Quick answer: Yes. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026, released 31 August 2026, would replace APP 7: draft APP 7 has seven subclauses and none of them mentions consent. But draft APP 7.7(c) keeps the Spam Act 2003 outside it, and the Spam Act still requires consent for a marketing SMS or email unless it is a designated commercial electronic message under Schedule 1.
Will I need consent to send marketing SMS and emails in Australia under the new privacy bill?
Yes — because the consent that governs your SMS and email has never come from the Privacy Act. It comes from the Spam Act 2003 (Cth), section 16(1), which prohibits sending a commercial electronic message with an Australian link that is not a designated commercial electronic message, and section 16(2), which lifts that prohibition where “the relevant electronic account-holder consented to the sending of the message”. Sections 16(3) and 16(4) add two narrow defences, for a sender who did not know and could not with reasonable diligence have ascertained the Australian link, and for a message sent by mistake, and section 16(5) puts the evidential burden for each of them on the sender. The Attorney-General’s Department released the exposure draft on 31 August 2026 and closed submissions on Friday 18 September 2026. It does not amend the Spam Act.
The boundary, stated plainly: the draft changes what the Privacy Act demands of marketers, not what the Spam Act or the Do Not Call Register Act demand. Those are separate instruments with separate regulators and separate penalties, and the ACMA enforces both today.
The conditions under which this answer changes are narrow and all of them are in the draft: if a future version of the Bill removed the Spam Act from draft APP 7.7, or if the Spam Act itself were amended, the analysis below would need redoing. Neither has happened.
What the exposure draft actually says about direct marketing
Item 27 of Schedule 2, Part 3 repeals clause 7 of Schedule 1 to the Privacy Act and substitutes a new APP 7 with seven subclauses. We read all seven in the exposure draft Bill on 22 September 2026. None of them requires consent.
- 7.1 — an organisation must not make a direct marketing communication “unless the organisation provides a simple means by which the individual may easily request not to receive direct marketing communications from the organisation”.
- 7.2 — on request, the organisation “must take such steps as are reasonable in the circumstances to give effect to the request”. Note the wording: current APP 7.7(a) says “within a reasonable period”; the draft substitutes a reasonable-steps duty and the phrase “reasonable period” appears nowhere in draft clause 7.
- 7.3 — every communication must be accompanied by information setting out how to opt out.
- 7.4 — that information must be all four of: “(a) set out in clear and plain language; and (b) readily understandable by an ordinary person; and (c) up-to-date; and (d) concise”. The limbs are cumulative, not a menu.
- 7.5 and 7.6 — ad-supported services may offer the service on different terms to someone who opts out, provided those terms “provide the individual with a genuine choice to continue to use the service without receiving direct marketing communications”. 7.6 defines an ad-supported service by reference only to revenue from making the communications, disregarding revenue from sales of the goods marketed.
- 7.7 — the principle “does not apply to the extent that any of the following apply”, and four things follow: (a) Division 5 of Part 7B of the Interactive Gambling Act 2001; (b) the Do Not Call Register Act 2006; (c) the Spam Act 2003; (d) any other Act of the Commonwealth, or a law in force in an external Territory, prescribed by the regulations.
The consultation paper puts the same point in one sentence: “The framework does not require consent for direct marketing, but entities must obtain consent to trade personal information.” Most readers assume the opposite, which is why that sentence is the whole page.
The draft also inserts a definition of direct marketing into section 6(1) with two cumulative limbs: the communication of advertising or marketing material to an individual where “(a) the individual is selected, identified or otherwise targeted (whether as an individual or as a member of a class) for receipt of the material; and (b) the selecting, identification or other targeting is done using personal information that relates to the individual”. Limb (b) is the line that matters — targeting that does not use personal information falls outside the definition entirely. The consultation paper explains the first limb as covering targeting “whether the individual is targeted individually or as part of a broader audience, segment, or cohort”, and lists emails, text messages, telemarketing calls, targeted social media advertising and online behavioural advertising as examples.
