Why Australian marketing compliance is two laws, not one
Australia regulates commercial electronic messages under the Spam Act 2003, enforced by the Australian Communications and Media Authority (ACMA) — every message needs valid consent, clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days. Separately, the Privacy Act 1988's Australian Privacy Principle 7 (APP 7), enforced by the OAIC, governs using personal information for direct marketing at all — including a materially higher consent bar for sensitive information (health, political, religious, sexual orientation) and rules on data that arrived via a third party.
This self-check walks your actual message through the risk areas that most often trip up Australian marketing sends, flags the specific phrase (or missing element) that triggered each one, explains which rule it touches, and suggests a compliant fix. It's the same discipline our Australia team applies when building campaigns for AU clients — see our Australia social media marketing page for the full strategy layer.
What this checker looks for
6 rule categories, drawn from the sources cited below — each one covers a specific pattern our checker scans your pasted text for:
- Missing sender identification — Spam Act 2003 section 17(1) requires that a commercial electronic message with an Australian link must clearly and accurately identify the individual or organisation who authorised the sending of the message, include accurate contact information, and that information must comply with any conditions in the regulations and be reasonably likely to be valid for at least 30 days after the message is sent. This check only fires once there's substantial pasted text to judge (an empty box isn't "missing sender ID", it's just empty). Source
- Missing unsubscribe mechanism — Spam Act 2003 section 18(1) requires every commercial electronic message with an Australian link to include a clear and conspicuous statement that the recipient may send an unsubscribe message, using an electronic address reasonably likely to be capable of receiving it. Schedule 2, clause 6 separately fixes the withdrawal-of-consent effective date at 5 business days after the unsubscribe message is sent. Section 18 does not require extra personal information or an account login to use the facility. Source
- Harvested or purchased contact list — Spam Act 2003 Schedule 2, clause 4(1) states plainly: "the consent of the relevant electronic account-holder may not be inferred from the mere fact that the relevant electronic address has been published." A narrow exception exists only for conspicuously published addresses tied to a specific role (clause 4(2)) — not a scraped or purchased general list. A message or internal brief referencing a purchased or scraped list is describing a send with no valid consent basis under this clause. Source
- Cold contact with no existing relationship — Consent under the Spam Act can be express or inferred, but inferred consent only holds where an existing commercial relationship makes the recipient's interest reasonable — language admitting a genuinely cold first contact is a signal worth checking against a real consent basis before sending, not an automatic breach on its own. Source
- Sensitive personal information used for direct marketing — Australian Privacy Principle 7 (APP 7) requires explicit consent before an organisation uses sensitive personal information — health details, political opinions, religious beliefs, sexual orientation and similar categories — for direct marketing, a materially higher bar than the general opt-out-based rule that applies to ordinary personal information. Source
- Third-party data sharing for marketing — APP 7 permits direct marketing using personal information collected from a third party only in narrower circumstances than data collected directly from the individual — a message revealing the contact came via a partner organisation surfaces a real question about whether the original consent covered this specific use. Source
Methodology — where this checklist comes from
Rules marked "verified" in our sourcing are fetched directly from primary authority and read in full: Privacy Act / APP 7 rules from the OAIC's own official direct-marketing guidance page, and Spam Act rules directly from the Act's own text at the Federal Register of Legislation — sections 17 (sender identification), 18 (unsubscribe) and Schedule 2 (consent). ACMA's own "avoid sending spam" page and the Federal Register's web viewer both proved unreachable to this session's fetch tooling, but the Register's own original-assent PDF rendered in full when read directly, which is what these rules now cite — corrected from an earlier version of this tool that cited a law-firm summary as primary, still kept as a corroborating secondary source. This is the same discipline our Singapore MOH checker and Hong Kong medical ad checker apply when a primary source is hard to reach: disclosed, not silently worked around. It is not a substitute for legal advice: treat a “no flags” result as a reasonable first pass, not clearance. Running a Singapore campaign instead? Use our PDPA & DNC checker.
Rules current as of: August 2026