Spam Act 2003 Australia: What Businesses Need to Know Before Sending Marketing Emails in 2026

If your business sends marketing emails to Australian customers, the Spam Act 2003 isn't optional reading; it's the law that decides whether your next campaign is a lead-generation win or a six-figure fine. The Australian Communications and Media Authority (ACMA) has spent the last few years ramping up enforcement, with penalties against household names like Sportsbet, Kogan, Woolworths, Uber, Telstra, and Tabcorp running into the millions of dollars. Heading into 2026, the rules haven't gotten any looser; if anything, ACMA is watching more closely than ever, and new SMS sender identification requirements are tightening the net further.
This guide breaks down exactly what the Spam Act 2003 requires, what's changed heading into 2026, and how to build an email marketing program that grows your list without growing your legal risk.
What Is the Spam Act 2003?
The Spam Act 2003 (Cth) is Australia's primary anti-spam legislation, in force since April 2004 and enforced by ACMA. It regulates commercial electronic messages (CEMs), a broad category that covers marketing emails, SMS, MMS, and instant messages that promote goods, services, land, or a business opportunity.
Crucially, the Act applies whenever there's an "Australian link." That means it covers messages sent from Australia, sent by an Australian business, or received by someone in Australia, so overseas companies emailing Australian customers are just as exposed as local businesses.
The Act is built around three core obligations. Miss any one of them and your email is non-compliant, even if you've nailed the other two.
The 3 Core Rules Every Business Must Follow
1. Consent
You can only send a commercial electronic message if the recipient has given consent either:
- Express consent: the person actively opted in (a signup form, a checkbox, a verbal agreement you've documented).
- Inferred consent there's an existing business or personal relationship, or the person has conspicuously published their business email address in a context that suggests they're open to being contacted about similar goods or services.
Buying a list, scraping emails from websites, or assuming silence equals consent are the fastest ways to breach this section, and it's the rule ACMA has prioritised most heavily in recent enforcement rounds.
2. Sender Identification
Every marketing email must clearly identify:
- The business or individual who authorised the message
- Accurate contact details (a valid email address, phone number, or postal address) that stay usable for at least 30 days after sending
Misleading "From" names, disguised sender identities, or dead contact details all breach this requirement.
3. A Functional Unsubscribe Facility
Every CEM needs a clear, working unsubscribe option, and requests must be processed promptly, generally within five business days. This is the single most common area ACMA flags in compliance alerts, because businesses often build the unsubscribe link but forget to test that it actually removes people from every list they're on.
What's Changed Heading Into 2026
SMS Sender ID Register. From 1 July 2026, businesses sending marketing SMS must register their Sender ID with their telco provider, part of a broader push to stop scammers impersonating trusted brands. If SMS is part of your marketing mix alongside email, this is a compliance step you can't skip.
Heavier, more frequent enforcement. ACMA's enforcement priorities have shifted from "educate first" to "penalise early," particularly around consent and unsubscribe failures. Recent multi-million-dollar penalties show that even a single non-compliant campaign, sent at scale, can trigger serious consequences.
"Any part of the message counts." Following the 2023 Ticketek case, ACMA confirmed that if even one element of a message, like a promotional banner inside an otherwise transactional email, has a commercial purpose, the entire message can be treated as a CEM and subject to the Act. Transactional emails (order confirmations, shipping updates, account notices) aren't automatically exempt if they carry marketing content.
How Much Can Non-Compliance Actually Cost?
Penalties under the Spam Act are calculated in Commonwealth penalty units, which are indexed periodically (the value increased to $364 per unit from 1 July 2026). In practical terms, that means:
- Individual contraventions can attract penalties in the hundreds of thousands of dollars per day
- Repeat or systemic breaches by a body corporate can reach into the millions of dollars per day
- ACMA can also issue infringement notices, accept enforceable undertakings (with independent monitoring and reporting obligations), and seek Federal Court injunctions
Recent enforcement history makes the scale of the risk clear: Commonwealth Bank agreed to a $7.5 million penalty, Sportsbet was hit with a record $2.5 million infringement notice plus roughly $1.2 million in required refunds, and Tabcorp faced a penalty of just over $4 million. These weren't obscure operators; they were large, resourced businesses that got the basics wrong.
A Practical Compliance Checklist for 2026
Before your next campaign goes out, run through this:
- Audit your list. Can you point to documented, timestamped consent (express or inferred) for every subscriber?
- Remove purchased or scraped lists. These rarely meet the consent bar under the Act.
- Check your sender identity. Does every email clearly name your business and provide live, valid contact details?
- Test your unsubscribe link regularly. Confirm it removes people from every list and automation you run, not just the one they clicked from.
- Review "transactional" emails for hidden promotion. If there's a banner, cross-sell, or offer inside it, treat it as a CEM.
- Register your SMS Sender ID with your telco if SMS is part of your marketing stack.
- Keep records. Opt-in timestamps, consent sources, and unsubscribe logs are your evidence if ACMA ever asks questions.
- Train whoever sends marketing messages, agencies, freelancers, and internal teams included. ACMA doesn't accept "our vendor sent it" as a defence.
Compliance Isn't a Reason to Stop Emailing; It's a Reason to Do It Properly
None of this means email marketing is off the table in Australia far from it. Email remains one of the highest-ROI channels available to businesses when it's built on genuine consent and clean data. Compliant lists convert better anyway: people who actively opted in are more engaged, less likely to mark you as spam, and more likely to become repeat customers.
This is exactly where a structured Email & Lifecycle Marketing program pays for itself proper opt-in flows, segmented automations, and unsubscribe handling built in from day one, on platforms like Klaviyo or HubSpot. If your current setup was built quickly and you're not sure it would hold up to an ACMA compliance alert, it's worth a proper audit before your next big send.
Getting the technical and legal foundations right also supports your broader digital marketing a clean, engaged list strengthens deliverability, which in turn protects your domain reputation for SEO and organic growth and any paid media retargeting audiences you build from your subscriber base.
Get Your Email Marketing Compliant and Converting
If you're unsure whether your current email program would survive an ACMA compliance check, book a free 30-minute audit with Onewebbie. We'll review your consent flows, sender setup, and unsubscribe process, and show you how a compliant, well-segmented email strategy can lift revenue not just reduce risk.