(03) 8832 8005

In January 2025, Lululemon Athletica Australia sent thousands of marketing messages that had no working unsubscribe option. Not a scam operation. Not a dodgy dropshipper. A global apparel brand with a legal team, running a normal Christmas and New Year campaign. The regulator found the messages went out between 1 December and 5 January, and the penalty came in at 702,900 dollars.

Here is the part that should make every Aussie Shopify founder sit up. Nobody at Lululemon decided to break the law. Someone changed a template, or launched a campaign from a tool that was not wired to the suppression list, or classified a promotional message as an account notification. That is a five minute mistake inside a marketing calendar, and it is the exact same five minute mistake sitting inside most Shopify stores right now.

The Australian Communications and Media Authority has issued more than 20 million dollars in spam penalties since 2020, and the pace is picking up. Commonwealth Bank paid 7.5 million dollars, the largest to date. Tabcorp paid 4 million in April 2025 and its TAB brand came back for a second serve in July 2026 at more than 2.7 million. Betfair paid 871,660 dollars for sending around 140 messages to people who had never consented or had already opted out. That is roughly 6,200 dollars per message.

Most Aussie stores treat Spam Act compliance as a footer problem. It is a systems problem, and if you are heading into Click Frenzy and Black Friday with a list you have been building for three years, now is the time to fix it. Here is the six layer system.

The three tests every commercial message has to pass

The Spam Act 2003 is genuinely simple. Every commercial electronic message you send to an Australian, by email, SMS, or instant message, has to pass three tests at the same time.

Fail any one of the three and the message is non-compliant. That matters because the maximum penalty for a corporation runs to 10,000 penalty units a day, which lands somewhere north of 3 million dollars a day on current values. No regulator is chasing a 60k a month Shopify store for that. But ACMA does act on consumer complaints, and one annoyed customer who cannot unsubscribe is enough to start a file.

The three tests are the easy part. The hard part is proving you passed them, at scale, across every flow and campaign, eighteen months after the send. That is what the six layers below are actually for.

Express consent means the person actively told you they want marketing. Inferred consent is much narrower than founders assume. It generally covers situations where someone has a genuine existing relationship with you and would reasonably expect the message, and it does not stretch to “they bought a candle in 2022 so we can text them about a sale in 2026”.

Four collection points cause almost every problem I see in Shopify stores.

The practical rule I give members: if you cannot describe the exact screen the person was looking at when they consented, and what the tick box said, do not send them marketing.

Consent history dashboard showing express and inferred consent records with sources and timestamps
Every profile should carry a consent source, method and timestamp. If your list cannot produce this view, you cannot prove consent.

When ACMA opens an investigation, it does not ask whether you had consent. It asks you to produce it. The burden sits with the sender, which means an undocumented list is treated the same as a list with no consent at all.

Four fields need to exist on every profile in your email and SMS platform.

Klaviyo stores most of this natively on the profile, but only if the integration is configured to capture it. Shopify’s customer records carry an email and SMS marketing consent state with a timestamp and a collection source. Export both quarterly and keep the file. Storage costs you nothing and it turns a stressful regulator letter into a five minute reply.

One more thing worth doing now: run a segment of every profile where consent source is blank. In most stores that segment is between 5 and 15 per cent of the list, and it is almost always the oldest, least engaged, most complaint-prone contacts. Those people are costing you deliverability and carrying your legal risk at the same time.

Layer 3: The sender identification line most stores get wrong

This is the least interesting layer and one of the most commonly breached. Every commercial message has to clearly identify the sender and provide accurate contact details that stay live for at least 30 days after the send.

For email, that means your legal or trading entity name plus a real contact point: a physical or postal address, a phone number, or a working contact URL. “Team Bondi Supply” and a link to your homepage is thin. Your registered business name, an address, and a support email is solid.

Three specific traps to check today:

Audit this by sending a test of every live flow and campaign template to yourself once a quarter, opening each one on a phone, and checking the footer renders. Templates drift. Someone always duplicates a flow and strips the footer to make the design tidier.

