This article is a general educational overview of Australian SMS marketing compliance. It does not constitute legal advice. Laws and ACMA guidance may change. For specific advice about your business circumstances, consult a qualified legal professional with expertise in Australian telecommunications and privacy law.
Every business that sends commercial SMS messages in Australia must comply with the Spam Act 2003 and the Privacy Act 1988. The penalties for non-compliance are serious - up to $2.22 million per day for serious contraventions - and the Australian Communications and Media Authority (ACMA) actively investigates complaints.
Yet many businesses run afoul of these laws not out of malice, but out of ignorance or ambiguity. This guide explains the rules clearly, provides practical examples and templates, and covers the key questions businesses ask about SMS consent in Australia.
Why SMS Opt-In Matters
Opt-in isn't just a legal obligation - it's the foundation of effective SMS marketing. A list of people who have actively chosen to receive your messages will:
- Have dramatically higher engagement rates than a purchased or scraped list
- Generate fewer opt-outs, keeping your list healthy and your deliverability strong
- Pose significantly lower complaint risk to regulators
- Reflect genuinely interested prospects - people likely to buy
The businesses that treat SMS compliance as a marketing quality standard - rather than a box-ticking exercise - build the most valuable databases over time.
The Three Rules of Australian SMS Marketing
The Spam Act 2003 sets three core obligations for anyone sending commercial electronic messages (including SMS) in Australia:
- Consent - You must have the recipient's consent (either express or inferred) before sending them a commercial SMS.
- Identify - Every marketing message must clearly identify the sending organisation and provide accurate contact details.
- Unsubscribe - Every marketing message must include a working, free unsubscribe mechanism, and opt-out requests must be honoured promptly.
All three requirements must be met. Meeting one or two is not sufficient.
Express Consent vs Inferred Consent
The Spam Act recognises two types of consent. Understanding the difference is critical because inferred consent has important limitations.
Inferred Consent in Practice
Inferred consent is commonly misunderstood. It does not mean "anyone who has ever given us their phone number". It means consent that can be reasonably inferred from the person's conduct and the existing relationship.
For example: if a customer purchased from your online store and provided their mobile number as part of the checkout process, inferred consent may exist to send them messages directly related to that transaction (e.g., order updates, service follow-ups). It does not automatically extend to all future marketing.
If in doubt, seek express consent. It's cleaner, better for your business, and makes record-keeping simpler.
How to Collect SMS Consent
1. Website Opt-In Forms
The most scalable method. Include a mobile phone field with a clearly labelled checkbox: "I agree to receive SMS marketing messages from [Business Name]. I can unsubscribe at any time by replying STOP."
Critical: the checkbox must be:
- Unticked by default - pre-ticked boxes do not constitute valid consent
- Clearly labelled - the purpose of the consent must be explicit
- Separate from other consents - bundling SMS consent into general T&Cs is problematic
- Voluntary - don't require SMS opt-in to complete a purchase or access a service
2. In-Store Opt-In
For bricks-and-mortar businesses, in-store consent can be collected via:
- Written sign-up forms at point of sale, with a clear consent checkbox
- Loyalty programme enrolment forms that include an SMS consent field
- Staff verbally offering SMS updates and recording consent (with the customer's knowledge)
- QR codes on signage linking to a digital opt-in form
Verbal consent is valid under the Spam Act, but it is the hardest to prove if challenged. If you collect consent verbally, record it immediately in your CRM or SMS platform with a timestamp and note of the circumstances.
3. Keyword Opt-In (SMS)
Keyword opt-in is one of the cleanest consent mechanisms available: the customer actively texts a keyword to your number, and you respond with a confirmation. This creates an auditable trail - the inbound message is proof of intent.
4. Double Opt-In
Double opt-in adds a confirmation step after the initial sign-up. After someone provides their number, they receive an SMS asking them to confirm their consent (e.g., "Reply YES to confirm you'd like SMS updates from [Business]. Reply NO to cancel."). Only confirmed numbers are added to your active list.
