Spam Act 2003: The Complete Compliance Guide

Australia's Spam Act 2003 is a strict opt-in regime enforced by ACMA. Prior consent required for every CEM, sender identification mandatory, functional unsubscribe processed within 5 business days. Complete 2026 compliance guide covering per-day penalty structure up to AUD 3.13M, express vs inferred consent, and recent enforcement including Commonwealth Bank's AUD 7.5M penalty.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
10 min read Updated Sep 18, 2026 350 views

Australia’s Spam Act 2003 is a strict opt-in regime enforced by the Australian Communications and Media Authority (ACMA). It requires prior consent for every commercial electronic message (CEM), clear sender identification in the body, and a functional unsubscribe processed within 5 business days. Penalties are capped by day of contravening conduct, not by message count, and the ceiling reaches AUD 3.64 million for a single day for a corporation already found in contravention. ACMA has issued more than AUD 20 million in fines since 2020, with Commonwealth Bank’s AUD 7.5 million penalty the largest to date.

Spam Act 2003 (Cth) · Act No. 129 of 2003 · In force since 10 April 2004 · Enforced by the Australian Communications and Media Authority (ACMA) · Applies to every commercial electronic message with an Australian link, sent from Australia or accessed on an Australian device · Maximum penalties set by section 25: 10,000 penalty units for all contraventions committed on one day by a corporation already found in contravention (approximately AUD 3.64M), and 2,000 penalty units in the same situation for an individual (approximately AUD 728,000), at the penalty unit value of AUD 364 in force from 1 July 2026.

2003
Enacted 2003, commenced 10 April 2004 across all Australian jurisdictions
$3.64M
Highest single-day corporate cap (AUD, 10,000 penalty units, repeat offender)
5 days
Maximum time to honour an unsubscribe request under ACMA guidance
$7.5M
Commonwealth Bank of Australia penalty, largest single Spam Act fine to date

The three requirements

The Spam Act imposes three cumulative obligations on every CEM. Miss any one and the message is non-compliant even if the other two are correctly implemented.

  • Consent. Express consent (documented opt-in) or inferred consent (existing business or personal relationship, or conspicuously published business address for a role-relevant message).
  • Identify. The message must clearly identify the sender’s individual or business name and provide accurate contact information (mailing address, phone, or website URL) valid for at least 30 days after the send.
  • Unsubscribe. A functional, low-friction unsubscribe facility valid for at least 30 days after the send, honoured within 5 business days per ACMA’s Standard.
The three cumulative Spam Act requirements for every commercial electronic message Every commercial electronic message must clear three requirements at once. Consent: express, a documented opt-in, or inferred from an existing business or personal relationship or a conspicuously published business address for a role-relevant message. Identify: the sender’s individual or business name plus accurate contact details, a mailing address, phone or website URL, valid for at least thirty days after the send. Unsubscribe: a functional, low-friction facility, also valid for at least thirty days after the send, and honoured within five business days under ACMA’s Standard. The three are cumulative, so missing one makes the message non-compliant even when the other two are correctly implemented. Designated commercial electronic messages, factual-information-only messages from government, registered political parties, religious organisations, charities or educational institutions, are exempt from the consent and unsubscribe requirements only. Three requirements, all three at once Every commercial electronic message with an Australian link has to clear all three. REQUIREMENT 1 Consent Express: documented opt-in, valid until withdrawn. Inferred: existing business or personal relationship, or a published business address for a role-relevant message. REQUIREMENT 2 Identify The sender’s individual or business name, plus accurate contact details: mailing address, phone or website. Valid 30 days after the send REQUIREMENT 3 Unsubscribe A functional, low-friction facility in the message. Valid 30 days after the send Honoured within 5 business days (ACMA Standard) + + Cumulative: miss one and the message is non-compliant, even if the other two are right. Narrow exemption: designated commercial electronic messages Factual information only, from government, a political party, a religion, a charity or an educational body: no consent and no unsubscribe required.
Consent, identification and unsubscribe apply together to every CEM. The designated-CEM exemption lifts only the first and the third, and only for factual-information-only messages from an exempt class of sender.
Express consent
Documented opt-in
Signup form, checkbox (unticked by default), or written request from the recipient. Store timestamp, source, and consent language for every subscriber. Valid until withdrawn.
Inferred consent
Business or personal relationship
Existing customer relationship, membership, employment, or ongoing business dealing. Also covers conspicuously published business addresses for role-relevant messages, provided no do-not-contact notice was posted.
Designated CEMs
Limited exemption
Factual-information-only messages from government, registered political parties, religious organisations, charities, or educational institutions are exempt from consent and unsubscribe requirements, provided they carry no promotional content.

Who must comply

The Spam Act uses an “Australian link” test rather than a strict location test. A CEM is in scope if it originates in Australia, is sent from an account, service, or device located in Australia, or is accessed on a computer, mobile, or other device located in Australia. Foreign senders emailing Australian recipients are within scope regardless of where the sender is based; Federal Court proceedings against foreign entities are viable under Australia’s extraterritorial jurisdiction.

The Act covers email, SMS, MMS, and instant messages. B2B messages are in scope in exactly the same way as B2C; there is no business-to-business exemption. Directors and officers can be held personally liable under section 16(9), and vicarious liability extends to employers for employee conduct.

