Australia
Australia’s Scams Prevention Framework: what the brand-impersonation obligations mean for you
Australia’s Scams Prevention Framework (SPF) is the first regime in the world to require regulated businesses to actively prevent, detect, and disrupt scams — including brand impersonation — with civil penalties reaching A$50 million per contravention and obligations phasing in across 2026 and 2027.
Last reviewed: July 20, 2026
- A$50M
- maximum Tier 1 civil penalty per contravention — or 30% of adjusted turnover if higher
- Source: Scams Prevention Framework
- Since 1 Jul 2026
- banks’ core obligations are in force
- Source: SPF timeline
- 1 Sep 2026
- SPF rules commence — with the sector codes, including the brand-impersonation duty, from 31 March 2027
- Source: SPF timeline
For APAC, the SPF is the closest thing to the EU’s NIS2: a real, time-boxed forcing function you can plan around. It imposes a combined, cross-sector prevent–detect–disrupt–respond–report regime on designated sectors — banks, telcos, and digital platforms — and many of the mid-market entities that fall in scope do not have in-house security teams. The urgency is highest now, because the obligations commence through 2026 and 2027.
What the SPF requires
The Scams Prevention Framework sets a combined, cross-sector prevent–detect–disrupt–respond–report regime. It explicitly calls for effective brand protection, including measures to limit impersonation, and for proactive detection mechanisms for scam and phishing activity — not just a reactive complaints process. Penalties are two-tiered, with Tier 1 contraventions reaching A$50 million or 30% of adjusted turnover.
The draft SPF Code names brand impersonation directly
Treasury’s exposure-draft SPF Common Code — released for consultation in May 2026, with consultation closing 25 June 2026 — contains a dedicated section 2-7 titled "Brand impersonation", and it is a civil penalty provision. It requires a regulated entity to have reasonable systems and processes to prevent its brand being used to facilitate scams, including to "(b) protect the communication channels for customer engagement from brand impersonation; (c) monitor the internet for brand impersonation; (d) for websites containing brand impersonation material—promptly send a request to the publisher of the website to remove the material". The draft code commences on the later of 31 March 2027 and its registration. It is an exposure draft, not final law — but it is the clearest statement any regulator has yet made of what brand protection is expected to look like in practice.
Who is in scope, and the timeline
The regulated sectors are banks, telcos, and designated digital platforms. Banks’ core obligations have been in force since 1 July 2026, the SPF rules commence on 1 September 2026, and the sector codes — including the draft brand-impersonation duty — follow from 31 March 2027. Because scope reaches SMB and mid-market entities that often lack dedicated resources, the practical gap is capacity, not intent.
How continuous brand monitoring maps to the obligation
Proactively detecting lookalike domains, cloned pages, and phishing infrastructure that targets your brand is exactly the kind of "proactive detection mechanism" the framework describes — and the draft Code’s duty to "monitor the internet for brand impersonation" and promptly request removal of impersonating material is a near-literal description of continuous monitoring plus takedown workflows. Automated evidence packs then support the respond-and-report duties, giving you a defensible record of what was found, when, and what was done about it.
How impersona.io helps
impersona.io generates 180+ permutations of your domain and checks each against live DNS and registration data, captures takedown-ready evidence, and alerts you when a new lookalike or certificate appears — a continuous detection posture that maps directly to the SPF’s expectations. It is self-serve, transparently priced, and needs no sales call to start.
Frequently asked questions
What is the Scams Prevention Framework?
It is Australia’s first-in-world combined regime requiring regulated businesses to prevent, detect, disrupt, respond to, and report scams. It explicitly includes brand-protection and proactive-detection obligations, with civil penalties up to A$50 million per contravention.
When do the obligations start?
Banks’ core obligations have been in force since 1 July 2026. The SPF rules commence on 1 September 2026, and the sector codes — including the draft brand-impersonation duty — follow from 31 March 2027. The urgency is highest now, while the timeline is live.
Does the SPF actually mention brand impersonation?
Yes — by name. Beyond the framework’s general call for effective brand protection and proactive detection, Treasury’s exposure-draft SPF Common Code contains section 2-7, "Brand impersonation": a civil penalty provision requiring regulated entities to have reasonable systems to prevent brand impersonation, including to "monitor the internet for brand impersonation" and, for websites carrying impersonating material, to "promptly send a request to the publisher of the website to remove the material".
Is the brand-impersonation duty final law?
Not yet. Section 2-7 sits in Treasury’s exposure draft of the SPF Common Code — consultation on the draft closed on 25 June 2026, and the code commences on the later of 31 March 2027 and its registration. The SPF Act itself is in force, and banks’ core obligations have applied since 1 July 2026.
We are a mid-market business in a designated sector — does this apply to us?
The regulated sectors are banks, telcos, and designated digital platforms, and scope can reach SMB and mid-market entities within them. Those organisations are often the ones without in-house resources, which is where an automated detection posture helps most.
Is impersona.io’s EU hosting a problem for an Australian buyer?
For most Australian buyers it is a non-issue. Data is stored and processed in the EU (Frankfurt) and encrypted. If you need in-region hosting for a regulated use case, ask us — we will be straight about current limits rather than overpromise.
Other regions
See your own exposure first
Your first brand check is free. It generates roughly 160 permutations of your domain and checks them against live DNS and domain registration data.