Lead Generation

How SDR Teams Stay Compliant with Australia’s Spam Act

how sdr team stay compliant with australian spam act
Frean Nismal

Frean Nismal

July 31, 20266

One email sequence. One unregistered sender ID. One unsubscribe link that quietly stopped working three months ago. That’s all it takes for an SDR team running appointment setting and cold outreach to become a six- or seven-figure liability under Australia’s Spam Act.

Commonwealth Bank of Australia found that out the hard way, to the tune of $7.5 million. Sportsbet paid $2.5 million, plus roughly $1.2 million in customer refunds. Telstra copped $626,000 after self-reporting its own breach. None of these is small operators. They’re companies with legal teams, compliance officers, and marketing platforms most SDR teams would envy, and they still got caught out.

If your outbound program is scaling volume without a compliance layer built in, the question isn’t whether there’s exposure. It’s how much, and how soon someone finds it.

The Real Risk Isn’t the Fine, It’s the Pipeline You Lose Fixing It

Here’s what actually happens when an SDR team gets flagged for non-compliant outreach: campaigns get paused mid-quarter while legal reviews every template. Lists get frozen. Reps sit idle. Pipeline that took months to build stalls out, right when the business needs it moving.

The fine is the visible cost. The invisible one is the quarter you lose sorting it out, and the damage to a sender’s reputation that takes far longer to rebuild than it took to break.

This is exactly why compliance can’t sit with legal alone. It has to be built into how SDR teams source, message, and manage every list, before a single email goes out.

What’s the maximum penalty under Australia’s Spam Act?

Penalties are calculated per day using penalty units and can reach millions of dollars for corporations. ACMA’s largest penalty to date, against Commonwealth Bank of Australia, was $7.5 million.

Don't wait for a frozen list to find out where your gaps are. Callbox can audit your current outbound setup and flag exposure before it costs you a quarter of your pipeline.

What Compliant Outreach Actually Requires

Three things, non-negotiably:

  1. Verifiable consent. Not “we assumed it was fine because it’s a business email.” Australia recognises express and inferred consent, but inferred consent is narrower than most teams assume. It doesn’t cover personal accounts, stale purchased lists, or contacts who’ve already opted out somewhere else in your stack.
  2. Clear identification. Real company name, real contact details, every message. A generic sales alias doesn’t cut it, and neither does an unregistered SMS sender ID (more on that below, because this one has a deadline attached).
  3. A working opt-out. Not tested once at setup and forgotten. ACMA’s enforcement pattern shows this is the single most common failure point, which also makes it the easiest one to get right if someone’s actually checking.

Miss any of these, and it doesn’t matter how good the messaging is. The campaign is exposed.

Does the Spam Act apply to B2B cold email in Australia? 

Yes. Inferred consent can apply to published business contacts, but identification and a working unsubscribe are still required regardless. 

A Deadline That’s Already Live: SMS Sender ID Registration

If SMS is part of your outbound cadence, this affects you directly, not eventually.

From 1 July 2026, any SMS sent under an unregistered branded sender ID displays as “Unverified” instead of your business name, and gets grouped with unknown senders, including likely scams. Registration is free, but verification can take several weeks, longer without an ABN.

Teams that haven’t registered are already watching open rates drop, and the gap between “registered” and “unverified” competitors is only going to widen as the deadline approaches. This isn’t a compliance nice-to-have. It’s a direct hit to response rates if it’s ignored..

What happens if I don’t register my SMS sender ID by July 2026?

Messages display as “Unverified” and may be grouped with likely scam senders, which materially hurts open and response rates.

Cold Calling Has Its Own Rulebook

Phone outreach sits under separate legislation, the Do Not Call Register Act 2006 and the Telemarketing and Research Calls Industry Standard. The non-negotiables:

  • No calls to Do Not Call Register numbers without a genuine exemption or express consent
  • Calling hours limited to 9 am to 8 pm weekdays, 9 am to 5 pm weekends, no public holidays
  • Caller ID presented, never blocked or spoofed
  • Clear identification of the caller and the business they represent
  • Opt-out requests honoured within 30 days

This is also where choosing the right telemarketing provider matters as much as the script itself. Some treat these rules as optional. Others build them into every call by default. A team hitting call volume targets while ignoring any of these isn’t actually ahead. They’re building risk faster than they’re building pipeline. 

Can I still cold call prospects in Australia? 

Yes, provided the number isn’t on the Do Not Call Register, calls stay within permitted hours, and the caller clearly identifies themselves and the business they represent. 

How Callbox Keeps Outbound Compliant Without Slowing It Down

This is where most in-house SDR teams hit a wall. Compliance takes deliberate infrastructure, consent tracking, verified list sourcing, registered sender IDs, tested opt-out flows, calling hour scheduling by timezone, and someone accountable for auditing all of it regularly. Building that alongside hitting quota is a lot to ask of a lean team.

It’s built into how Callbox runs every AU and NZ campaign from day one. Lists are sourced and verified before they ever reach a rep. Sender IDs are registered ahead of deadlines, not scrambled for after open rates drop. Opt-outs are actioned immediately, not queued. Call cadences are scheduled to stay inside legal hours automatically, so reps aren’t making that judgement call themselves at 7:45 pm on a Friday.

The result isn’t just fewer compliance headaches. It’s cleaner sender reputation, better deliverability, and outreach that converts because it’s landing with people who were always a legitimate fit to hear from you.

If you’d rather talk compliant outbound strategy face to face, we’ll be at Tech Week Singapore this September.

Techweek Image CTA

Quick Self-Audit: Is Your Outbound Actually Covered?

Run through this with your team this week:

  • Can you show, for any contact, why you believe you have consent to message them?
  • Does every template clearly identify your company with working contact details?
  • Has your unsubscribe link been tested in the last 90 days, not just assumed to work?
  • Is your SMS sender ID registered ahead of 1 July 2026?
  • Do your call scripts and hours align with the Do Not Call Register Act?
  • Is there one person accountable for catching opt-out requests immediately?

If two or more of these got a shrug instead of a confident yes, that’s real exposure sitting in your outbound program right now, not a hypothetical.

The Bottom Line 

Every business named in this article started the year with a functioning outbound program and no plan to end up in a compliance headline. That’s the pattern worth noticing. Non-compliance rarely looks reckless from the inside. It looks like a list that was fine last quarter, a sender ID nobody got around to registering, an unsubscribe link nobody’s tested since setup.

The businesses getting this right aren’t necessarily more cautious than everyone else. They’ve just made compliance part of how outbound runs, not a separate task competing for attention against quota. That’s the difference between an SDR program that scales safely and one that’s one audit away from a very expensive quarter.