Every marketing text you send needs three things in place: valid consent, clear sender identification and a working opt-out. From 1 July 2026, there’s a fourth requirement if you use a branded sender ID: it must be registered on the SMS Sender ID Register, or carriers will flag it as “Unverified.” Using a provider doesn’t shift the legal risk. Your business stays responsible for every message sent in its name.
TL;DR:
- Businesses using branded sender IDs must register them on the SMS Sender ID Register from July 2026, or carriers will tag them as “Unverified,” reducing open rates.
- Proper consent must be clearly recorded, with strong evidence such as timestamps and form copies, especially since inferred consent weakens over time.
- Unsubscribe mechanisms require testing for functionality, prompt removal across all platforms within five days, and clear wording like “Reply STOP to unsubscribe.”
- Outsourcing SMS sending does not shift legal liability; businesses must retain access to consent logs and ensure suppliers meet compliance standards.
- Sending promotional messages outside reasonable hours or misrepresenting offers breaches the Spam Act, and content must include identification and a clear opt-out option within character limits.
Table of Contents
- The Spam Act 2003 pillars: consent, identification and unsubscribe
- SMS Sender ID Register: what changed on 1 July 2026
- Proving consent the way ACMA expects
- Unsubscribe mechanics and the traps that break compliance
- Outsourcing and third-party providers: you stay liable
- ACMA enforcement: what happens if a complaint lands
- Pre-send and post-send compliance checklist
- Message content and timing rules that keep SMS from feeling intrusive
- What has to appear inside the message itself
- SMS marketing and the Australian Privacy Principles
- Data security for SMS marketing lists
- Responding to a consumer complaint about SMS marketing
- SMS compliance vs email and social media rules
- How Moor Marketing builds compliance into SMS growth programs
- Get your SMS program compliant and converting
- Sources
- FAQ
The Spam Act 2003 pillars: consent, identification and unsubscribe
The Spam Act 2003 is the federal law behind every SMS compliance requirement in Australia, and it rests on three pillars that translate directly into your campaign settings.
Consent comes in two forms. Express consent is unambiguous: a customer ticks a box, texts a keyword, or signs up through a form that clearly states they’ll receive marketing texts. Inferred consent is murkier. It exists where someone has an existing business relationship with you, such as a recent purchase, and would reasonably expect a marketing message. Inferred consent doesn’t cover a list bought from a third party or scraped from a business card at a trade show.
Identification means every commercial SMS needs to clearly show who sent it, whether that’s your business name in the message body or a recognisable sender ID. Business confirms this applies regardless of message length, so there’s no character-count excuse for dropping it.
Unsubscribe obligations are specific and non-negotiable:
- Opt-out requests must be actioned within five working days.
- The opt-out facility must stay functional for at least 30 days after the message is sent.
- You cannot ask for a login, extra personal details, or payment to process an opt-out.
SMS Sender ID Register: what changed on 1 July 2026
The SMS Sender ID Register was introduced to combat the wave of scam texts impersonating banks, delivery services and government agencies. From 1 July 2026, any business using an alphanumeric (branded) sender ID, such as “MOORMKT” instead of a phone number, must register that ID. Carriers now label unregistered branded sender IDs as “Unverified,” which tanks open rates and looks exactly like the scam behaviour the register was built to stop.
Who can register directly depends on your business structure:
- Entities with an ABN can register their sender ID directly through ACMA.
- Businesses without an ABN, such as some sole traders or overseas entities, need a certified telco or aggregator to register on their behalf.
- Everyone sending branded SMS should confirm their Australian Business Register details match exactly what they intend to register, since mismatches cause registration delays.
Pro Tip: Registration touches your telco’s systems, not just your marketing platform, so treat it as an operational project with a lead time, not a checkbox you tick the week before a campaign launches.
If your sender ID isn’t registered yet, fall back to sending from a standard mobile number until it clears. It’s slower to set up but keeps deliverability intact in the meantime.
Proving consent the way ACMA expects
Good record keeping is what separates a business that survives an ACMA inquiry from one that doesn’t. The strongest opt-in flows are a checkout tickbox with clear wording, a text-to-join keyword campaign, or a double opt-in confirmation. Weak or non-compliant practices include pre-ticked consent boxes, consent bundled into unrelated terms and conditions, and any list bought or scraped from outside your own audience.
