Business

Is Cold Emailing Legal in New Zealand? The Unsolicited Electronic Messages Act Explained

Cold email is legal in New Zealand under three conditions. Here are the consent, identification and unsubscribe rules from the Act, in plain English.

Jason Poonia Jason Poonia | | 14 min read
Is Cold Emailing Legal in New Zealand? The Unsolicited Electronic Messages Act Explained

Yes, cold emailing is legal in New Zealand. The Unsolicited Electronic Messages Act 2007 allows it as long as three conditions hold: you have consent of some kind, the message clearly identifies who sent it, and it carries a working unsubscribe. Miss any one of those and the message is unlawful, even if only one person received it.

Key Takeaways

  • The Act bans unsolicited commercial electronic messages, not cold email itself, and “unsolicited” has a legal definition that includes deemed consent for business addresses published in public.
  • Deemed consent applies only when an address was conspicuously published in a business capacity, carries no notice refusing unsolicited messages, and your message is relevant to that person’s business, role, functions or duties. All three, not any one.
  • Under section 9(3) the sender carries the onus of proof on consent. If you cannot show where the address came from and why the message was relevant, you lose that argument.
  • Sections 10 and 11 apply to every commercial message regardless of consent: accurate sender identification, contact details valid for at least 30 days, and a free unsubscribe functional for at least 30 days.
  • An unsubscribe takes legal effect 5 working days after it is used, so a suppression list that syncs weekly is not good enough.
  • The Department of Internal Affairs enforces it, and the court can order pecuniary penalties up to $200,000 against an individual and $500,000 against an organisation.

Most of what gets written about cold email compliance in New Zealand is a rewrite of an American CAN-SPAM article with the currency symbol changed. That matters, because CAN-SPAM is an opt-out regime and ours is not. In the United States you may email a stranger until they ask you to stop. Here, you need to be able to point to consent that already existed when you pressed send.

I have read a lot of outbound advice that treats a scraped list of info@ addresses as fair game because the address is public. That reading is wrong, and the part of the Act people lean on to justify it says something narrower than they think.

What Counts as a Commercial Electronic Message

Section 6 defines a commercial electronic message as one that markets or promotes goods, services, land, an interest in land, or a business or investment opportunity. It also captures a message that “provides a link, or directs a recipient, to a message” doing any of those things.

That last clause catches people. The Department of Internal Affairs spells out the consequence in its spam law guidance for businesses: “providing a hyperlink to a company web page in the signature of an otherwise non-commercial email would make it a commercial electronic message.” Your signature can convert a friendly introduction into a regulated commercial message.

Two other points. The DIA states plainly that “a single message may be spam”, so there is no bulk threshold to hide behind. And the Act applies to messages with a New Zealand link, which under section 4(2) includes messages originating here, not only messages received here. A Kiwi agency emailing Australian prospects is still inside the Act.

Section 9(1) says a person must not send an unsolicited commercial electronic message with a New Zealand link. Section 4 then defines “consented to receiving” in three forms.

Express consent. Someone ticked the box or filled in the form. The cleanest kind, and the easiest to evidence.

Inferred consent. Consent “that can reasonably be inferred from the conduct and the business and other relationships of the persons concerned”. An existing supplier, a current client, an active commercial relationship. Not a stranger who has never heard of you.

Deemed consent. This is the one that outbound sequences are built on, and it is worth reading in full. The Act deems consent to have been given when all of the following apply:

  • “an electronic address has been conspicuously published by a person in a business or official capacity”, and
  • “the publication of the address is not accompanied by a statement to the effect that the relevant electronic address-holder does not want to receive unsolicited electronic messages at that electronic address”, and
  • “the message sent to that address is relevant to the business, role, functions, or duties of the person in a business or official capacity”.

Three conditions joined by “and”. The outbound industry tends to treat the first one as the whole test. It is not. The relevance condition is a real constraint on what you are allowed to say, not a formality.

In practice, a generic pitch blasted to every info@ address in a scraped list fails the relevance test for most of that list, because the message was not written with any particular business, role or duty in mind. A message to a named operations manager about a problem you can demonstrate in their own booking flow is far stronger, because relevance is visible in the message itself.

