Marketing Compliance
The Consent Evidence File
If a person complains about a message they received, three questions decide the outcome: was there consent, can it be proved, and was the opt-out honoured in time. This page names the law that asks each question and the column or table in the Australian audience file that answers it. Audience figures are computed from that same file. All currency figures AUD.
Reference material for this proposal, not legal advice. Every instrument below links to the regulator or the legislation itself, and the operating platform will need counsel sign-off in each market before it sends.
Instruments in scope
7
Duties with evidence held
16 / 16
Consent rate on the file
84%
193 of 231 resolved people
Suppressed, not sent to
38
6 consent sources
Audience figures computed from the sample file Illustrative — from sample data
What Reaches Us
The Instruments That Reach a Marketing Send
Two statutes do most of the work and they do not overlap: the Spam Act governs the message, the Privacy Act governs the data behind it. The rest bind narrower surfaces — the phone, the sender ID, the claim in the creative, and the contract with each ad platform.
Instrument
- SPAMSPAM — Spam Act 2003 (Cth) and Spam Regulations 2021
- APP7APP7 — Privacy Act 1988 (Cth) — Australian Privacy Principles
- DNCRDNCR — Do Not Call Register Act 2006 (Cth)
- SMSIDSMSID — SMS Sender ID Register
- POLAPOLA — Privacy and Other Legislation Amendment Act 2024
- ACLACL — Australian Consumer Law — Schedule 2, Competition and Consumer Act 2010 (Cth)
- TERMSTERMS — Ad-platform custom audience terms
| Instrument | Regulator | What it reaches | Core duties | Guidance |
|---|---|---|---|---|
| SPAMSpam Act 2003 (Cth) and Spam Regulations 2021 | Australian Communications and Media Authority | Every commercial electronic message — email, SMS, MMS and instant message — with an Australian linkThe onus of proving consent sits with the sender, not the complainant. Consent cannot be inferred from the mere fact that an address has been published (Schedule 2, clause 4), and a withdrawal takes effect at the end of 5 business days (Schedule 2, clause 6). |
| Open source |
| APP7Privacy Act 1988 (Cth) — Australian Privacy Principles | Office of the Australian Information Commissioner | Collection, use, disclosure, quality, security and correction of personal informationAPP 7.4 has no impracticability escape and it applies even where the person and the business already have a relationship. Ancestry is sensitive information, so an ancestry-led send stands or falls on consent alone. |
| Open source |
| DNCRDo Not Call Register Act 2006 (Cth) | Australian Communications and Media Authority | Marketing voice calls and faxes — not marketing email or SMS, which the Spam Act coversThis one is dormant while the pilot sends only email and SMS. It binds the moment anyone picks up a phone against the landline column, which is why no segment in the prototype uses that column as a channel. |
| Open source |
| SMSIDSMS Sender ID Register | Australian Communications and Media Authority | Branded alphanumeric sender IDs on text messages to Australian numbersIn force from 1 July 2026. An unregistered branded sender ID is labelled Unverified by the carriers, which turns a compliance gap into a visible trust problem on the handset. |
| Open source |
| POLAPrivacy and Other Legislation Amendment Act 2024 | Office of the Australian Information Commissioner and the Federal Court | Enforcement, individual litigation and privacy-policy transparencyA person can now sue directly, without proving damage. Consent and lawful authority are defences to the tort — which is precisely what a dated, sourced consent record supplies. |
| Open source |
| ACLAustralian Consumer Law — Schedule 2, Competition and Consumer Act 2010 (Cth) | Australian Competition and Consumer Commission | The claims inside the creative — pricing, availability and event descriptionsConsent makes a send lawful; it does not make the claim inside it true. Ticket pricing, seat availability and artist billing all sit here. |
| Open source |
| TERMSAd-platform custom audience terms | Contractual — Meta, Google and TikTok | Hashed email and mobile uploaded for Custom Audiences or Customer MatchThese terms sit on top of the statutes, not instead of them. A breach is a contract claim and an account risk as well as a privacy question, which is why ancestry and language stay off the match file. |
| Open source |
Duty To Evidence
Every Duty, and the Column That Answers It
A duty with no evidence behind it is a hope. Each row names the clause, what it requires, and the column, table or template artefact that would be produced if a regulator asked. Where a warehouse test holds the duty in place, the test is named too — 2 of them touch consent directly.