For every subscriber, store a minimal evidence set that reconstructs consent on demand, following the content compliance requirements for SEO success:
- Timestamp of opt-in
- Exact copy or screenshot of the form shown at the time
- The channel used (checkout, landing page, SMS keyword) and any confirmation reply
- Campaign or form version, so you can trace consent back to a specific offer
This kind of immutable consent log is what ACMA investigators actually ask for, not a vague assurance that “the customer signed up somewhere.”
Inferred consent is riskier to rely on long term. It weakens the longer the relationship goes quiet, so a customer who bought once eighteen months ago is a poor candidate for inferred consent today. If you’re building a welcome flow off a first purchase, an SMS marketing setup for eCommerce makes the distinction between express and inferred consent explicit at the point of signup, which saves arguments later.
Unsubscribe mechanics and the traps that break compliance
An unsubscribe is only “functional” if a real person can act on it without friction, and the message that carries it has to receive replies. That second part trips up more businesses than you’d expect.
- Test that “Reply STOP” actually works. ACMA’s own guidance flags sending from a Sender ID that can’t receive inbound replies as one of the most common compliance failures, because the recipient’s opt-out simply vanishes.
- Check suppression syncs across platforms. A customer who opts out of SMS through your provider but still gets emails from a separate system hasn’t been unsubscribed, they’ve been partially unsubscribed.
- Reword vague unsubscribe copy. “Text STOP to opt out of promotions” is clearer than “Reply to unsubscribe,” which some recipients read as needing to reply with specific wording.
Pro Tip: Run a live test every quarter: send yourself a campaign, reply STOP, and confirm you stop receiving messages within the five-day window. It takes ten minutes and catches the exact failure that generates most complaints.
Outsourcing and third-party providers: you stay liable
Handing your SMS sends to a platform or agency doesn’t transfer legal responsibility. Research on outsourcing compliance risk is blunt on this point: the business that authorised the message is the business ACMA comes after, regardless of who pressed send.
Build these controls into every supplier relationship:
- Contractual access to consent logs, not just campaign reports.
- A written SLA that commits to processing unsubscribes within the five working day legal limit.
- Audit rights so you can review supplier practices, not just take their word for it.
- One shared suppression list across every channel and platform you use, so an opt-out on SMS also blocks email and vice versa.
A short supplier questionnaire before you sign, plus a periodic audit afterwards, catches most problems before ACMA does.
ACMA enforcement: what happens if a complaint lands
ACMA’s toolkit ranges from formal warnings to infringement notices, enforceable undertakings, and Federal Court action for serious or repeated breaches. The regulator actively publishes enforcement outcomes specifically to deter non-compliance, and the reputational damage from a public investigation often outweighs the financial penalty itself.
If a complaint reaches you, move fast. Preserve every consent record tied to the recipient in question before anything else. Pause the relevant campaign if the same issue could be affecting other subscribers. Bring in legal advice early rather than after ACMA has already opened a file, and document every remediation step you take, because that record is what demonstrates good faith if the matter escalates.
Pre-send and post-send compliance checklist
Run this before every commercial SMS campaign leaves the building, and again after it lands.
- Confirm opt-ins are current and match the consent type (express or inferred) you’re relying on for that segment.
- Match your sender ID to your ABR details exactly, particularly if it’s newly registered.
- Test the unsubscribe path end to end, including the reply channel.
- Deduplicate suppression lists across every platform touching that subscriber.
- Verify supplier controls are current, especially consent logs and SLA compliance.
- Brief staff on what counts as a “commercial” message versus transactional, since the line trips up a lot of teams.
After the send, monitor opt-out volume and any complaint flags, update suppression lists immediately, and log corrective actions if anything went wrong. That log becomes your evidence file if ACMA ever asks questions.
Message content and timing rules that keep SMS from feeling intrusive
Compliance isn’t only about consent and opt-outs. It covers what the message says and when it lands. Content that’s misleading about price, availability, or the nature of an offer breaches the Spam Act regardless of whether consent was valid, because consent covers receiving marketing, not being misled by it.
