LinkedIn Outreach: What Australian Law Requires, and What LinkedIn Requires

Two different rulebooks, often confused
Not legal advice. General information only. Verify with a lawyer, and check current ACMA and OAIC guidance.
The distinction that matters
LinkedIn's User Agreement is a contract, not legislation. Breaching it can cost you your account. It cannot get you fined.
Australian law is separate. It governs the personal information you collect and how you use it, regardless of which platform you're on.
Most people conflate these. They're different obligations with different consequences.
Part 1: The law
Privacy Act 1988 (Cth)
The Act and the Australian Privacy Principles govern personal information. A person's name, job title and work contact details are personal information.
The APPs most relevant to outreach:
- APP 3: Only collect personal information reasonably necessary for your functions
- APP 5: Take reasonable steps to notify a person when you collect their personal information, including when you collect it from someone else
- APP 6: Only use or disclose it for the purpose you collected it
- APP 10: Take reasonable steps to ensure it is accurate, up to date and complete
- APP 11: Take reasonable steps to protect it, and destroy or de-identify it when no longer needed
The Notifiable Data Breaches scheme under the same Act requires you to notify the OAIC and affected individuals of eligible data breaches.
A prospect database is personal information for these purposes.
The Act has historically included a small business exemption based on annual turnover. Privacy law in Australia has been under reform, confirm the current position rather than assuming the exemption applies to you.
Regulator: Office of the Australian Information Commissioner (OAIC).
Spam Act 2003 (Cth)
The Spam Act applies to commercial electronic messages: email, SMS, MMS and instant messaging.
Whether a LinkedIn direct message falls within that definition has not been settled by an Australian court or by published ACMA guidance. Do not assume it does or doesn't.
The safe approach is to meet the Spam Act's three requirements anyway (consent, sender identification, and a way to opt out) because doing so costs nothing.
Regulator: Australian Communications and Media Authority (ACMA).
Part 2: LinkedIn's own rules
LinkedIn's User Agreement prohibits, among other things:
- Using bots or other automated methods to access the service
- Scraping or copying profiles and data
- Creating a false identity or misrepresenting yourself
- Sharing your account credentials with a third party
Every automation tool on the market operates against these terms. That is worth stating plainly rather than pretending otherwise.
LinkedIn does not publish rate limits, acceptance-rate thresholds or the specific triggers for account restrictions.
Anyone who quotes exact numbers is quoting practitioner experience, not policy, including this article.
Part 3: What we do in practice
This section is operating practice, not law or platform policy.
Suppression across everything
When someone asks not to be contacted, that goes on a central list applied to every campaign and every channel, email, LinkedIn, SMS, phone.
Not per campaign, not per client.
Source you can name
Every contact should come from somewhere you could state out loud if asked.
"Your firm's website, on the team page" is an answer.
"We bought a list" is not.
Relevance to the role
Contact people about things connected to what they actually do.
This is both the legal footing for inferred consent under the Spam Act and the reason campaigns work.
Warm the account
Two weeks of ordinary activity before any outreach on a dormant profile.
Conservative volume, slowly increased
We ramp over weeks rather than starting at capacity.
Withdraw stale requests
Withdraw stale requests rather than letting hundreds sit pending.
Data handling
Prospect data held securely, refreshed, and deleted when the engagement ends.
The client owns it.
The checklist
Legal
☐ You can state where each contact came from
☐ Collection is limited to what you actually need
☐ Data held securely and destroyed when finished with
☐ Suppression requests honoured across all channels and campaigns
☐ Current Privacy Act obligations confirmed for your business
Platform
☐ You understand that automation breaches the User Agreement
☐ One tool, one location, consistent with your normal usage
☐ Volume ramped rather than started at capacity
Summary
Two rulebooks.
LinkedIn's costs you an account. Australian law costs you more than that.
Neither is usually what causes damage.
What causes damage is contacting people who have no reason to hear from you, in volumes that make checking impossible, which is also why those campaigns don't work.
Key legislation: Privacy Act 1988 (Cth) · Australian Privacy Principles · Notifiable Data Breaches scheme · Spam Act 2003 (Cth)
Regulators: OAIC · ACMA
Related Blog
Ready to Build
Your Pipeline?