Instrument
- SPAMSPAM — Australian Communications and Media Authority
- APP7APP7 — Office of the Australian Information Commissioner
- DNCRDNCR — Australian Communications and Media Authority
- SMSIDSMSID — Australian Communications and Media Authority
- POLAPOLA — Office of the Australian Information Commissioner and the Federal Court
- ACLACL — Australian Competition and Consumer Commission
- TERMSTERMS — Contractual — Meta, Google and TikTok
| Law | Clause | Duty | Evidence held | Test | On the prototype |
|---|---|---|---|---|---|
| SPAM | s 16 and Schedule 2 | Consent exists before a commercial message is sentThe marketing flag on the file is the current position of a consent event history, not a standalone tick. Any single record resolves back to the moment, the form and the stated purpose it was given under. | consented_for_marketingconsent_timestampconsent_sourceconsent_purposefact_consent_event | vw_marketable_audience has no person whose latest event is WITHDRAW | The consent gate stage of the end-to-end run |
| SPAM | s 16 — onus on the sender | The sender can prove consent for the specific addressConsent is stored as an event with a source, so the answer to “where did you get my address” is a row, not an assertion. Each consent source in the file is a real opt-in route: checkout, waitlist, newsletter, ballot, box office or a permission-based partner list. | fact_consent_eventconsent_sourcerecord_idperson_sk | not_null on the consent event grain — one row per grant or withdrawal | Consent sources in the audience run, and the consent-event table in the warehouse |
| SPAM | s 16 | The message goes only to the channel the person choseThe channel preference is consent in its own right and is enforced by a join at send time, not by a filter in a spreadsheet. Email-preferred people are never texted and mobile-preferred people are never emailed. | contact_preferenceemailmobilevw_marketable_audience | accepted_values on contact_preference — E or M only | The channel split on the audience run and every campaign segment |
| SPAM | s 17 | Every message identifies the sender and carries current contact detailsThis is a property of the template rather than the audience file. It lives in the material kit: the email and SMS creatives carry the legal entity name, the ABN and a contact route that stays correct for at least 30 days after the send. | Email nurture templateSMS on-sale creative | — | The marketing materials section |
| SPAM | s 18 and s 18(5) | A working, free unsubscribe, honoured within 5 business daysAn unsubscribe writes a withdrawal event, which flips the marketing flag and removes the person from the serving view. Suppression is therefore a consequence of the record rather than a manual step someone can forget. | fact_consent_eventconsented_for_marketingvw_marketable_audience | expression_is_true — the serving view excludes every withdrawal | The suppressed count on the audience run |
| APP7 | APP 3.3 | Sensitive information is collected only with consentAncestry and language are self-declared by the person at opt-in on ABS Census categories. A bought-in ancestry append cannot be used for marketing however it was collected, so the file has no route for one. | ethnicity_nationalitymarathi_speakingconsent_purpose | — | The ancestry and language rows in the column reference |
| APP7 | APP 7.4 | Sensitive information is used for direct marketing only with consentThe ancestry and language columns are gated by the same consent flag as the contact points, and they stay on owned sends. They never travel to an ad platform, where consent cannot be evidenced downstream. | ethnicity_nationalitymarathi_speakingconsented_for_marketing | — | The social and platform activation section |
| APP7 | APP 7.2(c) and 7.3(c) | A simple means to request no further direct marketing, stated in each messageOne opt-out path serves both regimes: the same link that satisfies the Spam Act unsubscribe writes the withdrawal event that satisfies the privacy obligation. | fact_consent_eventEmail nurture templateSMS on-sale creative | — | The marketing materials section |
| APP7 | APP 5 | The person is told at collection what is taken, why, and who receives itThe consent purpose is stored beside the consent itself, so the notice given at opt-in and the use made later can be compared on the same row. | consent_purposeconsent_sourceconsent_timestamp | — | The consent columns in the column reference |
