Skip to content

Can we market to a database we bought or inherited with a rent roll?

Not on the strength of the purchase. Consent under the Spam Act is given to a particular sender for particular messages, so it does not transfer with a business asset, and buying the data does not buy the permission. Before any email or SMS you need consent that covers you, and there is no bulk threshold, so a single message to one inherited contact is enough to contravene. The data transfer itself is a separate question under the Privacy Act.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Note that the Spam Act applies to your messages whether or not the Privacy Act binds your business.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Generally no. Consent is given to a sender the person chose to hear from, for messages of a kind they agreed to receive. A different business sending different messages is not what they agreed to.

Two qualifications worth knowing, because the answer is not always a flat no:

What you should not do is treat a spreadsheet with a "subscribed" column as evidence. Ask what the person was actually shown and when.

Sources: Spam Act 2003 (Cth); Privacy Act 1988 (Cth), APP 7 (Schedule 1) · ACMA spam rules

What should we get from the vendor at the point of sale?

Treat this as due diligence, because after settlement the exposure is yours and the vendor is gone.

Ask for, in writing:

If none of that exists, you have bought a contact list you cannot market to. That is worth knowing before you pay for it.

Sources: Spam Act 2003 (Cth); Privacy Act 1988 (Cth), APP 5 and APP 7 (Schedule 1) · ACMA spam rules

Can we email the list to ask them to opt in?

No, and this is the single most common attempted fix.

A message asking somebody to subscribe is itself a commercial electronic message, so it needs prior consent in its own right. The permission request is the contravention it was meant to cure.

There is no bulk threshold in the Spam Act, so sending it individually rather than as a campaign does not help. One unsolicited commercial electronic message to one person is enough.

What you can do instead:

Sources: Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth); Privacy Act 1988 (Cth), APP 7 (Schedule 1) · ACMA spam rules · See also cold-calling property owners and the DNC Register

Someone asks where we got their details. Do we have to tell them?

Yes, generally, and this is the obligation that exposes an inherited list.

APP 7.6 survives the Spam Act displacement. An individual can ask you to stop using or disclosing their information for direct marketing, ask you not to facilitate other organisations' direct marketing, and ask you to identify the source of the information. You must comply within a reasonable period and free of charge, and for the source request you generally must tell them unless it is impracticable or unreasonable to do so.

On an inherited database the honest answer is often "we acquired it from X when we bought their rent roll", which is exactly the answer that prompts a complaint if the person never dealt with X either. That is a reason to fix the list, not a reason to avoid answering.

Practically: record the source per contact at the point you import, not later. A field you can query is the difference between answering in a minute and reconstructing a chain of custody under pressure.

Sources: Privacy Act 1988 (Cth), APP 7.6 (Schedule 1) · OAIC APP Guidelines chapter 7 · OAIC APP guidelines

Does buying a list affect our small-business exemption?

It can, and the limb that catches it is not the one most people expect.

Section 6D removes the small-business exemption from an operator that trades in personal information. That covers disclosing personal information about another individual for a benefit, service or advantage, and it separately covers collecting personal information about another individual from anyone else for a benefit, service or advantage. Paying for a contact list is the second of those.

There are carve-outs. Disclosures and collections made with the consent of the individual concerned, and those required or authorised by or under legislation, are excluded from the trading analysis. So a transfer where the individuals have actually consented sits outside it, which is another reason the consent records matter commercially and not just legally.

The practical implication for a smaller business is that buying a database is one of the ways you can quietly become bound by the whole Privacy Act, having been exempt the day before.

Sources: Privacy Act 1988 (Cth), s 6D(4)(d) (provides a benefit, service or advantage to collect personal information about another individual) and its carve-out at s 6D(8) (released where the collection is with the individual's consent, or is required or authorised by or under an Australian law); the companion disclosure limb is s 6D(4)(c) with its carve-out at s 6D(7). ✅ Lettering closed against Compilation 104 (`verify/2026-07-29-s6D-6DA-turnover-ratchet.md`) · OAIC APP Guidelines chapter B · OAIC APP guidelines · See also selling a rent roll

→ The free 2-minute audit covers the contact data a business holds and whether it can actually be used.