If your business sends commercial SMS messages to Australian contacts, you are operating under a web of overlapping legislation - the Spam Act 2003, the Privacy Act 1988, and the Do Not Call Register Act 2006. Getting it wrong isn't just embarrassing - it can attract penalties of up to $2.22 million per day.
This guide breaks down each law, explains exactly what it requires of you, and shows you how to build a compliance framework that protects your business without stifling your marketing.
This article provides general educational information only and does not constitute legal advice. For advice specific to your circumstances, consult a qualified Australian lawyer or seek guidance directly from the ACMA or the Office of the Australian Information Commissioner (OAIC).
- Spam Act 2003 - Overview
- The Three Conditions for Compliant SMS
- Consent Requirements: Express vs Inferred
- Identification Requirements
- Unsubscribe Obligations
- Privacy Act 1988 & the Australian Privacy Principles
- Do Not Call Register
- Penalties for Non-Compliance
- How Monster SMS Keeps You Compliant
- Compliance Checklist
1. Spam Act 2003 - Overview
The Spam Act 2003 (Cth) is Commonwealth legislation that prohibits the sending of unsolicited commercial electronic messages originating from - or sent to - Australia. Despite its name, the Act is not limited to email. It covers SMS, MMS, email, and instant messages equally.
A message is "commercial" if it offers, advertises, or promotes:
- Goods, services, land, or a business opportunity
- A supplier of goods, services, land, or a business opportunity
- The content, use, or existence of a commercial website
Pure transactional messages - an appointment confirmation with no promotional content, a shipping notification, a two-factor authentication code - are generally not commercial messages and fall outside the Act. However, the moment you mix any promotional content into a transactional message (e.g., "Your order is dispatched. While you wait, check out our new range at..."), it may be treated as commercial.
Who enforces it? The Australian Communications and Media Authority (ACMA) is the regulator. ACMA can investigate complaints, compel records, issue formal warnings, seek enforceable undertakings, and apply to the Federal Court for civil penalties. It also co-operates with international spam enforcement bodies.
2. The Three Conditions for Compliant Commercial SMS
Under the Spam Act, every commercial SMS you send must simultaneously satisfy three conditions. Miss any one of them, and the message is non-compliant - regardless of how innocuous it seems.
Consent
The recipient must have consented - either expressly or by clear inference from their behaviour - to receive commercial messages from you. Consent must be current: it can be withdrawn at any time, and once withdrawn it must be honoured immediately.
Purchasing a contact list, scraping numbers from a website, or harvesting numbers from business directories does not constitute consent.
Identification
Every message must clearly and accurately identify the individual or organisation that authorised its sending. This means your business name - the one the recipient would recognise - must appear either as the alphanumeric sender ID or within the message body itself. A shortcode with no name is insufficient.
Unsubscribe
Every commercial SMS must include a functional, free, and clearly expressed way for the recipient to opt out of future messages. For SMS, "Reply STOP to unsubscribe" is the standard. When someone sends STOP, they must be removed from your list promptly - the Act specifies within 5 business days, but best practice (and most platforms) is immediate or same-day processing.
3. Consent Requirements: Express vs Inferred
Express Consent
Express consent is explicit, unambiguous, and directly given. It is the gold standard and should be your default approach wherever possible. Examples include:
- Ticking a clearly labelled SMS opt-in checkbox on a sign-up form (separate from the email opt-in)
- Sending a keyword to a shortcode ("Text JOIN to 0400 000 000 to receive offers from Bella Hair Studio")
- Scanning a QR code that pre-populates and sends an opt-in keyword
- Verbally consenting at point of sale where the purpose is clearly explained by staff
- Completing an in-store paper form that explicitly mentions SMS marketing
Express consent is easy to document and easy to defend. Every time you collect it, record the date, time, channel, and the exact wording of the consent request.
Inferred Consent
Inferred consent arises from an existing business relationship where the person's conduct implies they expect to receive messages from you. It is narrower than most businesses assume. Under the Spam Act, consent may be inferred where:
- The person is in a business or other relationship with the sender
- The message is directly relevant to the role or capacity in which the relationship exists
- There is no indication the person has objected to receiving such messages
Practical example: A customer books a haircut and provides their mobile number for appointment reminders. Sending a follow-up promotional offer for hair products may rely on inferred consent from that commercial relationship. However, best practice is to offer an explicit opt-in checkbox at the time of booking - don't rely on inferred consent as your primary basis.
