Australian Email Compliance: Why your Privacy Policy Isn’t Enough

Many businesses assume that publishing a privacy policy is the final legal step before sending marketing emails. In reality, privacy obligations, marketing consent requirements, and spam laws all play different roles. While they often overlap, they aren’t interchangeable. 

A privacy policy explains how you handle personal information, but doesn’t automatically permit you to send promotional emails or SMS messages. So, you’ll need more than one document to create a compliant marketing list, including consent opt-ins, unsubscribe records, and terms and conditions. 

When these elements don’t align, compliance gaps can appear, even if every individual document looks correct on its own.

In this guide, we’ll walk you through what each document does, how they work together, and where Australian businesses most commonly run into trouble.

Is a privacy policy enough to send marketing emails?

First things first. A privacy policy is not enough on its own. Rather, it’s an essential part of your compliance framework, but it is not the same thing as marketing consent.

A direct marketing privacy policy explains how your business collects, stores, uses, and discloses personal information. It tells customers what happens to their data once you’ve collected it.

Marketing consent is different. Depending on how you communicate with customers, the Australian Spam Act may require you to obtain consent before sending commercial electronic messages, including marketing emails and SMS.

Australian privacy principles can also apply when you use personal information for direct marketing. That means your marketing activities should be consistent with what your privacy policy says you do with customer information.

Looking at the customer journey helps illustrate why multiple documents are needed:

  1. A customer enters their email through a website form.
  2. The form explains what they’re signing up for.
  3. The privacy policy explains how their information will be handled.
  4. Your marketing platform records the subscription.
  5. Future campaigns honour their communication preferences.
  6. Every marketing message includes a working unsubscribe option.

If any part of that journey doesn’t match the others, your compliance process becomes harder to defend.

What does a privacy policy do?

A privacy policy explains how your business handles personal information throughout its lifecycle. Typically, it covers:

  • What personal information you collect
  • How you collect it
  • Why you collect it
  • How you use and store it
  • Who you disclose it to
  • How customers can access or correct their information
  • How they can contact you about privacy concerns

If your business sends marketing communications, your privacy policy should also explain that personal information may be used for those purposes. Similarly, if your email platform, CRM, or other service providers store or access customer information overseas, you need to include these details.

Importantly, your privacy policy should accurately reflect what your business actually does. For example, if you begin collecting customer preferences for personalised campaigns, introduce SMS marketing, or start sharing data with additional providers, your privacy policy should evolve accordingly.

Resources such as Lawpath’s Australian privacy policy guides and templates can help your business understand what information to include. However, always adapt any documents to reflect the business’s actual practices.

What does an opt-in notice do?

What a privacy policy doesn’t do is replace a clear opt-in notice in Australia. Simply stating that customer information “may be used for marketing” doesn’t automatically mean customers have agreed to receive promotional messages.

That’s when you need an opt-in notice, which appears when someone provides their email address or phone number.

Its purpose is straightforward: it tells people exactly what they’re signing up to receive.

Opt-in notices commonly appear on:

  • Newsletter sign-up forms
  • Checkout pages
  • Downloadable guide or lead magnet forms
  • Webinar registrations
  • Event registrations
  • Quote request forms
  • SMS marketing sign-ups

A well-designed opt-in notice can help capture express marketing consent in Australia while setting clear expectations from the beginning. 

Your opt-in notice should clearly communicate the following: 

  • Who is sending the marketing
  • What types of messages the person may receive
  • Whether communications will be sent by email, SMS, or both
  • That they can unsubscribe at any time
  • Where they can read the privacy policy
  • Whether any third parties are involved, where relevant

The opt-in notice should also connect naturally to your privacy policy so customers can understand how their personal information will be handled after submission.

Avoid bundling unrelated consents together. For example, someone requesting a quote may not necessarily expect to receive ongoing promotional newsletters unless that is clearly explained.

Finally, your marketing platform or CRM should record the subscription so there’s an operational record of how and when the contact joined your list.

What do terms and conditions do?

Terms and conditions serve a different purpose again.

Rather than explaining privacy practices or obtaining marketing consent, they establish the rules governing a website, service, offer, subscription, or transaction.

