GDPR vs the Spam Act 2003: cold email compared
In short
GDPR and the ePrivacy Directive protect personal data. The Spam Act 2003 regulates commercial electronic messages. They overlap on cold email without being versions of the same law: Australia runs on a consent test with no legitimate interest equivalent, sets a fixed five business day unsubscribe clock, and gives recipients no GDPR-style data rights at all.

On this page
- Two regimes built for different problems
- Legal basis: legitimate interest and soft opt-in against consent
- Identifying yourself: what each regime demands
- Unsubscribe and consent withdrawal timing
- Data subject rights exist under one regime and not the other
- Regulators and how each one enforces
- Penalties: turnover-linked fines against penalty units
- What a European sender actually changes for an Australian list
Two regimes built for different problems
GDPR and the ePrivacy Directive protect personal data. The Spam Act 2003 (Cth) regulates commercial electronic messages. They overlap on cold email without being the same law, and a European sender who assumes the Australian rules are simply a stricter or looser version of GDPR will get the compliance basis wrong in both directions.
The table below lines up the two regimes on the points that actually change how a cold email campaign gets built and run.
| EU: GDPR and ePrivacy | Australia: Spam Act 2003 | |
|---|---|---|
| Legal basis | Legitimate interest, GDPR Recital 47, or the ePrivacy soft opt-in for an existing customer relationship | Consent, express or inferred from a conspicuously published, relevant business address |
| B2B cold email | Generally permitted on legitimate interest, strictness varies by member state | Permitted only where a consent basis under the Act applies |
| Sender identification | ePrivacy Article 13 requires clear identification and a valid address to object to | Section 17 requires honest identification and accurate contact information |
| Unsubscribe or objection | Free and easy, offered at collection and with every message, no fixed day count in the Directive text | Functional facility required by section 18, consent withdrawal effective five business days after the request, Schedule 2 |
| Data subject rights | Access, correction, erasure and objection, under the Regulation | None. The Act regulates messaging conduct, not data handling |
| Regulator | The national data protection authority in each member state | The Australian Communications and Media Authority, ACMA |
| Penalties | Administrative fines set at EU level, scaled by severity | Penalty units, currently $364 each, up to 2,000 units for multiple same-day contraventions |
Legal basis: legitimate interest and soft opt-in against consent
GDPR Recital 47 treats direct marketing as capable of resting on a legitimate interest, provided the interests or fundamental rights of the person contacted are not overridden and the contact stays within what that person could reasonably expect. That is a balancing test, not a fixed rule, which is why practice varies by member state, with Germany and France applying it more strictly to B2B email than the UK or the Netherlands do.
The ePrivacy Directive’s Article 13 soft opt-in sits alongside legitimate interest for a narrower case: the sender obtained the address in the context of selling a product or service, is marketing its own similar products or services, and gave the customer a free and easy way to object both at collection and with every later message.
The Spam Act runs on consent instead of interest. Express consent exists where the account holder actually agreed to receive messages. Inferred consent exists under Schedule 2, clause 4, where the address was conspicuously published, it is reasonable to assume the publication carried the account holder’s agreement, and the message is relevant to the recipient’s work-related role. There is no legitimate interest equivalent, and no balancing test on the Australian side. Either the consent basis is there, or it is not.
Identifying yourself: what each regime demands
Both regimes require honest identification, but they anchor the requirement differently.
ePrivacy Article 13 requires that unsolicited commercial communications are identifiable as such, and that the sender gives the recipient a valid address to object to future messages. GDPR’s transparency obligations, which apply whenever personal data is processed for marketing, add further disclosure duties about who is processing the data and why.
Section 17 of the Spam Act is narrower and more mechanical: the message must clearly and accurately identify the individual or organisation that authorised it, and include accurate information for how the recipient can readily contact that individual or organisation. It does not ask why the data is being processed. It asks who sent the message and how to reach them, a lower bar to clear but not one that can be skipped.
