In January 2025, Lululemon Athletica Australia sent thousands of marketing messages that had no working unsubscribe option. Not a scam operation. Not a dodgy dropshipper. A global apparel brand with a legal team, running a normal Christmas and New Year campaign. The regulator found the messages went out between 1 December and 5 January, and the penalty came in at 702,900 dollars.
What’s in This Article
Here is the part that should make every Aussie Shopify founder sit up. Nobody at Lululemon decided to break the law. Someone changed a template, or launched a campaign from a tool that was not wired to the suppression list, or classified a promotional message as an account notification. That is a five minute mistake inside a marketing calendar, and it is the exact same five minute mistake sitting inside most Shopify stores right now.
The Australian Communications and Media Authority has issued more than 20 million dollars in spam penalties since 2020, and the pace is picking up. Commonwealth Bank paid 7.5 million dollars, the largest to date. Tabcorp paid 4 million in April 2025 and its TAB brand came back for a second serve in July 2026 at more than 2.7 million. Betfair paid 871,660 dollars for sending around 140 messages to people who had never consented or had already opted out. That is roughly 6,200 dollars per message.
Most Aussie stores treat Spam Act compliance as a footer problem. It is a systems problem, and if you are heading into Click Frenzy and Black Friday with a list you have been building for three years, now is the time to fix it. Here is the six layer system.
The three tests every commercial message has to pass
The Spam Act 2003 is genuinely simple. Every commercial electronic message you send to an Australian, by email, SMS, or instant message, has to pass three tests at the same time.
- Consent. The recipient gave you express consent, or you can point to a genuine basis for inferred consent. Silence is not consent. A purchased list is never consent.
- Identification. The message clearly identifies who sent it and how to contact you, and those details stay accurate for at least 30 days after the send.
- Unsubscribe. The message carries a functional, free, low friction unsubscribe that keeps working for at least 30 days, and you action the request within five business days.
Fail any one of the three and the message is non-compliant. That matters because the maximum penalty for a corporation runs to 10,000 penalty units a day, which lands somewhere north of 3 million dollars a day on current values. No regulator is chasing a 60k a month Shopify store for that. But ACMA does act on consumer complaints, and one annoyed customer who cannot unsubscribe is enough to start a file.
The three tests are the easy part. The hard part is proving you passed them, at scale, across every flow and campaign, eighteen months after the send. That is what the six layers below are actually for.
Layer 1: Fix the four places Aussie stores collect consent badly
Express consent means the person actively told you they want marketing. Inferred consent is much narrower than founders assume. It generally covers situations where someone has a genuine existing relationship with you and would reasonably expect the message, and it does not stretch to “they bought a candle in 2022 so we can text them about a sale in 2026”.
Four collection points cause almost every problem I see in Shopify stores.
- The checkout tick box. If it is pre-ticked, it is not express consent. Shopify lets you set the marketing checkbox to pre-selected. Turn that off. A slightly smaller list you can defend beats a bigger list you cannot.
- Competition and giveaway entries. Entry into a competition is consent to be contacted about the competition. If you want marketing consent, the entry form needs a separate, unticked, clearly worded opt-in. Bundling the two is the single most common breach in Aussie ecommerce.
- Back in stock and waitlist forms. Someone asking to be told when the Coastal Tee returns has consented to that notification. They have not consented to your Friday campaign. Either ask for both consents on the form, or keep those profiles out of campaign sends until they opt in properly.
- Imported lists. Your old Mailchimp export, the spreadsheet from the trade show, the contacts from the brand you acquired. If you cannot show how and when each of those people consented, you are sending on a hope. Run them through a re-permission campaign or leave them out.
The practical rule I give members: if you cannot describe the exact screen the person was looking at when they consented, and what the tick box said, do not send them marketing.

Layer 2: Build the consent record before you need it
When ACMA opens an investigation, it does not ask whether you had consent. It asks you to produce it. The burden sits with the sender, which means an undocumented list is treated the same as a list with no consent at all.
Four fields need to exist on every profile in your email and SMS platform.
- Consent source. Checkout tick box, welcome pop-up, keyword to shortcode, back in stock form, in-store iPad. Be specific enough that you could screenshot the page.
- Consent method. Express single opt-in, express double opt-in, or inferred. Tag inferred consent separately so you can suppress it fast if the rules tighten.
- Timestamp. Date and time, in a timezone you can explain.
- Consent text. The actual wording shown at the point of opt-in, versioned. When you change your pop-up copy, that is a new version.
Klaviyo stores most of this natively on the profile, but only if the integration is configured to capture it. Shopify’s customer records carry an email and SMS marketing consent state with a timestamp and a collection source. Export both quarterly and keep the file. Storage costs you nothing and it turns a stressful regulator letter into a five minute reply.
