Skip to main content
Rules Mate

Who must comply with APP 7 direct marketing: consent, opt-out & when you can't message (2026)?

The applicability test for APP 7 direct marketing: consent, opt-out & when you can't message (2026) (OAIC), computed across 35 industries, 9 business structures and 6 size bands.

Short answer: Some businesses

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and consumer customers.

What the obligation is

APP 7 restricts using or disclosing personal information for direct marketing and requires a simple opt-out — when it applies, the exceptions and penalties.

APP 7 of the Privacy Act restricts use of personal information for direct marketing. Mandatory opt-out + handling of requests to opt out; simplified consent regime for personal info collected directly.

The applicability test

Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and consumer customers.

How the regulator frames it: APP entities engaged in direct marketing.

What triggers it: Using personal info for direct marketing.

Jurisdiction: Commonwealth law, so the test is the same in every state and territory.

Which industries are in or out

Outcome across the 35 industries Rules Mate maps (11 of 35: yes; 24 of 35: depends on size or structure).

IndustryAnswer
Real estate agentsYes
Accountants & bookkeepersYes
Lawyers & solicitorsYes
ConveyancersYes
Trust & company service providersYes
Precious metals & stones dealersYes
Banks & ADIsYes
Aged care providersYes
NDIS providersYes
Health practitionersYes
Gambling & wageringYes
Fintech (non-bank)Depends on size or structure
General insurersDepends on size or structure
Superannuation trusteesDepends on size or structure
Credit licensees & mortgage brokersDepends on size or structure
Medical devices & therapeutic goodsDepends on size or structure
Private health insurersDepends on size or structure
Cafés & restaurantsDepends on size or structure
Hotels, pubs & licensed venuesDepends on size or structure
Retail tradeDepends on size or structure
E-commerce & online retailDepends on size or structure
Construction (residential & commercial)Depends on size or structure
ManufacturingDepends on size or structure
Agriculture, forestry & fishingDepends on size or structure
Mining & resourcesDepends on size or structure
Road transport & logisticsDepends on size or structure
Aviation (incl. drones)Depends on size or structure
Maritime & portsDepends on size or structure
Education — registered training orgsDepends on size or structure
Education — higher education providersDepends on size or structure
Software & SaaSDepends on size or structure
Professional services (general)Depends on size or structure
Charities & not-for-profitsDepends on size or structure
Telecommunications carriers / CSPsDepends on size or structure
Media & publishingDepends on size or structure

Business structure and size

Structure does not change the answer across all industries: for every structure the answer is "depends on size or structure".

Size bandAnswer across all industries, any structure
No employees (turnover $100K–$1M)Depends on size or structure
1–5 employees (turnover $100K–$1M)Depends on size or structure
6–19 employees (turnover $1M–$3M)Depends on size or structure
20–99 employees (turnover $3M–$10M)Yes
100–499 employees (turnover $10M–$100M)Yes
500+ employees (turnover $100M–$1B)Yes

Worked examples

Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:

  • Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: applies. AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)) · Sells to consumers.
  • Pty Ltd company in fintech (non-bank) with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out) and consumer customers.

Answers that bring it into scope

Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:

  • The business deals in crypto-assets or runs a digital currency exchange: it then applies (AML/CTF reporting entity — covered by the Privacy Act for AML/CTF activities (s 6E(1A)) · Sells to consumers).
  • The business is a registered NDIS provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b)) · Sells to consumers).
  • The business is an approved aged care provider: it then applies (provides a health service and holds health information — not covered by the small business exemption (Privacy Act s 6D(4)(b)) · Sells to consumers).
  • The business supplies government customers: it then applies (government customer — contracted service providers to the Commonwealth are covered (Privacy Act s 6D(4)(e)) · Sells to consumers).

What you must do, and when

When due
Continuous.
Frequency
Ongoing
Evidence to keep
Consent records; opt-out mechanism + register; marketing-list audit trail.
Status
Current
Priority
High

Penalty for not complying

Maximum penalty: Same penalty regime as other Privacy Act breaches; $50M / 30% turnover max.

Audit or assurance level

Self-assessment. Authority: Privacy Act 1988 (Cth) ss6D, 33C, Sch 1 APP 1; OAIC Guide to privacy regulatory action Ch 9.

Frequency: Ongoing. No mandated periodic audit. APP 1 requires an up-to-date privacy policy and reasonable practices and procedures.

Who can perform it: The entity itself. The OAIC may conduct a privacy assessment (s33C) at its discretion and can compel documents; you cannot commission an OAIC assessment as an audit.

What usually applies alongside it

Where it sits in the corpus

Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.

Regulator, legislation and tools

Regulated by Office of the Australian Information Commissioner.

OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.

Privacy Act 1988: Federal privacy Act.

Free tools that help with this obligation:

Questions

Who must comply with APP 7 direct marketing: consent, opt-out & when you can't message (2026)?
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and consumer customers.
Does APP 7 direct marketing: consent, opt-out & when you can't message (2026) apply to sole traders?
Depends on size or structure. Across every industry and every size band, the engine's answer for a sole trader is: depends on size or structure.
Does APP 7 direct marketing: consent, opt-out & when you can't message (2026) apply to businesses with 1–5 employees?
Depends on size or structure (1–5 employees, turnover $100K–$1M).
When is "APP 7 direct marketing: consent, opt-out & when you can't message (2026)" due?
Continuous.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.