Then there is section 9(3): “A person who contends that a recipient consented to receiving a commercial electronic message has the onus of proof in relation to that matter.” You are not presumed compliant. If the DIA asks, you produce the source of the address, the date, the page it was published on, and why the message was relevant to that person’s role. If your list came from a data vendor and you cannot answer those questions, you are carrying a risk you have not priced.

Our honest position, after building outbound for our own lead generation: deemed consent is a narrow permission for relevant, targeted, business-to-business messages, and it is being used to justify volume it was never written for. Volume has its own limits, which we go through in how many cold emails you can send a day before you land in spam.

Rule 2: The Message Has to Say Who Sent It

Section 10 applies to every commercial electronic message with a New Zealand link, consent or not. The message must clearly and accurately identify the person who authorised it, include accurate information about how the recipient can readily contact that person, and keep that contact information “reasonably likely to be valid for at least 30 days after the message is sent”.

Three common outbound habits sit badly against this. A throwaway lookalike domain you plan to burn in six weeks puts the 30-day validity of your contact details in doubt. A first name only, with no company name and no phone or postal contact, does not clearly identify who authorised the message. And a persona who does not exist fails the “accurately identifies” test outright.

Section 17 is the related trap for anyone outsourcing. If person A sends a message on behalf of person B, person B is taken to authorise it. Hiring an offshore appointment-setting agency does not move the obligation off your business. You are the one who has to be identified, and the one on the hook.

Rule 3: The Unsubscribe Has to Actually Work

Section 11 requires the unsubscribe facility to let the recipient tell the sender to stop, be “expressed and presented in a clear and conspicuous manner”, allow a response “using the same method of communication that was used to send the principal message”, cost the recipient nothing, and be “reasonably likely to be functional and valid for at least 30 days after the principal message is sent”.

For a plain-text cold email, “reply with unsubscribe and I will take you off the list” satisfies the same-method requirement, provided you honour it and the inbox stays monitored for at least 30 days. A one-click link works too. A preference centre that demands an account login does not, and neither does an unsubscribe pointing at a mailbox you abandon when you rotate domains.

Section 9(2) is the operational detail most sequences get wrong: once a recipient uses the unsubscribe facility, consent is “deemed to have been withdrawn with effect from the day that is 5 working days after the day on which the unsubscribe facility was used”. Five working days is the outer limit, not a target. If you send every three days and your suppression list syncs on Mondays, you can breach the Act while believing you processed the request.

What the Act Does Not Cover

Section 6(b) carves out messages that are not commercial electronic messages, even from a business: a quote or estimate the recipient asked for, a message that facilitates, completes or confirms a transaction they already agreed to, warranty or product recall or safety information about goods they bought, factual information about a subscription or account or loan they hold, information directly related to an employment relationship or benefit plan they are in, and delivery of goods or services they are entitled to receive.

These exemptions cover the message, not the sender, and the DIA’s hyperlink point applies here too. A transactional email is exempt right up until you bolt a promotion onto it.

Scraped Lists and Address-Harvesting Software

Section 13 prohibits using address-harvesting software or a harvested-address list in connection with, or with the intention of, sending unsolicited commercial messages in breach of section 9. Section 4 defines that software as software capable of, or marketed for use for, searching the internet for electronic addresses and collecting, compiling, capturing or otherwise harvesting them. That description fits a good portion of the tooling sold to outbound teams.

Section 14 puts the onus of proof on you again: if you contend your use of a harvested list was not connected to unlawful sending, you have to prove it. Buying the list from someone else does not clean it, because the definition turns on how the addresses were produced, not who sold them.

What It Costs if You Get It Wrong

Enforcement sits with the Department of Internal Affairs, whose guidance states that “failure to comply could mean a fine of up to $500,000”. The mechanism is section 45: the court may order a pecuniary penalty not exceeding $200,000 where the perpetrator is an individual, and $500,000 where it is an organisation. It can also order compensation and damages, and section 15 extends liability to anyone who aids, abets, procures or is knowingly concerned in a breach.

The defences in section 12 are narrow: the message was sent by a reasonable mistake of fact, or without your knowledge, for example through a virus. The onus of proof for the defence is on you.

The commercial cost usually arrives first anyway. Complaints damage sending reputation, and a domain with a complaint problem stops reaching inboxes long before anyone from the DIA calls.

