If you're sending commercial SMS messages to Australian contacts, the Spam Act 2003 applies to you — full stop. Ignorance of the law is not a defence, and the Australian Communications and Media Authority (ACMA) has demonstrated a willingness to pursue enforcement actions that result in significant penalties.
This guide explains exactly what the Spam Act requires, how it applies to SMS marketing, where businesses most commonly go wrong, and how to build a compliance framework that protects your business while still allowing effective marketing.
This article provides general educational information only. It is not legal advice. For advice specific to your business circumstances, consult a qualified Australian lawyer or seek guidance directly from the ACMA.
What is the Spam Act 2003?
The Spam Act 2003 (Cth) is Commonwealth legislation that prohibits the sending of unsolicited commercial electronic messages. "Electronic messages" includes email, SMS, MMS, and instant messages — the Act is not limited to email, despite common misconceptions.
The Act defines a commercial electronic message as any message that:
- Offers, advertises, or promotes goods, services, land, or a business opportunity
- Advertises or promotes a supplier of goods, services, land, or a business opportunity
- Assists a person to dishonestly obtain property, gain, or advantage from another
Transactional messages — order confirmations, appointment reminders with no promotional content, delivery notifications — generally fall outside the definition of "commercial electronic messages", though the line can blur when promotional content is mixed in.
The Three Conditions for Compliant Commercial SMS
Every commercial SMS you send must satisfy all three of the following conditions simultaneously:
Consent
The recipient must have consented to receive the message. Consent can be express (they explicitly opted in) or inferred (their behaviour implies consent, within the limits defined below). You cannot send commercial SMS to people who haven't consented, no matter how you obtained their number.
Consent can also be withdrawn at any time. Once a person opts out, you must stop sending them commercial messages immediately.
Identification
The message must accurately identify the individual or organisation that authorised the sending of the message. If you're sending on behalf of a client or using a white-label platform, the business name the recipient would recognise must appear in the message.
Simply using a shortcode or masked number without a business name is not sufficient. Something like "From: Bella Hair Studio" in the sender ID, or the name within the message body, satisfies this requirement.
Unsubscribe Mechanism
Every commercial message must include a functional, clearly expressed way for the recipient to opt out of future messages. For SMS, the standard approach is "Reply STOP to unsubscribe" — and this must actually work. When someone replies STOP, they must be removed from your send list promptly (the Act specifies within 5 business days, but best practice is immediate or same-day).
The unsubscribe mechanism must be free to use. You cannot charge a fee or require the recipient to visit a website and complete a multi-step process to unsubscribe from SMS.
Express vs Inferred Consent — What's the Difference?
Express Consent
Express consent is clear, unambiguous, and direct. Examples include:
- Ticking an opt-in checkbox on a form ("Yes, I'd like to receive SMS updates from [Business]")
- Sending a keyword to a shortcode ("Text JOIN to 1234 to receive offers")
- Verbally consenting at point of sale when the opt-in is clearly explained
Express consent is the gold standard. It's unambiguous, easy to document, and stands up to scrutiny.
Inferred Consent
Inferred consent is more complex and carries more compliance risk. Under the Spam Act, consent can be inferred from an existing business relationship — but only where certain conditions are met:
- The recipient has provided their phone number as part of a commercial transaction
- The message relates to the same kind of goods, services, or business activities covered by that transaction
- There is no indication the recipient doesn't wish to receive such messages
Importantly: a business card, a publicly listed phone number, or a contact form submission does not by itself constitute inferred consent for SMS marketing. The relationship must be a genuine commercial one relevant to the content of your messages.
Practical example: A customer purchases a haircut and provides their mobile number for appointment confirmation purposes. Sending them a promotional SMS about a new hair product range may rely on inferred consent from that commercial relationship — but it would be best practice to also offer an explicit opt-in during the booking process.
Penalties: How Much Can You Be Fined?
