Free Tool · Australia

Privacy Act & Spam Act Checker.

Paste your email, SMS or WhatsApp marketing message. We'll flag missing sender ID, missing unsubscribe, harvested-list language and Privacy Act consent risks before you hit send.

Quick answer: This checker flags missing sender identification, missing unsubscribe mechanism, harvested/purchased list language, cold-contact risk, and sensitive-information or third-party data-sharing risk in a marketing message against Australia's Spam Act 2003 and Privacy Act 1988 (APP 7). Paste your message for a rule-by-rule flag before you send.

Educational self-check — not legal advice. This tool flags common risk areas under the Spam Act 2003 and Privacy Act 1988's direct-marketing rule (APP 7), described generally. Final review of any Australian marketing campaign should be done against ACMA/OAIC's own published guidance or with your own adviser. Everything runs client-side in your browser — your message text is never sent anywhere or stored.

Why Australian marketing compliance is two laws, not one

Australia regulates commercial electronic messages under the Spam Act 2003, enforced by the Australian Communications and Media Authority (ACMA) — every message needs valid consent, clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days. Separately, the Privacy Act 1988's Australian Privacy Principle 7 (APP 7), enforced by the OAIC, governs using personal information for direct marketing at all — including a materially higher consent bar for sensitive information (health, political, religious, sexual orientation) and rules on data that arrived via a third party.

This self-check walks your actual message through the risk areas that most often trip up Australian marketing sends, flags the specific phrase (or missing element) that triggered each one, explains which rule it touches, and suggests a compliant fix. It's the same discipline our Australia team applies when building campaigns for AU clients — see our Australia social media marketing page for the full strategy layer.

What this checker looks for

6 rule categories, drawn from the sources cited below — each one covers a specific pattern our checker scans your pasted text for:

  • Missing sender identification — Under the Spam Act 2003, every commercial electronic message must clearly identify who is sending it and how to contact them — the sender's legal or trading name plus at least one working contact method. This check only fires once there's substantial pasted text to judge (an empty box isn't "missing sender ID", it's just empty). Source
  • Missing unsubscribe mechanism — The Spam Act 2003 requires every commercial electronic message to include a functional unsubscribe facility that must remain working for at least 30 days after sending, and requests must be actioned within about 5 working days — it cannot require extra personal information or an account login to use. Source
  • Harvested or purchased contact list — Scraping addresses, guessing addresses, or taking details from public profiles is explicitly not valid consent under the Spam Act 2003 — a message or internal brief that references a purchased or scraped list is describing a send with no valid consent basis at all, the most serious category of breach this Act covers. Source
  • Cold contact with no existing relationship — Consent under the Spam Act can be express or inferred, but inferred consent only holds where an existing commercial relationship makes the recipient's interest reasonable — language admitting a genuinely cold first contact is a signal worth checking against a real consent basis before sending, not an automatic breach on its own. Source
  • Sensitive personal information used for direct marketing — Australian Privacy Principle 7 (APP 7) requires explicit consent before an organisation uses sensitive personal information — health details, political opinions, religious beliefs, sexual orientation and similar categories — for direct marketing, a materially higher bar than the general opt-out-based rule that applies to ordinary personal information. Source
  • Third-party data sharing for marketing — APP 7 permits direct marketing using personal information collected from a third party only in narrower circumstances than data collected directly from the individual — a message revealing the contact came via a partner organisation surfaces a real question about whether the original consent covered this specific use. Source

Methodology — where this checklist comes from

Rules marked "verified" in our sourcing were fetched directly from the OAIC's own official direct-marketing guidance page and read in full this session. Spam Act rules are cited via a named Australian law firm's (Sprintlaw) published compliance summary, because ACMA's own "avoid sending spam" page timed out repeatedly to this session's fetch tool rather than resolving — logged here rather than silently worked around, the same discipline our Singapore MOH checker and Hong Kong medical ad checker already apply when a primary source is unreachable. It is not a substitute for legal advice: treat a “no flags” result as a reasonable first pass, not clearance. Running a Singapore campaign instead? Use our PDPA & DNC checker.

Rules current as of: July 2026

Cite this

shakalakaa (Plixitt Solutions). "Australia Privacy Act & Spam Act Checker." https://shakalakaa.my/tools/au-privacy-spam-checker. Updated 2026-07-31. Licensed under CC BY 4.0.

LET'S START
THE CONVO.