One more thing worth doing now: run a segment of every profile where consent source is blank. In most stores that segment is between 5 and 15 per cent of the list, and it is almost always the oldest, least engaged, most complaint-prone contacts. Those people are costing you deliverability and carrying your legal risk at the same time.
Layer 3: The sender identification line most stores get wrong
This is the least interesting layer and one of the most commonly breached. Every commercial message has to clearly identify the sender and provide accurate contact details that stay live for at least 30 days after the send.
For email, that means your legal or trading entity name plus a real contact point: a physical or postal address, a phone number, or a working contact URL. “Team Bondi Supply” and a link to your homepage is thin. Your registered business name, an address, and a support email is solid.
Three specific traps to check today:
- The 30 day rule and expiring links. If your footer contact link points at a landing page you take down after a campaign, you have breached it. Point contact links at a permanent page.
- Trading names versus legal entities. If you trade as three brands out of one Pty Ltd, each brand’s footer needs to make clear who is actually sending.
- SMS character pressure. Short messages tempt teams to drop identification. Your brand name in the sender ID plus a recognisable link domain does a lot of the work, but the opt-out instruction still has to be there.
Audit this by sending a test of every live flow and campaign template to yourself once a quarter, opening each one on a phone, and checking the footer renders. Templates drift. Someone always duplicates a flow and strips the footer to make the design tidier.

Layer 4: Unsubscribe mechanics and the transactional trap
The unsubscribe rules are where the real money has been lost. ACMA’s recent enforcement pattern is heavily weighted towards businesses that kept sending after someone opted out, or made opting out harder than it should be.
Your unsubscribe has to be functional, free, and easy. That rules out a few things stores still do: requiring a login to unsubscribe, making people fill in a reason, sending them to a preference centre with no clear “unsubscribe from everything” option, or charging anything beyond the normal cost of sending a reply. It must keep working for at least 30 days after the message goes out, and you have five business days to action the request.
Five business days is the legal ceiling, not the target. Modern platforms suppress instantly. If your median time to suppress is measured in days rather than hours, something manual is sitting in the middle of your stack, and that is exactly where a breach hides.
Now the trap. PointsBet paid 500,800 dollars in a case that involved, among other things, classifying marketing emails as non-commercial so they would not need an unsubscribe facility. That instinct is common in ecommerce. The order confirmation with a 20 per cent off code stitched into it. The “your loyalty balance” email with a shop now button. The account update that happens to feature this week’s new arrivals.
The test is not what you named the email in your ESP. It is whether the message has a commercial purpose. Once a promotional offer is inside a transactional message, the whole message is arguably commercial and needs an unsubscribe. Keep them separate. Your shipping notification does not need a discount code to do its job, and stitching one in puts your most deliverable message type at risk.
Do a classification pass across every automated message in your stack. Tag each one marketing or transactional, and for anything you tagged transactional, ask one question: is there an offer, a discount, a product recommendation, or a shop now button in here? If yes, either strip it or treat the message as marketing and give it an unsubscribe. We cover the deliverability side of this in more depth in the email deliverability playbook.
Layer 5: The SMS Sender ID Register changed the rules on 1 July
This one is new, it is Australian, and a lot of Shopify stores missed it completely.
The SMS Sender ID Register opened on 30 November 2025 and enforcement started on 1 July 2026. If you send SMS to Australian mobiles using a branded alphanumeric sender ID, the name that appears at the top of the thread instead of a phone number, that sender ID now has to be registered with ACMA through an approved telco or messaging provider.
If it is not registered, your brand name is stripped. The message displays as “Unverified” and gets grouped in with other unregistered senders, which on a modern handset means it sits alongside suspected scams. Your shipping notification, your back in stock alert and your Black Friday message all land in the bin drawer next to the fake toll notices.
The commercial damage is bigger than the compliance damage. SMS earns its keep because it is trusted and immediate. Australian SMS programmes typically run click rates between 8.9 and 14.5 per cent for campaigns, roughly seven times what email delivers, and unsubscribe rates under 1 per cent. Strip the brand name off the top of the message and you lose the thing that makes those numbers possible.

How to check and fix it this week:
- Send yourself a test SMS from your live sending profile. Look at the top of the thread on an Australian handset. If it says Unverified, or shows a raw number where your brand used to be, you have a problem.
- Confirm your ABR details are current. Registration checks your ABN, and the authorised contact or service of notice email in the Australian Business Register has to be up to date. Stale ABR details are the most common reason a registration stalls.
- Lodge through your messaging provider, not directly. Registration runs through ACMA approved telcos and providers. If you send SMS through Klaviyo, Attentive, ClickSend or a local aggregator, start with their support documentation.
- Have a director ready with photo ID. A verified business representative submits the registration with business details and identification.
- Register every sender ID you use. Including the one your support team replies from and any second brand. One approved ID does not cover the others.