What does not constitute inferred consent:
- A business card given at a networking event
- A mobile number listed publicly on a website
- A contact form submission where SMS was not mentioned
- A purchased or rented contact list
- A follow or connection on social media
| Scenario | Express Consent? | Inferred Consent? | Safe to Send? |
|---|---|---|---|
| Customer ticked SMS opt-in at checkout | ✓ Yes | - | ✓ Yes |
| Customer provided number for appointment reminders | ✗ No | ⚠ Possibly | ⚠ Marginal - add opt-in |
| Number collected via keyword campaign | ✓ Yes | - | ✓ Yes |
| Business card received at trade show | ✗ No | ✗ No | ✗ Do not send |
| Number from purchased marketing list | ✗ No | ✗ No | ✗ Do not send |
| Number scraped from website / directory | ✗ No | ✗ No | ✗ Do not send |
| Contact form submission - SMS not mentioned | ✗ No | ✗ No | ✗ Do not send |
4. Identification Requirements
Every commercial SMS must accurately identify the business that authorised it. This requirement exists to prevent consumers from receiving messages from anonymous senders they cannot identify or block.
How to meet the identification requirement
You can satisfy this in two ways:
- Alphanumeric sender ID: Set your sender ID to your business name (e.g., "BellaHair" or "RetailCo"). Most Australian SMS platforms support this. Note: recipients cannot reply to alphanumeric sender IDs, so you'll need a separate inbound number if you want two-way communication.
- Business name in the message body: If you're using a numeric sender (long number or shortcode), include your business name in the opening of the message - e.g., "Hi [Name], it's Bella Hair Studio. Your exclusive..."
Using a generic shortcode or virtual number without any business name in the message body does not satisfy the identification requirement. If the recipient cannot immediately tell who sent the message, you are likely non-compliant. This is one of the most common triggers for ACMA complaints.
Agencies and white-label platforms
If you send SMS on behalf of clients (e.g., you're a marketing agency or operate a reseller platform), the identification requirement applies to the business the recipient would recognise - your client, not your platform. Ensure your client's name is clearly present, not your agency's or your platform's brand.
5. Unsubscribe Obligations
The unsubscribe obligation is where many businesses - even those with good intentions - fall short. The Spam Act requires that every commercial message include an unsubscribe facility that is:
- Functional: It must actually work. A "Reply STOP" instruction that goes to an unmanned inbox and is never processed is not compliant.
- Clearly expressed: The recipient must be able to easily understand how to opt out. Buried fine print or vague instructions are not sufficient.
- Free to use: The recipient cannot be charged to unsubscribe. You cannot require them to visit a complex multi-step web form, call a premium-rate number, or pay any fee.
- Honoured within 5 business days: Once a person opts out, you must stop sending them commercial messages within 5 business days. Best practice is same-day or immediate suppression.
Acceptable unsubscribe formats for SMS
- "Reply STOP to unsubscribe" - the industry standard
- "Reply STOP to opt out" - equally acceptable
- "Text STOP to [number] to unsubscribe" - when using a non-reply sender ID
- A working URL that immediately processes the opt-out without requiring sign-in or additional steps
After someone unsubscribes
Once a contact has opted out, their number should be added to a suppression list - not simply removed from a send list. The suppression list ensures that even if the number is re-uploaded (for example, if your CRM is refreshed from a sales database), the person will not receive further messages.
Character budget: Including "Reply STOP to unsubscribe" costs 28 characters. Budget for it in your message design. It's a non-negotiable, not an afterthought.
6. Privacy Act 1988 & the Australian Privacy Principles
The Privacy Act 1988 (Cth) operates alongside the Spam Act and governs how you collect, store, use, and disclose personal information - including mobile phone numbers. The 13 Australian Privacy Principles (APPs) are the core of this framework.
