Email Marketing Compliance in Australia: A Small Business Guide

Email Marketing Compliance in Australia: A Small Business Guide
A Sydney café owner builds a customer list from loyalty sign-ups, sends a monthly newsletter, and gets a formal warning letter from the regulator. She didn't buy a list or spam strangers. She just never added an unsubscribe link that actually worked. This is the reality of email marketing laws Australia imposes: most breaches aren't malicious, they're administrative oversights that carry real financial risk. If you're running campaigns through Mailchimp, Klaviyo or straight from your CRM, the Spam Act 2003 applies to you whether you've read it or not.
Is email marketing still worth it for small businesses in Australia?
Yes, and by a wide margin. Email remains one of the highest-return channels available to small operators, provided the list is built and managed the right way. The problem isn't the channel, it's that too many owners treat compliance as optional paperwork rather than the thing that keeps the channel usable.
Compare that to paid channels, where every click costs money regardless of outcome. Email, once you own the list, is close to free per send. The catch is that owning the list the wrong way, through purchased contacts or vague opt-ins, exposes you to penalties that can wipe out months of marketing budget in one enforcement action. Compliance isn't a brake on email marketing. It's what makes the channel sustainable rather than a liability waiting to surface.
What does the Spam Act 2003 actually require?
The Spam Act 2003 requires three things for every commercial electronic message: consent from the recipient, clear identification of who sent it, and a working way to unsubscribe. Miss any one of these and the message counts as spam under Australian law, regardless of how relevant the content is.
The Act covers email, SMS and instant messaging, and it applies to any business sending commercial messages to Australian recipients, not just Australian-registered companies. The Australian Communications and Media Authority, which enforces the Act, states in its "Avoid sending spam" guidance that consent can be express or reasonably inferred, but it must exist before you send, not after someone complains. That distinction trips up a lot of small business owners who assume a general privacy policy on their website counts as consent. It doesn't.
Express vs inferred consent
Express consent is a direct yes: a customer ticks a box, fills in a sign-up form, or replies "subscribe" to a text asking permission. Inferred consent is murkier. It applies when someone has an existing business relationship with you and would reasonably expect to hear from you by email, such as a client who bought a service from you in the last 12 months.
Inferred consent doesn't stretch as far as most owners think. A person who enquired about your services but never bought anything is a much weaker case for inferred consent than an active customer. Trade show business cards, LinkedIn connections and old supplier contacts don't qualify at all. If you're building a database from networking events, you need express consent before that first marketing email goes out, not a hope that nobody complains. When in doubt, ask. A short follow-up email asking someone to confirm they want to hear from you is cheap insurance against a much larger problem later.
What must every marketing email include?
Every marketing email must clearly identify your business, include accurate contact details, and provide a functional unsubscribe link that processes requests within five business days. These three elements are non-negotiable under the Spam Act, and all three need to work in practice, not just exist in theory.
Identification means your actual trading name, not a generic "no-reply" address that gives no clue who sent the message. Contact details need to be genuine, meaning a real email address or phone number the recipient can use to reach you, not a dead mailbox. The unsubscribe function is where most small businesses fall down. It has to work the first time, without requiring a login, a phone call, or a multi-step form. Sprintlaw's Spam Act compliance guide notes that unsubscribe requests must be actioned promptly and that continuing to email someone after they've opted out is treated as a fresh breach, separate from whatever led to the unsubscribe in the first place.
Penalties for getting it wrong
The Spam Act 2003 allows for penalties up to $220,000 per day for corporations that breach its provisions, with the figure varying based on the size and history of the offending business. The Australian Communications and Media Authority can also issue formal warnings, infringement notices and enforceable undertakings well before a matter reaches that ceiling.
In practice, small businesses rarely see the maximum figure applied on a first offence. What actually happens is more mundane and still costly: a warning letter, a required compliance plan, and reputational damage if the complaint becomes public. Repeat or wilful breaches are where the larger fines get applied. The bigger risk for most Sydney SMBs isn't the theoretical maximum penalty, it's the operational cost of pausing campaigns, auditing an entire list retroactively, and rebuilding trust with subscribers who received emails they never agreed to.
Building a compliant list from scratch
If your current list has gaps in consent records, the safest move is a re-permission campaign: send one email asking existing contacts to actively confirm they want to keep hearing from you, and remove everyone who doesn't respond. This clears out the ambiguous inferred-consent contacts and gives you a smaller but fully compliant list to work from.
From there, every new sign-up form should capture the date, time and method of consent, stored somewhere you can retrieve it if a complaint ever comes in. Double opt-in, where a subscriber confirms via a follow-up email, adds friction but gives you the strongest possible evidence of express consent. It also tends to produce a more engaged list, since people who confirm twice are more likely to open what you send. If your website itself isn't converting these sign-ups into real leads in the first place, it's worth fixing that layer before scaling your list, since a compliant list built slowly from a strong site beats a large list built from thin consent.
Common questions
Does the Spam Act apply to B2B emails?
Yes. The Spam Act 2003 applies to commercial electronic messages regardless of whether the recipient is a business or a consumer. The only exemptions relate to specific categories like government bodies, registered charities and factual information updates, not the B2B versus B2C distinction many business owners assume exists.
Can I email a list I bought from a third party?
Generally no, unless you can prove every contact on that list gave express consent to receive marketing from your specific business. Most purchased lists fail this test immediately, which makes sending to them a straightforward Spam Act breach rather than a grey area.
How long does inferred consent last?
There's no fixed legal expiry, but the Australian Communications and Media Authority treats inferred consent as tied to an active or recent relationship. A customer who hasn't engaged with your business in two or three years is a weak case for inferred consent, and refreshing that consent explicitly is the safer path.
Email marketing pays off when the list behind it is clean, consenting and properly documented. Run a quick audit of your current sign-up forms and unsubscribe process this week, before your next send goes out, and treat compliance as part of the campaign rather than an afterthought. If your broader lead generation setup needs a look as well, our guide on Google Ads budgets covers how to make sure paid traffic feeds a list worth emailing in the first place.




