Do not call Australia rules: what the law actually requires
Learn how Australia's Do Not Call rules protect you from unwanted telemarketing. Understand what to expect and your rights regarding calls.
Australia’s Do Not Call Register lets people opt out of most unsolicited telemarketing calls and marketing faxes. Telemarketers must check the Register before dialling and follow strict Australian Communications and Media Authority (ACMA) industry standards, or they risk enforcement action.
The rules sit in the Do Not Call Register Act 2006, with ACMA as the regulator that administers the Register and polices breaches. Registration cuts down most telemarketing calls, but it doesn’t eliminate them entirely. Charities, political parties, and callers who have your express consent can still legally ring you.
Here’s what that means in practice:
- The Register covers voice calls and marketing faxes to personal and fax numbers, not business lines.
- Exempt organisations and consented callers can still contact you even after you register.
- Breaching the standards can trigger infringement notices, court undertakings, or prosecution.
Key Takeaways
Compliance with Australia’s Do Not Call Register depends on checking lists against the Register, respecting industry standards on timing and identification, and documenting consent properly.
| Point | Details |
|---|---|
| Legal basis is clear | The Do Not Call Register Act 2006 and ACMA jointly set and enforce the rules for telemarketing and marketing faxes. |
| Registration isn’t total protection | Exemptions and consent mean some legal calls will still get through even after registering. |
| Calling hours are strict | The Telemarketing Industry Standard 2017 sets permitted hours based on the recipient’s local time. |
| List washing is ongoing | Businesses must wash calling lists before every campaign and keep vendor washing receipts on file. |
| Enforcement carries real teeth | ACMA has issued six-figure infringement notices for telemarketing and spam breaches. |
| Automation supports, not replaces, compliance | Platforms like Conversational AI can automate list washing and consent logging on Australia-hosted infrastructure, alongside human compliance oversight. |
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Table of Contents
- What is the Do Not Call Australia rules framework?
- Who’s exempt from Do Not Call Australia rules?
- When can telemarketers legally call you?
- Running a compliant call list: what businesses must do
- What happens if you breach the rules?
- How to register, check a number, or complain
- Reduce unwanted calls: what you can do this week
- Where enterprise automation fits into compliance
- Why data sovereignty matters for regulated callers
- Keeping your outbound program compliant with Conversational AI
- Sources
What is the Do Not Call Australia rules framework?
The Do Not Call Register Act 2006 draws a clear line between telemarketing, research calls, and legitimate non-marketing contact. Telemarketing means calling to sell or promote goods, services, or an interest in property. Research calls (market or opinion research) sit under a separate but related standard, while marketing faxes get their own rules under the Fax Marketing Industry Standard 2021.
Not everything that rings your phone counts as telemarketing. Appointment reminders from your dentist, product recall notices, and debt collection calls tied to an existing account all sit outside the Act’s prohibition, because they’re not selling you something new.
Eligibility for the Register itself is narrower than most people assume:
- Personal numbers – home phones and mobiles can be registered.
- Fax numbers – eligible where used primarily for private or domestic purposes.
- Business numbers – generally ineligible, which surprises a lot of small business owners who try to register their landline.
ACMA administers the whole system, from registration through to compliance checks against telemarketers’ calling lists.
Who’s exempt from Do Not Call Australia rules?
A surprising number of callers are legally allowed to dial numbers on the Register. Charities, political parties and candidates, government bodies, educational institutions, and genuine researchers all fall under recognised exemptions. So does anyone who has your express consent to call.
Consent comes in two flavours, and the difference matters as shown in call recording consent laws for U.S. businesses.
- Express consent – you’ve actively agreed, in writing or verbally, to be contacted about a specific product or service.
- Inferred consent – arises from an existing relationship, such as a recent purchase or an ongoing account, but it isn’t indefinite and can be withdrawn at any time.
Here’s the part callers often gloss over: being exempt from the Register doesn’t mean being exempt from the industry standards. A charity can legally call a registered number, but it still has to follow the same calling-hours and identification rules as everyone else.
When can telemarketers legally call you?
The Telemarketing Industry Standard 2017 sets calling windows based on the recipient’s local time, not the caller’s.
Pro Tip: If a telemarketer rings outside these windows, that alone is a standards breach you can report to ACMA, even if the call content itself is otherwise compliant.
Permitted times generally run on weekdays and Saturdays, with calls barred on Sundays and public holidays. Beyond timing, callers must:
- Display a working calling line identification (CLI) number, not a blocked or “private” one.
- Keep that number contactable for at least 30 days after the call, per the ACMA’s own guidance on industry standards.
- State who they’re calling on behalf of and the purpose of the call early in the conversation.
- End the call immediately if you ask them to.
That last point isn’t optional courtesy. ACCC guidance confirms you have an absolute right to end a telemarketing call on the spot, regardless of any consent you gave earlier. Exempt callers, including charities and political parties, must meet every one of these same standards.
