Let’s begin with the question we get asked every so often: are there anti-spam rules and regulations specific to Queensland?
The answer is no. There are only federal regulations that apply to Queensland as well as all other states and territories. These regulations were first devised and put into force as early as 2003! The so-called Spam Act 2003 would later be amended in 2021 with the text called Spam Regulations.
We already tackled different ways how you can and should minimise spam. Here we’ll lay out in detail what these regulations mean for your business, and how to implement them.
But first, let’s see what spam actually is, as it can easily be mistaken for other forms of undesirable online activity.
What Spam Is (& What It Isn’t)

Let’s begin with how the government itself defines spam. In plain English, an email is spammy if it meets any of these three requirements:
- It’s unsolicited, that is, you are sending it without the person asking for it or consenting to it.
- It lacks clear or contains misleading identification of the sender.
- It lacks a clear and functional way to opt out of any future messaging.
In other words, anything that isn’t explicitly asked for or said yes to can classify as spam. This means not only emails but ANY messaging—including text messages or even communication on social media.
Ignore any of these and you could be facing very fat fines! In fact, the heaviest penalty to date was dished out back in 2023. The Commonwealth Bank had to pay a whopping $3.55 million for having sent 65 million emails that disregarded the bill. Not that the bank sent unsolicited or unsigned emails, mind you! The “only” thing it did was requiring users to log in when they wanted to unsubscribe.
In other words, they failed to provide a one-click way to opt out, probably hoping that the inconvenience of logging in and out would avert people from unsubscribing.
Other notable examples of companies that breached the act include the food delivery service DoorDash, the eyewear company Luxottica, as well as Pizza Hut, which had to dish out $2.5 million for emailing people who hadn’t subscribed. The list goes on to include Kogan, Ticketek, Sportsbet, Outdoor Supacentre, The Wine Group…
Spam vs. Scam
In our experience, people often tend to mistake spammers for scammers or even what we in the industry call time-wasters.
To draw the line between spam and scam, you need to know that not all spam is harmful or deceitful in its nature. Much of it can be perfectly legitimate! However, legitimate or not, the fact is that it just isn’t wanted and can very often be irrelevant. For example, you may receive a random email offering you sunglasses at 80% off from a company you’ve never heard of. Nor do you even need sunglasses!
Spamming is essentially a numbers game. It works in bulks where the point is to cast as wide a net and get in front of as many eyes as possible, whether people want it or not. Even completely legitimate communication can verge on spam if it starts happening more often than the recipient wants!
The line of consent is very fine, and it takes a lot of tact and attention to get it just right.
On the other hand, scammers will send you an email with a goal to trick or deceive you into giving away something of value. They are usually after your personal info or your money, and they do it by impersonating a trustworthy person, company or institution. For example, you get an email claiming to be from your bank asking you to “verify your account information” by entering your login details on a fake website.
There are other categories of unwanted communication too. At one time or another, you’ve probably dealt with time wasters, who aren’t malicious at all, but can still be annoying. They ask a lot of questions but never move things forward, just taking up your time. There are also cold callers, who typically call random numbers in order to sell something, whether the person on the other side is interested or not. They can be pushy and annoying, but their activity isn’t illegal outside the normal working hours.
Types of Consent
One of the most important concepts in the Spam Act is consent, which is defined as either express or inferred:
- Express Consent: This is when a person specifically agrees to receive marketing messages, typically by ticking a box on a form, signing up for a newsletter, or otherwise giving direct permission. In other words, I absolutely want to receive your emails, and I consciously act to enable it.
- Inferred Consent: This occurs when there’s an existing business or other relationships where it can be reasonably inferred that the recipient is open to receiving messages. For example, if I have purchased from your company in the past, the business might reasonably infer that I am willing to receive updates or offers.
The line here is sometimes blurry! So, if in any way possible, it’s always best to get express consent.
Consent in Practice (+ Examples)

Let’s say a landscaping business in Queensland collects emails from people who use their website to book a service. By ticking a box that says, “Yes, I would like to receive updates and offers,” the customer is providing express consent for the company to send marketing emails. If the customer leaves this box unchecked, the company is not allowed to email them for promotional purposes.
However, if the customer previously hired the company to landscape their garden, and the business sends a follow-up email to offer a discount on future services, this could fall under inferred consent. In this case, it’s reasonable to assume the customer might be interested in hearing from them again.
But what happens if the company sends an email advertising the services of their partners, which isn’t directly related to landscaping? This would cross the line of consent and could be regarded as a breach of the anti-spam rules.
Let’s see what other checkboxes this business has to tick in order to act by the rules.
They would have to provide clear identification, meaning business name and contact details, such as a phone number or an email address.
Another must is a clear “Unsubscribe” button that really does what it says it does, and does it quickly. You can optionally include an “Update Your Preferences” button that can be used to unsubscribe but also tweak the frequency of receiving emails from you.
As Arlo Hughes, one of our former clients and the founder of a roofing business in Brisbane (QLD) points out, the best way is to include a double opt-in where the user needs to confirm their subscription for your emails. “Moreover, the email can include a short note as a reminder why the user is receiving emails from the company. We always remind them that they are getting this email because they opted in either through our website or in-person, as customers or clients. This is because, in our experience, many people will mark your email as spam even if it’s not, mistakenly assuming that it’s not much different in effect from deleting or archiving an unwanted email. But if you remind them that it’s them who opted in and how they did it, they’ll be more considerate and hit ‘unsubscribe’ if that’s what they want,” Hughes told us.
Note that this reminder isn’t a must under Spam Act. Still, it acts nicely as another safety layer for you as a sender.
What Else is Illegal Under Spam Act?
As we said above, spammers play a numbers game.
And if you want to play a numbers game and send hundreds or thousands of emails every day, you can’t go around and manually scour websites for contact info. By that pace, it would take months to collect enough email addresses to make it work!
So to scale up their activity and make it at all viable, they use so-called email harvesting software. These are tools that are automated to screen gazillions of websites looking for one thing alone: email addresses.
Small wonder that such harvesting software was made completely illegal by the Spam Act! The very concept bypasses consent as such, so it’s no wonder that no businesses are allowed to use such software for any purposes.
Exemptions Under the Spam Act
Not every email you may want to send is covered by the Spam Act. Some exemptions include:
- Non-commercial messages: Emails or messages that do not contain any commercial content, such as personal emails or political messages, are exempt. Note, however, that this applies to registered organisations such as political parties or charities, as well as government and educational institutions.
- Transactional messages: Emails that are necessary for the completion of a transaction, such as receipts or booking confirmations, are also exempt.