Cold Email in Australia: What the Spam Act and Privacy Act Require

A practical guide to cold email laws in Australia. Learn Spam Act 2003 requirements, Privacy Act obligations, consent rules, unsubscribe compliance, and deliverability best practices.
Top authors
Ima Miri
Founder

The legislation, then the practice

Not legal advice. General information only. Verify with a lawyer and check current ACMA and OAIC guidance.

Part 1: The law

Spam Act 2003 (Cth)

You can lawfully email someone who has never heard of you and never opted in. That is worth stating plainly, because most people assume the opposite.

The Spam Act does not prohibit commercial email. It prohibits sending a commercial electronic message without meeting three requirements. The first of those, consent, does not necessarily mean the person explicitly said yes.

1. Consent: express or inferred

Express consent is where the recipient has directly agreed to receive messages.

Inferred consent does not require explicit agreement. It can arise from an existing business relationship or from the conspicuous publication of a work email address.

In broad terms, consent may be inferred where:

  1. A work-related email address is conspicuously published, for example on a company website, team page, or public directory
  2. It is not accompanied by a statement that unsolicited commercial messages are unwelcome
  3. Your message is relevant to the role or functions of that person

This is the provision that makes B2B cold outreach lawful in Australia. A person who has never heard of you, has no relationship with you, and did not opt in may still be contacted on this basis.

The relevance requirement is the key constraint. A practice manager’s published address may imply consent for messages about practice operations. It does not imply consent to receive any type of commercial message.

The question most people overlook: was the address actually published?

Many enrichment tools generate addresses using patterns, for example first.last@company.com, rather than sourcing a publicly listed address. Verification confirms an address works. It does not confirm that it was ever publicly published.

Inferred consent relies on conspicuous publication. If you cannot point to where the address was published, your legal basis may be weaker.

This area is not fully settled in public guidance and is worth confirming with a lawyer. In practice, it is a common gap in outbound systems and a strong reason to prioritise verifiable sources.

2. Identify the sender

The message must clearly and accurately identify who authorised the sending and include valid contact details.

3. Functional unsubscribe

The message must include a functional unsubscribe facility. Unsubscribe requests must be honoured within five working days, and the facility must remain functional for at least 30 days after the message is sent.

Regulator: ACMA. Spam can be reported to ACMA by the recipient.

Privacy Act 1988 (Cth)

The Australian Privacy Principles (APPs) govern personal information. A name and work email address are considered personal information.

APPRequirementAPP 3Collect only what is reasonably necessaryAPP 5Take reasonable steps to notify individuals you have collected their data, including from third partiesAPP 6Use information only for the purpose it was collectedAPP 10Ensure data is accurate, up to date, and completeAPP 11Secure data and destroy or de-identify when no longer needed

The Notifiable Data Breaches (NDB) scheme requires eligible breaches to be reported to the OAIC and affected individuals.

The Act has historically included a small business exemption based on turnover. Privacy law in Australia is under reform. Confirm your current obligations.

Regulator: OAIC.

Part 2: Provider requirements (not law, but enforced)

Email providers set their own rules and enforce them at the infrastructure level.

Since February 2024, Google and Microsoft require bulk senders to:

  • Authenticate with SPF, DKIM, and DMARC
  • Provide one-click unsubscribe
  • Maintain spam complaint rates below 0.3%

These are operational requirements, not legislation. Failing them results in blocked or rejected emails regardless of legal compliance.

Blocklists such as Spamhaus and SpamCop are independently operated. Listing can prevent delivery before a message is ever seen.

Part 3: What we do in practice

Operating practice, not law.

Separate sending domains
Outbound email is never sent from the primary business domain. This isolates deliverability risk.

Authentication first
SPF, DKIM, and DMARC are configured and verified before any sending begins.

Gradual volume ramp-up
New mailboxes start with low volume and increase over time to build reputation.

Pre-send verification
Bounce prevention is critical. Invalid addresses are the most avoidable source of domain damage.

Central suppression
Unsubscribes apply globally across all campaigns and clients, permanently. Not just within a single sequence.

Traceable data sources
Every contact should come from a source you can clearly explain. If you cannot answer “where did you get my details?” in one sentence, do not send.

Client ownership
All lists, replies, and data belong to the client and remain with them.

The checklist

Spam Act

  • Consent basis identified for every contact, express, existing relationship, or conspicuous publication
  • Message content relevant to the role tied to the published address
  • Sender clearly identified with valid contact details
  • Functional unsubscribe included in every message
  • Unsubscribes processed within five working days and applied globally

Privacy Act

  • Data collection limited to what is necessary
  • Reasonable steps taken to notify individuals
  • Data kept accurate, secure, and deleted when no longer needed
  • Data breach response process in place
  • Current legal obligations confirmed

Deliverability

  • Separate sending domains
  • SPF, DKIM, and DMARC configured and verified
  • One-click unsubscribe enabled
  • Contact lists verified before sending

Summary

Cold email is lawful in Australia. The Spam Act requires a valid consent basis, clear identification, and a working unsubscribe. The Privacy Act governs how personal data is collected, used, and stored.

Most issues are not legal. They are operational. Poor targeting and unverified data create deliverability problems, which can quickly become compliance risks.

Key legislation: Spam Act 2003 (Cth), Spam Regulations, Privacy Act 1988 (Cth), Australian Privacy Principles, Notifiable Data Breaches scheme
Regulators: ACMA, OAIC

Related Blog

We help brands grow through strategic design and digital experiences. From brand identity to powerful websites, our services are Impression.

Ready to Build
Your Pipeline?

Book A Pipeline Audit
connecting the dotconnecting dots