SMS compliance mistakes that can cost you thousands
The Spam Act 2003 is not a gentle law. The ACMA can and does issue infringement notices and pursue penalties running well into the tens and hundreds of thousands of dollars for businesses that send commercial messages without consent, without proper sender identification, or without a working unsubscribe. Most of the businesses that get caught were not running a scam. They made an avoidable mistake and sent it to a lot of people.
Here are the mistakes that actually cost money, and how to not make them. This is general information rather than legal advice, but every item here is a habit worth fixing before your next campaign goes out.
Mistake one: sending without real consent
This is the big one, and it is usually born of optimism. A business has a spreadsheet of phone numbers collected over years, from quotes, from a competition, from a supplier, from a bought list, and decides to text all of them an offer. The trouble is that having a number is not consent to market to it. Consent has to be express or reasonably inferred from a genuine relationship, and a bought or scraped list is neither.
The fix is to only market to numbers where you can point to the yes. If you cannot say how and when someone agreed to receive marketing from you, do not send them marketing. Collect consent cleanly going forward through keyword opt-ins or a signup form, and keep the record. There is a full walk-through in whether you have consent to text your customers.
Mistake two: an unsubscribe that does not work
The Act requires a functional unsubscribe on every marketing message. Two ways businesses break this:
- No opt-out at all. The message just sells, with no STOP and no link. That is a straightforward breach.
- An opt-out that is ignored. The customer replies STOP, but the next campaign texts them anyway because the list was exported before they opted out, or because one sending tool respects STOP and another does not.
The second failure is sneaky because you believe you are compliant. You have a STOP mechanism, it just leaks. The safe design is one suppression list that every sending path checks, so an opt-out in your inbox is honoured by your campaign tool and your Zapier flow alike. SMS365 handles STOP and START on every number and holds opt-outs in an append-only ledger, and the platform refuses to send to a suppressed number regardless of which door the message comes through. There is more on the mechanics in handling STOP and START the right way.
Test it before you trust it. Send yourself a campaign, reply STOP, and confirm you are actually suppressed on the next send.
Mistake three: the customer cannot tell who sent it
Every marketing message has to identify the sender. A text that just says "50% off this weekend, tap here" with no business name fails the sender identification requirement, and it also gets reported as spam because the recipient has no idea who it is. Name yourself in the message, or send from a registered alphanumeric sender ID that shows your business name on screen. Remember that Australian alphanumeric sender IDs must be registered on the ACMA register before you can use them, which is covered in alphanumeric sender IDs and the ACMA register explained.
Coastline Cafe: Winter menu is here, warm up with a $12 soup and roll combo all week. Reply STOP to opt out.
Business named, offer stated, opt-out included. That single line is compliant on all three counts.
Mistake four: dressing up marketing as a reminder
Transactional messages, a genuine appointment reminder or an invoice, sit outside the marketing rules, so some businesses try to shelter promotions there. They send an "appointment reminder" that also mentions this month's special, or an "invoice" that plugs a referral bonus. The moment a message has a marketing purpose, it is a marketing message and it needs consent, sender identification, and an unsubscribe, no matter what you called it.
Keep the two clean and separate. Your reminders remind. Your offers go to people who opted into offers. Mixing them puts your transactional messages, the ones you rely on, at risk of the marketing rules, which is the opposite of what you want.
Mistake five: no record when someone asks for one
If a complaint reaches the ACMA, the burden is on you to show you had consent and honoured the opt-out. "We definitely asked" is not evidence. A screenshot is not a record. What holds up is a consent trail: an append-only log of every opt-in and opt-out with a number and a timestamp, that you can export and hand over.
This is the mistake that turns a survivable complaint into an expensive one. A business that can produce a clean ledger showing the customer opted in on a given date and never opted out is in a very different position to one that can only shrug. SMS365 keeps consent as an append-only, exportable ledger for exactly this reason. You are not reconstructing history under pressure, you are printing it.
Two smaller traps sit alongside the record-keeping one and are worth naming here. First, sending marketing texts late at night or very early lands as intrusive and drives complaints and opt-outs even when it is technically legal. Keep marketing to reasonable hours in the recipient's time zone. Second, if your list has picked up overseas numbers, be aware that other countries have their own rules, and sending internationally without meaning to also costs more and can trigger blocks. A country allowlist that only permits the destinations you actually serve stops both problems, and SMS365 applies one to every send.
None of this is hard once the system is set up. The businesses that get burned are almost always the ones treating compliance as something to sort out later, sending first and hoping. Turn it around. Collect consent cleanly, send with your name on it, keep a working STOP and a real record, and keep marketing separate from reminders. Do that and the Spam Act stops being a threat and becomes a set of habits you barely notice. If you want to see how the consent tools and country controls are packaged, the pricing page lays it out.
Put this to work with SMS365
Two-way SMS, reminders, an AI assistant that books jobs and chases invoices, and Spam Act compliance built in. Prepaid, no lock-in, Australian-run.
See plans Explore use cases