Home / Blog
  • Guides / Australian SMS Compliance Guide: Spam Act 2003, Privacy A...
  • If your business sends commercial SMS messages to Australian contacts, you are operating under a web of overlapping legislation - the Spam Act 2003, the Privacy Act 1988, and the Do Not Call Register Act 2006. Getting it wrong isn't just embarrassing - it can attract penalties of up to $2.22 million per day.

    This guide breaks down each law, explains exactly what it requires of you, and shows you how to build a compliance framework that protects your business without stifling your marketing.

    ⚠️ Legal Disclaimer

    This article provides general educational information only and does not constitute legal advice. For advice specific to your circumstances, consult a qualified Australian lawyer or seek guidance directly from the ACMA or the Office of the Australian Information Commissioner (OAIC).

    In This Guide
    1. Spam Act 2003 - Overview
    2. The Three Conditions for Compliant SMS
    3. Consent Requirements: Express vs Inferred
    4. Identification Requirements
    5. Unsubscribe Obligations
    6. Privacy Act 1988 & the Australian Privacy Principles
    7. Do Not Call Register
    8. Penalties for Non-Compliance
    9. How Monster SMS Keeps You Compliant
    10. Compliance Checklist

    1. Spam Act 2003 - Overview

    The Spam Act 2003 (Cth) is Commonwealth legislation that prohibits the sending of unsolicited commercial electronic messages originating from - or sent to - Australia. Despite its name, the Act is not limited to email. It covers SMS, MMS, email, and instant messages equally.

    A message is "commercial" if it offers, advertises, or promotes:

    Pure transactional messages - an appointment confirmation with no promotional content, a shipping notification, a two-factor authentication code - are generally not commercial messages and fall outside the Act. However, the moment you mix any promotional content into a transactional message (e.g., "Your order is dispatched. While you wait, check out our new range at..."), it may be treated as commercial.

    Who enforces it? The Australian Communications and Media Authority (ACMA) is the regulator. ACMA can investigate complaints, compel records, issue formal warnings, seek enforceable undertakings, and apply to the Federal Court for civil penalties. It also co-operates with international spam enforcement bodies.

    2. The Three Conditions for Compliant Commercial SMS

    Under the Spam Act, every commercial SMS you send must simultaneously satisfy three conditions. Miss any one of them, and the message is non-compliant - regardless of how innocuous it seems.

    1

    Consent

    The recipient must have consented - either expressly or by clear inference from their behaviour - to receive commercial messages from you. Consent must be current: it can be withdrawn at any time, and once withdrawn it must be honoured immediately.

    Purchasing a contact list, scraping numbers from a website, or harvesting numbers from business directories does not constitute consent.

    2

    Identification

    Every message must clearly and accurately identify the individual or organisation that authorised its sending. This means your business name - the one the recipient would recognise - must appear either as the alphanumeric sender ID or within the message body itself. A shortcode with no name is insufficient.

    3

    Unsubscribe

    Every commercial SMS must include a functional, free, and clearly expressed way for the recipient to opt out of future messages. For SMS, "Reply STOP to unsubscribe" is the standard. When someone sends STOP, they must be removed from your list promptly - the Act specifies within 5 business days, but best practice (and most platforms) is immediate or same-day processing.

    Express Consent

    Express consent is explicit, unambiguous, and directly given. It is the gold standard and should be your default approach wherever possible. Examples include:

    Express consent is easy to document and easy to defend. Every time you collect it, record the date, time, channel, and the exact wording of the consent request.

    Inferred Consent

    Inferred consent arises from an existing business relationship where the person's conduct implies they expect to receive messages from you. It is narrower than most businesses assume. Under the Spam Act, consent may be inferred where:

    Practical example: A customer books a haircut and provides their mobile number for appointment reminders. Sending a follow-up promotional offer for hair products may rely on inferred consent from that commercial relationship. However, best practice is to offer an explicit opt-in checkbox at the time of booking - don't rely on inferred consent as your primary basis.