| APP7 | APP 10 | Personal information is accurate, up to date and completeRecords that fail a validation rule are quarantined rather than mailed, and identity resolution collapses duplicates to one person per email so the same person is not contacted twice under two records. | Validation rulesrecord_iddim_person | unique on the person key — one row per resolved person | The validate and resolve stages of the audience run |
| APP7 | APP 11 | Personal information is protected from misuse and unauthorised accessSensitive columns are flagged where they sit, and contact points are hashed before any platform upload, so the outbound artefact carries no readable address. | dim_personHashed match file | — | The warehouse tables and the social activation section |
| APP7 | APP 12 and APP 13 | A person can get access to their information and have it correctedThe record key and the person key make a single person findable in one query, and the merge lineage shows which source records were folded into their golden row. | record_idperson_skMerge lineage | — | The resolve stage of the audience run |
| DNCR | Do Not Call Register Act 2006 | Marketing calls go only to numbers washed against the registerThe landline column exists on the file but is not a channel in any segment, and the channel preference carries only email and mobile. Nothing in the prototype dials, so nothing needs a wash until a call programme is added. | phonecontact_preference | — | The channel preference row in the column reference |
| SMSID | From 1 July 2026 | A branded SMS sender ID is registered and each sending provider is authorisedA registration step before the first SMS campaign, taken through the sending telco. It sits with the SMS creative in the material kit rather than in the data. | SMS on-sale creative | — | The marketing materials section |
| ACL | s 18 and s 29 | Claims about price, availability and line-up are accurateCampaign copy draws its event facts from the ticket sale and campaign tables rather than from the creative brief, so a price or an on-sale date in an email can be traced to the row it came from. | dim_campaignfact_ticket_sale | — | The Leadership Team report specs |
| TERMS | Custom Audience and Customer Match terms | Only records with current consent are uploaded, and no sensitive category is used to targetThe upload is built from the serving view, so a withdrawal removes a person from the next upload as well as the next email. Ancestry and language segment the owned send only. | vw_marketable_audienceHashed match file | — | The social and platform activation section |
Sensitive Information
Why Ancestry and Language Sit Under a Stricter Rule
Columns carrying a legal duty
4
Warehouse columns flagged sensitive
1
Marathi at home, consented
118
A language-led send needs consent for the language flag itself
Racial or ethnic origin is sensitive information under s 6 of the Privacy Act, which changes the test twice over. APP 3.3 requires consent before it is collected at all. APP 7.4 then requires consent before it is used for direct marketing — and unlike the rules for ordinary personal information, there is no impracticability escape and no allowance for an existing customer relationship. An ancestry-led campaign therefore stands or falls on consent alone.
| Column | What it holds | Legal duty |
|---|---|---|
ethnicity_nationality | Ancestry, on ABS categories | Sensitive information — s 6, Privacy Act 1988 (Cth). APP 7.4 needs the person’s consent |
marathi_speaking | Marathi used at home | Travels with the same consent as the ancestry column |
consented_for_marketing | Current marketing consent | APP 7.4 — sensitive information may be used for direct marketing only with consent |
contact_preference | Channel the person chose — E email, M mobile | Spam Act 2003 (Cth) — consent, sender identification and a working unsubscribe |
The practical consequence is a collection rule: ancestry and language are self-declared by the person at opt-in, on ABS Census categories. A bought-in ancestry append cannot be used for marketing however it was collected, which is why the file has no route for one. See these columns on the prototype
In the Creative
Sender Identity, the Unsubscribe and the Sender ID
Three duties cannot be satisfied by data at all — they live in the template. They are also the three that ACMA can establish without any argument about consent, because a message either carries them or it does not.
