DxtraBETA
Back to blog
Use CasesAustraliaSmall Business July 2026 6 min read

My friend gave the roastery her email. A stranger sent the ad.

You give a small roastery your email for their updates — and a stranger's ad turns up. Sharing a mailing list is the fastest way to burn customer trust. Here's how Australia's Privacy Act and Spam Act actually see it, and how to run a list you'd be proud of.

Daryl ArnoldDaryl Arnold
A French press, a bag of single-origin coffee beans, and a phone showing a signup form on a warm cafe counter.

A friend of mine in Melbourne is serious about her coffee. A while back she found a small artisan roastery — one of those passionate, independent places that roasts in tiny batches and can tell you which farm the beans came from — and bought two single-origins for her French press. At the counter they asked if she would like to join the mailing list for bean updates and new releases. Of course she would; that is exactly the kind of small business you want to hear from. She filled in a Google Form with her name and email. No notice about what they would do with it, no privacy link, no "we might share this." Just a form.

A week later, an email landed in her inbox. Not from the roastery — from a premium coffee-machine company she had heard of but never contacted. A polished marketing email, out of nowhere. She had given her details to exactly one new place recently, and as far as she could tell there was only one way that company could have got her address.

She was not furious. She was disappointed. She told me about it over WhatsApp, and it stuck with me — because it is so avoidable, and because that feeling is the whole point of this piece.

Why it stings

Here is the deal a mailing list actually represents. When someone gives a small business their email, the two of you make a quiet promise: I'll let you into my inbox, you'll use it for what you said — and you won't hand it to strangers. It is a small act of trust, and for an independent shop it is a precious one, because trust is most of what you have that the big chains do not.

When that list gets shared — even with a "relevant" partner, even with the best intentions — the promise breaks. And the real cost is not legal. It is that my friend will think twice before signing up to the next little place she loves, and might not come back to this one. That is the trust tax, and customers notice it even when they cannot name the rule involved.

What actually went wrong here

Three things went sideways, and they map neatly onto how Australia's rules see it — not as a headline, but as backup for an instinct you already have.

No collection notice at signup. When you collect someone's email, the fair thing — and, under the Australian Privacy Principles, APP 5 — is to tell them right there who you are, what you will use it for, and whether it will be shared. A bare Google Form with none of that is the gap. Even a business not strictly bound today should do it, because it is simply how you keep the promise.

Passing the list to someone else's marketing. Using or disclosing personal information for direct marketing a person would not reasonably expect generally needs their consent (APP 6 and APP 7) — and disclosing someone's email to another company so that company can market to them (APP 7.3) is exactly the thing you have to ask about first. Nobody signing up for bean updates reasonably expects a coffee-machine supplier to email them.

The stranger's email itself. That message from a company my friend never dealt with runs into the Spam Act 2003, which says a marketing email needs the recipient's consent, must identify the sender, and must carry a working unsubscribe. And here is the part every small operator should know: the Spam Act has no small-business exemption. It binds every sender — the coffee-machine giant and the tiny roastery alike — for their own emails too.

The "we're too small" myth, busted three ways

Which brings us to the comfortable belief I hear constantly: we're too small for privacy law. It is worth taking apart, because it is precisely what lets a list get shared without a second thought.

Australia does have a small-business exemption in the Privacy Act — broadly, businesses under about A$3 million turnover. But lean on it and it lets you down in three places.

  1. It does not cover trading in data. The exemption falls away for a business that discloses personal information about someone to another party for a benefit (Privacy Act s.6D). The moment a roastery passes its list to a supplier in exchange for anything, the shield it was counting on may simply not be there.
  2. It is on the way out. Removing the small-business exemption is a proposed next stage of Australia's privacy reforms, and the government supports it — it is not law yet, and there is no settled start date, but sector-by-sector changes are already drawing some small businesses into privacy obligations, and the direction of travel is not subtle. Building your habits around an exemption that is actively being wound back is not a plan. (This area is moving through 2026 — worth checking where it stands when you read this.)
  3. The Spam Act never cared how small you are. As above — it applies to everyone, always.

Put those together and the "too small" comfort blanket is thinnest exactly where it matters: the moment you share a list.

The honest picture

Let me keep this proportionate, because scare stories are not the point. No regulator is coming for a roastery over one shared mailing list. (Australia can impose serious penalties for grave or repeated breaches — up to the greater of A$50 million, three times the benefit gained, or 30% of turnover — but that is aimed at the far end of misconduct, not a café.) The real stake is the one my friend felt: trust. The businesses people stay loyal to are the ones that treat their details with respect. Privacy-first, here, is just trust-first wearing a lanyard.

How to run a mailing list you'd be proud of

The fix is small and entirely within reach.

Put a proper collection notice and consent on the signup. Google Form, a card at the counter, or a tablet by the till — whatever you use, say who you are, what the list is for, and that you will not share it, and let people agree to that. Dxtra generates the privacy notice, the point-of-collection line, and the consent for you, and gives you a QR code you can put right on the counter or the signup card — ideal for a shop that lives at a counter, not a website. A customer scans, reads, opts in, and you have a record.

Never share the list without asking first. If a partner would genuinely be useful to your customers, tell your customers and let them opt in. Do not decide on their behalf.

Keep a working unsubscribe on every email. It is courtesy, and it is the law.

That is the afternoon's work, and it buys the thing the big chains struggle to earn: customers who trust you with their inbox because you have never once made them regret it.

Give your signup a proper privacy notice and consent — shareable by QR code → Dxtra generates all of it, hands you the QR code and short link, and you review everything before it goes live. From $10 a month (about A$14). If you also run a website, a free Dxtra scan will show you what else is quietly exposed.

My friend still loves good coffee. She just signs up more carefully now — which is a small loss for every lovely little roastery that would never have shared her details in the first place. Do not be the reason a good customer learns to be careful.


This article is for general information and is not legal advice. Privacy and spam obligations depend on your circumstances and are changing in Australia through 2026 — confirm anything that matters with the OAIC (oaic.gov.au), the ACMA (acma.gov.au), or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.