    What does not constitute inferred consent:

    Scenario Express Consent? Inferred Consent? Safe to Send?
    Customer ticked SMS opt-in at checkout ✓ Yes - ✓ Yes
    Customer provided number for appointment reminders ✗ No ⚠ Possibly ⚠ Marginal - add opt-in
    Number collected via keyword campaign ✓ Yes - ✓ Yes
    Business card received at trade show ✗ No ✗ No ✗ Do not send
    Number from purchased marketing list ✗ No ✗ No ✗ Do not send
    Number scraped from website / directory ✗ No ✗ No ✗ Do not send
    Contact form submission - SMS not mentioned ✗ No ✗ No ✗ Do not send

    4. Identification Requirements

    Every commercial SMS must accurately identify the business that authorised it. This requirement exists to prevent consumers from receiving messages from anonymous senders they cannot identify or block.

    How to meet the identification requirement

    You can satisfy this in two ways:

    ⚠️ Common Mistake

    Using a generic shortcode or virtual number without any business name in the message body does not satisfy the identification requirement. If the recipient cannot immediately tell who sent the message, you are likely non-compliant. This is one of the most common triggers for ACMA complaints.

    Agencies and white-label platforms

    If you send SMS on behalf of clients (e.g., you're a marketing agency or operate a reseller platform), the identification requirement applies to the business the recipient would recognise - your client, not your platform. Ensure your client's name is clearly present, not your agency's or your platform's brand.

    5. Unsubscribe Obligations

    The unsubscribe obligation is where many businesses - even those with good intentions - fall short. The Spam Act requires that every commercial message include an unsubscribe facility that is:

    Acceptable unsubscribe formats for SMS

    After someone unsubscribes

    Once a contact has opted out, their number should be added to a suppression list - not simply removed from a send list. The suppression list ensures that even if the number is re-uploaded (for example, if your CRM is refreshed from a sales database), the person will not receive further messages.

    Character budget: Including "Reply STOP to unsubscribe" costs 28 characters. Budget for it in your message design. It's a non-negotiable, not an afterthought.

    6. Privacy Act 1988 & the Australian Privacy Principles

    The Privacy Act 1988 (Cth) operates alongside the Spam Act and governs how you collect, store, use, and disclose personal information - including mobile phone numbers. The 13 Australian Privacy Principles (APPs) are the core of this framework.

    Key APPs for SMS marketing

    APP 3 - Collection of Solicited Personal Information

    You may only collect personal information (including mobile numbers) that is reasonably necessary for your functions or activities. You must collect directly from the individual where reasonable and practicable. Collecting numbers in bulk from third parties without a lawful basis raises serious privacy concerns.

    APP 5 - Notification of Collection

    At or before the time you collect a mobile number, you must take reasonable steps to notify the individual of:

    This is why a simple "Enter your mobile number" field with no accompanying notice is insufficient. A brief disclosure statement alongside the field satisfies APP 5.

    APP 6 - Use and Disclosure

    You may only use or disclose personal information for the primary purpose for which it was collected (or a related secondary purpose the individual would reasonably expect). If someone gave you their number for appointment reminders, using it for promotional SMS marketing is a different purpose - and requires fresh consent or a reasonable expectation basis.

    APP 11 - Security of Personal Information

    You must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Your SMS contact list is personal information. It should be stored securely, access-controlled, and not shared unnecessarily with third parties.

    Does the Privacy Act apply to your business?

    The Privacy Act currently applies to:

    Proposed reforms may lower or eliminate the turnover threshold. Even if you're currently exempt, applying Privacy Act principles is considered best practice and signals trustworthiness to your customers.

    Notifiable Data Breaches scheme: If your SMS contact list is breached (e.g., unauthorised access, accidental disclosure), and the breach is likely to result in serious harm, you may be required to notify affected individuals and the OAIC under the Notifiable Data Breaches (NDB) scheme.

    7. Do Not Call Register

    The Do Not Call Register Act 2006 (Cth) and its supporting framework established the Do Not Call Register (DNCR), operated by the ACMA. The Register allows Australian individuals and businesses to opt out of receiving unsolicited telemarketing calls and faxes.

