Spam Act 2003 (Cth): Australian Business Compliance Essentials

Alex Solo
byAlex Solo9 min read

If you run a business in Australia, chances are you rely on marketing to grow - email newsletters, SMS promotions, customer updates, and automated follow-ups are all common tools.

But there’s a legal line between “smart marketing” and spam. The Spam Act 2003 (Cth) sets the rules for commercial electronic messages, and it applies to businesses of all sizes (including small businesses and startups).

The good news is that compliance doesn’t have to be complicated. Once you understand the core requirements, you can put simple systems in place to reduce risk, avoid complaints, and build better trust with customers.

Below, we’ll walk you through what the Spam Act 2003 (Cth) is, when it applies, what you need to do to comply, and practical steps you can implement in your day-to-day marketing.

What Is The Spam Act 2003 (Cth) And Who Does It Apply To?

The Spam Act 2003 (Cth) is an Australian federal law that regulates commercial electronic messages. In plain terms, it’s designed to stop businesses (and individuals) from sending unsolicited marketing messages via certain digital channels.

It applies broadly - including to:

  • sole traders, companies, and partnerships
  • online businesses and eCommerce stores
  • service providers (tradies, agencies, consultants, clinics)
  • not-for-profits (where messages are “commercial” in nature)
  • anyone using third-party marketing platforms or agencies

Importantly, you can still be responsible even if you outsource marketing. If an agency or contractor sends messages “for your business”, you should treat that as your compliance risk too (which is why it’s worth having clear contracts and processes in place).

What Counts As A “Commercial Electronic Message”?

A message is likely to be a commercial electronic message if it has one of these purposes:

  • offering goods or services
  • promoting a business opportunity
  • advertising your business, brand, or supplier
  • directing someone to a website or landing page with a promotional angle

This can include:

  • marketing emails (newsletters, promo campaigns, abandoned cart emails)
  • SMS marketing messages
  • marketing messages sent through electronic messaging channels (for example, where a platform’s messaging function is used to send promotional content), depending on the circumstances

Some messages are more “transactional” (like receipts, delivery notifications, appointment reminders). These aren’t always treated the same way as marketing messages - but if you include promotional content, you may be sending a commercial electronic message (for example, adding a promotional banner and discount code).

The 3 Core Compliance Rules Under The Spam Act 2003 (Cth)

Most Spam Act compliance comes down to three practical rules. If you build your marketing processes around these, you’ll be in a much stronger position.

You generally need a customer’s consent before sending them commercial electronic messages.

Consent can be:

  • Express consent: the person actively agrees (for example, ticking a sign-up box, entering their email in a newsletter form, or choosing to receive SMS offers).
  • Inferred consent: consent is implied from the relationship and the person’s conduct (for example, an existing customer relationship where marketing messages are reasonably expected and relevant).

For small businesses, express consent is usually the safest and simplest approach - especially when you’re building email lists, running lead magnets, or collecting numbers at events.

Be careful with “inferred consent”. It can exist, but it’s not a blank cheque to market forever. You should still keep your messages relevant and give a clear unsubscribe option.

2. Identification (Be Clear About Who You Are)

Your message must clearly identify the business (or individual) who authorised sending it.

In practice, that means your marketing email or SMS should include accurate information like:

  • your business name (the name customers recognise)
  • ABN/ACN details where appropriate
  • contact details (email, phone, physical address, or other appropriate business contact method)

This is not just a legal requirement - it also helps deliverability and trust. If people can’t tell who you are, they’re more likely to report your message as spam.

3. Unsubscribe (Make It Easy To Opt Out)

You must include a functional unsubscribe facility in your commercial electronic messages.

Your unsubscribe must be:

  • clear (easy to find and understand)
  • functional (it actually works)
  • low friction (no unnecessary steps, no login required)

For emails, this is usually an unsubscribe link at the bottom of the message. For SMS, it might be “Reply STOP to unsubscribe” (or a similar clear instruction).

Once someone unsubscribes, you need to stop sending them marketing messages. Keeping good records matters here (especially if you use multiple platforms).

Common Spam Act Compliance Traps For Small Businesses

Many businesses breach the Spam Act 2003 (Cth) without intending to. It often happens when marketing processes grow faster than compliance systems.

