New Zealand: Unsolicited Electronic Messages Act 2007
New Zealand regulates commercial electronic messages under the Unsolicited Electronic Messages Act 2007 (UEM Act), enforced by the Department of Internal Affairs (DIA). The UEM Act covers email, SMS, MMS, and other electronic messages with a commercial purpose — and it diverges from Australia’s Spam Act 2003 next door on the consent axis: the Spam Act is a strict opt-in regime, while the UEM Act admits a materially broader inferred-consent footing. Consent under the UEM Act can be express or inferred — inferred consent reaches an existing business relationship and, in narrow circumstances, an address the recipient has conspicuously published — so the first message to a current customer does not need a fresh opt-in the way Australia’s Spam Act expects it. Either way the message must accurately identify the sender and carry a functional unsubscribe, and an unsubscribe request must be actioned within 5 working days. That divergence makes “reuse the Australian posture unchanged” the wrong default for NZ-bound traffic. A tenant who hard-codes “all of Australasia = strict AU-style opt-in” either over-blocks NZ traffic whose inferred-consent footing is lawful, or — worse — applies AU’s express-consent evidence expectations to a regime whose consent categories are different. This page maps each UEM Act obligation to the Orbit surface you already own so your reviewers close the NZ gaps deliberately.This page is documentation, not legal advice — an engineering map of
product surfaces, not a legal opinion. The UEM Act carries DIA
enforcement and civil penalties (up to NZ500,000 for an organisation per breach); have
counsel review your identification text, unsubscribe mechanics, and
your opt-out-actioning workflow. Orbit supplies the record-keeping
and suppression surfaces — the legal posture is yours.
Why New Zealand needs its own page
New Zealand sits in the same traffic basket as Australia for most Australasian senders, but the regimes diverge on the axis that matters:- Broader inferred consent. The Spam Act 2003 (AU) requires consent before the first commercial message, and its inferred- consent categories are narrow. The UEM Act (NZ) also gates on consent, but explicitly admits inferred consent from an existing business relationship and from a conspicuously published address — a materially wider footing for the first message to a current customer. The consent-default policy you set for NZ should reflect that — and the recommended posture below still captures express opt-in anyway, because an opt-in ledger is the strongest evidence you can hold in either regime.
- A 5-working-day unsubscribe clock. The UEM Act requires an unsubscribe request to be actioned within 5 working days — a NZ-specific grace period that differs from the US CAN-SPAM 10-day window and from CASL’s 10-business-day window. Orbit’s suppression write is near-real-time, so you land well inside the grace by construction — but an audit asks for the record, and the record is the timestamped suppression row.
- Voice: a distinct do-not-call expectation. New Zealand does not
run a statutory register under the UEM Act the way Australia runs
the Do Not Call Register Act 2006. NZ marketing voice operates
under a self-regulatory Do-Not-Call expectation (administered by
the Marketing Association NZ’s registry), separate from Australia’s
ACMA register. Scoping a voice scrub with
country=AUnever answers an NZ question — scrub withcountry=NZand keep the two registries conceptually apart.
Map the UEM Act obligations onto Orbit surfaces
The Act’s main duties for a commercial electronic message map to the same surfaces the CASL and CAN-SPAM pages use, with the NZ-specific clock on unsubscribe actioning.
A worked suppression-ledger check for a New Zealand mobile before a
campaign:
POST /api/v1/compliance/suppression-list/import carries the scope
column your bulk import decides: decide whether a New Zealand opt-out
blocks only the channel it arrived on or every channel you hold — the
recommended scope-all routing keeps one revocation semantics across
AU and NZ, so a recipient who opts out once stays opted out
everywhere (scope matrix).
Send-time posture for NZ traffic
NZ’s broader inferred-consent footing argues for a lighter consent- default than Australia’s strict opt-in, not a lighter identification or suppression posture. The knobs live on your posture map:- Keep
unknown_marketing_policy: refuse(the default) unless your counsel has told you the UEM Act’s inferred-consent footing covers the traffic class in question. - For NZ-only programs you may run
consent_default_policy: allow_on_missingwhere AU expectsdeny_on_missing— the Act’s inferred-consent footing makes that lawful for business-relationship traffic. The recommended posture is stilldeny_on_missingeverywhere in Australasia: one rule, and an express opt-in ledger that satisfies both regimes’ audits. - Identification and unsubscribe are never loosened for NZ: accurate sender identity and a functional unsubscribe are statutory on the inferred-consent footing too. The divergence is the consent footing, not the message content.
Worked configuration
Follow this sequence before the first NZ-bound send:1
Read the NZ country-rules row
GET /api/v1/compliance/country-rules?channel=sms (and
&channel=voice for dialer traffic) for the NZ row. Confirm the
sender types, the registration level, and the
stop_requirement — English STOP only, no localized keyword.2
Decide the consent posture
Set
consent_default_policy on your posture map. NZ’s UEM Act
admits inferred consent for business-relationship traffic, so
allow_on_missing is available where AU would expect
deny_on_missing — but deny_on_missing with a captured
express opt-in ledger is the posture that survives both an NZ DIA
review and an AU ACMA review.3
Register the sender identity
If the
NZ row’s registration is required or recommended,
file the Sender ID through
POST /compliance/sender-id-registrations and track approval —
the same flow as Sender-ID
Registration.4
Wire unsubscribe capture
Confirm List-Unsubscribe headers ride every outbound email and
that the STOP keyword routes into the suppression ledger at scope
all. The 5-working-day grace is satisfied near-real-time; the
timestamped row is the evidence.5
Scrub voice against NZ
For marketing calls, bulk-scrub the audience with
country=NZ —
distinct from the Australian register. Treat
intl_feeds_synced: false as “own-suppression only”, not a pass
(DNC scrub).6
Verify before first send
GET /api/v1/compliance/consent/lookup for a sample identifier;
GET /api/v1/compliance/suppression-list to confirm an opted-out
recipient is present and timestamped. Then send.Related references
- Australia Spam Act — the sibling Australasia page; strict opt-in where NZ admits broader inferred consent, with its own ACMA Do-Not-Call Register. Read both before running one Australasian program across the two countries.
- US CAN-SPAM — the other opt-out page; the List-Unsubscribe header behaviour this page points to lives there, with a 10-day unsubscribe window where NZ allows 5 working days.
- Consent Management — the opt-in ledger that is recommended for NZ and mandatory for AU.
- DNC Scrubbing — the per-country scrub
endpoint; scope NZ voice with
country=NZ, nevercountry=AU. - Opt-Out & Suppression Lists —
scope-
allrouting and the timestamped suppression row that answers the 5-working-day clock. - Country Compliance Requirements — the live NZ sender rows and the per-country validation checklist.
- Sender-ID Registration — the
registration flow for the NZ row’s
required/recommendedstates. - Regional Posture Hub — the index over every per-country page, including the matrix row for NZ.