| Law | Clause | Duty | How it is met | Evidence |
|---|---|---|---|---|
| SPAM | s 17 | Every message identifies the sender and carries current contact details | This is a property of the template rather than the audience file. It lives in the material kit: the email and SMS creatives carry the legal entity name, the ABN and a contact route that stays correct for at least 30 days after the send. | Email nurture templateSMS on-sale creative |
| SPAM | s 18 and s 18(5) | A working, free unsubscribe, honoured within 5 business days | An unsubscribe writes a withdrawal event, which flips the marketing flag and removes the person from the serving view. Suppression is therefore a consequence of the record rather than a manual step someone can forget. | fact_consent_eventconsented_for_marketingvw_marketable_audience |
| APP7 | APP 7.2(c) and 7.3(c) | A simple means to request no further direct marketing, stated in each message | One opt-out path serves both regimes: the same link that satisfies the Spam Act unsubscribe writes the withdrawal event that satisfies the privacy obligation. | fact_consent_eventEmail nurture templateSMS on-sale creative |
| SMSID | From 1 July 2026 | A branded SMS sender ID is registered and each sending provider is authorised | A registration step before the first SMS campaign, taken through the sending telco. It sits with the SMS creative in the material kit rather than in the data. | SMS on-sale creative |
One opt-out path serves both regimes: the link that satisfies the Spam Act unsubscribe writes the withdrawal event that satisfies APP 7. Two mechanisms would mean two chances to drift apart. See the material kit on the prototype
Ad Platforms
What Goes Up, and What Stays Behind
Uploadable contact points
193
Email 127 · mobile 66
Columns withheld from the upload
1
Ancestry and language segment owned sends only
| Goes up | Stays behind | |
|---|---|---|
| Contact points | Hashed email and hashed mobile, drawn from the serving view | Readable addresses, and the landline column |
| Consent state | Only records whose latest consent event grants permission | Withdrawals, and every suppressed person |
| Attributes | None — the match file is contact points only | Ancestry, the language flag, and any lookalike built on either |
| Cadence | A fresh upload per campaign, so a withdrawal drops out of the next one | A list that is uploaded once and left to go stale |
The custom-audience terms at Meta, Google and TikTok each require the uploader to warrant that it holds the rights and consents to share every contact point, and each restricts sensitive-category targeting on its own account. Those terms sit on top of the statutes rather than instead of them, so a breach is a contract claim and an account risk as well as a privacy question. See the platform uploads on the prototype
Where It Lives
The Record a Regulator Would Ask For
Consent is stored as an event, not as a tick. The flag on the file is the current position of that history, which is what lets a single person be traced back to the moment and the form they opted in through — and what makes a withdrawal a fact in the record rather than a manual deletion someone has to remember.
| Object | Kind | Grain | Columns |
|---|---|---|---|
fact_consent_event | fact | One row per consent event — granted or withdrawn | consent_event_skperson_skdate_skchannelpurposeactionsource |
vw_marketable_audience | view | One row per contactable person, per channel they chose | person_skchanneladdressstatesa2_code_2021marathi_speaking |
Tests that hold consent in place
| Test | On | Why it is there |
|---|---|---|
accepted_values | channel in (E, M) · action in (GRANT, WITHDRAW) · state in the eight codes | no free text in a controlled column |
expression_is_true | vw_marketable_audience has no person whose latest event is WITHDRAW | consent is enforced by a test, not by convention |
Records that fail one of the 6 validation rules are quarantined rather than mailed — 6 of them on the sample file. Illustrative — from sample data See the warehouse tables on the prototype
If Someone Complains
The Seven Steps, and the Clock on Each
A complaint is not the problem; a slow or undocumented response is. The Spam Act unsubscribe duty is strict — the clock starts when the request arrives, and intent is not a defence — while the OAIC expects a person to raise a privacy complaint with the business first and gives it 30 days to answer. Both clocks run from the same moment.
