Skip to main content
Rules Mate

The marketing consent stack: how the Spam Act, the Australian Privacy Principles and the Do Not Call Register interact

Rules Mate Editorial8 min read

Three separate regimes govern Australian direct marketing. Which one applies to which channel, how APP 7.8 carves them apart, and the consent record that satisfies all three.

Three regimes, one campaign

Australian direct marketing is governed by three separate statutes with two regulators, and a single campaign can breach all three. The Spam Act 2003 governs commercial electronic messages and the Do Not Call Register Act 2006 governs telemarketing and marketing faxes to registered numbers — both administered by the Australian Communications and Media Authority. Australian Privacy Principle 7, under the Privacy Act 1988, governs the use and disclosure of personal information for direct marketing and is administered by the Office of the Australian Information Commissioner.

They are not alternatives, and each has its own consent concept, its own exemptions and its own evidentiary burden. A business cannot run one consent flag across every channel and assume it holds up — the flag that satisfies the Spam Act for email does not by itself satisfy the Do Not Call Register Act for a phone call.

This article is about how the three fit together. For the detail of each, see the Spam Act rules, the Do Not Call Register obligations and APP 7 direct marketing.

Which regime governs which channel

ChannelPrimary regimeRegulatorAlso engaged
EmailSpam Act 2003ACMAPrivacy Act (collection, security, source disclosure)
SMS and MMSSpam Act 2003ACMAPrivacy Act
Instant messagingSpam Act 2003ACMAPrivacy Act
Voice telemarketingDo Not Call Register Act 2006ACMAPrivacy Act
Marketing faxDo Not Call Register Act 2006ACMAPrivacy Act
PostAPP 7OAIC
Targeted online advertising using customer listsAPP 6 and APP 7OAIC

Two boundaries are misread often. Section 5(5) of the Spam Act expressly excludes voice calls, and the Do Not Call Register does not reach email or SMS. Postal marketing sits outside both ACMA regimes and is governed by APP 7 alone, which is why direct mail programs frequently carry weaker consent documentation than email programs despite the same privacy obligations.

The Spam Act layer

The Spam Act 2003 imposes three requirements on every commercial electronic message with an Australian link: send only with consent (section 16), identify the sender accurately (section 17), and provide a functional unsubscribe (section 18).

Consent may be express or inferred, and ACMA is direct about the burden: it is up to the business to prove it. Inferred consent is narrow. Schedule 2 provides that consent may not be inferred from the mere fact an address has been published, and the limited exception for a conspicuously published work address falls away if the publication carries a statement that unsolicited commercial messages are not wanted — and the message must be relevant to that person's work-related functions. Buying a list, or treating a business card as consent for an unrelated product, sits outside all of that.

Identification requires the message to clearly and accurately identify the individual or organisation that authorised it, with accurate contact information reasonably likely to remain valid for at least 30 days after sending. A campaign sent shortly before a rebrand can become non-compliant after it lands.

Unsubscribe must be functional and low-friction, and the unsubscribe address must be capable of receiving messages for at least 30 days after the message is sent. ACMA is explicit that the option must not require the person to give extra personal information or to log in to, or create, an account. Withdrawal of consent takes effect at the end of five business days, so marketing must stop within that window.

Designated commercial electronic messages — certain messages from government bodies, registered political parties, religious organisations, charities and educational institutions, and messages of no more than factual information — are exempt from sections 16 and 18 but not from section 17. Reduced obligations, not none.

The Do Not Call Register layer

The Do Not Call Register Act 2006 makes it unlawful to make a telemarketing call, or send a marketing fax, to a registered Australian number unless it is a designated call or consent applies. Registration is open to numbers used primarily for private or domestic purposes, numbers used exclusively for faxes, government numbers and emergency service numbers.

The compliance mechanic is washing. The defence in section 11(3) requires the number to have been on a list submitted to the register and, during the 30-day period ending at the end of the day the call was made, not reported as registered. Section 12B(3) applies the same window to marketing faxes. A wash older than 30 days is no defence.

Consent overrides registration, which is why consent records must be channel-specific and retrievable per number — and the Act's consent rules are stricter than the Spam Act's, since consent may not be inferred from the mere publication of an Australian number, with no conspicuous-publication carve-out.

The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 then governs the calls that are permitted. Section 8 sets prohibited calling times:

Call typeWeekdaysSaturdaySundayNational public holidays
Telemarketing9am to 8pm9am to 5pmProhibitedProhibited
Research9am to 8.30pm9am to 5pm9am to 5pmProhibited

Times are those at the account-holder's usual residential address, and the only exception is express advance consent for that day and time. The Standard also prescribes what a caller must disclose at the start of a call and requires immediate termination on request.

The APP 7 layer and the carve-out in APP 7.8

APP 7.1 states the general rule: an organisation must not use or disclose personal information it holds for the purpose of direct marketing unless an exception applies.

The exceptions do most of the work. Under APP 7.2, an organisation may use personal information for direct marketing where it collected the information from the individual, the individual would reasonably expect it to be used that way, and a simple opt-out is provided. The reasonable-expectation test is objective, which is why the collection notice under APP 5 matters so much: it shapes what the individual could reasonably have expected. Under APP 7.3, where the information came from a third party or the individual would not reasonably expect the use, the organisation needs consent or it must be impracticable to obtain consent, and each communication must carry a prominent opt-out statement. APP 7.4 requires consent where sensitive information is used, with no reasonable-expectation shortcut. APP 7.6 and 7.7 let individuals ask not to receive direct marketing and ask the organisation to identify the source, to be given effect within a reasonable period — which the OAIC says would generally be no more than 30 days — and free of charge.