The boundary: what the new direct marketing framework does not cover
Four things sit outside draft APP 7, and the first two are the ones an outbound team actually lives with:
- Marketing email and SMS consent. Governed by Spam Act s 16, not APP 7. The ACMA’s own compliance note is stricter than most teams assume: “if an electronic message contains any promotional or sales content, it is commercial, regardless of whether the main content or purpose is factual” (the ACMA’s own italics), and a message can be commercial where promotional material is reachable through a link in it. The ACMA lists a bill or invoice with a banner advertisement as likely to be commercial.
- Calls to numbers on the Do Not Call Register. Governed by Do Not Call Register Act 2006 (Cth) s 11, not APP 7. Washing cadence and the designated-call exemptions are a separate question from anything in this draft.
- Gambling promotion under Division 5 of Part 7B of the Interactive Gambling Act 2001.
- Anything prescribed later by regulation under draft APP 7.7(d) — an open-ended limb that does not currently name anything.
What the draft does not do is release direct marketing from the rest of the Privacy Act. Draft APP 3.1 would require a collection, use or disclosure of personal information to be both “fair and reasonable in the circumstances” and “lawful”, subject to the exceptions in draft APP 3.3 (which lifts the fair and reasonable limb for law, court order, permitted general situation and permitted health situation) and draft APP 3.4 (government related identifiers), and draft APP 3.2 lists seven matters an entity must have regard to, including whether a reasonable person would expect the handling, whether the purpose could be met with less information, and whether the individual was given genuine choice. Consent-free marketing is not rule-free marketing.
Consent to trade is the duty that is genuinely new — and it has two layers
The consent obligation in the draft is not in APP 7 at all. It is in a new APP 4.2: “An organisation that holds personal information that relates to an individual must not trade the information unless the individual has consented to the trading of the information.”
Getting this right means counting two separate sets of limbs, because a disclosure escapes the consent duty either by not being a trade, or by falling in an exception. They are different provisions.
Layer one — what is not a trade at all. Draft section 6FC(1) would make a disclosure a trade if it is made “(a) for money or other consideration; or (b) for the purposes of direct marketing”. The consultation paper states there are four carve-outs from that definition, and the Bill sets them out as three paragraphs in draft 6FC(2) plus a fourth in draft 6FC(3):
- Draft 6FC(2)(a) — the disclosure is for the purposes of the recipient providing the individual “with a product or service that the individual requested from the recipient“. The request must run to the recipient, not to you. The consultation paper adds that this covers cases where the disclosing organisation receives a commission for facilitating that service.
- Draft 6FC(2)(b) — this limb requires both: (i) the disclosure is incidental to a transaction, or group of related transactions, in which someone takes over the business or part of the business; and (ii) disclosure of the information for money or other consideration “is not a substantial purpose of that transaction”. The proviso is doing real work: a sale structured around the customer list is not carved out.
- Draft 6FC(2)(c) — disclosure “made to a processor by a controller” for the purpose of the processor acting on the controller’s behalf in relation to the information.
- Draft 6FC(3) — this one also requires both limbs: (a) either the recipient’s functions include enabling or facilitating disclosure for the prevention, detection, investigation or remedying of unlawful activity or “wrongdoing of a serious nature, involving fraud”, or the recipient suspects such conduct relating to its own functions; and (b) the organisation “reasonably believes that the disclosure is necessary” for that purpose. A fraud-adjacent recipient alone is not enough.
Layer two — exceptions to the consent duty itself. Draft APP 4.6 disapplies APP 4.2 in two paragraphs: (a) where one or more of three things applies — the disclosure is required or authorised by or under an Australian law or a court or tribunal order, a permitted general situation exists, or the entity is an organisation and a permitted health situation exists — or (b) where the disclosure is of a government related identifier. Anyone who tells you there are exactly four ways to share data without consent has read draft 6FC and stopped.
And “consent” itself acquires a test. Section 6(1) of the Privacy Act today defines it in seven words — “consent means express consent or implied consent” — with no quality requirement attached. Item 2 of Schedule 1 to the draft repeals that definition and points to a new section 6AAB, under which consent “may be express or implied, but must be all of the following: (a) voluntary; (b) informed; (c) current; (d) specific; (e) unambiguous”. The only relief would be in draft s 6AAB(2), where paragraphs (c) and (d) do not apply to human research reviewed, approved and monitored under the applicable national statement on ethical conduct in human research.
