Spam Act 2003: cold email compliance in Australia
In short
Cold B2B email to Australian businesses is legal under the Spam Act 2003, provided the sender relies on a consent basis the Act recognises, identifies itself honestly and gives a working unsubscribe. The three real requirements sit in sections 16, 17 and 18. The inferred consent test that covers most B2B email sits in Schedule 2, and consent withdrawal takes effect five business days after an unsubscribe request is sent.

On this page
- Is cold email to Australian businesses legal
- The three requirements under the Spam Act
- Inferred consent for a conspicuously published business address
- The five business day unsubscribe window
- Address harvesting software is banned outright
- Penalties, in penalty units
- Where the Privacy Act fits in
- What a compliant cold email looks like in practice
Is cold email to Australian businesses legal
Yes. Cold B2B email to an Australian business is legal under the Spam Act 2003 (Cth), provided the sender holds a consent basis the Act recognises, identifies itself honestly, and gives the recipient a working way to opt out.
The Spam Act is a consent regime, not an opt-out regime. Section 16 prohibits sending a commercial electronic message with an Australian link unless the account holder consented to receive it. For B2B senders, the consent that matters most in practice is rarely a signed form. It is the inferred consent test in Schedule 2, which most legitimate business-to-business email relies on and which is covered below.
Three separate requirements sit under that consent test: who is sending the message, how the recipient can unsubscribe, and how fast that unsubscribe has to be honoured. Miss any one of the three and the message is unlawful even where the consent basis itself was never in question.
An Australian link is defined broadly. It covers a message where the recipient, the sender, or equipment used to send or access the message is in Australia. A European company sending into an Australian inbox sits squarely inside that scope, with no Australian office required to trigger the Act.
The three requirements under the Spam Act
Sections 16, 17 and 18 of the Spam Act set out the three things every commercial electronic message with an Australian link has to satisfy.
- Section 16, consent. The message must not be sent unless the account holder consented, either expressly or through the inferred consent test described below.
- Section 17, identification. The message must clearly and accurately identify the individual or organisation that authorised sending it, and give accurate information for how the recipient can readily contact that individual or organisation.
- Section 18, unsubscribe facility. The message must include a statement that the recipient can use an electronic address in the message to send an unsubscribe request, and that address has to stay functional for at least 30 days after the message is sent.
All three apply together on every message. A sender who gets the consent basis right but leaves out accurate contact information, or lets the unsubscribe address stop working after two weeks, has still breached the Act. None of the three requirements is optional or a best practice sitting on top of the law. They are the law.
Inferred consent for a conspicuously published business address
Almost no legitimate B2B sender collects a signed opt-in before the first email. What they rely on instead is Schedule 2, clause 4 of the Act: inferred consent from a conspicuously published address.
Two conditions have to hold together. First, the address has to be conspicuously published, on a company website, a public register or a business directory, and it has to be reasonable to assume the publication carried the account holder’s agreement. That assumption fails where the publication is accompanied by a statement to the effect that the account holder does not want unsolicited commercial electronic messages. A "no marketing emails" line anywhere near the published address removes the consent basis entirely.
Second, the message itself has to be relevant to the work-related business, functions or duties of the recipient. A cold pitch for a consumer product, sent to a business address found on a company website, does not clear this bar even where the first condition is met. The message has to speak to the person’s actual job rather than simply landing in an inbox that happened to be public.
Both conditions are judged at the point the message is sent, not retrospectively. Recording why an address was believed to be conspicuously published and relevant, at the time the record entered the list, is the only defensible way to satisfy this test if it is ever questioned.
The five business day unsubscribe window
Two separate clocks run on unsubscribes, and B2B senders regularly confuse them.
The first is section 18: the unsubscribe address named in a message has to keep working for at least 30 days after that particular message was sent. That is a minimum standing requirement on the facility itself, not a promise about how quickly a request gets processed once it arrives.