Clock
- Same daySame day — Logged and suppressed before anything else
- 5 days5 days — Business days, under the Spam Act
- 30 days30 days — Written answer, per OAIC guidance
- LaterLater — Escalation and retention
| # | Clock | Step | What happens | On the file |
|---|---|---|---|---|
| 1 | Same day | Log the complaint the day it arrives | Record who complained, the address they were reached on, what they received and the date. A person must raise a privacy complaint with the business before the Commissioner will consider it, so this record is the start of the defence rather than an internal note. | Complaint reference, contact point, message identifier |
| 2 | Immediate | Stop sending to that person before investigating | Suppress the address first and work out what happened second. The suppression costs one person from one campaign; getting the order wrong turns a single message into a repeated contravention. | Withdrawal event against the person key |
| 3 | 5 business days | Honour the opt-out inside 5 business days | The Spam Act unsubscribe duty is strict: the clock starts when the request is received, not when someone reads it, and intent is not a defence. | Timestamped withdrawal, and the serving view rebuilt without the person |
| 4 | Within days | Pull the consent record | One query on the consent event table returns the grant, its timestamp, the form it came from and the purpose stated, plus any later withdrawal. That extract is the answer to the complaint. | Consent extract for the person, with source and purpose |
| 5 | 30 days | Answer in writing within 30 days | The OAIC treats 30 days as a reasonable time for a business to respond. State the information relied on, invite a reply, and apologise where an obligation was missed rather than defending the indefensible. | Written response, kept alongside the consent extract |
| 6 | On referral | Handle escalation to the regulator | A message complaint goes to ACMA under the Spam Act; a personal-information complaint goes to the OAIC in writing once the 30 days have run. The OAIC seeks to resolve by conciliation first, and the complainant has to supply the business response — so a clear, dated answer shapes the case before it starts. | Regulator correspondence, joined to the original complaint reference |
| 7 | Through the limitation window | Retain the whole file | The longest window sets the retention period, and that window belongs to the Spam Act: ACMA may start a penalty proceeding up to six years after the contravention. The privacy windows are shorter — the OAIC will generally decline a complaint raised more than 12 months after the person became aware, and the statutory tort runs one year from awareness or three years from the invasion, whichever comes first. | Complaint, consent extract, response and suppression proof held together |
OAIC — handling privacy complaintsOAIC — what a complainant is told to do firstACMA — avoid sending spam
The Timers
Every Clock in One Place
| Duration | What it governs | Where it comes from |
|---|---|---|
| 5 business days | Act on an unsubscribe request | Spam Act s 18(5) |
| 5 business days | A withdrawal of consent takes effect | Spam Act Schedule 2, clause 6 |
| 30 days | The unsubscribe facility stays functional after a send | Spam Act s 18 |
| 30 days | Sender contact details stay accurate after a send | Spam Act s 17 |
| 30 days | Respond to a complaint before the person may go to the Commissioner | OAIC complaint guidance |
| 30 days | A Do Not Call Register wash stays current | Do Not Call Register Act 2006 |
| 12 months | The window in which the OAIC will generally accept a complaint | Privacy Act s 41 practice |
| 1 year, or 3 years | Limitation on the statutory tort — from awareness, or from the invasion, whichever is earlier | Privacy Act Schedule 2 |
| 6 years | The window in which ACMA may start a penalty proceeding after a contravention | Spam Act s 26(2) |
Two of these are easy to miss. A withdrawal of consent takes effect at the end of five business days, so a send queued on day four is still a send to a person who has withdrawn. And the retention window is set by the longest limitation period rather than by the marketing calendar: the privacy windows close in one to three years, but ACMA may start a Spam Act proceeding up to six years after the contravention, so six years is what the consent record and the send log have to survive.
The Downside
What It Costs to Get This Wrong
Spam Act maximums scale on three things: whether there is a prior record for that provision, whether the sender is a body corporate, and whether the higher-tier consent rule or a lower-tier rule was broken. The figures below are section 25 penalty units multiplied by the Commonwealth penalty unit of $364, which has applied since 1 July 2026.
