> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# New Zealand: Unsolicited Electronic Messages Act 2007

> Meet New Zealand's Unsolicited Electronic Messages Act 2007 — the DIA-enforced consent regime with a broad inferred-consent footing for commercial electronic messages, the 5-working-day unsubscribe clock, and the NZ Do-Not-Call expectation for marketing voice — mapped to the consent ledger, DNC scrub, and suppression surfaces Orbit already gives you.

# New Zealand: Unsolicited Electronic Messages Act 2007

New Zealand regulates commercial electronic messages under the
**Unsolicited Electronic Messages Act 2007** (UEM Act), enforced by the
Department of Internal Affairs (DIA). The UEM Act covers email, SMS,
MMS, and other electronic messages with a commercial purpose — and it
diverges from Australia's Spam Act 2003 next door on the consent axis:
the Spam Act is a strict **opt-in** regime, while the UEM Act admits
a materially **broader inferred-consent** footing. Consent under the
UEM Act can be express **or inferred** — inferred consent reaches an
existing business relationship and, in narrow circumstances, an
address the recipient has conspicuously published — so the first
message to a current customer does not need a fresh opt-in the way
Australia's Spam Act expects it. Either way the message must
accurately identify the sender and carry a functional unsubscribe,
and an unsubscribe request must be actioned within **5 working
days**.

That divergence makes "reuse the Australian posture unchanged" the
wrong default for NZ-bound traffic. A tenant who hard-codes "all of
Australasia = strict AU-style opt-in" either over-blocks NZ traffic
whose inferred-consent footing is lawful, or — worse — applies AU's
express-consent evidence expectations to a regime whose consent
categories are different. This page maps each UEM Act obligation to
the Orbit surface you already own so your reviewers close the NZ gaps
deliberately.

<Note>
  This page is documentation, not legal advice — an engineering map of
  product surfaces, not a legal opinion. The UEM Act carries DIA
  enforcement and civil penalties (up to NZ$200,000 for an
      individual and NZ$500,000 for an organisation per breach); have
  counsel review your identification text, unsubscribe mechanics, and
  your opt-out-actioning workflow. Orbit supplies the record-keeping
  and suppression surfaces — the legal posture is yours.
</Note>

***

## Why New Zealand needs its own page

New Zealand sits in the same traffic basket as Australia for most
Australasian senders, but the regimes diverge on the axis that matters:

* **Broader inferred consent.** The Spam Act 2003 (AU) requires
  consent *before* the first commercial message, and its inferred-
  consent categories are narrow. The UEM Act (NZ) also gates on
  consent, but explicitly admits **inferred consent** from an existing
  business relationship and from a conspicuously published address —
  a materially wider footing for the first message to a current
  customer. The [consent-default
  policy](/compliance/posture-overview) you set for NZ should reflect
  that — and the recommended posture below still captures express
  opt-in anyway, because an opt-in ledger is the strongest evidence
  you can hold in either regime.
* **A 5-working-day unsubscribe clock.** The UEM Act requires an
  unsubscribe request to be actioned within 5 working days — a
  NZ-specific grace period that differs from the US CAN-SPAM 10-day
  window and from CASL's 10-business-day window. Orbit's suppression
  write is near-real-time, so you land well inside the grace by
  construction — but an audit asks for the record, and the record is
  the timestamped suppression row.
* **Voice: a distinct do-not-call expectation.** New Zealand does not
  run a statutory register under the UEM Act the way Australia runs
  the Do Not Call Register Act 2006. NZ marketing voice operates
  under a self-regulatory Do-Not-Call expectation (administered by
  the Marketing Association NZ's registry), separate from Australia's
  ACMA register. Scoping a voice scrub with `country=AU` never
  answers an NZ question — scrub with `country=NZ` and keep the two
  registries conceptually apart.