The Spam Act provides for civil penalties. For organisations (companies), the maximum penalty is 10,000 penalty units per day of contravention. At the current value of the Commonwealth penalty unit, this translates to approximately $2.22 million per day.
For individuals, the maximum is 2,000 penalty units per day (approximately $444,000). These are per-day penalties — not per-message — but a single enforcement action can cover multiple days or a campaign period.
It's also worth noting that the ACMA can seek enforceable undertakings, injunctions, and formal warnings in addition to — or instead of — financial penalties. A public infringement notice can also cause reputational damage far exceeding the financial penalty.
ACMA Enforcement — Real Examples
The ACMA has been actively enforcing spam regulations. Some notable areas of enforcement include:
Unsubscribe failures
One of the most common enforcement triggers is failing to honour unsubscribe requests. Businesses that continue sending messages after recipients have replied STOP — whether due to technical failures, list management errors, or deliberate non-compliance — are a priority target for ACMA action.
Purchased or scraped lists
Using purchased or scraped contact lists for SMS marketing is a near-certain path to enforcement action. The recipients did not consent to receive messages from your business, and this is explicitly prohibited. ACMA investigations frequently begin with consumer complaints from people receiving messages from businesses they've never interacted with.
Misleading identification
Messages that obscure the sender's identity — using generic shortcodes without a business name, impersonating another organisation, or using misleading "From" names — can attract enforcement action under both the Spam Act and related consumer protection legislation.
Overlap With the Privacy Act 1988
The Spam Act and the Privacy Act 1988 (Cth) operate in parallel, and businesses conducting SMS marketing need to be mindful of both.
Australian Privacy Principles (APPs)
The Privacy Act governs the collection, use, storage, and disclosure of personal information, including mobile phone numbers. Key obligations relevant to SMS marketing include:
- APP 3 (Collection): You must only collect personal information that is reasonably necessary, and individuals must be notified of the collection and its purpose at the time of collection.
- APP 5 (Notification): When you collect a phone number, you should make clear that it may be used for SMS marketing (if that is your intent).
- APP 6 (Use/Disclosure): You generally cannot use a phone number for a purpose materially different from what the person was told when they provided it.
- APP 11 (Security): Contact lists must be secured against unauthorised access.
Note: The Privacy Act currently applies to organisations with an annual turnover exceeding $3 million, but proposed reforms may lower or remove this threshold. Small businesses should stay informed.
Record-Keeping: Your Compliance Safety Net
If you are ever subject to an ACMA investigation, your ability to demonstrate compliance depends entirely on your records. You should maintain:
- A dated record of how and when each contact provided consent (or the basis for inferred consent)
- Copies of the opt-in mechanisms (forms, keywords, scripts) used to collect consent
- A complete opt-out log: who unsubscribed, when, and when they were removed from the send list
- Copies of all commercial messages sent, including timestamps and recipient lists
Modern SMS platforms store much of this automatically. Ensure your platform exports or archives this data in a form you can access if needed.
Practical Compliance Checklist
✅ SMS Compliance Checklist for Australian Businesses
How Australian SMS Platforms Help With Compliance
Choosing the right platform significantly reduces your compliance burden. A good Australian SMS platform should:
- Automatically process STOP/unsubscribe replies and suppress future messages
- Maintain opt-in records and timestamps
- Provide delivery receipts and message logs
- Support dedicated virtual numbers (so recipients can always reply)
- Offer Australian-based support familiar with local regulations
MonsterSMS.ai was built for the Australian market with compliance front-of-mind. Unsubscribe handling is automatic, opt-in records are stored, and every message includes the tools you need to stay on the right side of the Spam Act. It's one less thing to worry about.
Further reading: The ACMA publishes detailed guidance on spam compliance at acma.gov.au. For Privacy Act guidance, visit the Office of the Australian Information Commissioner at oaic.gov.au.
Send Compliant SMS From Day One
Monster SMS handles unsubscribes automatically, stores opt-in records, and provides the tools Australian businesses need to market with confidence.
Start Free — 100 Messages