The Spam Act 2003 explained for SMS
What the Spam Act covers, in plain terms
The Spam Act 2003 is the Australian law that governs commercial electronic messages, which includes marketing and promotional SMS. It is administered by the Australian Communications and Media Authority, the ACMA, and the penalties for getting it seriously wrong run into large fines. For a small business the point is not to be frightened, it is to understand three straightforward rules and build them into how you text.
A message falls under the Act when it is commercial in nature, meaning it promotes or advertises goods, services or a business. A pure appointment reminder or a transactional message, like "your order is ready to collect", is generally not a marketing message. But the safe habit is to treat your marketing texts as squarely covered and follow the rules regardless, because the line can blur and the rules are not onerous.
The Act sets out three obligations for a commercial message: you must have consent, you must identify yourself, and you must provide a working unsubscribe. Get all three right and you are compliant. Miss any one and you are not. That is genuinely most of it.
Rule one: consent
You need the recipient's consent to send them a marketing text. Consent comes in two forms, and both are valid under the Act.
Express consent is when someone has clearly agreed to receive marketing from you: they ticked a box, filled in an opt-in form, texted a keyword to join your list, or told you in person and you recorded it. This is the strongest kind and the one to aim for. A hosted opt-in form, or a keyword people text to join, gives you a clean record of exactly this.
Inferred consent is narrower and more easily misunderstood. It can exist where there is an existing business relationship and the person would reasonably expect to hear from you, or where they have conspicuously published a business number without a statement saying they do not want marketing. Inferred consent is not a free pass to text anyone you have ever dealt with about anything. It is limited, it can lapse, and relying on it heavily is risky. When in doubt, get express consent.
The practical rule: keep a record of how and when you got consent for every contact. If the ACMA ever asks, "they agreed" is not an answer, "they submitted the opt-in form on this date" is. We go deeper on what counts in do you have consent to text customers.
Rule two: identify yourself
Every commercial message must make clear who is sending it. The recipient should be able to tell, from the message, which business is contacting them. You cannot send an anonymous or disguised marketing text.
In practice this is easy. Put your business name in the message. A text that opens "Beacon Electrical:" or signs off with the business name satisfies this, as long as it is genuine and current. The Act also expects your identifying details to be accurate and reasonably able to be contacted, so the sending identity should not be a dead end.
Here is a compliant message that hits all three obligations at once:
Beacon Electrical: Winter safety check special, $99 for a full switchboard inspection this month. Book: [link]. Reply STOP to opt out.
The business is named, so the recipient knows who is texting. The offer is clear. And the opt-out is right there, which brings us to the third rule.
Rule three: a working unsubscribe
Every commercial message must include a functional way to opt out, and it must actually work. For SMS the standard is "reply STOP". When someone texts STOP they must be removed, and the Act requires the unsubscribe to be honoured promptly, within five working days, though in practice a good system does it instantly.
Two things trip businesses up here. The first is an opt-out that does not function. If your STOP handling is broken, or the message tells people to reply STOP but nothing is listening, you have advertised a mechanism that does not work, which is its own breach. This is exactly why a proper platform treats STOP and START as working commands with a consent record kept for each, not as text someone has to read by hand. We cover the mechanics in STOP and START SMS opt-outs.
The second is charging or obstructing the opt-out. Unsubscribing must be free to the recipient beyond the ordinary cost of sending a text, and you cannot make them jump through hoops, log in somewhere, or explain why they are leaving. One word, STOP, and they are out.
A subtle but important point specific to SMS: an instruction like "reply STOP to opt out" is only honest if replies are actually read and acted on. If your number cannot receive messages, or nothing processes the reply, the instruction is a lie, and the Act requires the mechanism to genuinely work. If your setup cannot handle inbound STOP, marketing needs an alternative working unsubscribe, such as a link, and you should fix the underlying gap.
Building compliance in rather than bolting it on
The mistake most businesses make is treating compliance as something to check at the end. The better approach is to make it structural, so a non-compliant message is hard to send in the first place.
That means consent is captured at the point people join, through an opt-in form or a keyword, with the date recorded automatically. It means your business name is part of how you send. And it means STOP and START are handled by the system, with a consent record kept, so you can prove at any time that a person opted in, opted out, or opted back in, and exactly when.
A few habits keep you clean:
- Only text people who have given consent, and know which kind you are relying on for each contact.
- Name your business in every marketing message.
- Include a working opt-out in every marketing message, and make sure it actually works.
- Honour STOP immediately and keep the record.
- Do not buy lists or text numbers you scraped. Bought lists have no consent and are a fast route to trouble.
For the common traps that catch small businesses even when they mean well, see do you have consent to text customers and read it alongside your opt-out setup. None of this is complicated, but all of it matters, and the businesses that build it in from the start never have to think about it again.
The Spam Act is not there to stop you texting your customers. It is there to stop unwanted, anonymous, inescapable marketing, which is exactly the kind of texting you do not want to be doing anyway. Follow the three rules and compliant messaging is simply good messaging. If you want a platform that keeps consent records and handles STOP and START for you, our pricing page lays out how it works, prepaid with no lock-in.
Put this to work with SMS365
Two-way SMS, reminders, an AI assistant that books jobs and chases invoices, and Spam Act compliance built in. Prepaid, no lock-in, Australian-run.
See plans Explore use cases