Depending on your business, they may cover matters such as:

  • Customer accounts
  • Payments
  • Refunds
  • Acceptable use
  • Intellectual property
  • Liability
  • Subscriptions
  • Promotional offers

Marketing campaigns often require their own separate terms, particularly for competitions, giveaways, referral programs, or discount promotions.

While terms and conditions may mention marketing communications, you shouldn’t rely on them to obtain marketing consent. Nor should marketing consent be buried within lengthy legal terms that users wouldn’t reasonably expect.

What do unsubscribe records do?

Many businesses focus heavily on collecting subscribers but overlook what happens after someone opts out.

Unsubscribe records are just as important.

These records show who has withdrawn their permission to receive marketing communications and help ensure those preferences are respected in future campaigns.

Importantly, you should retain unsubscribe records even after removing the contact from your active mailing list. Otherwise, there is a risk that the same person could accidentally be re-added later.

For businesses using multiple marketing tools, suppression lists should work across all campaigns and platforms.

Some common operational problems include:

  • A customer unsubscribes from marketing emails but remains in the CRM and is then accidentally exported into a future campaign.
  • A customer opts out of SMS but still wishes to receive email, yet both preferences become mixed together.
  • One department exports customer data without first checking suppression lists.
  • A business migrates to a new email marketing platform and loses historical unsubscribe records.
  • Transactional emails begin including promotional content, causing marketing preferences to be overlooked.

For marketers using platforms like Constant Contact, maintaining accurate suppression records is just as important as growing the subscriber list itself. Good operational processes help prevent accidental marketing and provide useful evidence if a complaint is ever raised.

How do privacy policies, opt-in notices, terms, and unsubscribe records work together?

These documents each perform a different function.

Item Main job Where it appears Common gap
Privacy policy Explains how personal information is handled Website footer, forms, checkout, account pages Says marketing may occur, but the form does not capture clear consent
Opt-in notice Captures marketing permission or preference Forms, checkouts, lead magnets, events Checkbox language is vague or pre-ticked
Terms and conditions Set rules for the site, offer or transaction Website, campaign page, checkout, promotions Marketing consent is buried in unrelated terms
Unsubscribe records Track who opted out Email platform, CRM, suppression list Unsubscribes do not sync across tools

The most important principle is consistency.

Your privacy policy should support your sign-up process. Your opt-in language should match the marketing people actually receive. Your CRM should reflect customer preferences. And your unsubscribe records should prevent future promotional messages where appropriate.

If these documents contradict one another, compliance becomes much harder to demonstrate.

Where do businesses usually create compliance gaps?

Most compliance problems don’t arise because a business has no privacy policy. They arise because different systems, forms, and marketing processes stop matching one another over time.

Here are some common email marketing mistakes: 

  • A website form collects email addresses, but the privacy policy doesn’t mention marketing.
  • A lead magnet collects subscribers, and then those contacts begin receiving unrelated promotional campaigns.
  • Customers provide their email during checkout for order updates, but are automatically added to promotional newsletters.
  • Event registrations are later treated as newsletter subscriptions without clear notice.
  • SMS and email preferences are grouped, even though customers expect different communication channels.
  • CRM contact records don’t match the email marketing platform.
  • Historical unsubscribe records are lost during platform migration.
  • Unsubscribed contacts are accidentally re-uploaded from old spreadsheets.
  • Transactional emails include promotional offers that customers did not expect.
  • Purchased or third-party email lists are imported without reliable consent records.

Make sure to audit for these gaps using the checklist below — ensuring both compliance and better customer relationships. 

Before sending campaigns, ask:

  • Does each form explain what the person is signing up for?
  • Does the privacy policy mention marketing use of personal information?
  • Does the opt-in notice link to the privacy policy?
  • Do you capture email and SMS preferences separately where appropriate?
  • Do you retain unsubscribe records?
  • Do your tools respect suppression lists?
  • Do you review imported lists before upload?
  • Do you carefully assess purchased or third-party lists?
  • Do you keep transactional emails separate from promotional content?
  • Can you produce consent records if a complaint is made?

Can Australian businesses use purchased email lists?

Purchased email lists in Australia may present legal, operational, and commercial risks.

Even where a list provider claims contacts are “verified” or “permission-based”, the sending business still needs to consider whether it can lawfully send marketing communications to those recipients.