A Compliant New Zealand Cold Email, Annotated

Here is the shape of a message that holds up. The recipient and the business below are invented for illustration, and the annotations are the point rather than the copy.

Subject: Your online booking form on the Ponsonby page

Hi Sarah,

The booking form on your Ponsonby location page drops the phone field below the fold on mobile, so it submits without a contact number on most of the screen sizes I tested. Screenshot attached.

We fix this sort of thing for New Zealand service businesses. Happy to send the two changes I would make, no charge and no meeting. Reply “send it”.

If you would rather not hear from me, reply with “unsubscribe” and I will remove your address today.

Jason Poonia Lucid Media, Auckland info@lucidmedia.co.nz | +64 27 582 4369 | lucidmedia.co.nz

  • Relevance is visible in the first sentence. That is what supports deemed consent under section 4, alongside a record that the address was conspicuously published in a business capacity.
  • Full name, company, city, email and phone satisfy the identification and contact requirements in section 10, and have to stay valid for at least 30 days.
  • Reply-based unsubscribe meets section 11’s same-method and no-cost requirements, and actioning it immediately beats the 5 working days in section 9(2).
  • No fake persona, no burner domain. Both undercut section 10 before you have written a word.

Writing the relevant part well is a separate skill, and the subject line is where most of it shows up. We cover that in cold email subject lines that get opened by NZ business owners.

One more thing worth saying plainly. Compliance makes cold email lawful, not effective. Outbound earns replies when the message contains something the recipient did not already know about their own business, which is the principle behind most of the B2B marketing strategies that are actually working in 2026. Whether outbound belongs in your mix at all is a digital strategy question.

Frequently Asked Questions

Is it illegal to send cold emails in New Zealand?

No. Cold email is legal in New Zealand when the message meets the Unsolicited Electronic Messages Act 2007: you have express, inferred or deemed consent, the message clearly identifies you with contact details valid for at least 30 days, and it carries a free, functional unsubscribe. A message that misses any of the three is unlawful, even if you only sent one.

Yes, but consent includes the deemed consent in section 4, which can apply to business addresses. All three conditions have to hold: the address was conspicuously published by the person in a business or official capacity, the publication carried no statement refusing unsolicited messages, and your message is relevant to that person’s business, role, functions or duties. Under section 9(3) you carry the onus of proving it, so record where each address came from.

Yes. Section 11 makes it unlawful to send a commercial electronic message with a New Zealand link unless it includes a functional unsubscribe facility that is clear and conspicuous, usable by the same method the message arrived in, free to the recipient, and reasonably likely to work for at least 30 days. This applies even when the recipient consented, so it is not optional on warm lists either.

Does the Act cover LinkedIn messages and texts?

Texts, yes. The Act regulates messages sent to an “electronic address”, which section 4 defines as an address used with an email account, an instant messaging account, a telephone account, or a similar account. A promotional SMS is squarely covered. Messages inside a social platform’s own inbox turn on how that account is characterised, so the safe position is to hold them to the same identification and opt-out standards.

What is the fine for breaching the Act?

Under section 45, the court may order a pecuniary penalty of up to $200,000 against an individual and up to $500,000 against an organisation, on application by the Department of Internal Affairs. The DIA’s guidance for businesses states that failure to comply “could mean a fine of up to $500,000”. The court can also order compensation and damages, and liability extends to people who aid or are knowingly concerned in a breach.

Can I email an address I found on a company website?

Often yes, though not automatically. A publicly listed address on a company site will usually satisfy the “conspicuously published in a business capacity” condition, unless the page carries a statement refusing unsolicited messages, which some contact pages do. Relevance is what decides it: the message has to relate to that person’s business, role, functions or duties. A generic pitch to a general info@ inbox is the weakest version, because relevance is hardest to demonstrate there.


This article is general information about New Zealand law, not legal advice. If you are making decisions about compliance for your own outbound programme, get advice from a lawyer on your specific situation.

Written by

Jason Poonia

Jason Poonia is the founder and Managing Director of Lucid Media, helping NZ businesses grow online since 2018. With over 7 years delivering results for clients across New Zealand and internationally, Jason combines technical expertise with proven marketing strategies to help businesses attract more customers and build scalable systems. Background in Computer Science from the University of Auckland.