Here are some of the most common traps we see.

Buying Or Scraping Email Lists

Purchased lists and scraped contacts are high-risk. Even if the list seller says it’s “compliant” or “opt-in”, that doesn’t automatically mean you have consent to message those people.

If you can’t show that each recipient consented to receive marketing from your business specifically (or at least that consent clearly covers your type of marketing), you’re taking on risk.

Consent should be real and informed. If your sign-up form uses pre-ticked boxes or bundles marketing consent into something unrelated, you could end up with shaky consent evidence.

A safer approach is a clear opt-in statement at the point of collection (and a separate checkbox where appropriate), aligned with how you’ll actually use the data.

This is also where your privacy compliance should match your marketing practice - your Privacy Policy should accurately describe how you collect and use personal information, including marketing communications where relevant.

Letting Contractors Or Agencies Send Messages Without Oversight

Outsourcing marketing can save time, but you still need guardrails.

At a minimum, you’ll want:

  • clear written instructions on consent standards
  • approval workflows for campaigns (especially for SMS)
  • access to subscriber lists and suppression lists (unsubscribes)
  • contract terms that allocate responsibility appropriately

If you’re engaging people to do marketing or customer outreach for you, it can help to formalise the relationship with a Consulting Agreement so expectations and compliance responsibilities are clear.

Mixing Transactional Messages With Promotions

Messages like appointment reminders, receipts, and delivery notifications are generally expected by customers.

However, if you add marketing content (for example, “By the way, here’s 15% off your next booking” or “Check out our new product line”), you may be turning a transactional message into a commercial electronic message - which means consent and unsubscribe rules matter.

Forgetting That SMS Marketing Is Covered Too

SMS marketing is one of the easiest ways to trigger complaints, because it feels more intrusive.

If you’re sending SMS offers, treat it as a high-compliance channel:

  • get clear opt-in consent (and keep records)
  • identify your business in the message
  • include an unsubscribe option every time

How To Build A Practical Spam Act Compliance System (Without Overcomplicating It)

Compliance is much easier when you build it into your workflows. Here are practical steps you can implement now.

Step 1: Map Your Marketing Channels

Start by listing all the ways you send electronic messages to customers and leads, for example:

  • email marketing platform (newsletters, automations)
  • SMS platform
  • CRM follow-ups
  • booking software reminders
  • direct outreach campaigns

This helps you see where consent is required, where unsubscribe needs to be configured, and where messages might be slipping through without proper checks.

Where possible, collect express consent in a consistent way. For example:

  • online form checkbox: “I agree to receive marketing emails from .”
  • checkout consent: clear opt-in for promotions (not bundled into purchase terms)
  • in-person signups: written or digital sign-up with clear wording

Make sure your consent wording matches reality. If you plan to send both email and SMS, say so - and consider separate opt-ins so customers can choose.

If a complaint ever arises, your best protection is being able to show what happened.

Keep records such as:

  • date/time of signup
  • source (website form, purchase, event signup)
  • the wording shown at the time of consent
  • the customer’s contact details as entered

Many marketing platforms record this automatically - but only if you set up forms properly and avoid manual list uploads without documentation.

Step 4: Make Unsubscribe And Suppression Lists “Central”

One practical risk is sending messages from multiple systems that don’t talk to each other.

For example, someone unsubscribes from your email marketing list but is still in your CRM outreach sequence. From the customer’s perspective, they unsubscribed - so continuing to send messages can lead to complaints.

Try to centralise unsubscribes, or at least ensure suppression lists are exported/imported across systems on a regular schedule.

Step 5: Review Your Templates For Identification Details

Check your templates (email and SMS) include the required information. For emails, this is usually in the footer. For SMS, you might need to use a recognisable business name early in the message due to character limits.

If you operate through a company, it can also be worth ensuring your wider customer-facing documentation is consistent - for example, your website terms and customer terms. Depending on your setup, Website Terms and Conditions can help set clear rules around communications, accounts, and acceptable use (though they don’t replace Spam Act compliance).