One of the biggest challenges is proving consent.

If your business didn’t collect the email address directly, it may be difficult to demonstrate what the recipient agreed to, when they agreed, or whether they expected to hear from your business specifically.

Purchased lists can also increase:

  • Spam complaints
  • Unsubscribe rates
  • Poor engagement
  • Email deliverability problems
  • Sender reputation issues

Instead of purchasing contacts, businesses generally achieve stronger long-term results through permission-based list growth strategies such as:

  • Newsletter sign-up forms
  • Downloadable guides and lead magnets
  • Webinars
  • Industry events
  • Customer checkout opt-ins
  • Referral campaigns
  • Gated resources
  • Loyalty programs
  • Post-purchase communication preferences
  • Social media campaigns that encourage email subscriptions

These approaches create clearer customer expectations while providing stronger records of how contacts joined your list.

What should a compliant email sign-up flow include?

A compliant sign-up process involves more than collecting an email address. The entire customer journey should support clear expectations and accurate record-keeping.

A practical workflow looks like this:

  1. A website form or checkout collects the customer’s email address.
  2. The opt-in notice explains what communications the person is signing up to receive.
  3. The privacy policy explains how personal information will be collected, stored, and used.
  4. The marketing platform records the consent source and timestamp where possible.
  5. A welcome email confirms what subscribers can expect.
  6. Every marketing email includes sender identification and a working unsubscribe option.
  7. Unsubscribe requests are retained through suppression records.
  8. The CRM and marketing platform remain synchronised, so customer preferences stay current.

To make this process work, make sure you carefully check the following documents and content: 

Step What the business should check
Form Clear opt-in language
Privacy policy Marketing use and data handling covered
Consent record Source, date and form captured where possible
Contact list Segment reflects actual permission
Email template Sender details and unsubscribe included
CRM sync Preferences stay aligned
Unsubscribe Suppression record retained

For Constant Contact users, many of these operational records can be supported through consistent list management, tagging, and subscriber preference management, helping marketing teams maintain cleaner compliance processes over time.

What should businesses review before sending a campaign?

Before pressing send, it’s worth taking a few minutes to review both your marketing content and your contact list.

A simple pre-send checklist includes:

  • Was this list collected directly?
  • Do recipients expect this type of message?
  • Is consent recorded or reasonably supported?
  • Is the privacy policy current?
  • Does the campaign match the original opt-in?
  • Have unsubscribed contacts been excluded?
  • Are sender details clearly included?
  • Does the unsubscribe link work correctly?
  • Are SMS and email preferences separated where necessary?
  • Has the list been imported from another source?
  • Is the message promotional, transactional or a combination of both?
  • Does the campaign include offers from third-party partners?

Consistently completing these checks can reduce operational errors before they become customer complaints.

When should a business update its privacy policy or opt-in notice?

Privacy documents shouldn’t remain static as your marketing evolves. 

Review your privacy policy, opt-in notices, and related processes whenever significant changes occur, including when you:

  • Launch email marketing for the first time
  • Introduce SMS marketing
  • Adopt a new marketing platform
  • Add new lead generation forms or downloadable resources
  • Run competitions or giveaways
  • Import contacts from another system
  • Migrate between email marketing providers
  • Begin using customer data for segmentation or personalisation
  • Share customer information with additional third-party service providers
  • Expand into overseas markets
  • Acquire another business and inherit an existing customer list
  • Receive unsubscribe complaints
  • Change the types of marketing communications customers receive

Regular reviews don’t necessarily mean rewriting every document. Often, small updates to form wording, privacy disclosures, or marketing workflows are enough to keep your customer experience aligned with your legal obligations.

A compliant marketing list is built through consistency rather than a single document. 

When your privacy policy, opt-in notices, terms, consent records, and unsubscribe processes all work together, customers know what to expect — and your business is in a much stronger position to demonstrate responsible marketing practices.

This blog is intended for informational purposes only and does not act as a substitute for professional legal guidance.

Share with your network
Avatar photo

Constant Contact partner Lawpath is Australia’s largest platform for small business legal, tax, accounting and compliance – combining AI-powered automation with real lawyers and accountants, so every business gets the support it needs without the cost or complexity of traditional advisors.

Related Articles