The second is Schedule 2, clause 6(1): once a recipient sends an unsubscribe request, the withdrawal of consent takes effect at the end of five business days. After that point, sending another commercial electronic message to that address is a fresh breach of section 16, independent of whatever consent basis applied before the withdrawal. A sequence tool that queues the next touch three days after an unsubscribe and fires it on day four is technically inside the five-day allowance, but processing the request the same day it arrives is the only way to stay comfortably clear of the limit rather than counting it down to the edge.
Address harvesting software is banned outright
Sections 20 to 22 of the Act prohibit supplying, acquiring or using address-harvesting software, or a harvested-address list, where the person doing the supplying, acquiring or using is in Australia or carries on business there.
This sits apart from the consent rules entirely. A list built by scraping email addresses off web pages with automated harvesting software is prohibited conduct regardless of what the inferred consent test would otherwise allow, if the person building the list operates from or into Australia. It is a reason to be precise about how an Australian list is actually assembled, not only about what consent basis is claimed for the records once assembled. A list sourced from a public company register or a business directory, added through a compliant lookup, sits outside the prohibition. A list built by an unattended scraper pulling every visible address off a site does not.
Penalties, in penalty units
The Spam Act sets penalties in penalty units rather than fixed dollar amounts, so the real cost of a breach moves whenever the Commonwealth penalty unit value is indexed.
Section 25(3) sets a maximum of 100 penalty units for a body corporate with no prior contravention, for a single-day breach of section 16. Multiple contraventions within the same day can reach up to 2,000 penalty units. The current Commonwealth penalty unit value is $364, applying to offences committed on or after 1 July 2026, up from $330 for the period from 7 November 2024. At that rate, the single-day maximum works out to $36,400, and the multiple-contravention maximum to $728,000, though it is the unit count the Act actually sets, and that is what moves at each indexation rather than a fixed headline figure.
The Australian Communications and Media Authority, ACMA, is the regulator that investigates Spam Act complaints and can take enforcement action for breaches, most commonly around a broken or ignored unsubscribe facility. ACMA publishes its own compliance guidance directly at acma.gov.au/avoid-sending-spam, and that page is the primary reference for how the regulator expects senders to behave, rather than any single enforcement outcome.
Where the Privacy Act fits in
The Spam Act and the Privacy Act 1988 answer different questions, and treating them as one law is a common error.
Business contact details are not automatically outside the Privacy Act. The Office of the Australian Information Commissioner treats information that is only about a business, a body corporate, as sitting outside the definition of personal information, since the Act defines an individual as a natural person. But where a business contact record also identifies a natural person, a name and a direct email tied to that person, the Australian Privacy Principles can still apply to how the record is handled. The overlap is sharpest for sole traders, where the business and the individual are the same person.
Separately, the Privacy Act carries a small business exemption: it generally does not apply to a small business operator, defined as an entity with annual turnover of $3,000,000 or less, unless a specific exception applies. A sender operating from a small business may sit outside the Act’s general obligations for that reason alone. The Spam Act’s consent, identification and unsubscribe rules apply regardless of the sender’s size.
What a compliant cold email looks like in practice
Put the three sections and the two Schedule 2 tests together, and a compliant first message to an Australian business has a specific, checkable shape.
- The recipient’s address was found conspicuously published, on a company site, a public register or a directory, with no statement nearby declining unsolicited messages.
- The message content is relevant to that person’s actual role, not a generic pitch sent regardless of function.
- The sender is identified honestly, by organisation name, with accurate contact information included in the message itself.
- An unsubscribe link or address is present, described clearly, and stays functional for at least 30 days.
- Unsubscribe requests are processed the same day they arrive, well inside the five business day limit the Act allows.
- The list was built from a register, a directory or a compliant lookup service, never from harvesting software.
None of this requires a signed opt-in before the first message, which is the part that surprises senders arriving with European habits. What it requires is a specific and defensible reason the address was public, relevant and fairly obtained, recorded at the point the record entered the list rather than reconstructed after the fact.
Frequently asked
Is cold email legal in Australia?
Do I need opt-in consent for B2B email in Australia?
How fast must I honour an unsubscribe?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call