Your CRM program is probably working: open rates look fine, revenue is flowing, nobody’s complained. But “nobody’s complained yet” and “compliant” aren’t the same thing, and that’s where brands get burned.
Most compliance errors aren’t intentional. They stem from a missing filter, a mislabeled segment, or an unchecked suppression setting. Small gaps compound into real exposure under Australia’s Spam Act and Privacy Act, plus a dent in deliverability and trust.
Why compliance is a bigger deal than it looks
Email compliance is the foundation your CRM channel sits on. Getting it wrong risks more than a fine: sender reputation, inbox placement, and opted-in customers’ goodwill.
- Spam Act 2003 (Australia): ACMA has moved from reminders to active enforcement. Commonwealth Bank paid $7.5 million in 2024 for sending 170 million+ marketing messages without a working unsubscribe option, over 34 million without consent. Kogan ($310,800) and Latitude Finance (nearly $1.55 million) faced similar fines.
- Privacy Act (Australia): since the 2022 reforms, serious or repeated breaches can draw penalties of up to $50 million, 3x the benefit gained, or 30% of adjusted turnover.
The Spam Act requires express or inferred consent, a functional unsubscribe option, and opt-outs actioned within 5 business days. Reach the US, Canada, or the EU, and each region adds its own consent rules, so a locally compliant segment can still breach rules abroad.
The mistake hiding in plain sight: missing consent filters
Every major CRM platform has a consent filter, and every platform lets you build a segment without it: Klaviyo’s “because they subscribed,” Mailchimp’s marketing permissions field, Dotdigital’s channel-specific subscription status, Emarsys’s Opt-in field. Whatever the terminology used is, it confirms active opt-in, not just database existence as a customer. We’ve flagged this with multiple brands with accomplished in-house CRM teams and it’s a visibility problem, not a skill one.
These gaps creep in as programs evolve: a duplicated segment loses its consent condition, or a platform migration leaves historical records without marketing permissions. Campaigns keep sending successfully, so gaps go unnoticed for months.
Platforms won’t stop a technically valid but non-compliant send, so the consent filter isn’t optional, it’s the foundation of every segment.
Other compliance errors brands don’t realise they’re making
Missing consent filters get the headlines, but they’re rarely the only issue. At Pattern, we audit a brand’s entire CRM function from how the customers are acquired, how personal, and transactional information is gathered, stored and used, database performance and retention metrics. These are the key challenges we see often:
- List-level suppression instead of global suppression. A customer unsubscribes from one list but keeps receiving another.
Recommendation: set suppression at the account level, not the list level, so one unsubscribe blocks every future send. - Pre-ticked opt-in boxes or bundled consent. A pre-ticked checkout box, or a checkbox bundling a loyalty program with marketing emails, fails the “voluntary, specific, unambiguous” bar the Privacy Act reforms now enforce.
Recommendation: use unticked, single-purpose checkboxes for each consent type, and log the timestamp and source of every opt-in. - Slow unsubscribe processing. A delayed sync can mean one email too many after opting out.
Recommendation: sync suppression across every connected platform in real time, or at minimum daily, well inside the 5-business-day window. - Purchased or merged third-party lists. If contacts never opted in to your brand specifically, sending to them is a violation, not a grey area.
Recommendation: run a consent check before importing any acquired or third-party list, and exclude anyone without documented opt-in specific to your brand. - Ignoring regional consent rules. A segment that’s fully compliant in Australia can become a violation the moment it crosses into the US, Canada, or the EU.
Recommendation: segment subscribers by country or region and apply the appropriate consent rules for each audience - Complicated unsubscribe process. The Spam Act just requires a free, low-friction unsubscribe that keeps working for 30 days, no login, no extra steps. Gmail and Yahoo go further: bulk senders must let people unsubscribe instantly, with no confirmation step, or risk the spam folder.
Recommendation: Review your unsubscribe experience to ensure it requires no login or additional steps, and supports List-Unsubscribe and List-Unsubscribe-Post headers to meet Gmail and Yahoo bulk sender requirements.
Why a CRM audit is the fastest way to find these gaps
None of these errors show up on your campaign dashboard, where open rates and revenue can look healthy while a compliance gap sits underneath, waiting to surface as a complaint or suppression spike.
Pattern’s CRM compliance audit checks what you don’t see day to day: segment logic, suppression configuration, consent properties, and flow triggers, benchmarked against our CRM Maturity Scorecard. Built from auditing top-tier Australian retailers across 100+ checkpoints in acquisition, engagement, retention, segmentation, and platform hygiene, it produces a prioritised Optimisation Plan.
Ready to see what’s hiding in your CRM program?
Pattern’s CRM compliance audit exposes hidden compliance risks and also surfaces the segmentation, suppression and flow issues quietly capping your revenue. Fixing them protects the program and grows it. You walk away with a prioritised optimisation plan that closes compliance risk and flags quick-win and longer-term revenue opportunities.
Get a clear picture of where your CRM program stands, on compliance and on revenue, in one audit. Contact us now.
Frequently Asked Questions
It confirms a profile actively consented to email marketing, rather than just existing in your customer or order data. Segments built without it can include people who never opted in.
Yes. Unsubscribing suppresses marketing sends, but transactional emails like order confirmations and password resets are tied to a purchase or account action, not marketing consent.
More than most brands budget for, and the fines are just the start. Commonwealth Bank paid $7.5 million in 2024, and serious Privacy Act breaches can draw penalties up to $50 million or 30% of turnover. Overseas customers add CAN-SPAM, CASL, and GDPR penalties. Beyond fines, non-consented sends wreck your sender reputation program-wide.


