Your agent dials a number that was on the Do Not Call Register six months ago. That call can cost you. AI outbound calling compliance starts before the +61 or +64 line ever rings, and it is mostly about the list, not the agent.
Most penalties come from sloppy lists, not bad scripts. A clean list is the cheapest insurance you can buy. We scrub before we dial, log every consent, and keep the records to prove it.
We have run hundreds of outbound campaigns across New Zealand and Australia. The agent is fast. The list is where you get burned. This guide walks through the rules, the scrub, and the records that keep a campaign clean.
Every Australian list is washed against the Do Not Call Register, then your own opt-outs, before a single dial.
Which rules govern AI outbound calls in NZ and Australia?
Four sets of rules cover most AI outbound calling in NZ and Australia. In Australia it is the Do Not Call Register and the Spam Act 2003. In New Zealand it is the Unsolicited Electronic Messages Act 2007 plus the Privacy Act 2020. Each one targets a different channel.
The Do Not Call Register governs phone calls to numbers people have registered. The Spam Act 2003 governs commercial electronic messages, mostly SMS and email follow-ups. The NZ Unsolicited Electronic Messages Act covers New Zealand electronic messages the same way.
Then privacy law sits over all of it. In NZ that is the Privacy Act 2020, enforced by the Office of the Privacy Commissioner. In Australia that is the Privacy Act 1988 and the 13 Australian Privacy Principles, the APPs, enforced by the OAIC. Both share the Notifiable Data Breaches scheme for serious breaches.
The split matters. A number can be legal to dial but the contact details still need handling under privacy law. We treat both as one workflow. Our guide to the NZ Privacy Act 2020 for voice agents goes deeper on the privacy layer.
What is the Do Not Call Register, and who must scrub against it?
The Do Not Call Register is the Australian list of numbers that have opted out of unsolicited telemarketing. Run by the ACMA at donotcall.gov.au, it covers most marketing and research calls. Any business making those calls must scrub its list against it first.
You do not call the register to check one number at a time. You submit your whole list and it comes back marked. Registered numbers are removed before the agent gets them. Washing a list is the standard term.
There are exemptions. Existing customers, charities, and some research calls have carve-outs. We do not assume an exemption applies. We document why a number is dialled, or we drop it.
New Zealand has no single equivalent register. NZ relies on the Privacy Act and the do-not-contact requests you must honour. So an NZ campaign needs its own suppression list, built and respected by you. We cover the brand angle in our piece on the Do Not Call Register and brand protection.
How do the Spam Act 2003 and the NZ Unsolicited Electronic Messages Act apply?
These two laws govern the SMS and email that follow a call, not the call itself. The Spam Act 2003 in Australia and the NZ Unsolicited Electronic Messages Act 2007 both require consent, sender identification, and a working unsubscribe. They bite when your agent texts a quote or a booking link.
Most outbound campaigns send something after the call. A confirmation text. A follow-up email. The moment you do, these laws apply.
Three rules cover it. Get consent before you send. Name yourself clearly in the message. Give a one-step unsubscribe that works. We wire the unsubscribe back into the suppression list so the same person is never messaged twice.
This is where teams trip. They scrub the phone list, then blast an SMS to numbers that never agreed. The fix is to treat consent as one record per contact, shared across call and message.
One consent record per contact, shared across the call and the follow-up message.
How do you scrub a list before the agent dials?
You wash the list against the Do Not Call Register, then your own suppression list, then validate the formatting, all before a single dial. The order matters. Register first, your opt-outs second, bad numbers third. Only clean rows reach the agent.
Here is the sequence we run on every Australian campaign.
For New Zealand there is no register to wash against, so step one becomes your own suppression list plus any do-not-contact requests on file. The other steps stay the same.
A 200-dial campaign costs about 100 dollars NZD to run. Scrubbing first means you spend that on numbers you are allowed to reach. It also protects your numbers from complaints that get a line flagged. We cover that in our piece on why dialler numbers get burned.
Running outbound and not sure your list is clean?
See how we handle data residency, access, and audit trails on our AI voice agent security page.
What records should you keep?
Keep proof of three things: when you scrubbed, what consent you held, and every opt-out you honoured. Regulators do not take your word for it. The business that can show a dated scrub log and a consent record is the business that survives an audit.