The rule today versus the rule as drafted
Every cell below was read against the instrument named in it on 22 September 2026. The right-hand column is a draft with no commencement date.
| Duty | The rule today (instrument and clause) | The rule as drafted, 31 August 2026 |
|---|---|---|
| Consent to send a marketing email or SMS | Required, unless the message is a designated commercial electronic message. Spam Act 2003 s 16(1)(b) and Schedule 1, with the consent exception in s 16(2) and the meaning of consent in Schedule 2 | Unchanged. Draft APP 7.7(c) keeps the Spam Act outside APP 7; the Bill does not amend the Spam Act |
| Consent to use personal information for direct marketing | Privacy Act 1988 APP 7.1 prohibits it, subject to APP 7.2 (four cumulative conditions), APP 7.3 (five cumulative conditions, three of which contain an internal either/or), APP 7.4 (sensitive information, consent only) and APP 7.5 | Removed. No consent requirement appears in draft APP 7.1 to 7.7. Draft APP 3.1 fair, reasonable and lawful applies instead |
| Consent to trade personal information | No general consent-to-trade duty in the Privacy Act; disclosure is governed by APP 6, except a disclosure for the purpose of direct marketing, which APP 6.7(a) puts outside APP 6 | New. Draft APP 4.2, with the definition of trade in draft s 6FC (four carve-outs) and exceptions in draft APP 4.6 (two paragraphs) |
| Opt-out mechanism | A “simple means” under APP 7.2(c) and 7.3(c); give effect “within a reasonable period” under APP 7.7(a) | Simple means retained in draft 7.1; the deadline becomes “such steps as are reasonable in the circumstances” under draft 7.2 |
| Who owns the opt-out | The organisation that used or disclosed the information, described in APP 7.6 as “the first organisation” | The organisation that makes the communication (draft 7.1). The consultation paper says that where multiple entities are involved “the platform will generally be responsible for the opt-out requirement unless it is acting solely as a processor” |
| Cohort and segment targeting | The phrase “direct marketing” appears 33 times in lower case in the Privacy Act compilation and is defined nowhere in it; “cohort” and “segment” do not appear at all | Defined in s 6(1) with two cumulative limbs, covering targeting “whether as an individual or as a member of a class”, where the targeting uses personal information |
| Selling or buying a list | APP 7.1 prohibits an organisation using or disclosing personal information for direct marketing except under APP 7.2 to 7.5; other disclosures are governed by APP 6. The buyer is bound by APP 3 (collection) and APP 5 (notification) | Seller’s disclosure would be a trade under draft s 6FC(1)(a) and usually (b), so consent would be needed under draft APP 4.2. Buyer’s collection would have to be fair and reasonable in the circumstances and lawful under draft APP 3.1 |
| Right to be told the source of your data | APP 7.6(e) and APP 7.7(b) require the organisation to notify the individual of its source unless impracticable or unreasonable | No equivalent appears anywhere in draft clause 7. Item 26 also repeals subparagraphs 13K(1)(b)(v), (vi) and (vii) of the Act and substitutes a single reference to Australian Privacy Principle 7.3. Subparagraph 13K(1)(b)(viii), which references current APP 7.7(b) (notification of source), is not repealed by item 26 |
Count the limbs yourself: the numbers in this draft that get paraphrased wrong
Broader-than-the-instrument paraphrase is the most common error in Australian privacy commentary, and it is easy to check. Here is the count, taken from the Bill rather than from any summary of it.
| Provision | How many limbs | How they combine |
|---|---|---|
| Definition of direct marketing, s 6(1) | 2 | Cumulative — both (a) and (b) |
| What counts as a trade, draft s 6FC(1) | 2 | Either one is enough |
| Carve-outs from trade, draft s 6FC(2) and (3) | 4 | Any one applies; but draft 6FC(2)(b) and draft 6FC(3) each need both of their own sub-limbs |
| Exceptions to consent to trade, draft APP 4.6 | 2 paragraphs (one with 3 sub-limbs) | Any one is enough |
| Attributes of valid consent, s 6AAB(1) | 5 | All five, express or implied; (c) and (d) lifted only for reviewed, approved and monitored human research |
| Opt-out information requirements, draft APP 7.4 | 4 | All four |
| Regimes excluded from APP 7, draft APP 7.7 | 4 | Any one, to the extent it applies |
| Fair and reasonable factors, draft APP 3.2 | 7 | All must be had regard to |
| Commencement dates in clause 2 | 4 numbered rows, all blank | No date is set anywhere in the exposure draft |
Do I need consent to buy a lead list in Australia now?