Timing matters more with SMS than any other channel, because a text interrupts in a way email doesn’t. There’s no single legislated “quiet hours” rule for marketing SMS the way there is for telemarketing calls, but sending outside reasonable daytime hours, say before 8am or after 8pm local time, invites complaints even from subscribers who technically opted in. Frequency matters too: a subscriber who signed up for order updates and suddenly gets five promotional texts a week is far more likely to complain, and complaint volume is one of the signals that draws ACMA’s attention in the first place.
Keep offers specific and time-bound rather than vague (“Sale ends Sunday” beats “Big savings now”), and never disguise a promotional message as a service update to get around opt-out fatigue. That’s the kind of pattern ACMA guidance on common e-marketing mistakes specifically calls out, because it erodes the distinction between transactional and commercial messages that the whole consent framework depends on.
If you’re running automated flows, such as cart abandonment or post-purchase sequences, check where the transactional content ends and the promotional content begins. A shipping confirmation is transactional. A shipping confirmation with a discount code for a second purchase tacked on is commercial, and needs consent and an opt-out like any other marketing text.

What has to appear inside the message itself
Every commercial SMS needs enough information in the body for a recipient to identify who sent it and how to opt out, but there’s no requirement to cram in an ABN or postal address the way some email disclaimers do. Practically, that means your business name (or a recognisable brand sender ID once registered) and a working opt-out instruction, such as “Reply STOP to unsubscribe,” need to fit within your character budget alongside the actual offer.
Character limits push a lot of businesses to compress copy to the point where the sender or opt-out gets dropped entirely, and that’s a common source of accidental non-compliance rather than deliberate corner-cutting. Shop now: [link]. Reply STOP to opt out." That’s identification, an offer, and a functional unsubscribe in under 160 characters.
If your brand name doesn’t clearly identify the business (a sub-brand or a product line, for instance), add a short clarifier, because “identification” means the average recipient can tell who’s texting them, not just that a sender ID exists in the metadata. There’s no mandated disclaimer wording under the Spam Act, unlike some overseas SMS regimes that require specific opt-out phrasing. The requirement is functional: consent, identity, and a working unsubscribe, delivered in whatever wording gets that across clearly.
SMS marketing and the Australian Privacy Principles
The Spam Act governs how you send marketing texts. The Australian Privacy Principles, sitting under the Privacy Act, govern how you collect, store, and use the phone numbers and personal information behind those sends, and both frameworks apply simultaneously to any SMS program.
APP 3 requires you to collect personal information, including a mobile number, only by lawful and fair means, and only what’s reasonably necessary for the purpose stated at collection. If your signup form says “for order updates,” using that same number for unrelated promotional blasts later stretches beyond what was disclosed. APP 6 restricts using personal information for a secondary purpose without consent, which is directly relevant if you ever want to repurpose a customer service number list for marketing.
APP 1 requires a clear, accessible privacy policy explaining what you collect and why, which matters for SMS because a lot of businesses document their email data handling but forget to extend that policy to cover SMS numbers and opt-in records specifically. If you’re building or auditing a cookie consent and data collection setup for your site, the same audit should confirm your SMS opt-in forms and privacy policy language are consistent with each other, not treated as separate compliance projects.
Data security for SMS marketing lists
A phone number list is a smaller dataset than a full CRM export, but it’s still personal information under the Privacy Act, and a breach involving thousands of mobile numbers and opt-in histories carries the same notification obligations as any other data breach.
Practical security steps that apply specifically to SMS programs:
- Restrict access to your subscriber list and consent logs to staff who actually need it for campaign operations, not the whole marketing team.
- Encrypt exported subscriber lists, particularly if they’re shared with a supplier or agency for campaign execution.
- Set a retention policy. Numbers from people who unsubscribed years ago sitting in an old spreadsheet are a liability with no marketing upside.
- Vet any third-party platform’s own security posture before handing over your list, since a breach at your supplier is still your compliance problem to answer for.
Responding to a consumer complaint about SMS marketing
Most complaints start small: a recipient reports your number to their telco, or emails you directly saying they never signed up. How you respond in the following days matters as much as the campaign that triggered it.