For each campaign we store the scrub date and the register response. For each contact we store the consent basis and the source. For each opt-out we store the time and channel.
This is not paperwork for its own sake. If the OAIC or the OPC asks why a number was called, you answer in minutes. Our platform keeps the call transcript and the structured record on our Sydney servers, so the proof lives in one place.
There is a delete path too. If someone asks to be removed, we delete their record in 10 minutes and add them to suppression. That request is then permanent across calls and messages. The OAIC publishes its privacy guidance at oaic.gov.au.
What happens if you breach the Do Not Call Register?
Breaching the Do Not Call Register can mean court-ordered penalties from the ACMA, on top of the brand damage. The cost is rarely a single fine. It is the fine, the complaint handling, and the trust you lose with the people you wanted as customers.
The ACMA publishes enforcement actions at donotcall.gov.au. Penalties scale with the volume of breaching calls and how careless the conduct was. A documented scrub is your best defence.
For SMS and email, the Spam Act 2003 and the NZ Unsolicited Electronic Messages Act carry their own penalties. The OAIC handles privacy breaches in Australia under the Notifiable Data Breaches scheme. The OPC does the same in New Zealand.
The pattern is clear. A clean list and good records are far cheaper than the alternative. We would rather drop 5 percent of a list than risk one complaint that flags a number.
Scrub date, consent basis, and opt-out logs kept together so an audit takes minutes.
How does the agent stay compliant for every AI outbound calling compliance check?
The agent enforces the rules at run time, not just at scrub time. It only dials numbers the scrub passed. It discloses it is an AI on every call. It captures consent and opt-outs as structured data the moment they happen.
So compliance is not a checklist someone forgets. It is built into how the campaign runs.
A few things the agent does automatically.
The economics still work. An answered call averages about 30 seconds, around 40 cents at roughly 80 cents a minute. A Sydney agent produced 141 vendor leads in 90 days at 32.74 dollars per seller. A Christchurch developer booked viewings at 7.12 dollars each. Clean and compliant does not mean slow. To track the right numbers, see our outbound calling KPIs guide.
Want a compliant outbound campaign live?
Our AI sales agent runs the campaign end to end, and our security page shows how the records hold up.
Frequently Asked Questions
Do I need to scrub against the Do Not Call Register in New Zealand?
No. The Do Not Call Register is Australian and run by the ACMA. New Zealand has no single equivalent register. For NZ campaigns you build and honour your own suppression list. You also respect any do-not-contact requests on file, under the Privacy Act 2020 and the Unsolicited Electronic Messages Act 2007.
Does the agent tell people it is an AI?
Yes. The agent discloses it is an AI assistant near the start of every call, in both NZ and Australia. This is built in, not optional. Disclosure on every call keeps AI outbound calling compliance consistent. It also protects your brand with the people you call. See our privacy compliance overview for the full picture.
How often should I re-scrub my list?
Wash the list against the Do Not Call Register every time you run a campaign, not once a quarter. Numbers get added daily. A scrub from last month can include people who registered since. We re-wash before each campaign and log the date so the proof is always current.
What records prove I stayed compliant?
Three records: the dated scrub log with the register response, the consent basis per contact, and every opt-out with its time and channel. Our platform stores transcripts and structured records on our Sydney servers. If the OAIC or the OPC asks, you can answer in minutes rather than days.
Do the SMS and email rules apply to my calls too?
The Spam Act 2003 and the NZ Unsolicited Electronic Messages Act govern messages, not the live call. But almost every campaign sends a text or email afterward. The moment you do, you need three things. Consent, a sender ID, and a working unsubscribe wired into suppression.
Where is my data stored?
Your portal, transcripts, and structured records sit on our Sydney servers. Live audio is processed offshore by our voice infrastructure partner under documented arrangements. We never claim all data stays in Australia. That would not be honest. You can ask us to delete a record and we action it in 10 minutes.
Leonardo Garcia-Curtis
Founder & CEO at Waboom AI. Building voice AI agents that convert.
Ready to Build Your AI Voice Agent?
Let's discuss how Waboom AI can help automate your customer conversations.
Book a Free Demo