Today this is a Privacy Act 1988 (Cth) question, and the two sides of the transaction answer to different principles. The buyer is collecting: APP 3.2 lets an organisation collect personal information other than sensitive information only where the information is reasonably necessary for one or more of its functions or activities, APP 3.5 requires collection by lawful and fair means, APP 3.6 requires collection from the individual unless that is unreasonable or impracticable, and APP 5.1 requires the entity to take such steps, if any, as are reasonable in the circumstances either to notify the individual of such matters in APP 5.2 as are reasonable in the circumstances or to otherwise ensure the individual is aware of them — sensitive information carries its own consent rule in APP 3.3, with the exceptions in APP 3.4. The seller is disclosing: APP 6.1 bars use or disclosure for a secondary purpose unless the individual has consented or an exception in APP 6.2 or 6.3 applies, and APP 6.7(a) then takes an organisation’s use or disclosure of personal information “for the purpose of direct marketing” out of APP 6 altogether, which leaves a list disclosed for marketing under APP 7.1 and its exceptions in APP 7.2 to 7.5. Those are the rules in force on 22 September 2026.
Nothing in the paragraph above depends on the exposure draft. Everything that follows does, and the draft has no commencement date, so none of it binds anyone yet.
As the buyer, if the draft became law, nothing in draft APP 4.2 would bind you — it would bind the organisation that holds the information and trades it. Your exposure would be draft APP 3.1 (the collection would have to be fair and reasonable in the circumstances and lawful, subject to the exceptions in draft APP 3.3, draft APP 3.4 reaching only a use or disclosure of government related identifiers) and draft APP 5.1 (you would have to take such steps, if any, as are reasonable in the circumstances either to notify the individual of the fact and circumstances of the collection and the purposes of your intended use or disclosure, or to otherwise ensure the individual is aware of those matters). Then, the moment you send, the Spam Act and the Do Not Call Register Act apply in full — as they do today — and neither cares where the record came from.
As the seller, if the draft became law, a list sold for money would be a trade under draft s 6FC(1)(a). A list handed over free of charge so the recipient can market to those people would still be a trade under draft s 6FC(1)(b). The consultation paper reads that limb broadly: disclosure “for the purposes of direct marketing” is “intended to be interpreted broadly and includes disclosures that support or inform direct marketing, even where marketing is not the sole purpose”, giving disclosures of cookies or pixels in programmatic advertising as an example. So the practical question for anyone acquiring an Australian consumer list would stop being “is this list clean” and become “can the seller show the individual consented to the trading, and does that consent meet all five attributes in draft s 6AAB”. That is a question about the seller, and it is not one a list broker is asked today.
The Two-Ledger Rule: what to do before the bill lands
Here is a decision rule that is worth applying whether or not this draft ever passes, because it maps onto the two questions every Australian regulator asks.
The Two-Ledger Rule: keep a send ledger and a share ledger, and never let one stand in for the other.
- The send ledger answers “may we contact this person on this channel”. One row per person per channel: the consent basis (express or inferred), the wording shown at the time, the timestamp, the source, and every opt-out with the time it took effect. This is your Spam Act and Do Not Call Register evidence and it is already load-bearing today — the sender carries the evidential burden under Spam Act s 16(5). Our page on inferred consent under the Spam Act covers what an automated sender can and cannot establish on its own.
- The share ledger answers “did personal information leave our systems, to whom, for what consideration, and for what purpose”. One row per disclosure. Today this is an APP 6 record. Under the draft it becomes the evidence that decides whether a disclosure was a trade under draft s 6FC and, if so, whether consent existed under draft APP 4.2.
