An Australian company paid 871,660 Australian dollars for one hundred and fifty-four messages.
One hundred and fifty-four. Not one hundred and fifty-four thousand. It is the highest amount per message we have found in published decisions of recent years, and it comes from the country least talked about.
Australia: the country that fines by the message
The Spam Act 2003 imposes a consent regime, express or reasonably inferred. Its section 17 requires accurate sender identification, with contact details valid for at least thirty days after sending. Its section 18 requires a working unsubscribe mechanism for the same period, and withdrawal of consent takes effect after five business days.
In October 2024, the Australian communications authority made the Commonwealth Bank of Australia pay 7.5 million Australian dollars: more than 170 million marketing messages sent between November 2022 and April 2024 without an unsubscribe mechanism, including 34.8 million to people who had not consented or had withdrawn consent.
In July 2025, the same authority made Betfair pay 871,660 Australian dollars, with a two-year enforceable undertaking, for 154 messages sent to VIP customers between March and December 2024, without valid consent, and in part without an unsubscribe option.
Two cases, two orders of magnitude, one logic: it is not the volume that triggers the sanction, it is the nature of the breach.
Canada: implied consent has an expiry date
Canada’s anti-spam legislation works on express consent by default, with exceptions for implied consent, notably an existing business relationship.
The point everyone forgets: that implied consent expires after two years. Express consent does not expire, but may be withdrawn at any time.
Two formal obligations are added: identifying the sender and any party on whose behalf the message is sent, with a link to a page carrying that information accepted; and providing a postal address that stays valid for at least sixty days after sending.
Administrative penalties reach one million Canadian dollars per violation for an individual and ten million for a business.
One useful clarification, rarely given correctly: the private right of action, which would have allowed individuals to sue senders directly, never came into force. An order of 2 June 2017, published in the Canada Gazette on 14 June 2017, repealed the provision that was to trigger it on 1 July 2017. It remains suspended to this day.
United Kingdom: the ceiling was multiplied by thirty-five
The British regime rests on PECR 2003, whose regulation 22 sets an opt-in principle, tempered by a soft opt-in comparable to the French existing customer exception: contact details obtained in the course of a sale or negotiations for a sale, similar products or services, a simple and free means of refusal at collection and with every message.
The major change dates from 5 February 2026, with the entry into force of the corresponding provisions of the Data (Use and Access) Act 2025, passed on 19 June 2025.
Two effects, very different from each other.
The first is an opening: a new regulation 22(3A) creates a charitable soft opt-in, allowing a charity to email people who have expressed an interest in its purposes, without prior consent, under equivalent conditions.
The second is a considerable tightening: the penalty ceiling for breaches of PECR’s marketing rules, including regulation 22 on email, rises from 500,000 pounds to the ceiling of the UK data protection regime, that is 17.5 million pounds or 4 percent of annual worldwide turnover. The ICO confirmed this in its official statement the same day.
To gauge the gap, a fine issued just before that shift: on 20 January 2026, the ICO sanctioned ZMLUK Limited for 105,000 pounds for more than 67 million marketing emails sent without valid consent between January and July 2023. Under the new ceiling, the same case would be argued in an entirely different order of magnitude.
The three regimes, side by side
| Canada | United Kingdom | Australia | |
|---|---|---|---|
| Principle | Express consent, implied allowed | Opt-in, with soft opt-in | Express or inferred consent |
| Implied consent duration | 2 years | Not applicable | Not published |
| Contact details valid after sending | 60 days | Not published | 30 days |
| Effect of unsubscribe | No published deadline | No published deadline | 5 business days |
| Penalty ceiling | CAD 10m (business) | GBP 17.5m or 4% of worldwide turnover | Not verified |
One cell stays empty, and we leave it empty: we could not verify against an official source the current ceiling of the Australian Spam Act, expressed in penalty units reindexed since 2003. The actual sanctions, by contrast, are verified and published.
The rule that saves you keeping three spreadsheets
Four regimes, counting Europe. Opposing principles, different deadlines, ceilings with nothing in common.
There is nonetheless a common denominator, and it is short: consent whose origin and date you can prove, accurate sender identification, a valid postal address, an unsubscribe that works immediately and durably.
Four conditions that satisfy the strictest of the four regimes, and therefore all four. That is simpler to maintain than a country matrix, and it is also what the mailbox providers require, and they will not ask you where your recipient is.
The consent question, by contrast, remains governed by the recipient’s country, and it is the only variable that genuinely needs segmenting. In Europe it runs through the professional regime or prior consent; in the United States it does not arise.
What to do tomorrow morning
Segment your database by the recipient’s country of residence, not by language or mail domain. An address at gmail.com says nothing about the country, and the country decides the applicable regime.
Then check the date of your Canadian consents: beyond two years without a business relationship, implied consent has expired.
And if you address the United Kingdom, reread your arrangements against the new ceiling. A 500,000 pound risk and a 4 percent of worldwide turnover risk are not handled at the same level of the organisation.
Sources
- CRTC. Canada’s Anti-Spam Legislation: Frequently Asked Questions
- Canada Gazette (14 June 2017). Order Repealing the Order Fixing July 1, 2017 as the Day on which Certain Provisions of the Act Come into Force
- Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22
- Data (Use and Access) Act 2025, Schedule 13
- ICO (5 February 2026). Statement on the commencement of the Data (Use and Access) Act
- ICO (20 January 2026). Fines of £225,000 for nuisance marketing messages
- ACMA (October 2024). Commonwealth Bank pays $7.5m for more spam breaches
- ACMA (July 2025). Betfair pays $871k for VIP customer spam breaches
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