    Does the DNCR apply to SMS?

    This is an area of genuine confusion. The Do Not Call Register was primarily designed for voice calls and faxes, not SMS. The DNCR does not directly prohibit sending SMS to registered numbers in the same way it prohibits calling them.

    However, the DNCR is highly relevant to SMS marketers in two important ways:

    1. Wash your lists against the DNCR

    If you are running integrated campaigns that include both voice calls and SMS, the DNCR applies to your voice calls. A number registered on the DNCR cannot be called for telemarketing purposes - and many businesses find their SMS lists and calling lists overlap. Washing your lists against the DNCR before voice outreach is legally required (certain exemptions apply for research, charities, and political parties).

    2. Spirit of the Register

    A number on the DNCR is a strong signal that the individual does not want unsolicited commercial contact. While SMS marketing is governed by the Spam Act (consent-based) rather than the DNCR, sending promotional SMS to someone who has clearly registered to avoid unsolicited contact - and without their explicit SMS consent - is both ethically questionable and likely to generate ACMA complaints.

    Who can access the DNCR?

    Businesses can wash numbers against the DNCR via the ACMA's online portal. There is a fee schedule based on the volume of numbers washed. Accessing the Register without authorisation, or using it for purposes other than compliance checking, is prohibited.

    Key takeaway: The DNCR's primary direct impact on SMS marketers is in the context of multi-channel campaigns that include voice. For SMS-only campaigns, the Spam Act's consent requirement is your primary compliance framework - but always respect the spirit of the DNCR by obtaining clear, affirmative consent before sending any commercial SMS.

    8. Penalties for Non-Compliance

    The penalties under the Spam Act are significant and have been indexed over time. Non-compliance is not a minor regulatory risk - it can be existentially damaging for a small business.

    $2.22M
    Maximum per day for organisations (10,000 penalty units @ $222 each)
    $444K
    Maximum per day for individuals (2,000 penalty units @ $222 each)

    These are per-day penalties, not per-message. A campaign sent over five days could theoretically attract up to five days' worth of penalties. ACMA enforcement actions typically cover a campaign period, meaning the financial exposure can be substantial.

    Types of enforcement action

    ACMA has a range of enforcement tools available, including:

    Common enforcement triggers

    ⚠️ Real Risk

    ACMA actively monitors complaint patterns and investigates businesses that generate high volumes of complaints. A single disgruntled recipient who reports you to ACMA can trigger an investigation covering your entire SMS programme. You want clean records and compliant processes before that call comes.

    Privacy Act penalties

    Under the Privacy Act, serious or repeated privacy breaches can attract civil penalties of up to $50 million, or three times the benefit obtained from the contravention, or 30% of adjusted turnover (whichever is greater) - following reforms that substantially increased the penalty ceiling. The OAIC can also conduct investigations, accept enforceable undertakings, and make determinations.

    9. How Monster SMS Keeps You Compliant

    Monster SMS was built from the ground up for the Australian market - which means compliance isn't an afterthought bolted on later. It's baked into the platform's core functionality.

    🛑

    Built-in STOP Handling

    When a contact replies STOP, UNSUBSCRIBE, or OPT OUT, Monster SMS instantly suppresses them from all future sends - automatically, with no manual action required. The suppression persists even if the number is re-imported.

    📋

    Opt-Out Management

    Every opt-out is logged with a timestamp. Your suppression list is always current and exportable - giving you an audit trail if you ever need to demonstrate compliance to ACMA.

    ✅

    Consent Tracking

    Record how and when each contact provided consent. Import consent data via API or CSV, capture opt-ins from keyword campaigns, and maintain the documentation that compliance depends on.

    🔢

    Dedicated Virtual Numbers

    Every account gets a dedicated Australian virtual number. Recipients can always reply - meaning your STOP mechanism is always functional, satisfying both the spirit and the letter of the law.

    📊

    Delivery & Message Logs

    Full delivery receipts and message archives are retained. If you need to demonstrate what was sent, to whom, and when - the data is there.