Dashboard tracking time from unsubscribe request to suppression and message classification audit
Two numbers decide whether you have a problem: how fast opt-outs are suppressed, and how many messages went out after an opt-out.

Layer 4: Unsubscribe mechanics and the transactional trap

The unsubscribe rules are where the real money has been lost. ACMA’s recent enforcement pattern is heavily weighted towards businesses that kept sending after someone opted out, or made opting out harder than it should be.

Your unsubscribe has to be functional, free, and easy. That rules out a few things stores still do: requiring a login to unsubscribe, making people fill in a reason, sending them to a preference centre with no clear “unsubscribe from everything” option, or charging anything beyond the normal cost of sending a reply. It must keep working for at least 30 days after the message goes out, and you have five business days to action the request.

Five business days is the legal ceiling, not the target. Modern platforms suppress instantly. If your median time to suppress is measured in days rather than hours, something manual is sitting in the middle of your stack, and that is exactly where a breach hides.

Now the trap. PointsBet paid 500,800 dollars in a case that involved, among other things, classifying marketing emails as non-commercial so they would not need an unsubscribe facility. That instinct is common in ecommerce. The order confirmation with a 20 per cent off code stitched into it. The “your loyalty balance” email with a shop now button. The account update that happens to feature this week’s new arrivals.

The test is not what you named the email in your ESP. It is whether the message has a commercial purpose. Once a promotional offer is inside a transactional message, the whole message is arguably commercial and needs an unsubscribe. Keep them separate. Your shipping notification does not need a discount code to do its job, and stitching one in puts your most deliverable message type at risk.

Do a classification pass across every automated message in your stack. Tag each one marketing or transactional, and for anything you tagged transactional, ask one question: is there an offer, a discount, a product recommendation, or a shop now button in here? If yes, either strip it or treat the message as marketing and give it an unsubscribe. We cover the deliverability side of this in more depth in the email deliverability playbook.

Layer 5: The SMS Sender ID Register changed the rules on 1 July

This one is new, it is Australian, and a lot of Shopify stores missed it completely.

The SMS Sender ID Register opened on 30 November 2025 and enforcement started on 1 July 2026. If you send SMS to Australian mobiles using a branded alphanumeric sender ID, the name that appears at the top of the thread instead of a phone number, that sender ID now has to be registered with ACMA through an approved telco or messaging provider.

If it is not registered, your brand name is stripped. The message displays as “Unverified” and gets grouped in with other unregistered senders, which on a modern handset means it sits alongside suspected scams. Your shipping notification, your back in stock alert and your Black Friday message all land in the bin drawer next to the fake toll notices.

The commercial damage is bigger than the compliance damage. SMS earns its keep because it is trusted and immediate. Australian SMS programmes typically run click rates between 8.9 and 14.5 per cent for campaigns, roughly seven times what email delivers, and unsubscribe rates under 1 per cent. Strip the brand name off the top of the message and you lose the thing that makes those numbers possible.

Comparison of a registered branded SMS sender ID against an unverified sender, with an ACMA registration checklist
Same message, two outcomes. An unregistered branded sender ID loses the brand name and the thread history that goes with it.

How to check and fix it this week:

  1. Send yourself a test SMS from your live sending profile. Look at the top of the thread on an Australian handset. If it says Unverified, or shows a raw number where your brand used to be, you have a problem.
  2. Confirm your ABR details are current. Registration checks your ABN, and the authorised contact or service of notice email in the Australian Business Register has to be up to date. Stale ABR details are the most common reason a registration stalls.
  3. Lodge through your messaging provider, not directly. Registration runs through ACMA approved telcos and providers. If you send SMS through Klaviyo, Attentive, ClickSend or a local aggregator, start with their support documentation.
  4. Have a director ready with photo ID. A verified business representative submits the registration with business details and identification.
  5. Register every sender ID you use. Including the one your support team replies from and any second brand. One approved ID does not cover the others.

If you are still building your SMS channel, get the sender ID sorted before you spend a dollar acquiring subscribers. The mechanics of building the list itself are covered in the Shopify SMS marketing playbook.

