Every SMS campaign in Australia starts with one question: do you actually have the right to text this person? Get the answer wrong and you risk penalties under the Spam Act 2003, damaged customer trust, and wasted spend on messages nobody agreed to receive.
Australian law recognises two distinct types of permission for commercial SMS: express consent and inferred consent. They are not interchangeable, and using the wrong one for the wrong audience is one of the most common compliance mistakes businesses make. This guide explains what each type means, when you can rely on it, how to collect and record it properly, and how DataFlows helps you manage consent at scale without slowing down your marketing.
What Is SMS Consent
SMS consent is permission from a person to receive text messages from your business, and it is the legal foundation of every commercial SMS sent in Australia under the Spam Act 2003. Consent comes in two recognised forms: express and inferred. Express consent is explicit permission given in clear terms, such as a customer ticking a checkbox, replying "YES" to a keyword, or signing a form stating they agree to receive SMS marketing. Inferred consent exists when someone has an existing business relationship with you, such as a recent purchase, an active booking, or an ongoing account, and it would be reasonable to expect they want related messages as a result. Both forms must be specific, informed, and current: a customer who bought something years ago with no contact since is a weak case for inferred consent. Every message also needs a working opt-out method and clear sender identification, regardless of consent type. Getting this distinction right protects your business and respects your customers.
Why Consent Rules Matter for Australian Businesses
The Australian Communications and Media Authority (ACMA) enforces the Spam Act 2003, and it actively investigates complaints about unsolicited commercial messages. Penalties for sending commercial electronic messages without consent can run into hundreds of thousands of dollars for repeat or serious breaches, and ACMA publishes enforcement outcomes publicly, which means non-compliance carries reputational risk on top of financial risk.
Beyond regulation, consent is directly tied to results. Recipients who never agreed to hear from you are far more likely to mark messages as spam, ignore them entirely, or opt out at the first opportunity, which drags down your sender reputation and can affect deliverability for every future campaign. Businesses that build consent properly from the start end up with smaller but far more responsive lists, which consistently outperform large, poorly-permissioned ones.
Consent rules apply the same way whether you are a solo tradie sending appointment reminders, a retail chain running seasonal promotions, or a healthcare provider sending recall notices. The channel is the same, so the obligations are the same, even though the type of consent you can rely on will differ by relationship and context.
Key Benefits of Getting Consent Right
Stronger legal protection: documented, specific consent is your primary defence if a complaint is ever lodged with ACMA, and it shows a genuine attempt to comply rather than an oversight.
Higher engagement rates: people who actively opted in read, click, and act on messages at much higher rates than people who never asked to hear from you.
Lower opt-out and complaint rates: a properly consented list produces fewer unsubscribes and spam reports, which keeps your sending reputation healthy over time.
Better long-term deliverability: carriers and gateways monitor complaint rates, so clean consent practices help keep your messages landing in the inbox rather than being filtered.
More trust with customers: transparent opt-in builds the kind of relationship where customers welcome your messages instead of resenting them.
Step-by-Step: Building a Compliant Consent Workflow
Capture consent at the point of collection: whenever someone hands over their mobile number, whether on a website form, in-store signup sheet, or booking system, state clearly what they are agreeing to and how often you will message them.
Record the consent type and source: note whether consent was express or inferred, when it was given, and where it came from (checkout, keyword reply, event signup, and so on). This record is your evidence if it is ever questioned.
Separate your contacts by consent status: never merge an inferred-consent list (recent customers) with an express-consent marketing list. They have different rules and different expectations.
Refresh inferred consent regularly: inferred consent weakens over time. A customer relationship from three years ago does not justify a promotional text today. Review and prune lists on a set schedule.
Include an opt-out in every message: a simple "Reply STOP to opt out" line is a legal requirement, not an optional courtesy, and it must actually work when someone uses it.
Action opt-outs immediately: once someone opts out, they should never receive another marketing message from that list. Automate this so it cannot be missed.