The NZ row on [Country Compliance
Requirements](/compliance/country-requirements) carries the per-channel
sender rules; until now a reader assembling an NZ posture had no
canonical page to land on, unlike the
[Australia](/compliance/au-spam-act), [Canada](/compliance/casl-canada-anti-spam),
and [UK](/compliance/uk-pecr-eprivacy) pages. This page fills that gap.

***

## Map the UEM Act obligations onto Orbit surfaces

The Act's main duties for a commercial electronic message map to the
same surfaces the CASL and CAN-SPAM pages use, with the NZ-specific
clock on unsubscribe actioning.

| UEM Act obligation | Where the control lives in Orbit |
| - | - |
| **Accurate sender identification** — the message clearly identifies the person or organisation that authorised it, with accurate contact details | **Sender domain verification** for email (the same posture as requirement 1 on [US CAN-SPAM](/compliance/can-spam#from-identity--sender-domain)) and **Sender-ID registration** for SMS — submit through `POST /compliance/sender-id-registrations` via [Sender-ID Registration](/compliance/sender-id-registration) |
| **Functional unsubscribe facility** — every commercial message carries a working unsubscribe mechanism the recipient can use at no or low cost | **List-Unsubscribe headers** on every outbound email ([full header behavior](/compliance/can-spam#list-unsubscribe-header-behavior)) and the **suppression layer** — a click or an inbound STOP writes a suppression row via [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) |
| **Action unsubscribe within 5 working days** — an NZ-specific grace period; you must stop sending to the unsubscribed address within 5 working days of the request | The **suppression ledger** — a List-Unsubscribe click or an inbound STOP lands a timestamped suppression row near-real-time, well inside the grace; `GET /api/v1/compliance/suppression-list` records the `created_at` an audit asks for |
| **Consent with a wide inferred footing** — consent is the UEM Act gate, but inferred consent reaches business relationships and conspicuously published addresses; capturing express opt-in anyway is the strongest evidence posture and keeps one posture across AU + NZ | [Consent API](/compliance/consent-management) — a `POST /api/v1/compliance/consent` record with `state: opted_in` per `(identifier, channel)` pair, timestamped and exportable; where you rely on inferred consent for NZ, the ledger still records the tier so an audit sees which footing each send stood on |
| **STOP keyword** — an inbound STOP from an NZ mobile is a revocation; English-language STOP is the canonical keyword (no localized keyword regime like France's STOP au 36111) | The STOP handler routes the revocation into the suppression ledger; route it at scope `all` so an NZ mobile that STOPs your SMS is not then emailed or voice-dialed by the same program |

A worked suppression-ledger check for a New Zealand mobile before a
campaign:

```bash theme={null}
curl "https://api.orbit.devotel.io/api/v1/compliance/consent/lookup?identifier=%2B6421234567&channel=sms" \
  -H "X-API-Key: dv_live_sk_YOUR_KEY"
```

Where you rely on the UEM Act's inferred-consent footing, a missing
express consent row does not block the first NZ send the way it would
under AU's Spam Act — but a suppression row always does. For
suppression,
`POST /api/v1/compliance/suppression-list/import` carries the scope
column your bulk import decides: decide whether a New Zealand opt-out
blocks only the channel it arrived on or every channel you hold — the
recommended scope-`all` routing keeps one revocation semantics across
AU and NZ, so a recipient who opts out once stays opted out
everywhere ([scope matrix](/compliance/opt-out-suppression)).

***

## Send-time posture for NZ traffic

NZ's broader inferred-consent footing argues for a lighter consent-
default than Australia's strict opt-in, not a lighter identification
or suppression posture. The knobs live on your [posture
map](/compliance/posture-overview):

* Keep `unknown_marketing_policy: refuse` (the default) unless your
  counsel has told you the UEM Act's inferred-consent footing covers
  the traffic class in question.
* For NZ-only programs you may run `consent_default_policy:
  allow_on_missing` where AU expects `deny_on_missing` — the Act's
  inferred-consent footing makes that lawful for business-relationship
  traffic. The recommended posture is still `deny_on_missing`
  everywhere in Australasia: one rule, and an express opt-in ledger
  that satisfies both regimes' audits.
* Identification and unsubscribe are never loosened for NZ: accurate
  sender identity and a functional unsubscribe are statutory on the
  inferred-consent footing too. The divergence is the consent footing,
  not the message content.