Two design consequences fall out of the rule immediately. First, the draft moves the opt-out duty to the organisation that makes the communication, so an opt-out captured mid-conversation by an agent has to propagate to every channel, not just the one it was spoken on — the mechanics are in our guide to handling an opt-out mid-conversation. Second, “reasonable steps” under draft 7.2 is a proportionate standard: the consultation paper says what counts will depend on factors such as “the size and resources of the entity, technical feasibility, the time and cost involved, and the sensitivity of the information”. A large sender does not get the small sender’s excuse.
Zian AI runs phone, SMS, email and WhatsApp agents from one platform with CRM integrations into HubSpot, Salesforce, HighLevel and Zapier, which is what makes a single cross-channel suppression record practical rather than four channel silos that disagree. Zian is in partnership-application beta. Apply For Partnership.
For the wider reform timeline — the statutory tort already in force and the APP 1 automated-decision obligation commencing 10 December 2026 — see our earlier Australian Privacy Act review briefing for AI outbound teams, written eleven days before this draft appeared. The rules as they stand today across jurisdictions are in our AI outreach compliance guide covering the Spam Act, TCPA and GDPR.
What the regulator is penalising today, while the draft is still a draft
None of the reform above is enforceable. The current rules are, and the ACMA published the numbers itself.
- In its article of 22 July 2026, the ACMA states: “Businesses have paid more than $12 million in penalties for spam and telemarketing breaches over the past 18 months.”
- The same article records that Tabcorp Holdings Limited paid more than $2.7 million in penalties after the ACMA found that, between February 2024 and June 2025, it made 351 calls to numbers on the Do Not Call Register without consent, 82 calls outside permitted hours and nearly 4,000 calls without properly identifying itself as the caller and/or the purpose of the call; and that it self-reported sending more than 217,000 marketing emails and SMS over a 16-day period to customers who had unsubscribed from specific marketing channels.
- The ACMA’s quarterly report for January to March 2026 records a $702,900 infringement penalty paid by Lululemon Athletica Australia Pty Ltd for sending over 370,000 marketing emails that did not contain a way to unsubscribe, and a $376,200 infringement penalty paid by Lycamobile Pty Ltd for breaching mobile number fraud rules.
- In that quarter the ACMA gave 967 compliance alerts to businesses and received more than 4,500 complaints about alleged breaches of telemarketing and spam laws. Solar, insurance and electricity were the most complained about industries.
Note what is missing from that list: not one of those penalties turns on the Privacy Act. They all turn on the two Acts the new APP 7 would continue to exclude.
Frequently asked questions
Do I need consent to send marketing SMS and email in Australia in 2026?
Yes. Section 16(1) of the Spam Act 2003 (Cth) prohibits sending a commercial electronic message that has an Australian link and is not a designated commercial electronic message, and section 16(2) removes that prohibition only where the relevant electronic account-holder consented. The exposure draft released on 31 August 2026 does not amend the Spam Act, and draft APP 7.7(c) keeps the Spam Act outside the new direct marketing principle.
Does the new Australian privacy bill ban direct marketing?
No, and it does not require consent for it either. The draft APP 7 has seven subclauses and none of them mentions consent. What it requires is a simple opt-out mechanism, reasonable steps to action an opt-out, and opt-out information in every communication that is in clear and plain language, readily understandable by an ordinary person, up-to-date and concise. Direct marketing would still have to be fair, reasonable and lawful under draft APP 3.1.
What is the new direct marketing framework under APP 7?
It is a proposed replacement for the current APP 7, set out in item 27 of Schedule 2 Part 3 of the exposure draft. It drops the current prohibition in APP 7.1 and the conditions in APP 7.2 to 7.5, and replaces them with an opt-out framework, a statutory definition of direct marketing in section 6(1) that covers targeting a person as a member of a class, and a modified rule for ad-supported services. It is a draft only.
Do I need consent to buy a lead list in Australia now?