| Sender | Prior record | Rule broken | Per contravention | Same-day maximum |
|---|---|---|---|---|
| Body corporate | No | Consent rule | $36,400 | $728,000 |
| Body corporate | No | Sender identity or unsubscribe | $18,200 | $364,000 |
| Body corporate | Yes | Consent rule | $182,000 | $3,640,000 |
| Body corporate | Yes | Sender identity or unsubscribe | $91,000 | $1,820,000 |
| Individual | No | Consent rule | $7,280 | $145,600 |
| Individual | No | Sender identity or unsubscribe | $3,640 | $72,800 |
| Individual | Yes | Consent rule | $36,400 | $728,000 |
| Individual | Yes | Sender identity or unsubscribe | $18,200 | $364,000 |
Derived from Spam Act s 25 penalty units Calculated
How the other regimes sit beside this table
| Point | What it means |
|---|---|
| The Spam Act ceiling is a Federal Court maximum | Section 25 scales on three things: whether there is a prior record for that provision, whether the sender is a body corporate, and whether the higher-tier consent rule or a lower-tier rule was broken. ACMA more often uses infringement notices paired with court-enforceable undertakings, and it lists enforcement outcomes publicly — the reputational cost travels further than the penalty. |
| Privacy Act penalties now run in three tiers | The top tier has applied since 13 December 2022: for a serious interference with privacy the maximum is the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover for the relevant period. From 11 December 2024 two tiers sit beneath it — a middle tier for an interference that falls short of serious, and a lower tier carrying infringement notices for administrative breaches of the principles. |
| The first civil penalty judgment has landed | On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over its handling of a data breach — the first civil penalty decision in the history of the Privacy Act. Conduct does not have to be deliberate, and relying on an external provider does not transfer the duty. |
| Individuals can now sue without proving damage | The statutory tort covers intentional or reckless serious invasions of privacy, including misuse of information. Damages for non-economic loss are capped at the level that applies to defamation, and a court may order an apology or an injunction instead of or alongside damages. Consent and lawful authority are defences. |
This is why consent health is a standing Leadership Team report rather than an operational detail: the downside is measured in penalty units and the evidence is a query. See the report specs on the prototype
Before Going Live
What the Pilot Needs Before Its First Send
The data side of this is built. What remains is the operating side — the entity details in the footer, the sender ID registration, and the opt-in wording that has to carry consent for two sensitive fields.
| # | Before the first send | Why |
|---|---|---|
| 1 | Legal entity name, ABN and a contact route in the footer of every template | Section 17 asks who sent this and how the person reaches them, and the answer has to stay correct for 30 days after the send. |
| 2 | Branded SMS sender ID registered through each sending telco, and each provider authorised | From 1 July 2026 an unregistered branded ID is shown as Unverified on the handset. |
| 3 | Opt-in wording reviewed for the ancestry and language fields | Consent under APP 3.3 and APP 7.4 has to be informed, voluntary, current and specific. A bundled tick inside a general privacy policy does not reach that bar for sensitive information. |
| 4 | A privacy policy and a collection notice for the operating platform, per jurisdiction | APP 1 and APP 5, and the automated-decision disclosure that applies from 10 December 2026. |
| 5 | A written complaint procedure naming a privacy contact and an address | The OAIC directs people to the business first, using the route set out in its privacy policy. A missing route becomes a complaint about the complaint. |
| 6 | Ad-platform audience terms accepted by the entity that holds the consent | The upload warranty binds whoever clicks accept. If that is an agency rather than the consent holder, the warranty is given by a party that cannot evidence it. |
Sources
Where Each Statement Comes From
| Instrument | Regulator | Source |
|---|---|---|
| SPAM | Australian Communications and Media Authority | Spam Act 2003 (Cth) and Spam Regulations 2021 |
| APP7 | Office of the Australian Information Commissioner | Privacy Act 1988 (Cth) — Australian Privacy Principles |
| DNCR | Australian Communications and Media Authority | Do Not Call Register Act 2006 (Cth) |
| SMSID | Australian Communications and Media Authority | SMS Sender ID Register |
| POLA | Office of the Australian Information Commissioner and the Federal Court | Privacy and Other Legislation Amendment Act 2024 |
| ACL | Australian Competition and Consumer Commission | Australian Consumer Law — Schedule 2, Competition and Consumer Act 2010 (Cth) |
| TERMS | Contractual — Meta, Google and TikTok | Ad-platform custom audience terms |
Statutory text is linked to the regulator that enforces it or to the consolidated legislation. Figures drawn from the audience file carry the sample-data label, and figures worked out from penalty units carry the calculated label, so a reader can tell at a glance which numbers move when the file changes and which move when the law does.