A copy-pasteable posture call for an NZ marketing program that
captures opt-in anyway:

```bash theme={null}
curl -X PATCH "https://api.orbit.devotel.io/api/v1/compliance/posture" \
  -H "Authorization: Bearer $ORBIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "consent_default_policy": "deny_on_missing",
    "unknown_marketing_policy": "refuse"
  }'
```

Run the same posture for NZ as AU and the regimes' difference becomes
a surplus of evidence, not a gap.

***

## Worked configuration

Follow this sequence before the first NZ-bound send:

<Steps>
  <Step title="Read the NZ country-rules row">
    `GET /api/v1/compliance/country-rules?channel=sms` (and
    `&channel=voice` for dialer traffic) for the `NZ` row. Confirm the
    sender types, the `registration` level, and the
    `stop_requirement` — English STOP only, no localized keyword.
  </Step>

  <Step title="Decide the consent posture">
    Set `consent_default_policy` on your posture map. NZ's UEM Act
    admits inferred consent for business-relationship traffic, so
    `allow_on_missing` is available where AU would expect
    `deny_on_missing` — but `deny_on_missing` with a captured
    express opt-in ledger is the posture that survives both an NZ DIA
    review and an AU ACMA review.
  </Step>

  <Step title="Register the sender identity">
    If the `NZ` row's `registration` is `required` or `recommended`,
    file the Sender ID through
    `POST /compliance/sender-id-registrations` and track approval —
    the same flow as [Sender-ID
    Registration](/compliance/sender-id-registration).
  </Step>

  <Step title="Wire unsubscribe capture">
    Confirm List-Unsubscribe headers ride every outbound email and
    that the STOP keyword routes into the suppression ledger at scope
    `all`. The 5-working-day grace is satisfied near-real-time; the
    timestamped row is the evidence.
  </Step>

  <Step title="Scrub voice against NZ">
    For marketing calls, bulk-scrub the audience with `country=NZ` —
    distinct from the Australian register. Treat
    `intl_feeds_synced: false` as "own-suppression only", not a pass
    ([DNC scrub](/compliance/dnc-scrub)).
  </Step>

  <Step title="Verify before first send">
    `GET /api/v1/compliance/consent/lookup` for a sample identifier;
    `GET /api/v1/compliance/suppression-list` to confirm an opted-out
    recipient is present and timestamped. Then send.
  </Step>
</Steps>

***

## Related references

* [Australia Spam Act](/compliance/au-spam-act) — the sibling
  Australasia page; strict opt-in where NZ admits broader inferred
  consent, with its own ACMA Do-Not-Call Register. Read both before
  running one Australasian program across the two countries.
* [US CAN-SPAM](/compliance/can-spam) — the other opt-out page; the
  List-Unsubscribe header behaviour this page points to lives there,
  with a 10-day unsubscribe window where NZ allows 5 working days.
* [Consent Management](/compliance/consent-management) — the opt-in
  ledger that is recommended for NZ and mandatory for AU.
* [DNC Scrubbing](/compliance/dnc-scrub) — the per-country scrub
  endpoint; scope NZ voice with `country=NZ`, never `country=AU`.
* [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) —
  scope-`all` routing and the timestamped suppression row that answers
  the 5-working-day clock.
* [Country Compliance Requirements](/compliance/country-requirements) —
  the live NZ sender rows and the per-country validation checklist.
* [Sender-ID Registration](/compliance/sender-id-registration) — the
  registration flow for the NZ row's `required` / `recommended` states.
* [Regional Posture Hub](/compliance/country-rules-directory) — the
  index over every per-country page, including the matrix row for NZ.