Key APPs for SMS marketing
APP 3 - Collection of Solicited Personal Information
You may only collect personal information (including mobile numbers) that is reasonably necessary for your functions or activities. You must collect directly from the individual where reasonable and practicable. Collecting numbers in bulk from third parties without a lawful basis raises serious privacy concerns.
APP 5 - Notification of Collection
At or before the time you collect a mobile number, you must take reasonable steps to notify the individual of:
- Your identity and contact details
- The purpose of collection (including if it will be used for SMS marketing)
- Whether it will be disclosed to third parties
- Their right to access and correct the information
- How they can complain about a privacy breach
This is why a simple "Enter your mobile number" field with no accompanying notice is insufficient. A brief disclosure statement alongside the field satisfies APP 5.
APP 6 - Use and Disclosure
You may only use or disclose personal information for the primary purpose for which it was collected (or a related secondary purpose the individual would reasonably expect). If someone gave you their number for appointment reminders, using it for promotional SMS marketing is a different purpose - and requires fresh consent or a reasonable expectation basis.
APP 11 - Security of Personal Information
You must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Your SMS contact list is personal information. It should be stored securely, access-controlled, and not shared unnecessarily with third parties.
Does the Privacy Act apply to your business?
The Privacy Act currently applies to:
- Organisations with an annual turnover exceeding $3 million
- Health service providers (regardless of turnover)
- Businesses that trade in personal information
- Various other prescribed categories
Proposed reforms may lower or eliminate the turnover threshold. Even if you're currently exempt, applying Privacy Act principles is considered best practice and signals trustworthiness to your customers.
Notifiable Data Breaches scheme: If your SMS contact list is breached (e.g., unauthorised access, accidental disclosure), and the breach is likely to result in serious harm, you may be required to notify affected individuals and the OAIC under the Notifiable Data Breaches (NDB) scheme.
7. Do Not Call Register
The Do Not Call Register Act 2006 (Cth) and its supporting framework established the Do Not Call Register (DNCR), operated by the ACMA. The Register allows Australian individuals and businesses to opt out of receiving unsolicited telemarketing calls and faxes.
Does the DNCR apply to SMS?
This is an area of genuine confusion. The Do Not Call Register was primarily designed for voice calls and faxes, not SMS. The DNCR does not directly prohibit sending SMS to registered numbers in the same way it prohibits calling them.
However, the DNCR is highly relevant to SMS marketers in two important ways:
1. Wash your lists against the DNCR
If you are running integrated campaigns that include both voice calls and SMS, the DNCR applies to your voice calls. A number registered on the DNCR cannot be called for telemarketing purposes - and many businesses find their SMS lists and calling lists overlap. Washing your lists against the DNCR before voice outreach is legally required (certain exemptions apply for research, charities, and political parties).
2. Spirit of the Register
A number on the DNCR is a strong signal that the individual does not want unsolicited commercial contact. While SMS marketing is governed by the Spam Act (consent-based) rather than the DNCR, sending promotional SMS to someone who has clearly registered to avoid unsolicited contact - and without their explicit SMS consent - is both ethically questionable and likely to generate ACMA complaints.
Who can access the DNCR?
Businesses can wash numbers against the DNCR via the ACMA's online portal. There is a fee schedule based on the volume of numbers washed. Accessing the Register without authorisation, or using it for purposes other than compliance checking, is prohibited.
Key takeaway: The DNCR's primary direct impact on SMS marketers is in the context of multi-channel campaigns that include voice. For SMS-only campaigns, the Spam Act's consent requirement is your primary compliance framework - but always respect the spirit of the DNCR by obtaining clear, affirmative consent before sending any commercial SMS.
8. Penalties for Non-Compliance
The penalties under the Spam Act are significant and have been indexed over time. Non-compliance is not a minor regulatory risk - it can be existentially damaging for a small business.
These are per-day penalties, not per-message. A campaign sent over five days could theoretically attract up to five days' worth of penalties. ACMA enforcement actions typically cover a campaign period, meaning the financial exposure can be substantial.