If you are still building your SMS channel, get the sender ID sorted before you spend a dollar acquiring subscribers. The mechanics of building the list itself are covered in the Shopify SMS marketing playbook.
Layer 6: Wire consent capture into Shopify properly
Most stores collect SMS consent in a way that is technically legal and practically undocumented. Here is the setup I would run on a Shopify and Klaviyo stack, which takes about twenty minutes.
- Update your terms and privacy policy first. Both need to describe what messages you will send, how often, and how to opt out. Do this before you switch anything on.
- Turn on SMS marketing at checkout. In Shopify admin, go to Settings, then Checkout, then Marketing options, and toggle SMS on. Leave the box unticked by default.
- Enable SMS in Klaviyo and connect the sending number. You need an Australian sending number before consent will sync, and consent only flows for regions where SMS is available.
- Set the list to double opt-in. The subscriber confirms before they land in your sendable audience. It slightly reduces raw list growth and dramatically improves both the quality of your consent record and your engagement rates.
- Check the sync. Consent flows through when a customer enters their number, ticks the box and continues, whether or not they finish the order. Place a test order and confirm the profile shows the consent source and timestamp.
- Separate transactional consent. If you want to text order updates to people who have not opted into marketing, ask for that separately and store it as its own consent state.
Do the same audit on your email pop-up. One tick box for the offer, clear wording about what they are signing up for, and a link to your privacy policy. Stores worried this will crush their opt-in rate are usually surprised: the drop is small and the quality lift is not.
The compound effect: clean consent quietly makes you money
Founders treat this as a cost. It is not. Every one of the six layers above also happens to be a deliverability lever, and deliverability is a revenue lever.
Think about what the layers actually do. Express consent means the people on your list asked to be there, so they open. A documented consent source lets you suppress the undocumented segment, which is the segment generating your complaints. Fast opt-out processing means you never message someone who has already told you to stop, which is the fastest way to earn a spam complaint. Separating marketing from transactional protects the deliverability of your order confirmations, which are the emails customers actually want.
The benchmark maths backs this up. Email lists churn 25 to 30 per cent a year no matter what you do, and a healthy unsubscribe rate sits between 0.1 and 0.5 per cent per send. Klaviyo’s 2026 data has ecommerce campaigns averaging a 1.69 per cent click rate against 5.58 per cent for flows. Flows win because the recipient chose that moment. Consent is the same principle applied to the whole list.
The stores that get hammered in November are almost always the ones that mailed the whole database, including the 12 per cent nobody could account for, hit a complaint spike in week one, and spent Black Friday in the promotions tab. The stores that clean up in August send to a smaller, documented, engaged list and land in the inbox on the day it matters. Same list, different revenue, and the difference was decided three months earlier.
Your 12 point pre-peak compliance checklist
Work through this once, before your first peak campaign goes out. It takes an afternoon. Give it to whoever owns email and SMS in your business and ask for it back with a tick and a screenshot against each line.
- 1. Checkout consent box is unticked by default for both email and SMS.
- 2. Every opt-in form has its own marketing consent, separate from competition entry or a back in stock request.
- 3. Consent source is recorded on 100 per cent of sendable profiles. Build the segment where it is blank and quarantine it.
- 4. Undocumented contacts are re-permissioned or suppressed before peak, not during it.
- 5. Every template footer carries your legal entity name and a permanent contact point.
- 6. Footer contact links resolve to pages that will still exist in 30 days.
- 7. Unsubscribe works in one click, with no login, no reason field and no fee.
- 8. Median time from opt-out to suppression is under 24 hours, well inside the five business day limit.
- 9. Zero messages sent to a profile after its opt-out timestamp. Run this as a query, not a vibe.
- 10. Every automated message is tagged marketing or transactional, and no transactional message carries an offer.
- 11. Every branded SMS sender ID is on the ACMA register and a live test shows the brand name, not Unverified.
- 12. A quarterly consent export is saved somewhere you can find it in two years.
Run it again in January, then every quarter. Templates drift, staff change, apps get added. The audit is the control, not the one-off cleanup.
If your privacy settings need the same treatment, the wider obligations are covered in the Shopify privacy compliance playbook. Consent under the Spam Act and personal information under the Privacy Act are separate regimes, and passing one does not mean you have passed the other.
Start with the two checks that catch the most
If you only do two things this week, do these. Send yourself a live SMS and check whether your brand name still appears at the top of the thread. Then run a query for any message sent to a profile after that profile opted out, going back twelve months.
The first tells you whether the July change has quietly broken your best performing channel. The second is the exact question a regulator asks first, and the answer is usually not zero.
Neither takes an hour. Both are worth more than another round of subject line testing.
Inside eCommerce Circle, consent and list health is one of the core pillars we work on with every member before peak season. If you want a second opinion on yours, let’s talk.