The interaction rule is APP 7.8. The OAIC's APP 7 guidelines state that "APP 7 does not apply to the extent that the Do Not Call Register Act 2006, the Spam Act 2003 or any other legislation prescribed by the regulations apply."

Read that carefully: it is a partial carve-out, not a safe harbour. Where the Spam Act governs a message, APP 7 steps back to that extent — but every Privacy Act obligation outside APP 7 keeps running. Collection of the address is still governed by APP 3 and APP 5, its security by APP 11. Compliance with the Spam Act does not immunise the underlying data practice.

The consent record that satisfies all three

Because the burden of proving consent sits with the business under both ACMA regimes, and because APP 7 turns on what the individual could reasonably have expected, the artefact that resolves all three is a per-individual consent record with six fields:

  • The identifier consented for — the specific address or number, not just a person record.
  • The channels consented to, recorded separately. Email consent is not call consent.
  • The exact versioned wording of the consent statement and collection notice, so you can reproduce what the individual saw.
  • When and how consent was given — timestamp and source, whether a form, a checkout, an in-store capture or a third party.
  • Express or inferred, and where inferred, the relationship relied on.
  • Withdrawal, with its timestamp and the channel it applies to.

Two failure modes recur in enforcement. The first is an unsubscribe suppressed in one system and not another, so a person who opted out of a newsletter keeps receiving promotional messages from a different platform. The second is a list acquired through an acquisition or co-registration deal, where the acquirer cannot reproduce the consent wording the individual originally saw and therefore cannot prove consent at all.

Run the marketing compliance check against a live campaign rather than a policy, and treat any list you cannot trace back to a wording version as unconsented.

What enforcement has actually cost

ACMA enforces the Spam Act and the Do Not Call Register Act through Federal Court proceedings, infringement notices, formal warnings and court-enforceable undertakings. Two outcomes against the same operator show the scale and the pattern (checked August 2026):

  • In June 2025 Tabcorp Holdings paid $4,003,270 after ACMA found it sent 2,598 messages with no unsubscribe option, 3,148 with inadequate sender information, and 11 without consent, and gave a three-year court-enforceable undertaking.
  • In July 2026 the same operator paid a further $2.7 million over telemarketing and spam breaches — 351 calls to numbers on the Do Not Call Register without consent, 82 calls made outside permitted hours, and around 4,000 calls without proper caller identification — plus self-reported marketing to unsubscribed customers.

In that second media release ACMA noted that businesses had paid more than $12 million in penalties for spam and telemarketing breaches over the preceding 18 months.

Maximum penalties under the Spam Act sit in section 25, expressed in penalty units per day. A body corporate with no prior court finding faces up to 2,000 penalty units for two or more contraventions of section 16 in a single day; one with a prior finding faces up to 10,000. Those unit counts have not changed since 2003 — what has grown is the unit value, which rose to $364 on 1 July 2026, making the daily maxima $728,000 and $3,640,000. Any dollar figure published earlier understates current exposure, so use the penalty estimator with the current unit value.

None of these outcomes turned on a novel legal question. They turned on unsubscribe plumbing, list hygiene, calling windows and caller identification — operational controls, not legal interpretation.

Frequently asked

Does complying with the Spam Act mean we have satisfied our privacy obligations?

No. APP 7.8 provides that APP 7 does not apply to the extent that the Spam Act 2003 or the Do Not Call Register Act 2006 applies, but that is a partial carve-out from APP 7 only. Every other Privacy Act obligation continues to run: the collection of the address remains governed by APP 3 and the notification requirements of APP 5, security by APP 11, and access and correction by APPs 12 and 13. Spam Act compliance does not validate the underlying data practice.

Does the Spam Act cover telemarketing calls?

No. The Spam Act 2003 covers commercial electronic messages — email, SMS, MMS and instant messaging. Voice calls and marketing faxes fall under the Do Not Call Register Act 2006 and the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017. Postal marketing falls under neither and is governed by APP 7 alone, which is why direct mail programs often carry weaker consent documentation than email programs despite the same privacy obligations applying.

How quickly must we action an unsubscribe request?

ACMA's guidance for business states that a business must generally stop sending marketing within five business days of an unsubscribe request. The unsubscribe facility itself must be functional and low-friction — ACMA is explicit that it must not require the person to provide extra personal information or to log in to, or create, an account. Sender identification details must also remain correct for at least 30 days after a message is sent.

Can we call a number on the Do Not Call Register if the person is our customer?

Only if you hold consent for calls to that number, or an exemption applies to your organisation or to the type of call. Consent overrides registration, which is why consent records must be channel-specific and retrievable per number rather than held as a single flag on a customer record. An existing commercial relationship does not by itself create consent to be called, and the business carries the burden of proving the consent it relies on.

What should a compliant marketing consent record contain?

Six fields, per individual: the specific identifier consented for (the email address or number, not just the person); the channels consented to, recorded separately; the exact versioned wording of the consent statement and collection notice the individual saw; the timestamp and source of the consent; whether the consent was express or inferred, and the relationship relied on where inferred; and any withdrawal with its timestamp and channel. A list that cannot be traced back to a wording version should be treated as unconsented.

Related

Related reading