← Back to blog

Avoid £17.5m fines: 5 GDPR SMS consent steps for UK SMEs (2026)

August 29, 2026
Avoid £17.5m fines: 5 GDPR SMS consent steps for UK SMEs (2026)

You cannot send marketing text messages to individuals in the UK without explicit consent or a valid soft opt-in, and every message must name the sender and offer a working opt-out. GDPR SMS consent UK rules sit on top of PECR, the regulation that actually governs whether you can send. Get either wrong and the Data Use and Access Act 2025 has sharpened the ICO's teeth considerably.


TL;DR:

  • Always verify explicit consent for individuals and document the consent process, especially if using a purchased list, to avoid PECR violations.
  • Use separate, clear opt-in checkboxes with detailed wording about purpose and frequency, and link directly to your privacy notice.
  • Ensure your SMS platform processes STOP replies automatically and supports full audit trails, including suppression list exports.
  • Regularly update and audit suppression lists and opt-out processing to prevent reusing unverified numbers and avoid hefty fines.
  • Automate consent workflows across channels with integrated tools like Talk2Aiva to reduce manual errors and maintain compliance at scale.

Table of Contents

Compliance quick checklist: what to do right now

Before your next campaign goes out, run your contact list through this audit.

  • Segment by recipient type. Split individuals and sole traders from genuine corporate subscribers. This single step catches most compliance gaps.
  • Verify the legal basis for individuals. Confirm explicit SMS consent exists, or that soft opt-in conditions are fully met and documented.
  • Check sender identification and opt-out. Every text needs a recognisable sender name and a working "reply STOP" mechanism.
  • Keep exportable consent logs. You need to produce evidence on demand, not reconstruct it after the fact.
  • Stop using unverified bought lists. A purchased number list rarely comes with PECR-compliant consent attached.

Pro Tip: Run this checklist quarterly, not just before big campaigns. Consent status changes as customers opt out, numbers get reassigned, and old records go stale.

How PECR and UK GDPR interact for SMS marketing

PECR (the Privacy and Electronic Communications Regulations) decides whether you may send a marketing text at all. It's the specific rulebook for electronic marketing, sitting alongside UK GDPR rather than replacing it. ICO guidance on PECR restricts unsolicited marketing by phone, text, fax and email, and demands a clear affirmative action for consent. Pre-ticked boxes fail that test outright.

UK GDPR governs something different: how you process the personal data behind that phone number. It gives customers subject access rights, sets rules for controllers and processors, and demands you can document your lawful basis. As one practitioner summary puts it, these regimes work together rather than substituting for each other. Satisfying PECR's consent rule doesn't automatically tick your UK GDPR documentation box, and vice versa.

This dual structure matters practically:

  • PECR consent answers "may I send this text?"
  • UK GDPR consent and documentation answer "can I prove I was allowed to, and can the recipient exercise their rights?"

The Data Use and Access Act 2025 raised the stakes for getting this wrong, pushing PECR penalties up to match UK GDPR's ceiling. That change alone should move consent hygiene from a compliance afterthought to a standing agenda item.

Valid consent under UK GDPR is freely given, specific, informed, unambiguous, and backed by a clear affirmative action. A customer ticking a box themselves counts; a box you've pre-ticked for them does not.

  1. Use a separate, unchecked opt-in box for SMS. Don't bundle it with email or postal marketing consent. State exactly what they're signing up for.
  2. Name the sender, frequency and purpose in the form copy. "Receive up to 2 texts a month from [Your Business] about appointment reminders and offers" beats a vague "yes, contact me".
  3. Link to your privacy notice at the point of capture, not buried three clicks away.
  4. Implement double opt-in where practical. Send a confirmation text ("Reply YES to confirm you'd like offers from [Business]. Reply STOP to opt out") and log the reply. This creates contemporaneous evidence that's far harder to challenge than a signed form filed away somewhere.
  5. Record the details immediately: phone number, timestamp, IP address or point of capture, method used, and the exact wording shown to the customer.

Pro Tip: Screenshot your consent form wording every time you change it. If a regulator asks about a sign-up from eighteen months ago, you need the wording as it existed then, not as it exists now.

Recordkeeping, platforms and DPAs: building an auditable trail

Practical guides recommend recording the exact consent wording, timestamp, collection channel, and supporting evidence for every contact. Most compliance teams retain these records for three to five years, long enough to cover typical complaint and audit windows, and export them regularly rather than trusting a single system to hold everything forever.

