Compliance

GDPR vs the Spam Act 2003: cold email compared

Done-for-you B2B outbound · Original data

In short

GDPR and the ePrivacy Directive protect personal data. The Spam Act 2003 regulates commercial electronic messages. They overlap on cold email without being versions of the same law: Australia runs on a consent test with no legitimate interest equivalent, sets a fixed five business day unsubscribe clock, and gives recipients no GDPR-style data rights at all.

On this page
  1. Two regimes built for different problems
  2. Legal basis: legitimate interest and soft opt-in against consent
  3. Identifying yourself: what each regime demands
  4. Unsubscribe and consent withdrawal timing
  5. Data subject rights exist under one regime and not the other
  6. Regulators and how each one enforces
  7. Penalties: turnover-linked fines against penalty units
  8. What a European sender actually changes for an Australian list

Two regimes built for different problems

GDPR and the ePrivacy Directive protect personal data. The Spam Act 2003 (Cth) regulates commercial electronic messages. They overlap on cold email without being the same law, and a European sender who assumes the Australian rules are simply a stricter or looser version of GDPR will get the compliance basis wrong in both directions.

The table below lines up the two regimes on the points that actually change how a cold email campaign gets built and run.

EU: GDPR and ePrivacyAustralia: Spam Act 2003
Legal basisLegitimate interest, GDPR Recital 47, or the ePrivacy soft opt-in for an existing customer relationshipConsent, express or inferred from a conspicuously published, relevant business address
B2B cold emailGenerally permitted on legitimate interest, strictness varies by member statePermitted only where a consent basis under the Act applies
Sender identificationePrivacy Article 13 requires clear identification and a valid address to object toSection 17 requires honest identification and accurate contact information
Unsubscribe or objectionFree and easy, offered at collection and with every message, no fixed day count in the Directive textFunctional facility required by section 18, consent withdrawal effective five business days after the request, Schedule 2
Data subject rightsAccess, correction, erasure and objection, under the RegulationNone. The Act regulates messaging conduct, not data handling
RegulatorThe national data protection authority in each member stateThe Australian Communications and Media Authority, ACMA
PenaltiesAdministrative fines set at EU level, scaled by severityPenalty units, currently $364 each, up to 2,000 units for multiple same-day contraventions

GDPR Recital 47 treats direct marketing as capable of resting on a legitimate interest, provided the interests or fundamental rights of the person contacted are not overridden and the contact stays within what that person could reasonably expect. That is a balancing test, not a fixed rule, which is why practice varies by member state, with Germany and France applying it more strictly to B2B email than the UK or the Netherlands do.

The ePrivacy Directive’s Article 13 soft opt-in sits alongside legitimate interest for a narrower case: the sender obtained the address in the context of selling a product or service, is marketing its own similar products or services, and gave the customer a free and easy way to object both at collection and with every later message.

The Spam Act runs on consent instead of interest. Express consent exists where the account holder actually agreed to receive messages. Inferred consent exists under Schedule 2, clause 4, where the address was conspicuously published, it is reasonable to assume the publication carried the account holder’s agreement, and the message is relevant to the recipient’s work-related role. There is no legitimate interest equivalent, and no balancing test on the Australian side. Either the consent basis is there, or it is not.

Identifying yourself: what each regime demands

Both regimes require honest identification, but they anchor the requirement differently.

ePrivacy Article 13 requires that unsolicited commercial communications are identifiable as such, and that the sender gives the recipient a valid address to object to future messages. GDPR’s transparency obligations, which apply whenever personal data is processed for marketing, add further disclosure duties about who is processing the data and why.

Section 17 of the Spam Act is narrower and more mechanical: the message must clearly and accurately identify the individual or organisation that authorised it, and include accurate information for how the recipient can readily contact that individual or organisation. It does not ask why the data is being processed. It asks who sent the message and how to reach them, a lower bar to clear but not one that can be skipped.

The ePrivacy soft opt-in requires an objection mechanism offered at collection and repeated with every message, but the Directive text does not set a specific number of days within which an objection has to take effect.

