SMS Marketing Compliance: GDPR, Consent and Opt-Outs

SMS OptOut

Table of Contents

SMS marketing compliance means three things: you have the recipient’s prior consent (or a legal exception such as the soft opt-in) before you send a promotional text, you identify yourself clearly, and every message offers a free, simple way to opt out that you honour promptly. In the EU and UK those rules come from the ePrivacy rules and the UK’s PECR for the message itself, and from GDPR for the personal data behind it; many countries add sender registration and permitted sending hours on top.

This guide covers each requirement, what a consent record should contain, how opt-outs should work, and where local rules differ. It also shows how the SMS.to opt-out and compliance tools handle the mechanics for you.

Which laws apply to SMS marketing in the EU and UK?

Two sets of rules work together. One controls whether you may send the marketing message at all; the other controls how you collect, store and use the phone numbers and names on your list.

LawWhat it controlsKey requirement for SMS marketing
ePrivacy Directive 2002/58/EC, Article 13 (EU)Sending marketing by “electronic mail”, which includes SMSPrior consent, except the soft opt-in for existing customers; never hide your identity; give a valid address to stop messages
GDPR (Regulation 2016/679) (EU)Personal data on your listConsent must meet the GDPR standard; you must be able to prove it; people can object to direct marketing at any time
PECR, regulation 22 (UK)Marketing texts and emails to individualsSpecific consent or the soft opt-in; a simple, free way to refuse at collection and in every message
UK GDPR and the Data Protection Act 2018Personal data on your listThe same principles as the EU GDPR, enforced by the ICO

The ePrivacy Directive is implemented through each member state’s own law, so details such as how the soft opt-in applies can vary between EU countries. The penalties are significant: GDPR Article 83 allows fines of up to EUR 20 million or 4% of worldwide annual turnover, and the ICO confirmed in its February 2026 statement that, from 5 February 2026, it can fine up to GBP 17.5 million or 4% of global turnover under PECR.

GDPR Article 4(11) defines consent as a freely given, specific, informed and unambiguous indication of the person’s wishes, given by a statement or a clear affirmative action. In practice:

  • An action, not a default. An unticked box the person ticks, a keyword they text to you, or a signature on a paper form. Recital 32 of the GDPR says silence, pre-ticked boxes and inactivity are not consent.
  • Specific to texts and to you. The ICO’s electronic mail marketing guidance says you need specific consent to texts from you. Consent to email does not cover SMS, and “carefully selected partners” does not cover a partner who was never named.
  • Separate from your terms. Agreeing to terms of sale is not agreeing to marketing.
  • As easy to withdraw as to give. Article 7(3) of the GDPR requires this, which is why the opt-out in every message matters.

Clear sign-up wording names the brand, the channel, the content and the frequency, for example: “Tick to get texts from us about offers and new arrivals, up to four a month. You can opt out at any time.” Bought or rented lists fail these tests, because the people on them never agreed to hear from you, and the ICO guidance says the soft opt-in does not cover bought-in lists either.

Article 7(1) of the GDPR says that where you rely on consent, you must be able to demonstrate it. If a customer complains or a regulator asks, “they signed up on our website” is not enough. Keep these fields for each contact:

FieldExample
Phone numberIn international format, such as +44 or +357
Date and timeThe moment consent was given, with the time zone
SourceCheckout page URL, keyword to a virtual number, store tablet, paper form reference
Wording shownThe exact sign-up text or a version number for it
ScopeWhich brand, which channel and which types of message
ConfirmationThe welcome or double opt-in message sent, and its delivery report
Opt-outDate, time and method, if the person later withdrew

Keep the record for as long as you send to the number, and for a reasonable period afterwards so you can answer complaints.

What is the soft opt-in and when can you use it?

The soft opt-in lets you text existing customers without separate consent, under Article 13(2) of the ePrivacy Directive and regulation 22(3) of PECR. All of these conditions must be met:

  1. You got the number in the course of a sale, or negotiations for a sale, of a product or service to that person.
  2. You only market your own similar products or services.
  3. You gave a simple, free way to refuse when you collected the number, and you repeat it in every message.

It does not cover prospects, competition entrants who bought nothing, or numbers from another company. In the UK, the Data (Use and Access) Act 2025 added a separate soft opt-in for charities contacting supporters, described in the ICO’s summary of the PECR changes. Because EU member states implement Article 13(2) in their own laws, confirm how the soft opt-in works in each country before relying on it there.

How should opt-out work in every marketing text?

