Skip to main content
Free Tool · Australia

Privacy Act & Spam Act Checker.

Paste your email, SMS or WhatsApp marketing message. We'll flag missing sender ID, missing unsubscribe, harvested-list language and Privacy Act consent risks before you hit send.

Quick answer

This checker flags missing sender identification, missing unsubscribe mechanism, harvested/purchased list language, cold-contact risk, and sensitive-information or third-party data-sharing risk in a marketing message against Australia's Spam Act 2003 and Privacy Act 1988 (APP 7). Paste your message for a rule-by-rule flag before you send.

Educational self-check — not legal advice. This tool flags common risk areas under the Spam Act 2003 and Privacy Act 1988's direct-marketing rule (APP 7), described generally.

Final review of any Australian marketing campaign should be done against ACMA/OAIC's published guidance or with your own adviser. Everything runs client-side in your browser — your message text is never sent anywhere or stored.

These rules are published openly. Check our sourcing, or correct us.

Why Australian marketing compliance is two laws, not one

Australia regulates commercial electronic messages under the Spam Act 2003, enforced by the Australian Communications and Media Authority (ACMA) — every message needs valid consent, clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days.

Separately, the Privacy Act 1988's Australian Privacy Principle 7 (APP 7), enforced by the OAIC, governs using personal information for direct marketing at all — including a materially higher consent bar for sensitive information (health, political, religious, sexual orientation) and rules on data that arrived via a third party.

More detail on this section

This self-check walks your actual message through the risk areas that most often trip up Australian marketing sends, flags the specific phrase (or missing element) that triggered each one, explains which rule it touches, and suggests a compliant fix.

It's the same discipline our Australia team applies when building campaigns for AU clients — see the Australia social media marketing page for the full strategy layer.

What this checker looks for

6 rule categories, drawn from the sources cited below — each one covers a specific pattern our checker scans your pasted text for:

  • Missing sender identification — Spam Act 2003 section 17(1) requires that a commercial electronic message with an Australian link must clearly and accurately identify the individual or organisation who authorised the sending of the message, include accurate contact information, and that information must comply with any conditions in the regulations and be reasonably likely to be valid for at least 30 days after the message is sent. This check only fires once there's substantial pasted text to judge (an empty box isn't "missing sender ID", it's just empty). Source (opens in a new tab)
  • Missing unsubscribe mechanism — Spam Act 2003 section 18(1) requires every commercial electronic message with an Australian link to include a clear and conspicuous statement that the recipient may send an unsubscribe message, using an electronic address reasonably likely to be capable of receiving it. Schedule 2, clause 6 separately fixes the withdrawal-of-consent effective date at 5 business days after the unsubscribe message is sent. Section 18 does not require extra personal information or an account login to use the facility. Source (opens in a new tab)
  • Harvested or purchased contact list — Spam Act 2003 Schedule 2, clause 4(1) states plainly: "the consent of the relevant electronic account-holder may not be inferred from the mere fact that the relevant electronic address has been published." A narrow exception exists only for conspicuously published addresses tied to a specific role (clause 4(2)) — not a scraped or purchased general list. A message or internal brief referencing a purchased or scraped list is describing a send with no valid consent basis under this clause. Source
  • Cold contact with no existing relationship — Consent under the Spam Act can be express or inferred, but inferred consent only holds where an existing commercial relationship makes the recipient's interest reasonable — language admitting a genuinely cold first contact is a signal worth checking against a real consent basis before sending, not an automatic breach on its own. Source (opens in a new tab)
  • Sensitive personal information used for direct marketing — Australian Privacy Principle 7 (APP 7) requires explicit consent before an organisation uses sensitive personal information — health details, political opinions, religious beliefs, sexual orientation and similar categories — for direct marketing, a materially higher bar than the general opt-out-based rule that applies to ordinary personal information. Source (opens in a new tab)
  • Third-party data sharing for marketing — APP 7 permits direct marketing using personal information collected from a third party only in narrower circumstances than data collected directly from the individual — a message revealing the contact came via a partner organisation surfaces a real question about whether the original consent covered this specific use. Source (opens in a new tab)

Methodology — where this checklist comes from

Rules marked "verified" in our sourcing are fetched directly from primary authority and read in full: Privacy Act / APP 7 rules from the OAIC's own official direct-marketing guidance page, and Spam Act rules directly from the Act's own text at the Federal Register of Legislation — sections 17 (sender identification), 18 (unsubscribe) and Schedule 2 (consent).

ACMA's own "avoid sending spam" page and the Federal Register's web viewer both proved unreachable to this session's fetch tooling, but the Register's own original-assent PDF rendered in full when read directly, which is what these rules now cite — corrected from an earlier version of this tool that cited a law-firm summary as primary, still kept as a corroborating secondary source.

This is the same discipline our Singapore MOH checker and Hong Kong medical ad checker apply when a primary source is hard to reach: disclosed, not silently worked around. It is not a substitute for legal advice: treat a “no flags” result as a reasonable first pass, not clearance.

Running a Singapore campaign instead? Use our PDPA & DNC checker.

Rules current as of: August 2026

Related free tools

Related compliance checkers

The same self-check pattern, applied to other markets and verticals — all openly sourced, same as this one.

  • Cite this
  • shakalakaa (Plixitt Solutions). “Australia Privacy Act & Spam Act Checker.”
  • https://shakalakaa.com/au/tools/au-privacy-spam-checker · Updated 2026-10-09
  • Licensed under CC BY 4.0.

shakalakaa (Plixitt Solutions). "Australia Privacy Act & Spam Act Checker." https://shakalakaa.my/tools/au-privacy-spam-checker. Updated 2026-10-09. Licensed under CC BY 4.0.

FAQ

Frequently Asked Questions

What does the Spam Act 2003 require in a marketing message?+

Consent to send it (express or a genuine existing-relationship basis for inferred consent), clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days.

Can I buy or scrape a contact list for Australian marketing?+

No — scraping addresses, guessing addresses, or taking details from public profiles is explicitly not valid consent under the Spam Act 2003, regardless of unsubscribe or sender-ID compliance elsewhere in the message.

Does the Privacy Act require anything beyond the Spam Act?+

Yes — Australian Privacy Principle 7 (APP 7) requires a simple opt-out mechanism for direct marketing generally, and explicit consent specifically before using sensitive personal information (health, political, religious, sexual orientation) for direct marketing.

Does this replace legal review of my campaign?+

No — this is an educational first-pass self-check covering the Spam Act and Privacy Act rules most relevant to a marketing message, not legal clearance. Always confirm anything borderline against ACMA/OAIC's published guidance or your adviser before sending.

What does the Spam Act 2003 require in a marketing message?

Consent to send it (express or a genuine existing-relationship basis for inferred consent), clear sender identification with a working contact method, and a functional unsubscribe facility that stays working for at least 30 days.

Can I buy or scrape a contact list for Australian marketing?

No — scraping addresses, guessing addresses, or taking details from public profiles is explicitly not valid consent under the Spam Act 2003, regardless of unsubscribe or sender-ID compliance elsewhere in the message.

More questions (2)

Does the Privacy Act require anything beyond the Spam Act?

Yes — Australian Privacy Principle 7 (APP 7) requires a simple opt-out mechanism for direct marketing generally, and explicit consent specifically before using sensitive personal information (health, political, religious, sexual orientation) for direct marketing.

Does this replace legal review of my campaign?

No — this is an educational first-pass self-check covering the Spam Act and Privacy Act rules most relevant to a marketing message, not legal clearance. Always confirm anything borderline against ACMA/OAIC's published guidance or your adviser before sending.

Let's talk

Let's start the convo.