Most stores collect SMS consent in a way that is technically legal and practically undocumented. Here is the setup I would run on a Shopify and Klaviyo stack, which takes about twenty minutes.

  1. Update your terms and privacy policy first. Both need to describe what messages you will send, how often, and how to opt out. Do this before you switch anything on.
  2. Turn on SMS marketing at checkout. In Shopify admin, go to Settings, then Checkout, then Marketing options, and toggle SMS on. Leave the box unticked by default.
  3. Enable SMS in Klaviyo and connect the sending number. You need an Australian sending number before consent will sync, and consent only flows for regions where SMS is available.
  4. Set the list to double opt-in. The subscriber confirms before they land in your sendable audience. It slightly reduces raw list growth and dramatically improves both the quality of your consent record and your engagement rates.
  5. Check the sync. Consent flows through when a customer enters their number, ticks the box and continues, whether or not they finish the order. Place a test order and confirm the profile shows the consent source and timestamp.
  6. Separate transactional consent. If you want to text order updates to people who have not opted into marketing, ask for that separately and store it as its own consent state.

Do the same audit on your email pop-up. One tick box for the offer, clear wording about what they are signing up for, and a link to your privacy policy. Stores worried this will crush their opt-in rate are usually surprised: the drop is small and the quality lift is not.

Founders treat this as a cost. It is not. Every one of the six layers above also happens to be a deliverability lever, and deliverability is a revenue lever.

Think about what the layers actually do. Express consent means the people on your list asked to be there, so they open. A documented consent source lets you suppress the undocumented segment, which is the segment generating your complaints. Fast opt-out processing means you never message someone who has already told you to stop, which is the fastest way to earn a spam complaint. Separating marketing from transactional protects the deliverability of your order confirmations, which are the emails customers actually want.

The benchmark maths backs this up. Email lists churn 25 to 30 per cent a year no matter what you do, and a healthy unsubscribe rate sits between 0.1 and 0.5 per cent per send. Klaviyo’s 2026 data has ecommerce campaigns averaging a 1.69 per cent click rate against 5.58 per cent for flows. Flows win because the recipient chose that moment. Consent is the same principle applied to the whole list.

The stores that get hammered in November are almost always the ones that mailed the whole database, including the 12 per cent nobody could account for, hit a complaint spike in week one, and spent Black Friday in the promotions tab. The stores that clean up in August send to a smaller, documented, engaged list and land in the inbox on the day it matters. Same list, different revenue, and the difference was decided three months earlier.

Your 12 point pre-peak compliance checklist

Work through this once, before your first peak campaign goes out. It takes an afternoon. Give it to whoever owns email and SMS in your business and ask for it back with a tick and a screenshot against each line.

Run it again in January, then every quarter. Templates drift, staff change, apps get added. The audit is the control, not the one-off cleanup.

If your privacy settings need the same treatment, the wider obligations are covered in the Shopify privacy compliance playbook. Consent under the Spam Act and personal information under the Privacy Act are separate regimes, and passing one does not mean you have passed the other.

Start with the two checks that catch the most

If you only do two things this week, do these. Send yourself a live SMS and check whether your brand name still appears at the top of the thread. Then run a query for any message sent to a profile after that profile opted out, going back twelve months.

The first tells you whether the July change has quietly broken your best performing channel. The second is the exact question a regulator asks first, and the answer is usually not zero.

Neither takes an hour. Both are worth more than another round of subject line testing.

Inside eCommerce Circle, consent and list health is one of the core pillars we work on with every member before peak season. If you want a second opinion on yours, let’s talk.

The Spam Act Playbook: What Aussie Shopify Brands Get Wrong About Email and SMS Consent
Team eCommerce Circle

Written by

Team eCommerce Circle

Helping Shopify brand owners scale smarter through the eCommerce Circle coaching community.

Leave a Reply

Your email address will not be published. Required fields are marked *

Thank You

Your application for the eCommerce Circle was successfully submitted.
We’ll get back to you through your provided details shortly.

Thank You

Your enrolment was successfully submitted, and we’ve added you to the waitlist for your preferred cohort.

Not a Circle Member Yet?
Only members can join cohorts!
Join here.