What happened
On 22 July 2026, the Australian Communications and Media Authority (ACMA) announced that TAB — the wagering arm of Tabcorp — had paid more than $2.7 million in penalties for breaching Australia's spam and telemarketing laws. Between February 2024 and June 2025, the regulator found TAB made 351 telemarketing calls to numbers on the Do Not Call Register without consent, placed 82 calls outside permitted calling hours, and made almost 4,000 calls without properly identifying the caller or the purpose of the call. Separately, TAB self-reported that it had sent more than 217,000 marketing emails and SMS messages over a 16-day period in 2025 to customers who had already unsubscribed from those specific marketing channels.
ACMA member Samantha Yorke was blunt about what the pattern showed: "When people join the Do Not Call Register or unsubscribe from marketing messages, they are making a clear choice... Those choices must be respected." She added that "the scale and range of these breaches point to serious weaknesses in TAB's compliance systems" — and that ACMA would be watching closely to ensure the company fixes them.
This is TAB's second ACMA penalty for spam-related conduct in about two years — it was fined more than $4 million in 2024 over unlawful marketing messages sent via SMS and WhatsApp to VIP customers. This time, TAB has entered into a fresh court-enforceable undertaking requiring an independent review of its telemarketing systems, alongside the compliance undertaking already in place from the earlier case.
Why it matters to your business
Two separate Commonwealth laws sit behind this one case, and both are enforced by ACMA: the Spam Act 2003, which covers commercial email, SMS and MMS, and the Do Not Call Register Act 2006, which covers telemarketing calls and marketing faxes. Unlike the Privacy Act, neither has a small-business turnover exemption. A five-person business sending a marketing newsletter or running an outbound calling list is covered by exactly the same consent, identification and unsubscribe rules as a national brand.
It's tempting to read a $2.7 million fine as an enterprise-scale problem. The underlying failures aren't: a pre-ticked sign-up box, an unsubscribe link that quietly doesn't work, a calling list that hasn't been checked against the register recently — these are ordinary small-business mistakes, made every day by businesses with no intention of breaking the law. The difference is scale, not kind. And TAB being fined twice for the same category of conduct is a sign ACMA is treating this as a live, actively enforced area — not a dusty law nobody checks.
What the Spam Act actually requires
ACMA's own guidance boils the Spam Act down to three things every commercial email, SMS or MMS must get right. Here's each one, in plain English, with what TAB's case shows about what happens when it goes wrong.
Get real consent before you send anything
What: you need express or "inferred" consent before sending a marketing message. Express consent — someone actively ticking a box, filling in a form, or saying yes over the phone — is the gold standard. Inferred consent is narrower than most people assume: it only covers an existing relationship where the person would reasonably expect that specific type of marketing, not "they bought something from us once."
Why it matters: under the Spam Act, the burden of proof sits with you — ACMA's guidance is explicit that "it's up to you to prove that you have a person's consent." A pre-ticked sign-up box isn't a genuine opt-in, and can put your whole marketing list on shaky legal ground.
How: check your sign-up forms for pre-ticked marketing boxes, and keep a simple record of who consented, when, and how (form, phone, in person).
Identify yourself properly in every message
What: every commercial message must accurately identify your business name (or you and your ABN) and include correct contact details, accurate for at least 30 days after you send it — even if someone else sends the message on your behalf.
Why it matters: almost 4,000 of TAB's calls failed exactly this test — not properly identifying the caller or the purpose of the call. It's an easy thing to get sloppy about, especially in SMS where character limits invite shortcuts.
How: check your email footer and SMS sign-off actually name your business (or ABN), not just a product brand or campaign name.
Make unsubscribing genuinely easy — and honour it fast
What: every commercial message needs a working unsubscribe option that doesn't require a login or extra personal information, stays functional for 30 days, and — critically — is honoured within 5 working days of the request.
Why it matters: this is the exact failure in TAB's second breach — continuing to message more than 217,000 times to customers who had already opted out. An unsubscribe button that "works" but is ignored is not compliance.
