Free Tool · Australia

Privacy Act & Spam Act Checker.

Paste your email, SMS or WhatsApp marketing message. We'll flag missing sender ID, missing unsubscribe, harvested-list language and Privacy Act consent risks before you hit send.

Quick answer: This checker flags missing sender identification, missing unsubscribe mechanism, harvested/purchased list language, cold-contact risk, and sensitive-information or third-party data-sharing risk in a marketing message against Australia's Spam Act 2003 and Privacy Act 1988 (APP 7). Paste your message for a rule-by-rule flag before you send.

Educational self-check — not legal advice. This tool flags common risk areas under the Spam Act 2003 and Privacy Act 1988's direct-marketing rule (APP 7), described generally. Final review of any Australian marketing campaign should be done against ACMA/OAIC's own published guidance or with your own adviser. Everything runs client-side in your browser — your message text is never sent anywhere or stored.

These rules are published openly. Check our sourcing, or correct us.

Why Australian marketing compliance is two laws, not one

Australia regulates commercial electronic messages under the Spam Act 2003, enforced by the Australian Communications and Media Authority (ACMA) — every message needs valid consent, clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days. Separately, the Privacy Act 1988's Australian Privacy Principle 7 (APP 7), enforced by the OAIC, governs using personal information for direct marketing at all — including a materially higher consent bar for sensitive information (health, political, religious, sexual orientation) and rules on data that arrived via a third party.

This self-check walks your actual message through the risk areas that most often trip up Australian marketing sends, flags the specific phrase (or missing element) that triggered each one, explains which rule it touches, and suggests a compliant fix. It's the same discipline our Australia team applies when building campaigns for AU clients — see our Australia social media marketing page for the full strategy layer.

What this checker looks for

6 rule categories, drawn from the sources cited below — each one covers a specific pattern our checker scans your pasted text for:

  • Missing sender identification — Spam Act 2003 section 17(1) requires that a commercial electronic message with an Australian link must clearly and accurately identify the individual or organisation who authorised the sending of the message, include accurate contact information, and that information must comply with any conditions in the regulations and be reasonably likely to be valid for at least 30 days after the message is sent. This check only fires once there's substantial pasted text to judge (an empty box isn't "missing sender ID", it's just empty). Source
  • Missing unsubscribe mechanism — Spam Act 2003 section 18(1) requires every commercial electronic message with an Australian link to include a clear and conspicuous statement that the recipient may send an unsubscribe message, using an electronic address reasonably likely to be capable of receiving it. Schedule 2, clause 6 separately fixes the withdrawal-of-consent effective date at 5 business days after the unsubscribe message is sent. Section 18 does not require extra personal information or an account login to use the facility. Source
  • Harvested or purchased contact list — Spam Act 2003 Schedule 2, clause 4(1) states plainly: "the consent of the relevant electronic account-holder may not be inferred from the mere fact that the relevant electronic address has been published." A narrow exception exists only for conspicuously published addresses tied to a specific role (clause 4(2)) — not a scraped or purchased general list. A message or internal brief referencing a purchased or scraped list is describing a send with no valid consent basis under this clause. Source
  • Cold contact with no existing relationship — Consent under the Spam Act can be express or inferred, but inferred consent only holds where an existing commercial relationship makes the recipient's interest reasonable — language admitting a genuinely cold first contact is a signal worth checking against a real consent basis before sending, not an automatic breach on its own. Source
  • Sensitive personal information used for direct marketing — Australian Privacy Principle 7 (APP 7) requires explicit consent before an organisation uses sensitive personal information — health details, political opinions, religious beliefs, sexual orientation and similar categories — for direct marketing, a materially higher bar than the general opt-out-based rule that applies to ordinary personal information. Source
  • Third-party data sharing for marketing — APP 7 permits direct marketing using personal information collected from a third party only in narrower circumstances than data collected directly from the individual — a message revealing the contact came via a partner organisation surfaces a real question about whether the original consent covered this specific use. Source

Methodology — where this checklist comes from

Rules marked "verified" in our sourcing are fetched directly from primary authority and read in full: Privacy Act / APP 7 rules from the OAIC's own official direct-marketing guidance page, and Spam Act rules directly from the Act's own text at the Federal Register of Legislation — sections 17 (sender identification), 18 (unsubscribe) and Schedule 2 (consent). ACMA's own "avoid sending spam" page and the Federal Register's web viewer both proved unreachable to this session's fetch tooling, but the Register's own original-assent PDF rendered in full when read directly, which is what these rules now cite — corrected from an earlier version of this tool that cited a law-firm summary as primary, still kept as a corroborating secondary source. This is the same discipline our Singapore MOH checker and Hong Kong medical ad checker apply when a primary source is hard to reach: disclosed, not silently worked around. It is not a substitute for legal advice: treat a “no flags” result as a reasonable first pass, not clearance. Running a Singapore campaign instead? Use our PDPA & DNC checker.

Rules current as of: August 2026

Frequently Asked Questions

Consent to send it (express or a genuine existing-relationship basis for inferred consent), clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days.
No — scraping addresses, guessing addresses, or taking details from public profiles is explicitly not valid consent under the Spam Act 2003, regardless of unsubscribe or sender-ID compliance elsewhere in the message.
Yes — Australian Privacy Principle 7 (APP 7) requires a simple opt-out mechanism for direct marketing generally, and explicit consent specifically before using sensitive personal information (health, political, religious, sexual orientation) for direct marketing.
No — this is an educational first-pass self-check covering the Spam Act and Privacy Act rules most relevant to a marketing message, not legal clearance. Always confirm anything borderline against ACMA/OAIC's own published guidance or your adviser before sending.

Cite this

shakalakaa (Plixitt Solutions). "Australia Privacy Act & Spam Act Checker." https://shakalakaa.my/tools/au-privacy-spam-checker. Updated 2026-08-20. Licensed under CC BY 4.0.

LET'S START
THE CONVO.