Unsubscribe and consent withdrawal timing
The ePrivacy soft opt-in requires an objection mechanism offered at collection and repeated with every message, but the Directive text does not set a specific number of days within which an objection has to take effect.
The Spam Act does. Section 18 requires the unsubscribe address in a message to stay functional for at least 30 days after that message was sent. Separately, Schedule 2, clause 6(1) sets the moment consent withdrawal takes effect: five business days after the unsubscribe request is sent. Any further commercial electronic message to that address after the five days is a fresh breach of section 16, independent of the consent basis that applied to the original message.
A European sender used to the language of handling requests promptly should not carry that phrase across unchanged. Australia sets a specific business day count, and the safer operational target is same-day processing rather than testing how close to the five-day allowance is still safe.
Data subject rights exist under one regime and not the other
GDPR gives the person contacted a set of rights over their own data: access to what is held, correction, erasure in defined circumstances, and the right to object to processing, direct marketing included. Those rights exist independently of whether the original contact was lawful.
The Spam Act creates no equivalent regime. It is a messaging conduct statute, not a data protection statute, and it does not give an Australian recipient a right to see, correct or delete what a sender holds about them. Australia’s Privacy Act 1988 is the closer analogue to GDPR on data handling, and it carries its own scope limits, including a small business exemption for operators with annual turnover of $3,000,000 or less. A European sender should not assume the Spam Act covers what GDPR covers. It covers a narrower question: whether this particular message was allowed to be sent.
Regulators and how each one enforces
GDPR and ePrivacy enforcement runs through each member state’s national data protection authority, so a complaint about an email sent from Germany into France can involve two different regulators depending on where the sender and the processing sit.
Australia has one regulator for commercial electronic messages: the Australian Communications and Media Authority. ACMA investigates complaints, publishes its own compliance guidance directly at acma.gov.au/avoid-sending-spam, and can take enforcement action against senders who breach the Act. Its focus in practice tends to fall on mechanical failures, a missing or broken unsubscribe facility being the most common, rather than on contesting whether a given inferred consent judgement was reasonable.
Penalties: turnover-linked fines against penalty units
GDPR fines are set and structured at the EU level and scale with the severity of the breach and the size of the organisation involved. The exact tiers sit in the Regulation itself and are outside the scope of an Australia-focused comparison.
The Spam Act works differently. Section 25(3) sets a maximum of 100 penalty units for a body corporate’s single-day breach of section 16, rising to 2,000 penalty units where multiple contraventions happen within the same day. The Commonwealth penalty unit is currently valued at $364, applying to conduct from 1 July 2026 onward, which puts the top end of a single day’s exposure at $728,000. Unlike GDPR, the figure is not linked to the sender’s turnover. It is fixed by statute and moves only when the penalty unit itself is indexed.
What a European sender actually changes for an Australian list
Four adjustments matter more than the others when a list built on GDPR habits gets pointed at Australia.
- Swap the consent test. Legitimate interest is not a basis the Spam Act recognises. Every Australian record needs either express consent or a defensible inferred consent basis, recorded at the point the record was added.
- Watch the five-day clock, not a vague standard. Schedule 2, clause 6(1) sets a specific number. Build the unsubscribe process to clear it same-day rather than testing how close to five business days is still safe.
- Drop the data subject rights assumptions. An Australian recipient asking to see what data is held is invoking something closer to the Privacy Act than the Spam Act, and the two statutes have different scope and different exemptions.
- Work from ACMA’s guidance, not the DPA’s. ACMA’s own guidance at acma.gov.au/avoid-sending-spam is the primary reference, and its focus on unsubscribe mechanics is a useful checklist independent of which consent basis was used.
None of this makes Australia harder to enter than the EU. It makes it a different test, built around consent and message mechanics rather than data processing, and the two lists deserve separate compliance logic even when the product and the pitch stay the same.
Frequently asked
Does GDPR apply to a European company sending cold email into Australia?
Is inferred consent under the Spam Act the same as GDPR’s legitimate interest?
Which regime has stricter penalties?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call