How: test your own unsubscribe link today. Does it actually stop messages? Does anything still arrive from you a week later? If a person unsubscribes from a marketing list but not a transactional one, is that distinction actually respected on your end?
If you cold-call: the Do Not Call Register applies too
Telemarketing sits under separate legislation — the Do Not Call Register Act 2006 — but it's the other half of TAB's fine. Any call with a commercial purpose to a number on the register requires consent, and businesses that telemarket are expected to check their calling lists against the register before each campaign — a process ACMA calls "washing," and one that industry guidance points to doing on roughly a 30-day cycle. Permitted calling hours and proper caller identification apply as well — both of which TAB was fined for getting wrong. If you outsource telemarketing to a call centre or agency, the law places the compliance obligation on you as well as them — a contract that's silent on this doesn't transfer the risk away.
The other 2026 rule almost nobody's talking about: SMS Sender ID
Running quietly alongside all of this is a separate, newer rule. From 1 July 2026, any business sending branded text messages — where your business name appears at the top of the message instead of a phone number — must have that sender ID registered on ACMA's SMS Sender ID Register. If it isn't, the message now arrives on your customer's phone stamped "Unverified" and grouped alongside likely scam texts — exactly the company your booking confirmation or delivery notice doesn't want to keep.
Registrations have been open since November 2025 and, per industry reporting, applications can take several weeks to process — so if you haven't registered yet, the honest advice is to start now rather than wait. You can register through your telco or SMS provider, or directly with ACMA using an active ABN and proof of brand or domain ownership. And it's worth checking even if you don't think you send branded SMS yourself: if a booking system, CRM or marketing platform texts your customers on your behalf, that message may be going out under your business name without you having set anything up — worth a quick email to your provider to confirm who owns that registration. If you only ever text customers from a standard mobile or landline number, none of this applies to you.
What this guide is not
Precision matters more than drama here, so let's be exact about the edges.
- This is not legal advice. Whether a particular relationship qualifies for "inferred" consent, or whether your list-washing arrangement with a contractor meets the Do Not Call Register's requirements, are judgement calls about your specific business. A professional — or ACMA's own published guidance — should confirm the edge cases.
- A small business's exposure isn't automatically $2.7 million. ACMA scales its enforcement response — from a warning through to significant penalties — to the scale and seriousness of the conduct. The dollar figure here reflects TAB's size and repeat conduct; the underlying rules are identical for a business of any size.
- AegorIQ does not check your marketing lists, consent records or telemarketing practices. Those live in your CRM, email platform or calling software — not on your public website. What we check is described honestly below, and the complete list is published here.
Where a website scan fits in
Two things in this guide are visible on your website, and both are checks AegorIQ runs on every tier — including the free Scorecard. The first is direct: we check whether the sign-up boxes on your site are pre-ticked — under the Spam Act, that's not valid consent, and it's a mistake we've found on live Australian business websites. The second is related rather than identical: we check your SPF, DKIM and DMARC records — the settings that let email providers verify a message claiming to be from your business genuinely is. That's not a consent or unsubscribe check; it's about your legitimate messages being trusted rather than filtered or spoofed — a different problem from the one TAB was fined for, but part of the same broader picture of a business's outbound communications being trustworthy. Being honest about the limits: a scan can't see your consent records, your calling lists, or whether your unsubscribe process is actually honoured within five working days. Those are worth checking directly, using the steps above.
Sources
- ACMA — TAB pays $2.7m for telemarketing and spam breaches (22 July 2026)
- Cyber Daily — Bad bet: TAB fined $2.7m over spam and telemarketing breaches (22 July 2026, incl. ACMA quotes and 2024 penalty history)
- ACMA — Avoid sending spam (consent, identification and unsubscribe requirements under the Spam Act 2003)
- Do Not Call Register — About the Do Not Call Register and Industry FAQs
- Sprintlaw — Do Not Call Register: Rules for Australia (list-washing cadence)
- ACMA — SMS Sender ID Register (rule in force from 1 July 2026)
- Prospa — New SMS sender ID rules from 1 July 2026: what small businesses need to know