    🤖

    AI-Powered Two-Way Compliance

    Monster SMS's AI agents can recognise unsubscribe intent even in natural language ("take me off your list", "stop texting me") and automatically trigger suppression - going beyond simple keyword matching.

    Australian-first: Monster SMS operates on Australian carrier routes, with Australian-based support that understands local regulations. Unlike global platforms that apply US or EU compliance logic, Monster SMS is tuned for the Spam Act 2003 and Privacy Act 1988 from day one.

    Beyond the platform itself, Monster SMS provides help documentation and setup guidance to ensure your campaigns are structured correctly - including opt-in language templates, message compliance reviews, and best-practice recommendations from our team.

    10. Australian SMS Compliance Checklist

    Use this checklist as a practical reference before launching any SMS marketing programme:

    ✅ SMS Compliance Checklist for Australian Businesses
    ☐ Consent documented for every contact: Each person on your send list has either given express consent (with date, method, and wording recorded) or there is a clear, documented basis for inferred consent.
    ☐ Opt-in language is explicit and specific: Your sign-up forms, checkboxes, or keyword flows state exactly what the person is consenting to - including that they will receive SMS marketing from your business by name.
    ☐ No purchased, scraped, or third-party lists: Every contact on your list has opted in directly with your business. You do not use lists sourced from list brokers, web scrapers, or database vendors.
    ☐ Business name identified in every message: Your trading name appears in every commercial SMS - either as the alphanumeric sender ID or in the message body, every time, without exception.
    ☐ Unsubscribe instruction included: "Reply STOP to unsubscribe" (or equivalent) is present in every commercial message. It is clearly readable and not buried.
    ☐ STOP replies are processed immediately: Your platform automatically suppresses anyone who replies STOP, UNSUBSCRIBE, or any opt-out variant. There is no delay, no manual step required.
    ☐ Suppression list is maintained: Opt-outs are stored in a permanent suppression list, not just removed from a campaign send list - ensuring re-imported numbers are still blocked.
    ☐ Privacy collection notice in place: When collecting mobile numbers, individuals are informed of the purpose (including SMS marketing) and given a clear opt-in mechanism, per APP 5.
    ☐ Number data is secured: Access to your SMS contact list is restricted to authorised personnel. Security measures - access controls, encryption at rest - are in place, per APP 11.
    ☐ Message archive maintained: You retain copies of messages sent, recipient lists, timestamps, and delivery records for a reasonable period (7 years is a conservative safe standard aligned with general business record-keeping practice).
    ☐ Sending hours observed: Commercial SMS is only sent between reasonable hours - as a rule, 8 am–9 pm local time for the recipient, Monday to Saturday. Exercise caution on Sundays and public holidays.
    ☐ DNCR considered for multi-channel campaigns: If your campaign includes voice outreach, your calling list has been washed against the Do Not Call Register before dialling.
    ☐ Platform compliance reviewed: Your SMS provider operates on compliant Australian carrier routes, processes STOP replies automatically, and can provide records if required by a regulator.

    Further reading: The ACMA publishes detailed spam compliance guidance at acma.gov.au/spam. For Privacy Act guidance and notifiable data breach obligations, visit the Office of the Australian Information Commissioner at oaic.gov.au. The Do Not Call Register is managed at donotcall.gov.au.

    SMS compliance in Australia is not as complex as it might initially appear. The rules are clear, the expectations are reasonable, and the tools to comply are readily available. The businesses that get into trouble are almost always those who knew the rules and chose a shortcut - purchased lists, ignored STOP replies, dropped the sender name to save characters.

    Build your programme on a foundation of genuine consent, clear identification, and bulletproof opt-out handling, and you'll not only stay on the right side of the law - you'll run more effective campaigns, because a consenting, engaged list always outperforms a large uncontested one.

    Send Compliant SMS From Day One

    Monster SMS handles STOP replies automatically, logs every opt-out with a timestamp, and gives you the audit trail you need - built for the Australian market, built for the Spam Act 2003.

    Start Free - 100 Messages No credit card required  ·  Up and running in minutes