Outbound Atlas

Atlas/The law/The regimes

Australia, New Zealand and APAC

Australia and New Zealand allow cold B2B email only through 'inferred consent' for published, role-relevant addresses; Singapore and Brazil are opt-out; Japan is opt-in with a business-address exception; India has no email law yet but a consent-based privacy act arriving in 2027.

Lawmedium confidence9 minupdated 2026-10-059 sources
Jurisdiction
Australia, New Zealand, Singapore, India, Brazil, Japan
Regime
Mixed
Cold B2B email
AU/NZ: allowed via inferred consent for published, role-relevant addresses; SG/BR: opt-out; JP: opt-in with business-publication exception; IN: unregulated until DPDP
Penalty
Australia: up to 10,000 penalty units per day for repeat corporate offenders; Japan ¥30M; Brazil 2% of local revenue (R$50M cap)
Enforced by
ACMA (AU), DIA (NZ), IMDA/PDPC (SG), Data Protection Board (IN), ANPD (BR), MIC/CAA (JP)

Outside North America and Europe the picture splits three ways. Australia and New Zealand run consent laws with a written exception for published business addresses, and Australia enforces hard: businesses paid over A$16M in spam penalties in the 18 months to March 2025. Singapore and Brazil are opt-out in practice. Japan is opt-in but exempts addresses businesses publish themselves. India has no email-specific law, but its consent-centred data protection act takes full effect on 13 May 2027.

These markets matter mainly as buyers and senders, not as recipients of US-style volume. Australian and Indian agencies are a visible part of the cold-email agency ecosystem (Non-English markets, Lead-gen agencies).

Australia: the Spam Act 2003

Australia requires consent for every commercial electronic message, by email or SMS, B2B or B2C. Consent can be express or inferred, and inferred consent includes a statutory "conspicuous publication" rule that is more precise than Canada's.

Under Schedule 2, clause 4, an account-holder is taken to consent when four conditions hold:

  1. The address lets the public reach a particular employee, officer, partner or self-employed person, or a role or function within an organisation.
  2. It "has been conspicuously published".
  3. "It would be reasonable to assume that the publication occurred with the agreement" of that person or organisation.
  4. The publication is not accompanied by a statement that the holder "does not want to receive unsolicited commercial electronic messages".

Even then, consent covers only messages "relevant to the work-related business, functions or duties" of the person, or to the office, role or function concerned.

So what

Australia wrote the cold-email compliance spec into statute. The address must be published, the publication must look authorised, there must be no no-spam notice, and the pitch must be relevant to the role. Each of these can be checked and logged at import. An SMTP-guessed address fails condition 2.

Every message must also identify the sender and carry a functional unsubscribe. ACMA enforcement in 2025 focused on unsubscribe mechanics. Opt-outs must be honoured within 5 working days and cannot require a login or extra personal details.

Penalties are set in penalty units per day under section 25:

OffenderPer contravention (s.16 sending rules)Per day cap
Body corporate, no prior record100 penalty units2,000 penalty units
Body corporate, prior record500 penalty units10,000 penalty units
Not verified

At a Commonwealth penalty unit of A$330 (our understanding of the rate since November 2024, not re-verified here), the daily caps are about A$660,000 and A$3.3M. Infringement notices and court-ordered penalties are calculated per day of sending, which is why multi-day campaigns produce seven-figure notices.

Enforcement is frequent and mostly B2C:

CompanyDateFactsAmount
TabcorpNotice dated 10 Apr 2026190 contraventions over 4 days in April 2025: email and SMS after consent was withdrawnA$1,254,000
TelstraMar 202510.4M texts with non-compliant unsubscribe; 43,228 sent without consentA$626,000 + enforceable undertaking
Gap in the record

We found no ACMA action against a B2B cold emailer or a sequencing platform. ACMA's targets are banks, telcos, retailers and gambling operators with consent and unsubscribe failures. Australia also has the Privacy Act (APP 7 on direct marketing), which we did not research in this pass.

New Zealand: Unsolicited Electronic Messages Act 2007

New Zealand's law follows the same design as Australia's. It is opt-in, with express, inferred and deemed consent, and deemed consent covers conspicuously published business addresses where the message relates to the recipient's role. Sender identification and a functional unsubscribe are mandatory. The Department of Internal Affairs (DIA) enforces it.

Not verified

We could not fetch the NZ statute or DIA guidance (legislation.govt.nz and nzlii blocked automated access). The maximum pecuniary penalty of NZ$500,000 for organisations (NZ$200,000 for individuals) and the deemed-consent wording are from prior knowledge, not verified here.