Your SMS platform matters here as much as your legal wording. Before signing with any provider, confirm it:

  • Processes STOP replies automatically and immediately, without manual intervention
  • Exposes a suppression list you can view and export on demand
  • Supports full audit-trail export in a usable format
  • Comes with a signed data processing agreement (DPA) that clarifies who is controller and who is processor

If your provider can't answer these points clearly, that's your answer about whether to sign.

Managing opt-outs, suppression lists and campaign hygiene

Reply STOP is the minimum opt-out standard gov.uk requires, but treat it as a floor, not a ceiling. Process every opt-out before your next send, not after.

  • Test every opt-out channel you offer (STOP, unsubscribe link, customer service request) and confirm they all write to the same suppression list.
  • Segment by consent scope. A customer who consented to appointment reminders hasn't consented to promotional offers, and sending anyway breaches PECR.
  • Audit your campaign flows monthly. Manual list exports and re-imports are where suppressed numbers quietly slip back into circulation.

Given that penalty exposure now runs to £17.5 million or 4% of global turnover under DUAA 2025, a stale suppression list is an expensive place to cut corners.

Common mistakes, enforcement pitfalls and quick fixes

Recurring enforcement patterns are strikingly consistent: invalid consent, slow opt-out handling, and reused third-party lists without proof of consent. Add pre-ticked boxes and bundled consent to that list, and you've covered most real-world failures.

If you spot any of these in your own systems:

  1. Pause the affected campaign segment immediately rather than continuing while you investigate.
  2. Run a re-permission campaign asking suspect contacts to actively re-confirm consent.
  3. Remove anyone who doesn't respond within a reasonable window.
  4. Document every remediation step with dates and actions taken.
  5. Consult legal counsel if the exposure involves a large list or a live complaint.

Pro Tip: Keep a simple remediation log from day one of any fix. Showing a regulator "we caught this and corrected it" lands very differently to them finding it first.

Manual consent tracking breaks down at volume: someone forgets to update a spreadsheet, a STOP reply gets missed on a Friday afternoon, a bought list gets loaded without a second thought. Talk2Aiva builds consent handling into the workflow itself, capturing enquiries across calls, SMS, website chat and social media with consent flags attached at the point of capture, not bolted on afterwards.

Hand updating consent on smartphone workflow

That structure means opt-in wording stays consistent across every channel, double opt-in confirmations fire automatically, and suppression lists update the moment someone replies STOP, rather than whenever a team member remembers to check. For a deeper look at how SMS fits into customer communication generally, see how SMS supports property follow-up and the wider legal picture in UK call recording law.

A pragmatic, risk-based view for SMEs

A pragmatic, risk-based view for SMEs — overview diagram

If you run a small service business, don't try to fix everything at once. Fix consent collection for individuals and sole traders first, because that's where misclassification risk concentrates. Make STOP processing immediate, non-negotiable, and centralise your consent logs in one exportable system.

Automation earns its place here precisely because manual tracking fails quietly. Task someone specific with testing your opt-out flow monthly, and keep evidence of that test.

— James Paul

Building compliant SMS consent by hand means juggling spreadsheets, form logic, and suppression lists across separate systems, and hoping nothing falls through the gaps between them. Talk2Aiva is the alternative to that manual patchwork: it captures consent at the point of enquiry across calls, SMS, chat and social media, then keeps that record, and the suppression list it feeds, in one auditable place.

Talk2Aiva

Guided onboarding means your consent workflows, opt-in wording, and double opt-in confirmations get set up correctly from day one, rather than retrofitted after an ICO complaint. Ongoing technical support means someone is checking your STOP handling behaves as it should, not just at launch but months later when campaign volume grows and the room for manual error grows with it. If you run appointment reminders alongside promotions, similar logic to the consent-scope segmentation in text marketing for salon growth applies directly to how Talk2Aiva separates transactional and promotional consent. See how it works on the Talk2Aiva platform page and book a walkthrough to see your own consent workflow mapped out.

Sources

For the primary documents behind this article: the ICO's PECR guidance covers consent and soft opt-in rules directly; gov.uk's direct marketing law page sets out sender identification and opt-out duties; and background on WhatsApp GDPR compliance for UK professionals covers adjacent messaging consent principles worth knowing.