Today, no. As the law stands on 22 September 2026, a buyer of personal information that is not sensitive has no consent duty under the Privacy Act: the buyer must satisfy APP 3.2 (reasonably necessary for one or more of its functions or activities), APP 3.5 (lawful and fair means), APP 3.6 (collect from the individual unless that is unreasonable or impracticable) and APP 5.1 (take such steps, if any, as are reasonable in the circumstances to notify the individual of the APP 5.2 matters that are reasonable in the circumstances, or otherwise ensure the individual is aware of them). Sensitive information is different: APP 3.3 requires consent unless APP 3.4 applies. Under the exposure draft the consent duty would still sit with the seller, because draft APP 4.2 binds the organisation that discloses the list, and the draft has no commencement date and binds nobody yet. Sending to the list is still governed by the Spam Act and the Do Not Call Register Act.
When does the Privacy Amendment (Personal Data Protection) Bill 2026 commence?
There is no commencement date. Clause 2 of the exposure draft Bill contains a commencement table with four numbered rows and every one of them is blank. Every page of the document is headed EXPOSURE DRAFT and the bill number line is blank. Consultation opened on 31 August 2026 and closed on 18 September 2026.
Does the draft change the Do Not Call Register rules for phone calls?
No. Draft APP 7.7(b) excludes the Do Not Call Register Act 2006 from the new principle in the same way that current APP 7.8(a) excludes it, so calls to registered numbers continue to be governed by section 11 of that Act rather than by the Privacy Act.
Where every figure on this page comes from
| Figure | Who published it | Link | Date read |
|---|---|---|---|
| Consultation opened 31 August 2026, closed 18 September 2026 | Attorney-General’s Department | consultations.ag.gov.au privacy reform | 22 September 2026 |
| Draft APP 7.1 to 7.7; draft APP 4.2 and 4.6; draft s 6FC carve-outs; draft s 6AAB consent attributes; draft APP 3.1 to 3.4; draft APP 5.1; item 26 amendments to s 13K(1)(b); blank commencement table | Attorney-General’s Department, exposure draft Bill | Exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 (PDF) | 22 September 2026 |
| “The framework does not require consent for direct marketing, but entities must obtain consent to trade personal information”; “four carve-outs”; cohort wording; platform opt-out responsibility; reasonable steps factors | Attorney-General’s Department, consultation paper | Privacy Reform Consultation Paper (PDF) | 22 September 2026 |
| Current APP 3, APP 5, APP 6 and APP 7.1 to 7.8 wording and condition counts; current s 6(1) definition of consent; “direct marketing” appearing 33 times and “cohort” and “segment” not at all; s 13K(1)(b) subparagraph numbering including (viii) | Federal Register of Legislation, Privacy Act 1988 (Cth) | Privacy Act 1988 compilation | 22 September 2026 |
| Spam Act s 16(1) to 16(5); Schedule 1 designated commercial electronic messages (items 3 and 4); Schedule 2 meaning of consent | Federal Register of Legislation, Spam Act 2003 (Cth), compilation No. 10 | Spam Act 2003 compilation | 22 September 2026 |
| APP 1 automated-decision obligation commencing 10 December 2026 | Federal Register of Legislation, Privacy and Other Legislation Amendment Act 2024 (Cth), commencement table item 7 (Schedule 1, Part 15) | Privacy and Other Legislation Amendment Act 2024 | 22 September 2026 |
| Do Not Call Register Act s 11 | Federal Register of Legislation, Do Not Call Register Act 2006 (Cth) | Do Not Call Register Act 2006 compilation | 22 September 2026 |
| $12 million over 18 months; $2.7 million; 351 calls; 82 calls; nearly 4,000 calls; 217,000 messages over 16 days; February 2024 to June 2025 | ACMA, article dated 22 July 2026 | ACMA: TAB pays $2.7m for telemarketing and spam breaches | 22 September 2026 |
| $702,900; 370,000 emails; $376,200; 967 compliance alerts; 4,500+ complaints; the “any promotional or sales content” test; the bill or invoice with a banner advertisement example | ACMA, quarterly report January to March 2026 | ACMA: Action on scams, spam and telemarketing, January to March 2026 | 22 September 2026 |
This is general information, not legal advice, and it is current as at 22 September 2026. Every provision quoted was read against the exposure draft or the Federal Register compilation named beside it on that date. An exposure draft is not law, has no commencement date and can change before introduction; your obligations turn on your own facts. Get advice.