Every marketing text needs an opt-out, and it must be free apart from the normal cost of sending a reply: PECR regulation 22(3)(c) requires a “simple means of refusing (free of charge except for the costs of the transmission of the refusal)”. Short wording at the end of the message is enough:

[Brand]: 20% off everything this weekend only. Shop now: [link] Reply STOP to opt out

Operational details decide whether it actually works:

  • Match the method to the sender. “Reply STOP” only works from a number that can receive messages. An alphanumeric sender ID cannot receive replies, so use an opt-out link instead. On SMS.to, adding STOPSMS {optout} to the text inserts a short link on the nosmsto.me domain.
  • Accept the words people actually use. In the US, the FCC’s rule at 47 CFR 64.1200(a)(10) treats replies such as “stop”, “quit”, “end”, “revoke”, “opt out”, “cancel” and “unsubscribe” as revocation and requires it to be honoured within ten business days. The CTIA Messaging Principles and Best Practices (May 2023) also expect one confirmation message after an opt-out and nothing more.
  • Act fast. Saudi Arabia’s spam regulation (article 4.6.6.3, as published by stc) allows no more than 24 hours. SMS.to’s opt-out documentation says link opt-outs can take up to 24 hours to take effect, so do not schedule a follow-up to the same list within a day of a campaign.
  • Keep a suppression list. GDPR Article 21(3) says data must no longer be used for direct marketing once someone objects, and the ICO guidance tells senders to keep a “do not contact” list and screen against it. Keep the number on that list even if you delete everything else, so it is not re-imported from another source.

Are there quiet hours for marketing texts?

Some countries set legal sending windows for marketing. Others leave it to good practice. A few examples:

CountryRuleSource
United StatesNo telephone solicitations before 8am or after 9pm, recipient’s local time47 CFR 64.1200(c)(1)
United Arab EmiratesNo marketing texts between 9pm and 7amTDRA spam policy, article 8.3
Saudi ArabiaNo promotional messages from 10pm to 9am, and from 1am to 12pm during RamadanCST spam regulation, article 4.4.10
FranceOur route notes restrict marketing SMS to weekday daytime, outside 8pm to 8amSMS.to sender ID requirements

Wherever you send, schedule in the recipient’s time zone and avoid early mornings, late evenings and public holidays.

What are the sender ID rules?

Article 13(4) of the ePrivacy Directive bans marketing that disguises or conceals who it is from, so the sender and the first words of the text should make you obvious. Beyond that, many countries now require the sender itself to be registered. Our sender ID requirements by country list shows the current position for each market. Some examples:

  • United Kingdom: brand names are accepted and are registered on our routes before live traffic.
  • Spain: the CNMC confirmed that from 15 September 2026, messages whose alias is not in its Alias Registry are blocked.
  • India: senders using their own header register their entity, headers and templates on DLT, as TRAI’s advice to senders explains.
  • United States: alphanumeric senders are not supported. You send from a registered toll-free number, a 10DLC number or a short code; see our comparison of 10DLC, short codes and toll-free numbers.

Do the same rules apply to transactional texts?

Not in the same way. A text that only serves the customer, such as an order update, a booking confirmation or a one-time passcode, is not direct marketing. It still needs a lawful basis under GDPR, but not marketing consent. The line is easy to cross: add “and 10% off your next order” to a delivery update and it becomes a marketing message, with all the rules above. Keep service and marketing texts separate, and never put promotions in passcode messages.

What does a compliant SMS campaign look like?

  1. Every number has a consent record, or meets all three soft opt-in conditions.
  2. The list has been screened against your suppression list.
  3. The sender ID is registered where required and clearly identifies you.
  4. The text names your brand and contains a working, free opt-out.
  5. The send is scheduled inside legal hours in each recipient’s time zone.
  6. Opt-outs flow back into your CRM and suppression list.
  7. You have a data processing agreement with your SMS provider.

How SMS.to handles compliance

SMS.to is operated by Intergo Telecom, a licensed telecom operator, and the platform is built with the rules above in mind:

  • One-click opt-out links on the nosmsto.me domain, added with STOPSMS {optout}. Opted-out numbers are skipped on later sends, and you are not charged for them.
  • Opt-in and opt-out management for contacts and lists, in the dashboard and through the API, so opt-outs can sync with your CRM.
  • Two-way numbers for keyword opt-ins and STOP replies, with replies delivered to your systems by webhook.
  • Sender ID guidance for each market, including registration where it is required.
  • GDPR-aligned processing, with a data processing agreement available on request. See our GDPR compliance statement for details.
  • Team members with layered access, so you control who in your organisation can send and with how many credits.

For the full list of tools, see SMS.to features. For the rest of the campaign process, from list building to measurement, read our SMS marketing guide, and for keyword and reply handling see our guide to two-way SMS.

Rules change often. This guide reflects the rules as of September 2026; check with your account manager before launching a campaign.

FAQs

Do I need consent to send marketing texts to existing customers?

Not always. In the UK and EU the soft opt-in lets you text customers who bought from you about your own similar products, if you offered an opt-out when you collected the number and in every message.

Is “Reply STOP to opt out” enough?

Only if recipients can actually reply, which means sending from a number rather than an alphanumeric sender ID. Otherwise use an opt-out link, and honour every opt-out promptly.

Does GDPR apply to businesses outside the EU?

Yes, if you offer goods or services to people in the EU or monitor their behaviour, GDPR applies to the personal data you hold about them, wherever your business is based.

Can I text people who gave their number at a competition or event?

Only if the form clearly asked for consent to marketing texts from you. Entering a competition is not a purchase, so the soft opt-in does not apply.

Planning campaigns in several countries? Talk to our sales team about sender registration, opt-out setup and local rules before you launch.

author avatar
Marios Italos

More Articles

Firmao is a cloud-based, all-in-one business system covering CRM, invoicing and tasks. Here is what
A step-by-step guide to SMS marketing: getting consent, choosing a sender ID, writing and personalising