Penalties and enforcement

Per-day, not per-message. Section 25 caps civil penalties by day of contravening conduct, and the cap does not move with message volume. What moves it is who sent the message and whether they have been found in contravention before. A corporation with no prior finding faces up to 100 penalty units for a single contravention of section 16(1), (6) or (9), and up to 2,000 penalty units for everything it sent that day (approximately AUD 728,000). A corporation already found in contravention faces 500 penalty units for a single contravention and 10,000 for the day (approximately AUD 3.64M). Individuals sit at exactly one fifth of those figures, and contraventions of the identification and unsubscribe provisions at exactly half. Enforcement has intensified since 2020: Commonwealth Bank AUD 7.5M (2023) plus AUD 3.55M (2022), Sportsbet AUD 2.5M (2024, largest infringement notice), Latitude Finance AUD 1.55M (2022), Ticketek, Woolworths, Uber, Kogan (AUD 310,800, 2021), and Telstra AUD 626,000 for self-reported breaches. ACMA received 5,700+ consumer complaints in Q1 2025 alone.

Spam Act penalties ACMA has actually imposed, in Australian dollars Horizontal bars comparing the penalties named in this guide, in Australian dollars. Commonwealth Bank 7.5 million in 2023 and 3.55 million in 2022; Sportsbet 2.5 million in 2024, the largest infringement notice; Latitude Finance 1.55 million in 2022; Telstra 626,000 for self-reported breaches; Kogan 310,800 in 2021. A dashed line marks 3.64 million dollars, the highest amount a corporation can be penalised for a single day of contravening conduct, which only the largest penalty exceeds. More than 20 million dollars in total has been issued since 2020, and Ticketek, Woolworths and Uber have also been penalised. What ACMA has actually charged, in Australian dollars The penalties named in this guide, largest first. $3.64M: highest one-day cap Commonwealth Bank 2023 $7.5M Commonwealth Bank 2022 $3.55M Sportsbet 2024 $2.5M Latitude Finance 2022 $1.55M Telstra $626,000 Kogan 2021 $310,800 Penalties run per day of contravening conduct, not per message. More than $20M issued since 2020; Ticketek, Woolworths and Uber were also penalised.
The largest penalty sits above the ceiling for a single day, which is what a per-day calculation produces when contravening conduct runs across many days.

Compliance checklist

  • Document consent source, timestamp, and exact language for every Australian subscriber
  • Refresh inferred consent against the relationship context regularly, if the business relationship has ended, revert to express consent
  • Include sender name, current business address, and one working contact channel in every CEM
  • Provide a prominent unsubscribe link processed within 5 business days, valid for at least 30 days after each send
  • Maintain a suppression list shared across all campaigns, subsidiaries, and third-party senders acting on your behalf
  • Audit list origin before importing purchased, rented, or third-party contacts, if you cannot document consent, purge before sending
  • Review outbound flow after any product launch or acquisition: legacy consents may not extend to the new context

Common misconceptions

“B2B email is exempt.” No. The Spam Act does not carve out B2B communications. Cold prospecting to Australian companies requires express or inferred consent, and inferred consent requires more than just a published address, the message must be relevant to the recipient’s role and no do-not-contact notice must be posted.

“Ten business days matches CAN-SPAM.” No. ACMA’s compliance guidance requires processing unsubscribe requests within 5 business days, not 10. This is a common trap for US-based senders operating a shared marketing stack.

“Adding factual content makes it exempt.” No. The designated commercial electronic message exemption is narrow: the message must contain factual information only, from a specific class of exempt sender (government, charity, political party, religion, or educational institution). Adding a link to a product page pulls the whole message back into standard scope.

“Penalties only hit banks and telcos.” No. Retail (Kogan, Woolworths), gambling (Sportsbet), finance (Latitude), and ticketing (Ticketek) have all been fined. The current ACMA priorities target volume offenders and unsubscribe failures, regardless of sector.

Frequently asked questions

Does the Spam Act apply to foreign senders?

Yes, under the “Australian link” test in section 7. A CEM sent from anywhere in the world is in scope if it is accessed on a device located in Australia. Federal Court proceedings against foreign entities are viable, and ACMA has cooperated with overseas regulators on cross-border cases.

How long does consent last?

Express consent is valid until the recipient withdraws it. Inferred consent based on an existing business or personal relationship stays valid while the relationship continues; ACMA has taken the view that a “reasonable time” after a transaction is generally considered to be around two years, but this is fact-dependent. Conspicuously-published-business-address consent lasts until the address is withdrawn or a do-not-contact notice is posted.

What are penalty units and how do they convert to dollars?

A Commonwealth penalty unit is the base measure for federal fines, indexed periodically; the value is AUD 364 from 1 July 2026. The maxima sit in section 25, not section 24: section 24 is the power to order a pecuniary penalty, section 25 is the table of ceilings. That table scales on two axes, body corporate or not, and previously found in contravention or not. For a contravention of section 16(1), (6) or (9), a single contravention is capped at 20 penalty units for an individual and 100 for a corporation with no prior finding, rising to 100 and 500 once there is one; everything sent on the same day is capped at 400, 2,000, 2,000 and 10,000 respectively. Contraventions of the identification and unsubscribe provisions are capped at half those figures.

Do transactional emails need to comply?

Purely transactional messages (order confirmations, receipts, account updates, service disruption notices) are generally not commercial electronic messages under the Spam Act because they lack a commercial purpose. Adding promotional content, cross-sell offers, or upsell links converts the whole message into a CEM subject to full consent, identification, and unsubscribe requirements.

How does the Spam Act interact with the Privacy Act 1988?

The Spam Act governs the sending of CEMs; the Privacy Act governs collection, use, and disclosure of personal information (including email addresses) by organisations meeting the Australian Privacy Principles threshold. Both apply simultaneously. The Office of the Australian Information Commissioner (OAIC) handles Privacy Act complaints; ACMA handles Spam Act complaints. A single incident (for example, unauthorised marketing to an existing customer list) can trigger parallel proceedings under both regimes.

Where to go next

Sending to an Australian list? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate ACMA complaints from recipients who never gave valid consent. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.


About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.