← Back to blog

Booking Businesses: SMS Opt In Compliance That Survives an ACMA Audit

September 16, 2026
Booking Businesses: SMS Opt In Compliance That Survives an ACMA Audit

You must have consent before sending any commercial SMS, identify who you are in every message, and provide a working unsubscribe every single time. From 1 July 2026, unregistered branded sender IDs risk being blocked or flagged 'Unverified' according to ACMA requirements. Keep proof of consent and propagate every opt-out within five business days, or you're exposed to an ACMA investigation.


TL;DR:

  • Sending branded sender IDs will require registration with telcos or messaging providers before July 2026 to prevent being flagged as unverified or blocked.
  • Businesses must prove explicit consent with clear records, avoiding bundled or inferred consent without proof, especially for marketing messages.
  • SMS campaigns must include a working, free unsubscribe mechanism and clearly identify the sender in every message to comply with legal obligations.
  • Separating transactional and marketing messages and obtaining separate consent for each helps prevent accidental non-compliance.
  • Regularly testing and syncing suppression lists, along with building compliance into booking platforms, reduces operational gaps and long-term legal risks.

Animalbooking
Simplify Your Booking Operations
Animal Booking helps pet service providers manage bookings, payments, and customer interactions without relying on texts and spreadsheets.
Visit Animal Booking

Table of Contents

SMS opt-in compliance starts with one question: did the person actually agree to hear from you, in a way you can prove? The Spam Act recognises two forms of consent, and businesses conflate them constantly.

Express consent is explicit and unambiguous. The customer ticks a box, types a keyword, or verbally agrees while you record it. There's no guesswork involved.

Inferred consent is narrower than most marketers assume. It only applies when there's an existing relationship and the message relates directly to that relationship, such as a groomer texting an existing client about a service update. It does not extend to buying a list, scraping numbers off an invoice, or assuming silence means agreement. The Sinch compliance guide recommends treating inferred consent as a fallback, not a strategy.

Practical opt-in patterns that hold up:

  • A web form checkbox with plain wording: "I agree to receive booking reminders and offers by SMS."
  • A keyword flow (text JOIN to a number) with an immediate confirmation reply.
  • Face-to-face consent captured at the point of sale, logged in your system on the spot.

Patterns that get businesses in trouble:

  • Pre-ticked checkboxes or consent bundled into terms and conditions.
  • Asking for consent by sending an unsolicited SMS first (that message itself breaches the Act).
  • Treating a missed opt-out reply as ongoing permission.

Every commercial SMS in Australia rests on three pillars, and missing anyone of them is a breach. ACMA's guidance is blunt about it: you need consent, clear sender identification, and a functional unsubscribe mechanism, full stop.

Consent has to exist before you send, not after. Identification means the recipient can tell who you are without opening the message, ideally your business name in the sender field or the first line of text. Unsubscribe means a free, working opt-out that doesn't require a phone call, a login, or a reply to a dead number.

Quick reference: unsubscribe requests must be honoured promptly, typically within a few business days as required by regulation, and the opt-out mechanism itself must keep working for at least 30 days after a campaign send, per Business guidance on commercial electronic messages.

Here's what trips people up:

  • Reply STOP is the industry norm, but it only works if your platform actually processes it automatically rather than routing to a shared inbox nobody checks.
  • You cannot charge for opting out, and you cannot make someone jump through steps (calling a support line, filling in a form) to stop messages.
  • Sender identification needs to stay accurate after the send too. If your business rebrands or changes numbers, update the identification string before the next campaign, not after a complaint.
  • Do Not Call Register applies to voice telemarketing, not SMS. Businesses regularly assume DNC coverage protects them from SMS obligations, and it doesn't. SMS marketing sits entirely under the Spam Act.

Treat these three requirements as gates, not guidelines. If any one fails, the message is non-compliant regardless of how good your intentions were.

Consent that you can't prove is functionally the same as no consent, at least from an audit standpoint. Build your sign-up flow and recordkeeping around that reality.

  1. Write plain-language consent copy. State exactly what the person is agreeing to (reminders, promotions, both) and how often they'll hear from you.
  2. Use separate checkboxes for transactional and marketing consent. Never bundle them into one tick.
  3. Never collect consent by SMS itself. The request has to happen through a channel the person already engaged with (web form, POS, app).
  4. Log four data points per contact: timestamp, channel, the exact wording they saw, and a source identifier such as a form ID or campaign ID.
  5. Store this in a CRM or messaging platform, not a spreadsheet. Platform logs with backups hold up far better under scrutiny than a CSV someone edited manually last Tuesday.
  6. Sync suppression lists across every system that can send a message, so an opt-out in one tool actually blocks sends from another.

Consent also intersects with privacy law. Collecting and storing phone numbers for marketing purposes triggers obligations under the Privacy Act and Australian Privacy Principles, on top of the Spam Act's rules. Retention policies matter here too: keep consent records for as long as you're sending to that contact, plus a buffer after they leave your list.

Pro Tip: Test your own suppression system quarterly. Opt yourself out through every channel you offer, then check whether a message from a different system still lands in your inbox five business days later. If it does, you've found your weakest link before ACMA does.

Sender ID register and sending options: numbers vs alphanumeric IDs

From 1 July 2026, branded alphanumeric sender IDs must be registered through participating telcos or messaging providers, or they risk being labelled 'Unverified' or blocked outright, according to the MobileDigital ACMA guide. If your business name currently appears as the sender, this change directly affects deliverability.

Registration typically takes some time through telcos and providers, so leaving it until shortly before a campaign risks being blocked.