Types of enforcement action
ACMA has a range of enforcement tools available, including:
- Formal warnings - publicly issued and reputationally damaging
- Infringement notices - on-the-spot penalties for specific contraventions
- Enforceable undertakings - binding commitments to change practices, with court-enforceable consequences for breach
- Injunctions - court orders to cease non-compliant conduct
- Civil penalty orders - sought in the Federal Court; the highest sanction
Common enforcement triggers
- Unsubscribe failures: Continuing to send after a person has replied STOP is the single most common enforcement trigger. Consumer complaints about this are easily verifiable.
- Purchased or harvested lists: Sending to people who never consented - especially at scale - attracts serious scrutiny.
- Misleading identification: Disguising who sent a message violates both the Spam Act and consumer protection legislation.
- No unsubscribe mechanism: Sending commercial SMS without any opt-out instruction is non-compliant from the first message.
ACMA actively monitors complaint patterns and investigates businesses that generate high volumes of complaints. A single disgruntled recipient who reports you to ACMA can trigger an investigation covering your entire SMS programme. You want clean records and compliant processes before that call comes.
Privacy Act penalties
Under the Privacy Act, serious or repeated privacy breaches can attract civil penalties of up to $50 million, or three times the benefit obtained from the contravention, or 30% of adjusted turnover (whichever is greater) - following reforms that substantially increased the penalty ceiling. The OAIC can also conduct investigations, accept enforceable undertakings, and make determinations.
9. How Monster SMS Keeps You Compliant
Monster SMS was built from the ground up for the Australian market - which means compliance isn't an afterthought bolted on later. It's baked into the platform's core functionality.
Built-in STOP Handling
When a contact replies STOP, UNSUBSCRIBE, or OPT OUT, Monster SMS instantly suppresses them from all future sends - automatically, with no manual action required. The suppression persists even if the number is re-imported.
Opt-Out Management
Every opt-out is logged with a timestamp. Your suppression list is always current and exportable - giving you an audit trail if you ever need to demonstrate compliance to ACMA.
Consent Tracking
Record how and when each contact provided consent. Import consent data via API or CSV, capture opt-ins from keyword campaigns, and maintain the documentation that compliance depends on.
Dedicated Virtual Numbers
Every account gets a dedicated Australian virtual number. Recipients can always reply - meaning your STOP mechanism is always functional, satisfying both the spirit and the letter of the law.
Delivery & Message Logs
Full delivery receipts and message archives are retained. If you need to demonstrate what was sent, to whom, and when - the data is there.
AI-Powered Two-Way Compliance
Monster SMS's AI agents can recognise unsubscribe intent even in natural language ("take me off your list", "stop texting me") and automatically trigger suppression - going beyond simple keyword matching.
Australian-first: Monster SMS operates on Australian carrier routes, with Australian-based support that understands local regulations. Unlike global platforms that apply US or EU compliance logic, Monster SMS is tuned for the Spam Act 2003 and Privacy Act 1988 from day one.
Beyond the platform itself, Monster SMS provides help documentation and setup guidance to ensure your campaigns are structured correctly - including opt-in language templates, message compliance reviews, and best-practice recommendations from our team.
10. Australian SMS Compliance Checklist
Use this checklist as a practical reference before launching any SMS marketing programme:
Further reading: The ACMA publishes detailed spam compliance guidance at acma.gov.au/spam. For Privacy Act guidance and notifiable data breach obligations, visit the Office of the Australian Information Commissioner at oaic.gov.au. The Do Not Call Register is managed at donotcall.gov.au.
SMS compliance in Australia is not as complex as it might initially appear. The rules are clear, the expectations are reasonable, and the tools to comply are readily available. The businesses that get into trouble are almost always those who knew the rules and chose a shortcut - purchased lists, ignored STOP replies, dropped the sender name to save characters.
Build your programme on a foundation of genuine consent, clear identification, and bulletproof opt-out handling, and you'll not only stay on the right side of the law - you'll run more effective campaigns, because a consenting, engaged list always outperforms a large uncontested one.
Send Compliant SMS From Day One
Monster SMS handles STOP replies automatically, logs every opt-out with a timestamp, and gives you the audit trail you need - built for the Australian market, built for the Spam Act 2003.
Start Free - 100 Messages No credit card required · Up and running in minutes