Singapore: Spam Control Act 2007

Singapore is opt-out for email. The Spam Control Act regulates unsolicited commercial messages sent in bulk. Bulk means more than 100 messages with the same or similar subject matter in 24 hours, more than 1,000 in 30 days, or more than 10,000 in a year. Unsubscribe requests must take effect within 10 business days. A cold sequence of a few hundred near-identical emails per day crosses the bulk threshold quickly, even with spintax (Spintax and message variants).

Not verified

The Act's labelling duty (an "" tag in the subject line), the required unsubscribe facility and the civil damages for recipients (commonly cited as S$25 per message, capped at S$1M) are from prior knowledge; the section we fetched did not include them. Singapore's PDPA Do Not Call registry covers phone numbers, not email. PDPA obligations on the collection of personal data still apply.

India: no email statute, DPDP arriving

India has no anti-spam law for email. TRAI's commercial-communication rules cover calls and SMS only. The change is the Digital Personal Data Protection Act 2023, which commences in phases: the Board and core provisions on 13 November 2025, parts of sections 6 and 27 on 13 November 2026, and the rest on 13 May 2027. The Data Protection Board acts as adjudicator.

DPDP is built around consent and a short list of "legitimate uses". It has no GDPR-style legitimate-interest basis. Once fully in force, processing a named individual's work email for prospecting will need consent or a defensible fit within those uses. That is a sharper constraint on India-sourced lead data than anything in force today.

Not verified

The maximum penalty of ₹250 crore (for security-safeguard failures, per the Act's Schedule) is widely reported but was not verified in this pass. The MeitY copy of the Act returned an error.

Brazil: LGPD and legitimate interest

Brazil has no federal anti-spam statute that we could confirm. Cold B2B email is governed by the LGPD, which, like GDPR, allows processing on "the legitimate interest of the data controller or a third party" unless it overrides the data subject's rights. The ANPD can fine up to 2% of a company's revenue in Brazil, capped at R$50 million per infraction. In practice that makes Brazil an opt-out market with GDPR-style documentation duties: a legitimate-interest assessment, a privacy notice, and honoured objections.

Japan: opt-in with a business-address exception

Japan's Act on Regulation of Transmission of Specified Electronic Mail has required prior opt-in consent for advertising email since its 2008 amendment, with display obligations for sender identity and opt-out. Article 3(1) lists exceptions, including email addresses that have been publicly disclosed. The Ministry of Internal Affairs and Communications describes these as addresses published for business purposes. Corporate fines reach ¥30 million, and individuals face up to one year's imprisonment for the most serious offences. The Ministry and the Consumer Affairs Agency enforce, supported by a spam consultation centre run by the Japan Data Communications Association.

Not verified

The exact scope of the business-publication exception (including whether a "no advertising" notice next to the published address removes it) and individual fine levels were not fully verified. Our fetches returned summaries, not the article text.

What this means for an entrant

  • Australia is the template for compliance-as-a-feature. Its four-part inferred-consent test maps one-to-one to fields a platform can capture: source URL, publication context, presence of a no-spam notice, and role relevance. Build the Australia check first, and the Canada (Canada: CASL) and Japan checks are variations of it.
  • Unsubscribe speed is what regulators fine. Tabcorp and Telstra were fined over opt-out failures, not over the idea of marketing. A cross-inbox, cross-workspace suppression service honoured in hours covers Australia's 5 working days, Singapore's and Canada's 10 business days, and the US rule in one build.
  • Singapore's bulk thresholds make volume a legal variable. Above 100 similar messages a day, the bulk rules apply. A volume sequencer selling into Singapore needs the labelling and unsubscribe defaults switchable per recipient country.
  • India is a 2027 cliff for data sellers. Platforms bundling lead databases (Built-in lead database, Contact data and enrichment) and Indian agencies scraping contacts face a consent regime with no legitimate-interest fallback. Watch the rules before building India-facing data features.
  • APAC is a buyer market more than a recipient market. These countries matter mostly because Australian and Indian agencies buy sequencers to email the US and UK. The law you need to get right for them is the recipient's: United States: CAN-SPAM and state email laws, UK: PECR and DUAA 2025.
9 sources cited on this page · 7 domains
  1. over A$16M in spam penalties in the 18 months to March 2025 acma.gov.au
  2. 13 May 2027 en.wikipedia.org
  3. Schedule 2, clause 4 legislation.gov.au
  4. 5 working days claytonutz.com
  5. A$1,254,000 acma.gov.au
  6. Spam Control Act sso.agc.gov.sg
  7. the legitimate interest of the data controller or a third party en.wikipedia.org
  8. publicly disclosed laws.e-gov.go.jp
  9. published for business purposes soumu.go.jp