A few common scenarios illustrate how this plays out in practice. A retail store collecting phone numbers at checkout for order updates has inferred consent for transactional messages about that order, but needs express consent before adding the customer to a promotional SMS list. A gym member who signs up and ticks a box agreeing to receive class reminders and offers has clear express consent for both. A tradie who quoted a job six months ago and never heard back has a fading case for inferred consent, and should treat any follow-up message carefully or seek fresh opt-in.
Express vs Inferred Consent: A Quick Comparison
Understanding when each type applies is easier with a side-by-side view of how they differ in practice.
Source of permission: express consent comes from a direct, affirmative action such as ticking a box or replying to a keyword, while inferred consent comes from the nature of an existing relationship, such as a purchase or booking.
Strength as evidence: express consent is easy to document and defend, since you have a clear record of the action taken. Inferred consent is judged on reasonableness, which makes it more open to interpretation and dispute.
How long it lasts: express consent generally remains valid until the person withdraws it. Inferred consent weakens over time and is tied to how recent and relevant the underlying relationship still is.
Best used for: express consent supports ongoing promotional and marketing campaigns. Inferred consent is best limited to directly related follow-ups, such as order updates, appointment reminders, or service notifications.
Risk if misapplied: treating a weak or stale inferred relationship as if it were express consent for broad marketing is one of the most common sources of Spam Act complaints.
How DataFlows Helps You Manage Consent
DataFlows gives Australian businesses the tools to collect, store, and act on consent correctly, rather than relying on spreadsheets or guesswork. Contact Lists let you tag each contact with their consent type and source, so your team always knows who can receive marketing messages and who should only get transactional updates.
When you run SMS Campaigns through DataFlows, you can target only contacts with valid express consent, keeping promotional sends separate from transactional traffic. Every campaign message can include a compliant opt-out instruction, and opt-outs are processed automatically so unsubscribed numbers are never contacted again.
If you collect consent through sign-up forms, checkout flows, or CRM tools, the Zapier integration, Power Automate integration lets you automatically add new opt-ins to the right DataFlows contact list the moment someone signs up, with no manual data entry and no risk of stale records.
For businesses running keyword-based opt-ins, such as "Text JOIN to [number] for offers," DataFlows' SMS API can capture the reply, timestamp the consent, and add the contact to the correct list automatically. If you also need a recognisable, registered sender identity for your campaigns, DataFlows supports Sender IDs so recipients see your business name rather than an unfamiliar number.
Best Practices for SMS Consent and Opt-In
Be specific about what you're asking for: "agree to receive updates" is vague. Say exactly what kind of messages and roughly how often.
Never buy or rent contact lists: purchased lists carry no valid consent for your business and are a direct compliance risk.
Keep an audit trail: store the date, method, and wording used to obtain each contact's consent in case you ever need to demonstrate compliance.
Make opting out effortless: a working STOP keyword should be in every marketing message, with no extra steps or delays.
Review inferred-consent lists on a schedule: set a review period (for example, 12 months) after which inferred consent is treated as expired unless renewed.
Match your sender ID to your brand: a registered, recognisable sender ID reduces confusion and opt-outs caused by recipients not recognising who is texting them.
Conclusion
Consent is not a box to tick once and forget. It is an ongoing part of how you run SMS communication in Australia, and getting it right protects your business while making your messages genuinely welcome. Start by auditing how your current contact lists were built, separate express from inferred consent, and put a working opt-out process in place if you don't already have one.
Ready to manage consent properly and send compliant campaigns? Sign up at DataFlows to set up Contact Lists, Sender IDs, and SMS Campaigns that keep your marketing on the right side of the Spam Act.
You May Also Like
SMS Australian Business SMS Compliance: The Complete 2026 Guide
The Spam Act 2003 & SMS Marketing: What Australian Businesses Must Know
SMS Sender ID Registration in Australia
Best SMS Marketing Strategies
SMS Marketing with DataFlows