Your practical options:

  • Dedicated two-way number: better for genuine conversation, reply handling, and keyword opt-ins, though it carries per-message costs and character limits.
  • Registered alphanumeric ID: stronger for brand recognition in one-way broadcasts like appointment reminders, but useless if you need two-way replies for STOP handling.

Whichever you choose, put your business name in the message body itself, not just the sender field, and test the full reply path before launch, not after your first complaint.

Transactional vs marketing messages: why the line matters

A booking confirmation and a promotional discount code are not the same category of message, and treating them as interchangeable is one of the fastest ways to invalidate consent.

Transactional messages relate directly to a service the customer already booked: appointment reminders, confirmations, payment receipts. Marketing messages promote something new: discounts, referral offers, seasonal campaigns.

Consent for one doesn't cover the other. A customer who agreed to receive a reminder for their dog's grooming appointment hasn't agreed to receive a promotional blast about your new loyalty program. Sending marketing content to a transactional-only list is exactly the kind of cross-use that generates complaints and, eventually, enforcement attention.

Control it with:

  • Separate consent flags per message type, stored against the contact record.
  • Distinct lists for transactional and marketing sends, never merged.
  • A pre-send check that confirms the campaign type matches the list's consent scope.

Common compliance failures and how to fix them fast

Most SMS breaches aren't malicious. They're operational gaps that nobody noticed until a customer complained.

ACMA enforcement has produced multi-million dollar penalties in cases involving missing consent, unclear sender identification, or broken unsubscribe paths, according to industry reporting. Enforcement is frequently triggered by a single complaint about a STOP request that didn't work.

The pattern repeats across failures:

  • Unsubscribe links or STOP replies that go nowhere, often because a platform migration broke the automation.
  • Bundled consent buried in terms and conditions rather than a standalone opt-in.
  • Suppression lists that update in one system but never sync to the messaging platform actually sending the texts.
  • Marketing content disguised as a service update to dodge marketing consent rules.

If you find one of these in your own setup, the fix order matters: audit your current lists first, pause sends to any contact with contested or unclear consent, repair the suppression sync, and then notify affected contacts if the breach was significant enough to warrant it.

How booking platforms build compliant SMS into everyday operations

Booking platforms sit in an unusual spot: nearly every message they send starts life as transactional (a confirmation, a reminder) and then someone wants to layer marketing on top. The approach treats transactional and marketing messages as separate systems from the start, not a setting you toggle later.

Consent gets captured at the point of booking with plain-language wording, and the timestamp, source, and exact opt-in text get logged automatically rather than left to someone's memory. Reminder sequences stay walled off from promotional campaigns, so a client who booked a grooming appointment doesn't end up on a discount blast they never agreed to.

Booking platform SMS compliance workflow

Pro Tip: If you're building or auditing a booking system's messaging, check whether your reminder tool and your marketing tool can even see each other's suppression lists. If they can't, you have a compliance gap regardless of how good either tool is individually.

Perspective: fix the system, not just the wording

Most SMS compliance advice focuses on copy, on getting the opt-in checkbox wording right. That's necessary but nowhere near sufficient. Consent is perishable. It decays the moment your suppression lists stop talking to each other, and no amount of well-worded consent language fixes a broken sync between your CRM and your messaging platform.

The businesses that stay compliant long-term don't rely on a one-time legal review. They test their own opt-out paths quarterly, treat consent metadata as a living record rather than a form submission you file away, and build monitoring into their release process so a platform update can't silently break the STOP flow. Compliance that depends on nobody touching the system is not compliance. It's luck with a deadline.

— AnimalBooking

A practical option for compliant booking reminders

Some booking platforms give pet service businesses a faster path to the checklist this article just laid out, instead of stitching together a CRM, a reminder tool, and a spreadsheet of opt-outs by hand. Consent can be captured at the booking step, metadata can be stored automatically, and transactional reminders can stay separated from marketing activity so one never contaminates the other.

Animalbooking

Setup takes minutes rather than weeks, and the automated reminder system handles suppression without needing a developer to wire two platforms together. If you're a groomer, boarder, vet, or mobile pet business trying to match your messaging against every item on this checklist, start with online booking set up to capture consent the moment a client books, and go from there.

Official guidance and industry resources to consult

For the legal detail behind every claim in this article, go straight to the source. ACMA's spam guidance covers consent, identification, and unsubscribe obligations directly. business.gov.au offers a practical summary aimed at small business owners. For sender ID registration specifics and enforcement trends, the MobileDigital ACMA guide and the Sinch compliance guide go deeper on operational detail. Check publication dates before relying on any guide, and get legal advice for anything involving multiple jurisdictions or unusual consent scenarios.

Sources

FAQ

What does SMS opt-in mean?

SMS opt-in is a customer's explicit or narrowly inferred agreement to receive text messages from a business, captured before any commercial message is sent. It must be provable through records like timestamps and the exact wording the customer saw.

What is SMS compliance?

SMS compliance means meeting the Spam Act's three core requirements: obtaining consent before sending, clearly identifying your business in every message, and providing a working, free unsubscribe option. From 1 July 2026, it also means registering branded sender IDs.

What is a good SMS opt-out rate?

There's no single benchmark stated in regulatory guidance, but a sudden spike in opt-outs usually signals a messaging or frequency problem worth investigating immediately, since ACMA enforcement is often triggered by complaints about failed opt-out attempts.

Do employees have to opt-in for text messages?

Internal workplace texts about rosters or operational matters generally fall outside the Spam Act's commercial message rules, but any promotional or marketing content sent to staff still requires the same consent standards as customer messaging.

No. Consent is scoped to what the customer actually agreed to, so a transactional booking reminder opt-in doesn't extend to promotional content. Some platforms keep these consent types and lists separate to avoid cross-use.