant.
Letting Contractors Or Agencies Send Messages Without Oversight
Outsourcing marketing can save time, but you still need guardrails.
At a minimum, you’ll want:
- clear written instructions on consent standards
- approval workflows for campaigns (especially for SMS)
- access to subscriber lists and suppression lists (unsubscribes)
- contract terms that allocate responsibility appropriately
If you’re engaging people to do marketing or customer outreach for you, it can help to formalise the relationship with a Consulting Agreement so expectations and compliance responsibilities are clear.
Mixing Transactional Messages With Promotions
Messages like appointment reminders, receipts, and delivery notifications are generally expected by customers.
However, if you add marketing content (for example, “By the way, here’s 15% off your next booking” or “Check out our new product line”), you may be turning a transactional message into a commercial electronic message - which means consent and unsubscribe rules matter.
Forgetting That SMS Marketing Is Covered Too
SMS marketing is one of the easiest ways to trigger complaints, because it feels more intrusive.
If you’re sending SMS offers, treat it as a high-compliance channel:
- get clear opt-in consent (and keep records)
- identify your business in the message
- include an unsubscribe option every time
How To Build A Practical Spam Act Compliance System (Without Overcomplicating It)
Compliance is much easier when you build it into your workflows. Here are practical steps you can implement now.
Step 1: Map Your Marketing Channels
Start by listing all the ways you send electronic messages to customers and leads, for example:
- email marketing platform (newsletters, automations)
- SMS platform
- CRM follow-ups
- booking software reminders
- direct outreach campaigns
This helps you see where consent is required, where unsubscribe needs to be configured, and where messages might be slipping through without proper checks.
Step 2: Standardise How You Collect Consent
Where possible, collect express consent in a consistent way. For example:
- online form checkbox: “I agree to receive marketing emails from .”
- checkout consent: clear opt-in for promotions (not bundled into purchase terms)
- in-person signups: written or digital sign-up with clear wording
Make sure your consent wording matches reality. If you plan to send both email and SMS, say so - and consider separate opt-ins so customers can choose.
Step 3: Keep Basic Consent Records
If a complaint ever arises, your best protection is being able to show what happened.
Keep records such as:
- date/time of signup
- source (website form, purchase, event signup)
- the wording shown at the time of consent
- the customer’s contact details as entered
Many marketing platforms record this automatically - but only if you set up forms properly and avoid manual list uploads without documentation.
Step 4: Make Unsubscribe And Suppression Lists “Central”
One practical risk is sending messages from multiple systems that don’t talk to each other.
For example, someone unsubscribes from your email marketing list but is still in your CRM outreach sequence. From the customer’s perspective, they unsubscribed - so continuing to send messages can lead to complaints.
Try to centralise unsubscribes, or at least ensure suppression lists are exported/imported across systems on a regular schedule.
Step 5: Review Your Templates For Identification Details
Check your templates (email and SMS) include the required information. For emails, this is usually in the footer. For SMS, you might need to use a recognisable business name early in the message due to character limits.
If you operate through a company, it can also be worth ensuring your wider customer-facing documentation is consistent - for example, your website terms and customer terms. Depending on your setup, Website Terms and Conditions can help set clear rules around communications, accounts, and acceptable use (though they don’t replace Spam Act compliance).
How The Spam Act 2003 (Cth) Interacts With Other Laws (Privacy, Consumer Law, And Contracts)
Spam compliance doesn’t sit in a vacuum. In practice, your marketing activities often touch other legal obligations too.
Privacy And Personal Information Handling
If you collect personal information (like names, email addresses, phone numbers, or behavioural data), you may have obligations under Australian privacy law as well.
Even if your business is not strictly required to comply with the Privacy Act 1988 (Cth) due to turnover thresholds, customers still expect good privacy practices - and many platforms you use may require it contractually.
A clear Privacy Policy is one of the simplest ways to explain:
- what personal information you collect
- how and why you collect it
- how you use it for marketing
- how customers can opt out or contact you
Australian Consumer Law And Marketing Claims
If your message includes promotional claims (like discounts, “limited time offers”, “best price”, “free trial”, or performance claims), you also need to ensure those claims are accurate and not misleading.
This is where the Australian Consumer Law (ACL) becomes relevant - your marketing should reflect what you actually offer, including any key conditions, fees, time limits, and exclusions.
For many small businesses, the risk isn’t just spam complaints - it’s also the compounding issue of making unclear or misleading promotional statements. Being transparent in marketing protects your brand and reduces disputes later.
Contracts With Marketing Providers And Staff
If staff members or contractors are responsible for outreach campaigns, make sure their role and limits are clear.
For example:
- who can approve a campaign
- what lists can be used
- how unsubscribes must be handled
- what training is required before someone sends messages
If you have employees who handle sales or marketing, a tailored Employment Contract can help clarify expectations, confidentiality, and how business systems (including customer data) must be used.
Key Takeaways
- The Spam Act 2003 (Cth) regulates commercial electronic messages such as marketing emails and SMS, and it applies to businesses of all sizes.
- To stay compliant, focus on the three core requirements: consent, identification, and a working unsubscribe option.
- Common compliance risks include buying email lists, relying on unclear “inferred consent”, and mixing promotions into transactional messages.
- Build compliance into your workflows by standardising consent collection, keeping basic consent records, and centralising unsubscribe/suppression lists across platforms.
- Spam compliance often overlaps with other legal areas like privacy and consumer law, so your marketing practices should align with your broader customer documentation and processes.
If you’d like help reviewing your marketing processes or putting the right legal documents in place for compliant customer communications, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.