Acknowledge the complaint and locate the consent record for that specific number within 24 to 48 hours if possible. If you can produce a timestamp, opt-in form copy, and channel, most complaints resolve immediately because the paper trail settles the dispute. If you can’t produce that record, treat it as a genuine unsubscribe and suppress the number across every channel immediately, regardless of whether you believe consent existed.
Confirm the unsubscribe processed within the five working day legal window ACMA sets, and follow up with the complainant to confirm it’s done. If the complaint escalates to ACMA directly, respond to any information request promptly and provide the same consent documentation. Delayed or incomplete responses to ACMA enquiries tend to escalate a minor complaint into a formal investigation faster than the original complaint would have on its own.
SMS compliance vs email and social media rules
SMS carries a stricter, faster compliance clock than most other digital channels, and treating it like “email with a shorter character limit” is where a lot of businesses go wrong.
Email under the Spam Act has broadly the same three pillars, consent, identification, unsubscribe, but SMS enforcement of the five-day opt-out window and 30-day functional period is applied with less tolerance, partly because a text interrupts a phone in a way an email sitting in an inbox doesn’t. Social media advertising on platforms like Meta or TikTok doesn’t fall under the Spam Act at all; it’s governed instead by each platform’s own advertising policies and, more broadly, by Australian Consumer Law around misleading claims. That means a retargeting ad and a marketing text promoting the same sale sit under completely different compliance regimes, even though they might use the same customer list.
The sender ID registration requirement is unique to SMS. Nothing in email or social advertising has an equivalent, because impersonation and scam risk is specifically a phone number and branded-sender problem. If you’re running a coordinated campaign across email and SMS, build separate compliance checklists for each channel rather than assuming a single consent record covers both. A customer who consented to email marketing hasn’t automatically consented to SMS, and vice versa.

How Moor Marketing builds compliance into SMS growth programs
Compliance and revenue aren’t in tension when the program’s built right from the start. Consent capture, sender ID setup, and supplier oversight get designed alongside the campaign calendar, not bolted on afterwards. That approach protects deliverability and keeps subscriber lists clean, which tends to lift customer lifetime value because the people still on your list actually want to hear from you.
— Liza
Get your SMS program compliant and converting
Many agencies treat compliance as legal’s problem and growth as marketing’s problem. Some providers coordinate both from the same senior strategist, so SMS programs don’t stall waiting for approval on the consent flow. That’s the practical difference for an eCommerce brand trying to move fast on the 1 July 2026 sender ID deadline without creating a mess a lawyer has to untangle later.

Some Email & SMS Growth Marketing services cover consent audits, sender ID registration support, suppression list consolidation across email and SMS, and ongoing campaign execution, all run by a senior strategist rather than handed off to a junior account manager. If you want a program that treats compliance as part of the growth build rather than a separate checklist, get in touch through Moormarketing’s main site and we’ll walk you through what a compliant, revenue-focused SMS setup looks like for your brand.
Sources
FAQ
What are the regulations for SMS marketing in Australia?
Commercial SMS must have consent (express or inferred), clearly identify the sender, and include a functional unsubscribe under the Spam Act 2003. From 1 July 2026, branded sender IDs also need registration on the SMS Sender ID Register.
What is SMS compliance?
SMS compliance means every marketing text meets the Spam Act’s consent, identification, and unsubscribe requirements, plus, from mid 2026, sender ID registration if you use a branded sender ID. It also includes handling subscriber data under the Australian Privacy Principles.
What are the new ACMA SMS rules for 2026?
From 1 July 2026, businesses using alphanumeric branded sender IDs must register them through the SMS Sender ID Register, or carriers will mark the sender as “Unverified.” Entities with an ABN can register directly; others need a certified telco to register on their behalf.
What is the best way to run compliant SMS marketing in Australia?
There’s no single “best” platform, but the safest approach pairs a compliant opt-in flow with centralised consent logging and a tested unsubscribe path across every channel. Services like Moormarketing’s Email & SMS Growth Marketing build these controls in from the setup stage rather than adding them after a campaign is already live.
How long do I have to action an SMS unsubscribe request?
Unsubscribe requests must be actioned within five working days, and the opt-out facility must stay functional for at least 30 days afterwards. You cannot charge a fee or require extra personal details to process it.





