Spam Act Compliance for Professional Services Newsletters: Consent, Unsubscribe & What Actually Counts
Newsletters are one of the highest-value marketing tools a law firm, accounting practice or clinic has — and one of the easiest to get quietly wrong. Most firms aren't being reckless; they're working off a vague "we've dealt with this client before, so we're fine" without checking what that actually covers. The gap between "feels reasonable" and "meets the Spam Act" is where the risk sits. 💖
What most professional services firms get wrong
- Treating "existing business relationship" as unlimited — it has real boundaries around recency, relevance and reasonable expectation, not an indefinite licence to email anyone who's ever been a client.
- Importing old contact lists wholesale — a list bought, inherited from a merger, or scraped from LinkedIn connections isn't consent, no matter how professional the context.
- Burying or breaking the unsubscribe link — a functional, low-friction unsubscribe is a legal requirement, not a nice-to-have.
- Vague sender identification — "no-reply@" with no firm name or ABN doesn't meet the identification requirement.
- Assuming B2B is exempt — there's no blanket carve-out just because the recipient is a business.
The practical compliance checklist
Run every campaign against this before you hit send:
— Do I have express consent (opt-in) OR a genuine, current existing business relationship with relevant content?
— Is my organisation clearly identified — legal/trading name, ABN, and a real contact method (not just a no-reply address)?
— Is there a working, low-friction unsubscribe link?
— Will the unsubscribe request be processed within five business days?
— Is this list free of purchased, scraped or third-party contacts I can't trace consent for?
— Have I documented how and when each contact gave consent, or the basis for inferred consent?
If any line is unticked, that's the fix to make before the next send — not a reason to send anyway "just this once."
What this looks like across different practices
How consent actually works, mechanically
Express consent should be recorded somewhere — a timestamped form submission, a ticked checkbox, a signed intake form — not just remembered. Inferred consent relies on all three of: a genuine relationship, that relationship being reasonably recent, and content the person would reasonably expect. All three need to be true together. When in doubt, ask for express opt-in rather than lean on an inferred-consent argument that might not hold up.
Mistakes that create real exposure
- Merging lists after a merger without re-checking consent — inherited contacts don't inherit clean consent automatically.
- Letting "reply to unsubscribe" stand in for a real link — it adds friction the Act is designed to avoid and increases the chance requests get missed.
- Not documenting consent basis at all — if you can't show how or when someone consented, you can't defend the send if questioned.
- Treating a spam complaint as a one-off nuisance — repeated complaints on the same list are worth investigating before they escalate.
Frequently asked questions
Does this apply to one-to-one emails from a partner, or just bulk newsletters?
The Act is aimed at commercial electronic messages generally, which can include individual emails with a commercial purpose — though enforcement focus sits overwhelmingly with bulk sends. If you're unsure where a specific message sits, that's a question for your lawyer, not a guess.
Can I email a business contact I met at a networking event, without opt-in?
This is genuinely one of the greyer areas — a business card exchange alone is a weak basis for inferred consent. The more cautious approach is to ask directly rather than assume the conversation implied consent.
What actually happens if we get it wrong?
Penalties under the Act can be significant and the ACMA does take enforcement action, but for most firms the more immediate cost is reputational — spam complaints damage deliverability and trust well before regulatory action would occur.
Is a "we value your privacy" line at the bottom of the email enough?
No — that's not a substitute for the specific identification and unsubscribe requirements, however good it sounds.
Please note: general information, not legal advice — check current ACMA guidance and confirm your specific situation with a lawyer before relying on it.
Keep reading 🤍
I help Gold Coast and Brisbane businesses grow with branding, websites and marketing that actually works.
Work with me ✦