Business LawQuest LegalAustralia’s world-first scam laws are here – and they could impact your marketing

September 24, 2025

Australia’s world-first scam laws are here – and they could impact your marketing  

In a bid to crack down on scams, Australia has introduced world-leading legislation: the Scams Prevention Framework (SPF). If your business markets to customers, collects personal data or operates online, you need to know what’s changed.  

Australians are losing more than $2 billion a year to scams. The SPF aims to protect residents from scams and the criminals who target them. Across key sectors such as banking, telcos and social media, the message is clear: scam prevention is now a legal obligation. The ripple effect will reach many Australian businesses, especially those involved with digital marketing or data handling. 

What is the Scams Prevention Framework? 

The SPF is a new legal regime introduced under the Competition and Consumer Act 2010, aimed at stopping scams before they ever reach consumers. It gives regulators stronger tools to enforce scam prevention standards and introduces strict new penalties for any businesses that don’t comply.  

Under the framework, businesses in designated sectors must take reasonable steps to prevent, detect, disrupt, respond to and report scams. These obligations are tied to enforceable codes and record-keeping rules – and serious breaches can incur civil penalties of up to $50 million. 

Who’s affected right now? 

Currently, the SPF applies to: 

  • Banking and financial services, regulated by ASIC 
  • Telecommunications providers, regulated by ACMA 
  • Digital platforms (e.g. social media, search engines), regulated by the ACCC 

However, the law is designed to be scalable. The government has already flagged superannuation, insurance and cryptocurrency as next in line, and businesses that touch consumer data, run digital ads, or handle payments should similarly be watching closely. 

What’s considered a scam? 

The Act defines a scam as a deceptive attempt to engage a person or small business using a regulated service that, if successful, would cause financial loss, unauthorised access to personal information, or other forms of harm. That includes phishing, impersonation, and fake offers – the kinds of scams that often imitate everyday digital marketing tactics. 

What does this mean for marketing, privacy and compliance? 

Even if your business isn’t in a designated sector, the SPF sets a new benchmark for digital accountability. Businesses must take more responsibility for the safety of their digital experiences. That means: 

  • Misleading or high-pressure marketing tactics could raise compliance flags, especially if they mimic common scam behaviours (e.g. heightened urgency, ambiguous offers, or impersonation). 
  • Consent collection and privacy policies need to be crystal clear. Pre-ticked boxes, buried disclaimers or overly broad data use statements won’t suffice. 
  • Storing and handling personal data now carries more risk. Lax security, unclear data use or sharing customer info with third parties could all be areas of concern. 
  • Doing nothing is no longer a defence. The SPF is built on the idea that inaction can still be a breach if it fails the ‘reasonable steps’ test. Reasonably documented action is required – not just good intentions. 

Four ways your business can prepare now 

Even if these scam laws don’t yet apply to your business, it’s wise to align your practices with the new requirements. Doing so will ensure you’re ready for future changes. Here are four simple steps to get started:

  • Audit your marketing and consent practices 

Are customers clearly opting in to hear from you? Do your subject lines and calls to action avoid manipulative or misleading language? 

  • Update your privacy policy and make it accessible 

Ensure yours accurately reflects the data you collect, why, how it’s stored and who it’s shared with. 

  • Secure your data storage systems 

Use up-to-date software and limit internal access to sensitive information. Don’t keep data longer than needed. 

  • Train your team 

Make sure staff understand what counts as scam-like behaviour and how to avoid it in customer-facing communications. 

Why this all matters 

With AI and technology ever more present in our daily lives, the risk of scams increases with it. Action needs to be taken, and the onus is on businesses to do their due diligence. By acting early, your business can reduce risk, stay compliant, and build trust at a time when customers are more cautious than ever.  

Need a legal check-up? The Scams Prevention Framework is just the beginning of a new compliance era. Quest Legal can help you stay ahead by reviewing your business and ensuring your practices are ironclad.