Double opt-in is not legally required in Australia (unlike the GDPR regime in Europe), but it is best practice because it:
- Verifies the number is active and belongs to the person who opted in
- Creates an indisputable record of consent - you have both the opt-in request AND the confirmation
- Reduces spam complaints (people who accidentally opt in will not confirm)
- Improves list quality - only engaged subscribers make it through
Record-Keeping Requirements
Under the Spam Act, you must be able to demonstrate consent if challenged. This means keeping records of:
- How and when consent was collected - the specific form, mechanism, or conversation through which each subscriber opted in.
- The consent wording - what exactly did the subscriber agree to? Keep copies of all form versions used over time.
- Date and time of consent - timestamp every opt-in, ideally with IP address for web forms.
- Opt-out records - when someone unsubscribed, by what mechanism, and when processing was completed.
- List sources - for every segment of your database, be able to explain where the numbers came from and what consent exists.
How long should you keep records? The general advice is at least three years, consistent with broader commercial record-keeping standards. Consent records should be retained for as long as you're sending to that number, plus a reasonable period after.
Make a habit of recording the consent source in your CRM or SMS platform for every contact - e.g., "Opted in via website checkout 14/03/2025" or "Signed loyalty form in-store 22/06/2025". A structured note on every record makes compliance audit trivial.
Opt-Out and Unsubscribe Obligations
Every commercial SMS you send must include a simple, working opt-out mechanism. Under the Spam Act, you must:
- Include an unsubscribe option in every marketing message - "Reply STOP to unsubscribe" is the standard.
- Process opt-out requests within 5 business days of receiving them.
- Not charge the recipient any fee to unsubscribe - it must be free.
- Not send any further commercial messages to that number after the opt-out is processed.
- Retain the opt-out on your suppression list indefinitely - even if the person later re-opts in, their opt-out history should be recorded.
While the law allows up to 5 business days, best practice is to process STOP requests instantly. Most modern SMS platforms (including Monster SMS) handle this automatically - the number is immediately added to a suppression list and excluded from all future campaigns. Manual processing is a risk you don't need to take.
Opt-Out Wording Options
What You Can and Can't Do
- Send to customers who have expressly opted in
- Send transactional messages (order confirmations, appointment reminders) without marketing consent
- Use inferred consent for messages closely related to a prior transaction
- Collect consent via web forms, in-store, or keyword opt-in
- Send during reasonable hours (8am–9pm weekdays, 9am–5pm weekends)
- Re-engage lapsed subscribers who opted in (ensure consent hasn't lapsed)
- Send marketing SMS without prior consent
- Purchase third-party SMS lists and blast them
- Use pre-ticked consent boxes
- Bundle SMS consent into general T&Cs without a specific clear option
- Ignore or delay STOP requests
- Charge for unsubscribing
- Send messages without identifying your organisation
- Re-add opted-out numbers to your list
Penalties for Non-Compliance
The ACMA takes spam complaints seriously and has real enforcement powers. Penalties under the Spam Act are substantial:
| Contravention Type | Maximum Penalty |
|---|---|
| Sending commercial messages without consent | Up to $2.22 million per day |
| Failing to include an unsubscribe mechanism | Up to $2.22 million per day |
| Failing to action an unsubscribe request within 5 business days | Up to $2.22 million per day |
| Sending messages without identifying the sender | Up to $2.22 million per day |
| Assisting someone else to spam (aiding and abetting) | Penalties also apply to individuals |
These are the maximum penalties - in practice, ACMA typically pursues smaller businesses with warnings and enforceable undertakings before escalating to fines. However, the ACMA has imposed multi-million dollar penalties on Australian businesses in recent years for repeated or egregious spam violations.
Beyond direct fines, non-compliance can result in: formal warnings, enforceable undertakings (binding compliance plans), injunctions, reputational damage from public enforcement action, and civil liability from affected recipients.
The ACMA receives spam complaints through its Spam SMS Reporting Service. When complaints are received about a particular sender, ACMA can request records, audit compliance, and issue formal notices. Most compliance investigations begin with a single complaint from a member of the public. A robust consent and records management system is your best protection.
Consent Management Tools
Managing consent manually across a large SMS database is error-prone and time-consuming. The right tools make it automatic and auditable. When evaluating an SMS platform for compliance, look for:
- Automatic STOP processing - STOP replies should instantly suppress the number, with no manual action required.
