The Unsolicited Electronic Messages Act 2007 governs commercial electronic messages sent to or from New Zealand — email, text, instant messaging. It is administered by the Department of Internal Affairs, and penalties for breach can be substantial.
The requirements are simple to state and routinely breached by businesses that consider themselves entirely legitimate.
The three requirements
Every commercial electronic message must:
- Be sent with consent — express, inferred or deemed.
- Clearly identify the sender and how to contact them.
- Include a functional unsubscribe facility, and unsubscribe requests must be honoured promptly.
All three apply. A message with perfect consent and no unsubscribe facility is still a breach.
The three kinds of consent
Express consent is where the person has actively agreed to receive messages — ticking a box that was not pre-ticked, signing up to a list, asking to be added. It is the strongest basis and the one to build on.
Inferred consent arises where consent can reasonably be inferred from the person’s conduct and their existing business relationship with you. An existing customer can generally be sent messages relevant to what they bought. It does not extend indefinitely, and it does not cover unrelated products.
Deemed consent applies where a person has conspicuously published their work address without a statement that they do not want to receive commercial messages, and the message is relevant to their work role. This is narrower than it sounds. Scraping addresses from a website and sending unrelated marketing does not qualify, because relevance to the person’s role is required.
Why bought lists are a problem
Purchasing a mailing list almost never gives you consent, because consent was given to someone else for their purposes, not to you.
The Act does not recognise transferred consent as a general matter, and a list vendor’s assurance that everyone opted in is not a defence you can rely on. If you cannot evidence the consent yourself, you do not have it.
There is also a Privacy Act dimension. The new IPP 3A, in force since 1 May 2026, requires notification where personal information is collected indirectly — which is exactly what buying a list is. So a bought list now creates two separate compliance problems rather than one.
Unsubscribe: the mechanics that get businesses in trouble
- It must work. Broken links are among the most common complaints.
- It must be free and simple. Requiring someone to log in, create an account or phone during business hours is not a functional facility.
- It must be honoured promptly — within a short statutory period, not at the next list refresh.
- It must apply across your systems. A person who unsubscribes from a marketing platform and then receives messages from a different system in the same business has not been unsubscribed.
Transactional messages — order confirmations, delivery notices, account statements — are treated differently from marketing. But a message that mixes transactional content with promotion is generally treated as commercial, so bundling a sale into a delivery notification brings it within the Act.
Address-harvesting software
The Act specifically prohibits using address-harvesting software or a harvested-address list to send unsolicited commercial messages. Scraping tools that build prospect lists from websites and social platforms sit directly in this prohibition.
Record keeping
The practical protection in a complaint is evidence of consent. Keep, for each contact:
- How consent was obtained — form, event, purchase, sign-up.
- When, with a timestamp.
- What they were told they were consenting to.
- The unsubscribe history.
Most reputable email platforms record this automatically. Businesses running lists out of spreadsheets generally cannot produce it.
Practical guidance
- Build your own list. It is slower and it is the only durable approach.
- Use double opt-in for new subscribers — it produces cleaner evidence and better engagement.
- Do not pre-tick consent boxes.
- Segment so that inferred consent is only used for genuinely related messaging.
- Test your unsubscribe link on every send.
- Suppress unsubscribes centrally, across every system that can send.
- Review your privacy statement to cover indirect collection following IPP 3A.
The Department of Internal Affairs publishes guidance on the Act and a complaints process at dia.govt.nz, and the Office of the Privacy Commissioner publishes guidance on the Privacy Act obligations that sit alongside it. Both are free.
General information only, not legal advice.