Running a compliant call list: what businesses must do
If your business calls Australian numbers, “list washing” isn’t a suggestion, it’s an operational necessity. Washing means checking your calling list against the Register before every campaign, not just once when you build it.
Here’s a practical sequence for keeping your program clean:
- Wash your list against the Register immediately before each calling campaign begins, not weeks in advance.
- Record express consent properly — capture the date, method, and scope of what the person agreed to.
- Treat consent as time-limited. The ACMA’s own industry guide points to roughly three months as a sensible refresh point for consent records.
- Get washing receipts from any vendor you outsource calling to, and put that requirement in the contract.
- Verify CLI display on outbound systems before a campaign goes live, so calls aren’t accidentally sent as blocked numbers.
- Log complaints and act on them fast, feeding patterns back into your suppression lists.
Pro Tip: Outsourcing your telemarketing doesn’t outsource your liability. The ACMA industry guide is explicit that the business commissioning the calls remains responsible for compliance, even when a third party dials the phone.
What happens if you breach the rules?
ACMA doesn’t just issue warnings and move on. Its enforcement toolkit includes infringement notices, court-enforceable undertakings, and, for serious or repeated breaches, prosecution.
Real enforcement history backs this up. ACMA’s own compliance and breaches page documents organisations, including retailers and financial services firms, that have faced six-figure infringement notices for telemarketing and spam breaches.
If your business has been contacted by ACMA about a possible breach, that’s the point to bring in legal or compliance counsel, not after a notice has already landed. Key enforcement facts to remember:
- Infringement notices can be issued without a court process.
- Court-enforceable undertakings often require public reporting on remediation steps.
- Repeated or wilful breaches escalate toward prosecution.
How to register, check a number, or complain
Getting on the Register takes minutes; seeing the results takes longer.
- Register online at the Do Not Call Register website, or by phone. It’s free, and covers eligible personal and fax numbers.
- Wait up to 30 days. ACMA is upfront that registration can take that long to meaningfully reduce calls, and that some calls will still get through legally due to exemptions and consent.
- Lodge a complaint if calls continue past that window and don’t fall under a known exemption. Include the call date and time, the number that displayed (or lack of CLI), and what the caller said.
Reduce unwanted calls: what you can do this week
Registering is step one, not the whole solution. Layer these on top:
- Register every eligible personal and fax number, then turn on your phone’s built-in call-blocking and your carrier’s spam-filtering features.
- Never hand over personal or financial details to a caller you didn’t initiate contact with, no matter how legitimate they sound.
- Withdraw consent in writing if you’ve previously agreed to be contacted and want that to stop.
Pro Tip: Suspected scam calls belong with Scamwatch, while persistent illegal telemarketing (wrong hours, no CLI, ignoring stop requests) belongs with ACMA. Reporting to the right body speeds up action considerably.
Where enterprise automation fits into compliance
For businesses running high call volumes, manually washing lists and tracking consent expiry doesn’t scale well. Australia-hosted automation platforms can handle scheduled list washing, centralised consent logging, and CLI management as built-in workflow steps.
- Automated wash schedules reduce the human error that causes accidental breaches.
- Centralised consent records make audit requests from ACMA far less painful.
- None of this replaces legal judgement. A platform can enforce a rule; it can’t interpret a grey-area exemption for you.
Why data sovereignty matters for regulated callers
Regulated sectors, think finance, healthcare, and insurance, carry compliance obligations that stack beyond the Do Not Call Register itself. Keeping consent records and call logs on Australian-hosted infrastructure makes audit trails simpler to produce when ACMA or a client comes asking. Technical teams weighing up their options are welcome to get in touch for a walkthrough of how that works in practice.
— Sowrabh
Keeping your outbound program compliant with Conversational AI
Conversational AI is built for exactly this problem: businesses that need outbound calling, SMS, and follow-up workflows to stay compliant without a compliance officer manually checking every list. Because the platform runs on Australia-hosted private cloud infrastructure, consent records, call logs, and CLI settings stay under your control rather than sitting on servers offshore.

The platform’s outbound campaign management lets you schedule list washing against the Register, log express consent against a timestamp, and keep calling line identification consistent across voice, SMS, and email channels, all from one system that plugs into your existing CRM. It doesn’t replace legal advice or a proper compliance review, but it does remove a lot of the manual risk that trips businesses up during an ACMA audit. If your team is managing outbound calls or messages at any real volume, it’s worth reviewing how Conversational AI’s platform handles consent and list management before your next campaign goes out.
Sources
- Compliance and breaches - Do Not Call Register (ACMA)
- Do Not Call Register Act 2006 - Federal Register of Legislation
- Telemarketing and door-to-door sales - ACCC
Recommended
- Sovereign AI in Australia: the enterprise compliance guide - Conversational AI
- Prevent data offshore transfers: AI compliance guide for privacy teams - Conversational AI
- What is outbound voice automation? A guide for professionals - Conversational AI
- Data breach consequences: real examples and what to do - Conversational AI