Home / Blog
  • Guides / SMS Opt-In Requirements in Australia: Get It Right
  • ⚠️ Important Disclaimer

    This article is a general educational overview of Australian SMS marketing compliance. It does not constitute legal advice. Laws and ACMA guidance may change. For specific advice about your business circumstances, consult a qualified legal professional with expertise in Australian telecommunications and privacy law.

    Every business that sends commercial SMS messages in Australia must comply with the Spam Act 2003 and the Privacy Act 1988. The penalties for non-compliance are serious - up to $2.22 million per day for serious contraventions - and the Australian Communications and Media Authority (ACMA) actively investigates complaints.

    Yet many businesses run afoul of these laws not out of malice, but out of ignorance or ambiguity. This guide explains the rules clearly, provides practical examples and templates, and covers the key questions businesses ask about SMS consent in Australia.

    Why SMS Opt-In Matters

    Opt-in isn't just a legal obligation - it's the foundation of effective SMS marketing. A list of people who have actively chosen to receive your messages will:

    The businesses that treat SMS compliance as a marketing quality standard - rather than a box-ticking exercise - build the most valuable databases over time.

    The Three Rules of Australian SMS Marketing

    The Spam Act 2003 sets three core obligations for anyone sending commercial electronic messages (including SMS) in Australia:

    1. Consent - You must have the recipient's consent (either express or inferred) before sending them a commercial SMS.
    2. Identify - Every marketing message must clearly identify the sending organisation and provide accurate contact details.
    3. Unsubscribe - Every marketing message must include a working, free unsubscribe mechanism, and opt-out requests must be honoured promptly.

    All three requirements must be met. Meeting one or two is not sufficient.

    Express Consent vs Inferred Consent

    The Spam Act recognises two types of consent. Understanding the difference is critical because inferred consent has important limitations.

    Inferred Consent in Practice

    Inferred consent is commonly misunderstood. It does not mean "anyone who has ever given us their phone number". It means consent that can be reasonably inferred from the person's conduct and the existing relationship.

    For example: if a customer purchased from your online store and provided their mobile number as part of the checkout process, inferred consent may exist to send them messages directly related to that transaction (e.g., order updates, service follow-ups). It does not automatically extend to all future marketing.

    If in doubt, seek express consent. It's cleaner, better for your business, and makes record-keeping simpler.

    How to Collect SMS Consent

    1. Website Opt-In Forms

    The most scalable method. Include a mobile phone field with a clearly labelled checkbox: "I agree to receive SMS marketing messages from [Business Name]. I can unsubscribe at any time by replying STOP."

    Critical: the checkbox must be:

    Example - Web Form Consent Wording
    ☐ Yes, I'd like to receive SMS updates including special offers and new arrivals from [Business Name]. You can unsubscribe at any time by replying STOP to any message. Message frequency varies. Standard message rates may apply.
    Keep it brief, honest, and specific about what kind of messages will be sent.

    2. In-Store Opt-In

    For bricks-and-mortar businesses, in-store consent can be collected via:

    Verbal consent is valid under the Spam Act, but it is the hardest to prove if challenged. If you collect consent verbally, record it immediately in your CRM or SMS platform with a timestamp and note of the circumstances.

    Example - In-Store Loyalty Sign-Up Form
    Join the [Store Name] Rewards Club Name: _______________________ Mobile: ______________________ Email: ________________________ ☐ I'd like to receive exclusive SMS offers and loyalty updates from [Store Name]. I understand I can unsubscribe at any time by replying STOP. Signature: _________________ Date: ___________
    Always include a signature line for paper forms - this is your consent record.

    3. Keyword Opt-In (SMS)

    Keyword opt-in is one of the cleanest consent mechanisms available: the customer actively texts a keyword to your number, and you respond with a confirmation. This creates an auditable trail - the inbound message is proof of intent.