The Spam Act does. Section 18 requires the unsubscribe address in a message to stay functional for at least 30 days after that message was sent. Separately, Schedule 2, clause 6(1) sets the moment consent withdrawal takes effect: five business days after the unsubscribe request is sent. Any further commercial electronic message to that address after the five days is a fresh breach of section 16, independent of the consent basis that applied to the original message.

A European sender used to the language of handling requests promptly should not carry that phrase across unchanged. Australia sets a specific business day count, and the safer operational target is same-day processing rather than testing how close to the five-day allowance is still safe.

Data subject rights exist under one regime and not the other

GDPR gives the person contacted a set of rights over their own data: access to what is held, correction, erasure in defined circumstances, and the right to object to processing, direct marketing included. Those rights exist independently of whether the original contact was lawful.

The Spam Act creates no equivalent regime. It is a messaging conduct statute, not a data protection statute, and it does not give an Australian recipient a right to see, correct or delete what a sender holds about them. Australia’s Privacy Act 1988 is the closer analogue to GDPR on data handling, and it carries its own scope limits, including a small business exemption for operators with annual turnover of $3,000,000 or less. A European sender should not assume the Spam Act covers what GDPR covers. It covers a narrower question: whether this particular message was allowed to be sent.

Regulators and how each one enforces

GDPR and ePrivacy enforcement runs through each member state’s national data protection authority, so a complaint about an email sent from Germany into France can involve two different regulators depending on where the sender and the processing sit.

Australia has one regulator for commercial electronic messages: the Australian Communications and Media Authority. ACMA investigates complaints, publishes its own compliance guidance directly at acma.gov.au/avoid-sending-spam, and can take enforcement action against senders who breach the Act. Its focus in practice tends to fall on mechanical failures, a missing or broken unsubscribe facility being the most common, rather than on contesting whether a given inferred consent judgement was reasonable.

Penalties: turnover-linked fines against penalty units

GDPR fines are set and structured at the EU level and scale with the severity of the breach and the size of the organisation involved. The exact tiers sit in the Regulation itself and are outside the scope of an Australia-focused comparison.

The Spam Act works differently. Section 25(3) sets a maximum of 100 penalty units for a body corporate’s single-day breach of section 16, rising to 2,000 penalty units where multiple contraventions happen within the same day. The Commonwealth penalty unit is currently valued at $364, applying to conduct from 1 July 2026 onward, which puts the top end of a single day’s exposure at $728,000. Unlike GDPR, the figure is not linked to the sender’s turnover. It is fixed by statute and moves only when the penalty unit itself is indexed.

What a European sender actually changes for an Australian list

Four adjustments matter more than the others when a list built on GDPR habits gets pointed at Australia.

None of this makes Australia harder to enter than the EU. It makes it a different test, built around consent and message mechanics rather than data processing, and the two lists deserve separate compliance logic even when the product and the pitch stay the same.

Frequently asked

Does GDPR apply to a European company sending cold email into Australia?
No. GDPR and the ePrivacy Directive operate within their own territorial and material scope, and an Australian recipient’s business email address is not automatically GDPR data just because the sender is a European company. The message is governed by the Spam Act 2003 once it lands in an Australian inbox, not by GDPR.
Is inferred consent under the Spam Act the same as GDPR’s legitimate interest?
No, though they solve a similar problem. GDPR’s legitimate interest under Recital 47 is a balancing test weighed against the recipient’s rights and expectations. The Spam Act’s inferred consent under Schedule 2, clause 4 is a fixed two-part test: the address has to be conspicuously published with no statement declining unsolicited messages, and the message has to be relevant to the recipient’s work-related role. There is no balancing step.
Which regime has stricter penalties?
They are structured too differently to rank directly. GDPR fines are set at EU level and scale with the organisation’s turnover and the severity of the breach. The Spam Act sets a fixed maximum in penalty units, currently up to 2,000 units at $364 each for multiple same-day contraventions, unrelated to the sender’s size.

Want the accounts behind these numbers?

Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.

Book a strategy call