- Suppression list management - opted-out numbers should be stored permanently and automatically excluded from all future campaigns.
- Consent source recording - the ability to tag contacts with how and when they opted in.
- Opt-in confirmation flows - built-in support for double opt-in if required.
- Audit logs - exportable records of all opt-ins, opt-outs, and message history for compliance auditing.
- Australian hosting - data sovereignty matters; ensure your subscriber data is stored in Australia under Australian privacy law.
Monster SMS is built for the Australian market with all of the above: automatic STOP processing, suppression lists, consent tracking, and Australian data hosting. Compliance is baked into the platform rather than bolted on.
Practical Examples and Scenarios
Scenario 1: Retail Customer Who Purchased Online
Situation: A customer bought from your online store in December and provided their mobile number at checkout. Can you add them to your SMS marketing list?
Answer: Not automatically. If they did not specifically opt in to SMS marketing during checkout (e.g., tick a clearly labelled checkbox), you only have implied consent for transactional messages related to that purchase. To send ongoing marketing, you need to seek express consent - for example, in your post-purchase email, invite them to opt in to SMS updates.
Scenario 2: Networking Event Business Card
Situation: You collected 50 business cards at a trade event. Can you text all of them about your promotion?
Answer: Generally, no - or only very narrowly. Exchanging business cards in a business context creates limited inferred consent for relevant business-to-business communications, but it does not extend to broad promotional SMS campaigns. Sending a mass promotional SMS to business card contacts is high-risk and likely non-compliant. The safer approach is to email them and offer an SMS opt-in.
Scenario 3: Customer Requests a Quote via SMS
Situation: A customer texts your business to request a quote. You respond with the quote. Can you then follow up with promotional messages?
Answer: There is inferred consent to respond to their enquiry and follow up on the quote in context. However, this does not extend to unrelated promotional SMS campaigns. To add them to your marketing list, you would need to seek express consent - either in conversation or via a follow-up form.
When in doubt, ask. Sending a quick opt-in request - "Want to receive our offers and updates via SMS? Reply YES to join, or simply ignore this message." - is far safer than assuming consent exists. And a database of people who actively said YES is worth more than any purchased list.
SMS Compliance Checklist
Use this checklist to audit your SMS marketing programme:
- Every number on my SMS list has documented express or valid inferred consent.
- I can tell you exactly how and when each subscriber opted in.
- My opt-in forms use an un-ticked checkbox with clear, specific wording.
- Every marketing SMS includes my business name and contact details.
- Every marketing SMS includes a STOP unsubscribe instruction.
- STOP requests are processed automatically (or within 5 business days at most).
- Opted-out numbers are stored permanently on a suppression list.
- I do not send marketing SMS before 8am or after 9pm on weekdays.
- I do not send marketing SMS before 9am or after 5pm on weekends.
- I have not purchased or used any third-party SMS lists.
- My consent records are kept for at least three years.
- I review my compliance practices at least annually.
Getting Started the Right Way
Building a compliant SMS programme from day one is far easier than retrofitting compliance onto an existing database. If you're starting fresh, here's the ideal sequence:
- Set up your SMS platform with automatic STOP handling and suppression lists configured.
- Build opt-in points: website form, in-store sign-up, keyword opt-in, loyalty programme.
- Implement double opt-in for web and keyword channels.
- Tag every subscriber with their consent source and date in your CRM.
- Create templates that include your business identification and STOP instruction in every message.
- Train any staff who collect SMS consents on what valid consent requires.
- Review your database quarterly for hygiene - remove inactive numbers and verify consent records.
If you're inheriting an existing database, the safest approach is a re-engagement and re-consent campaign before running any new marketing. Send a single message that identifies your business and invites recipients to confirm they want to keep receiving messages - and move only those who confirm to your active list.
Monster SMS is designed to make this entire process manageable. With built-in compliance tools, Australian data hosting, and automatic opt-out handling, the platform does the heavy lifting so you can focus on great messaging rather than compliance anxiety.
Build a Compliant SMS List That Actually Converts
Monster SMS handles opt-outs automatically, tracks consent, and keeps your data in Australia. Start free - 100 messages included.
Start Free - 100 MessagesAustralian-hosted · Auto STOP processing · Spam Act compliant · No credit card required