    Example - Keyword Opt-In Confirmation Message
    Thanks for joining [Business Name] SMS updates! You'll receive exclusive offers and news. Msg freq varies. To stop receiving messages, reply STOP at any time. Help: reply HELP or call [number].
    Send immediately upon receiving the opt-in keyword. This doubles as the consent confirmation record.

    4. Double Opt-In

    Double opt-in adds a confirmation step after the initial sign-up. After someone provides their number, they receive an SMS asking them to confirm their consent (e.g., "Reply YES to confirm you'd like SMS updates from [Business]. Reply NO to cancel."). Only confirmed numbers are added to your active list.

    Double opt-in is not legally required in Australia (unlike the GDPR regime in Europe), but it is best practice because it:

    Example - Double Opt-In Confirmation SMS
    Hi! To confirm you'd like SMS offers from [Business Name], reply YES. Reply NO to cancel. This is a one-time confirmation - we won't message you again without it.
    Keep the confirmation message simple and non-commercial - it's a verification request, not a marketing message.

    Record-Keeping Requirements

    Under the Spam Act, you must be able to demonstrate consent if challenged. This means keeping records of:

    How long should you keep records? The general advice is at least three years, consistent with broader commercial record-keeping standards. Consent records should be retained for as long as you're sending to that number, plus a reasonable period after.

    ✅ Good Practice: CRM Notes

    Make a habit of recording the consent source in your CRM or SMS platform for every contact - e.g., "Opted in via website checkout 14/03/2025" or "Signed loyalty form in-store 22/06/2025". A structured note on every record makes compliance audit trivial.

    Opt-Out and Unsubscribe Obligations

    Every commercial SMS you send must include a simple, working opt-out mechanism. Under the Spam Act, you must:

    🚨 Critical: Process STOP Requests Immediately

    While the law allows up to 5 business days, best practice is to process STOP requests instantly. Most modern SMS platforms (including Monster SMS) handle this automatically - the number is immediately added to a suppression list and excluded from all future campaigns. Manual processing is a risk you don't need to take.

    Opt-Out Wording Options

    Standard opt-out (standalone)
    Reply STOP to unsubscribe.
    Standard opt-out (with help option)
    Reply STOP to unsubscribe or HELP for info.
    Extended opt-out (for new subscribers)
    To stop receiving messages from [Business Name], reply STOP at any time. No cost to unsubscribe.

    What You Can and Can't Do

    ✅ You CAN
    • Send to customers who have expressly opted in
    • Send transactional messages (order confirmations, appointment reminders) without marketing consent
    • Use inferred consent for messages closely related to a prior transaction
    • Collect consent via web forms, in-store, or keyword opt-in
    • Send during reasonable hours (8am–9pm weekdays, 9am–5pm weekends)
    • Re-engage lapsed subscribers who opted in (ensure consent hasn't lapsed)
    ❌ You CANNOT
    • Send marketing SMS without prior consent
    • Purchase third-party SMS lists and blast them
    • Use pre-ticked consent boxes
    • Bundle SMS consent into general T&Cs without a specific clear option
    • Ignore or delay STOP requests
    • Charge for unsubscribing
    • Send messages without identifying your organisation
    • Re-add opted-out numbers to your list

    Penalties for Non-Compliance

    The ACMA takes spam complaints seriously and has real enforcement powers. Penalties under the Spam Act are substantial:

    Contravention Type Maximum Penalty
    Sending commercial messages without consent Up to $2.22 million per day
    Failing to include an unsubscribe mechanism Up to $2.22 million per day
    Failing to action an unsubscribe request within 5 business days Up to $2.22 million per day
    Sending messages without identifying the sender Up to $2.22 million per day
    Assisting someone else to spam (aiding and abetting) Penalties also apply to individuals

    These are the maximum penalties - in practice, ACMA typically pursues smaller businesses with warnings and enforceable undertakings before escalating to fines. However, the ACMA has imposed multi-million dollar penalties on Australian businesses in recent years for repeated or egregious spam violations.

