Skip to content

Australia

Australia’s Scams Prevention Framework: what the brand-impersonation obligations mean for you

Australia’s Scams Prevention Framework (SPF) is the first regime in the world to require regulated businesses to actively prevent, detect, and disrupt scams — including brand impersonation — with civil penalties reaching A$50 million per contravention and obligations phasing in across 2026 and 2027.

Last reviewed: July 20, 2026

A$50M
maximum Tier 1 civil penalty per contravention — or 30% of adjusted turnover if higher
Source: Scams Prevention Framework
Since 1 Jul 2026
banks’ core obligations are in force
Source: SPF timeline
1 Sep 2026
SPF rules commence — with the sector codes, including the brand-impersonation duty, from 31 March 2027
Source: SPF timeline

For APAC, the SPF is the closest thing to the EU’s NIS2: a real, time-boxed forcing function you can plan around. It imposes a combined, cross-sector prevent–detect–disrupt–respond–report regime on designated sectors — banks, telcos, and digital platforms — and many of the mid-market entities that fall in scope do not have in-house security teams. The urgency is highest now, because the obligations commence through 2026 and 2027.

What the SPF requires

The Scams Prevention Framework sets a combined, cross-sector prevent–detect–disrupt–respond–report regime. It explicitly calls for effective brand protection, including measures to limit impersonation, and for proactive detection mechanisms for scam and phishing activity — not just a reactive complaints process. Penalties are two-tiered, with Tier 1 contraventions reaching A$50 million or 30% of adjusted turnover.

The draft SPF Code names brand impersonation directly

Treasury’s exposure-draft SPF Common Code — released for consultation in May 2026, with consultation closing 25 June 2026 — contains a dedicated section 2-7 titled "Brand impersonation", and it is a civil penalty provision. It requires a regulated entity to have reasonable systems and processes to prevent its brand being used to facilitate scams, including to "(b) protect the communication channels for customer engagement from brand impersonation; (c) monitor the internet for brand impersonation; (d) for websites containing brand impersonation material—promptly send a request to the publisher of the website to remove the material". The draft code commences on the later of 31 March 2027 and its registration. It is an exposure draft, not final law — but it is the clearest statement any regulator has yet made of what brand protection is expected to look like in practice.

Who is in scope, and the timeline

The regulated sectors are banks, telcos, and designated digital platforms. Banks’ core obligations have been in force since 1 July 2026, the SPF rules commence on 1 September 2026, and the sector codes — including the draft brand-impersonation duty — follow from 31 March 2027. Because scope reaches SMB and mid-market entities that often lack dedicated resources, the practical gap is capacity, not intent.

How continuous brand monitoring maps to the obligation

Proactively detecting lookalike domains, cloned pages, and phishing infrastructure that targets your brand is exactly the kind of "proactive detection mechanism" the framework describes — and the draft Code’s duty to "monitor the internet for brand impersonation" and promptly request removal of impersonating material is a near-literal description of continuous monitoring plus takedown workflows. Automated evidence packs then support the respond-and-report duties, giving you a defensible record of what was found, when, and what was done about it.

How impersona.io helps

impersona.io generates 180+ permutations of your domain and checks each against live DNS and registration data, captures takedown-ready evidence, and alerts you when a new lookalike or certificate appears — a continuous detection posture that maps directly to the SPF’s expectations. It is self-serve, transparently priced, and needs no sales call to start.

Frequently asked questions

What is the Scams Prevention Framework?

It is Australia’s first-in-world combined regime requiring regulated businesses to prevent, detect, disrupt, respond to, and report scams. It explicitly includes brand-protection and proactive-detection obligations, with civil penalties up to A$50 million per contravention.

When do the obligations start?

Banks’ core obligations have been in force since 1 July 2026. The SPF rules commence on 1 September 2026, and the sector codes — including the draft brand-impersonation duty — follow from 31 March 2027. The urgency is highest now, while the timeline is live.

Does the SPF actually mention brand impersonation?

Yes — by name. Beyond the framework’s general call for effective brand protection and proactive detection, Treasury’s exposure-draft SPF Common Code contains section 2-7, "Brand impersonation": a civil penalty provision requiring regulated entities to have reasonable systems to prevent brand impersonation, including to "monitor the internet for brand impersonation" and, for websites carrying impersonating material, to "promptly send a request to the publisher of the website to remove the material".

Is the brand-impersonation duty final law?

Not yet. Section 2-7 sits in Treasury’s exposure draft of the SPF Common Code — consultation on the draft closed on 25 June 2026, and the code commences on the later of 31 March 2027 and its registration. The SPF Act itself is in force, and banks’ core obligations have applied since 1 July 2026.

We are a mid-market business in a designated sector — does this apply to us?

The regulated sectors are banks, telcos, and designated digital platforms, and scope can reach SMB and mid-market entities within them. Those organisations are often the ones without in-house resources, which is where an automated detection posture helps most.

Is impersona.io’s EU hosting a problem for an Australian buyer?

For most Australian buyers it is a non-issue. Data is stored and processed in the EU (Frankfurt) and encrypted. If you need in-region hosting for a regulated use case, ask us — we will be straight about current limits rather than overpromise.

Other regions

See your own exposure first

Your first brand check is free. It generates roughly 160 permutations of your domain and checks them against live DNS and domain registration data.