How The Spam Act 2003 (Cth) Interacts With Other Laws (Privacy, Consumer Law, And Contracts)

Spam compliance doesn’t sit in a vacuum. In practice, your marketing activities often touch other legal obligations too.

Privacy And Personal Information Handling

If you collect personal information (like names, email addresses, phone numbers, or behavioural data), you may have obligations under Australian privacy law as well.

Even if your business is not strictly required to comply with the Privacy Act 1988 (Cth) due to turnover thresholds, customers still expect good privacy practices - and many platforms you use may require it contractually.

A clear Privacy Policy is one of the simplest ways to explain:

  • what personal information you collect
  • how and why you collect it
  • how you use it for marketing
  • how customers can opt out or contact you

Australian Consumer Law And Marketing Claims

If your message includes promotional claims (like discounts, “limited time offers”, “best price”, “free trial”, or performance claims), you also need to ensure those claims are accurate and not misleading.

This is where the Australian Consumer Law (ACL) becomes relevant - your marketing should reflect what you actually offer, including any key conditions, fees, time limits, and exclusions.

For many small businesses, the risk isn’t just spam complaints - it’s also the compounding issue of making unclear or misleading promotional statements. Being transparent in marketing protects your brand and reduces disputes later.

Contracts With Marketing Providers And Staff

If staff members or contractors are responsible for outreach campaigns, make sure their role and limits are clear.

For example:

  • who can approve a campaign
  • what lists can be used
  • how unsubscribes must be handled
  • what training is required before someone sends messages

If you have employees who handle sales or marketing, a tailored Employment Contract can help clarify expectations, confidentiality, and how business systems (including customer data) must be used.

Key Takeaways

  • The Spam Act 2003 (Cth) regulates commercial electronic messages such as marketing emails and SMS, and it applies to businesses of all sizes.
  • To stay compliant, focus on the three core requirements: consent, identification, and a working unsubscribe option.
  • Common compliance risks include buying email lists, relying on unclear “inferred consent”, and mixing promotions into transactional messages.
  • Build compliance into your workflows by standardising consent collection, keeping basic consent records, and centralising unsubscribe/suppression lists across platforms.
  • Spam compliance often overlaps with other legal areas like privacy and consumer law, so your marketing practices should align with your broader customer documentation and processes.

If you’d like help reviewing your marketing processes or putting the right legal documents in place for compliant customer communications, you can reach us at 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo

Alex is Sprintlaw's co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Defences To Misleading And Deceptive Conduct For Australian Businesses

Defences To Misleading And Deceptive Conduct For Australian Businesses

Most business owners don’t set out to mislead anyone. You’re trying to sell your product or service, win customers, and stand out in a crowded market. But marketing moves fast, websites change...

9 Sept 2026
Read more
Can Your Business Use AI-Generated People In Advertising?

Can Your Business Use AI-Generated People In Advertising?

Using AI-generated people in ads can save time, but are you exposing your business to copyright, consent or misleading advertising risks?

8 Sept 2026
Read more
Invitation To Treat Examples: Practical Business Scenarios In Australia

Invitation To Treat Examples: Practical Business Scenarios In Australia

If you run a business, you probably “make offers” all the time - price lists, online listings, quotes, advertisements, and even stock displayed in your shop. But legally, not everything that looks...

2 Sept 2026
Read more
What Is IP Protection? A Practical Guide For Startups And Small Businesses

What Is IP Protection? A Practical Guide For Startups And Small Businesses

If you’re building a startup or small business, chances are you’re creating value that isn’t “physical” - your brand name, logo, product design, website content, code, marketing materials, and even the processes...

27 Aug 2026
Read more
Who Does Public Liability Insurance Cover?

Who Does Public Liability Insurance Cover?

If you run a small business, you’re probably juggling a lot at once: customers, staff, suppliers, rent, cash flow, marketing - and the constant pressure to keep things running smoothly. In the...

25 Aug 2026
Read more
Australian Affiliate Marketing: Legal Checklist & Setup Guide

Australian Affiliate Marketing: Legal Checklist & Setup Guide

Affiliate marketing can be a low-cost, scalable way to grow your sales - and it’s increasingly common for Australian small businesses to use affiliates, creators, publishers and partners to promote products and...

7 July 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.