    Beyond direct fines, non-compliance can result in: formal warnings, enforceable undertakings (binding compliance plans), injunctions, reputational damage from public enforcement action, and civil liability from affected recipients.

    📋 ACMA Compliance Investigations

    The ACMA receives spam complaints through its Spam SMS Reporting Service. When complaints are received about a particular sender, ACMA can request records, audit compliance, and issue formal notices. Most compliance investigations begin with a single complaint from a member of the public. A robust consent and records management system is your best protection.

    Consent Management Tools

    Managing consent manually across a large SMS database is error-prone and time-consuming. The right tools make it automatic and auditable. When evaluating an SMS platform for compliance, look for:

    Monster SMS is built for the Australian market with all of the above: automatic STOP processing, suppression lists, consent tracking, and Australian data hosting. Compliance is baked into the platform rather than bolted on.

    Practical Examples and Scenarios

    Scenario 1: Retail Customer Who Purchased Online

    Situation: A customer bought from your online store in December and provided their mobile number at checkout. Can you add them to your SMS marketing list?

    Answer: Not automatically. If they did not specifically opt in to SMS marketing during checkout (e.g., tick a clearly labelled checkbox), you only have implied consent for transactional messages related to that purchase. To send ongoing marketing, you need to seek express consent - for example, in your post-purchase email, invite them to opt in to SMS updates.

    Scenario 2: Networking Event Business Card

    Situation: You collected 50 business cards at a trade event. Can you text all of them about your promotion?

    Answer: Generally, no - or only very narrowly. Exchanging business cards in a business context creates limited inferred consent for relevant business-to-business communications, but it does not extend to broad promotional SMS campaigns. Sending a mass promotional SMS to business card contacts is high-risk and likely non-compliant. The safer approach is to email them and offer an SMS opt-in.

    Scenario 3: Customer Requests a Quote via SMS

    Situation: A customer texts your business to request a quote. You respond with the quote. Can you then follow up with promotional messages?

    Answer: There is inferred consent to respond to their enquiry and follow up on the quote in context. However, this does not extend to unrelated promotional SMS campaigns. To add them to your marketing list, you would need to seek express consent - either in conversation or via a follow-up form.

    💡 The Golden Rule

    When in doubt, ask. Sending a quick opt-in request - "Want to receive our offers and updates via SMS? Reply YES to join, or simply ignore this message." - is far safer than assuming consent exists. And a database of people who actively said YES is worth more than any purchased list.

    SMS Compliance Checklist

    Use this checklist to audit your SMS marketing programme:

    Getting Started the Right Way

    Building a compliant SMS programme from day one is far easier than retrofitting compliance onto an existing database. If you're starting fresh, here's the ideal sequence:

    1. Set up your SMS platform with automatic STOP handling and suppression lists configured.
    2. Build opt-in points: website form, in-store sign-up, keyword opt-in, loyalty programme.
    3. Implement double opt-in for web and keyword channels.
    4. Tag every subscriber with their consent source and date in your CRM.
    5. Create templates that include your business identification and STOP instruction in every message.
    6. Train any staff who collect SMS consents on what valid consent requires.
    7. Review your database quarterly for hygiene - remove inactive numbers and verify consent records.

    If you're inheriting an existing database, the safest approach is a re-engagement and re-consent campaign before running any new marketing. Send a single message that identifies your business and invites recipients to confirm they want to keep receiving messages - and move only those who confirm to your active list.

    Monster SMS is designed to make this entire process manageable. With built-in compliance tools, Australian data hosting, and automatic opt-out handling, the platform does the heavy lifting so you can focus on great messaging rather than compliance anxiety.

    Build a Compliant SMS List That Actually Converts

    Monster SMS handles opt-outs automatically, tracks consent, and keeps your data in Australia. Start free - 100 messages included.

    Start Free - 100 Messages

    Australian-hosted · Auto STOP processing · Spam Act compliant · No credit card required