Consent-aware marketing under Australian law: APP 7 of the Privacy Act 1988 requires explicit consent for direct marketing.; Spam Act 2003 mandates a functional unsubscribe option in all commercial messages.; Recheck consent close to sending, including sender, purpose and channel eligibility.
Image: Automation Marketing Lab

Consent Approvals

Consent-aware marketing automation under Australian law

Design marketing workflows that retain permission evidence, respect withdrawals and check eligibility before each send.

Consent-aware marketing automation checks whether a particular marketing action is permitted for a particular person now. It keeps evidence for the decision, respects withdrawals and holds an action when eligibility cannot be established.

A person’s entry into a workflow yesterday does not establish eligibility for a send today. Check permission and message requirements again close to sending.

Define the decision

Start with the proposed action: who is sending, through which channel, for what purpose and to which address or number? Record the basis relied on, along with narrower preferences and exclusions. A download request, a purchase and agreement to ongoing promotions are different events.

APP 7 of the Privacy Act 1988 (Cth) governs some uses or disclosures of personal information for direct marketing. The Spam Act 2003 (Cth) sets requirements for commercial electronic messages, including consent, sender identification and a functional unsubscribe facility.

Check the requirements for the particular action rather than treating a general permission status as sufficient. The decision record should connect the basis relied on to the proposed use and channel.

APP 7 generally prohibits an organisation from using or disclosing personal information it holds for direct marketing unless an exception applies. Where direct marketing is permitted, the organisation must allow the individual to request not to receive communications and comply with that request.

For commercial electronic messages, check that the applicable Spam Act consent requirement is met, the sender is identified with contact details, and the message includes a functional unsubscribe facility. These checks are separate from the APP 7 decision.

Key compliance thresholds under Australian privacy laws

  • APP 7 Exception ThresholdPersonal information collected directly from individual may be used for marketing if they would reasonably expect it.
  • Spam Act Consent RequirementMust include functional unsubscribe link and identifiable sender with contact details.
  • Withdrawal Response TimeMust cease sending within 30 days of withdrawal request under ATO guidelines.
  • Data Source DisclosureIndividuals can request source of personal information; response required unless impracticable.

Distinguish APP 7 pathways

The exceptions in APP 7.2 and 7.3 apply to personal information other than sensitive information; APP 7.4 contains a separate exception relating to sensitive information. APP 7.2 and 7.3 distinguish information collected directly from the individual where they would reasonably expect direct marketing, from information collected from a third party or used in ways they would not reasonably expect.

Third-party sources can include data-list providers, mobile applications and lead-generation or data-enhancement services. Treat the information’s source and the person’s reasonable expectations as part of the decision, not as interchangeable evidence.

Both exceptions require a simple way to opt out. Where the information came from someone else, or the individual would not reasonably expect it to be used for direct marketing, additional requirements apply to make the opt-out right known.

An individual can also ask an organisation for the source of their personal information. The organisation must provide it unless doing so is impracticable or unreasonable, so the process should make it possible to answer that request.

Using third-party data for direct marketing

  • ProsCan expand reach and improve targeting with enriched datasets from lead generators or data-enhancement services.
  • ConsRequires additional transparency: must inform individuals of the source and provide a clear opt-out mechanism if they did not expect their data to be used for marketing.

Make permission understandable

For consent to the handling of personal information, the OAIC says consent should be informed, clearly explain how the organisation wants to handle the information, and be communicated in plain English rather than legal or technical language.

The OAIC describes express privacy consent as given openly and obviously, verbally or in writing; a handwritten, electronic or voice signature can be an example. For non-sensitive personal information, implied consent may apply where an organisation reasonably believes it has consent.

Spam Act consent is a distinct check: consent may be express or inferred. Rely on inferred consent only where an existing commercial relationship relates to the subject matter of the marketing message.

Check that the consent covers the sender, purpose and channel, and remains current. Permission to send email does not by itself establish permission to send SMS, and providing contact details to receive a receipt is not permission to receive marketing.

Express vs implied consent under Australian law

  • Express ConsentGiven openly – in writing, electronically, or verbally. Includes signed forms, checkbox selections, or voice confirmation.
  • Implied ConsentReasonably inferred from conduct, e.g., providing contact details during a purchase. Only applies where the individual would reasonably expect marketing related to that transaction.
  • Spam Act Inferred ConsentOnly valid if there’s an existing commercial relationship related to the subject matter of the message.
  • Key LimitationImplied consent does not cover new purposes or channels (e.g., SMS after email opt-in).

Keep an explainable state

Separate the current decision from the events supporting it. Keep enough evidence to explain the basis relied on and connect it to the proposed use.

For consent records, retain the method, terms and date and time consent was obtained. If relying on inferred consent, preserve the facts and assessment behind it.

State for a proposed actionResponse
Current basis and no applicable withdrawalContinue to the other campaign checks.
Applicable withdrawal or suppressionStop the affected marketing action.
Missing or conflicting evidenceHold for a documented decision.
Purpose or channel outside the recorded scopeEstablish an appropriate basis through a permitted route before using that scope.

These are operating choices, not platform status labels. Do not send a promotional message merely to ask someone who withdrew whether they want to rejoin.

For privacy consent decisions, retain what handling was explained and whether the response was express or implied. A general status alone does not establish that consent supports the proposed use.

Check close to the send

A contact can withdraw while a journey waits. Recheck eligibility at the last point where the intended send can still be stopped, including whether current permission covers the sender, purpose and channel.

If the permission record cannot be read, hold the action and alert an owner. Check sender identification and contact details, and confirm that the message has a functional unsubscribe facility.

Record the decision against the campaign and message version. Keep it separate from the sender’s outcome: an eligible message may never have been submitted, and a timed-out submission needs investigation before a retry.

Carry withdrawals through sending routes

Withdrawal events change the eligibility decision and should remain connected to the same person, channel, sender and purpose. Where a withdrawal applies, the affected marketing action is not eligible.

Detailed withdrawal handling and cross-tool suppression propagation are covered by the sibling articles.

Review decisions and outcomes

Before launch, set expected results for eligibility decisions and held actions, then inspect the actual sending route with controlled records where it can be safely contained. A workflow preview alone cannot confirm what a separate sender did.

After launch, review held actions and mismatches between the permission record and sending systems. Every intended send should have an answer to two questions: why was this person eligible at that moment, and what happened to the action?

In this guide

  1. Storing the source and date of a marketing permissionRecord who gave marketing permission, when, how and for what scope, while preserving later changes and withdrawals.
  2. Stopping messages when a contact withdraws permissionHandle a marketing withdrawal across waiting, scheduled and provider-bound messages, then confirm suppression.
  3. Propagating suppression changes across marketing toolsTrack suppression updates through every sending tool, reconcile failures and prevent stale syncs from restoring eligibility.
  4. Testing permission checks at the moment of sendUse controlled cases to check current permission, late withdrawals and the sender's actual action before launch.

More from Consent Approvals

Consent Approvals

Automated campaign approvals

Automated campaign approvals move a draft to the people who must review it, record their decisions and release it only when the approved version is ready.

Consent Approvals

Propagating suppression changes across marketing tools

Track suppression updates through every sending tool, reconcile failures and prevent stale syncs from restoring eligibility.