Marketing texts to individuals in the UK require valid consent under PECR and must also satisfy UK GDPR and the Data Protection Act. Before you send anything, check five things: documented consent, a clear opt-out, visible sender identity, compliant sending hours and proper recordkeeping. Business-to-business contacts work differently, so read on before you assume an exemption applies.
TL;DR:
- Valid consent must be collected separately and specifically for SMS marketing, with clear wording, timestamps, and records of who obtained it.
- Businesses must honor immediate, free opt-outs through simple replies like "STOP" and update suppression lists across all systems consistently.
- Sender identity must be clear, using either long numbers, short codes with registration, or alphanumeric IDs, with strict rules depending on volume and reply capabilities.
- Marketing messages sent outside of 9am to 8pm hours or containing misleading claims risk regulatory action, especially in sensitive sectors like healthcare or finance.
- Keeping thorough, accessible records of consent, opt-outs, and campaign details is crucial to defend against ICO enforcement or penalties.
Table of Contents
- Five core compliance requirements for SMS marketing in the UK
- What counts as valid consent for SMS in the UK
- Opt-outs, suppression lists and ongoing list hygiene
- Sender identity and number types: what you must show and the special short-code rules
- Approved sending hours, message content limits and sensitive sectors
- B2B v B2C: when PECR consent applies and how the soft opt-in works for business contacts
- Record keeping, lawful basis and how to document compliance
- Penalties, enforcement examples and director-level risks
- Practical checklist and ready-to-use templates
- How Talk2Aiva helps service businesses run compliant SMS
- Differences in SMS marketing rules post-Brexit compared to EU regulations
- Specific rules for SMS marketing to numbers registered with TPS
- Guidance on cross-border SMS marketing targeting UK recipients
- Summary of recent legal updates or upcoming changes in UK SMS marketing law
- Why compliance deserves priority over campaign volume
- Get compliant SMS marketing set up without the guesswork
- Where to check the rules yourself
- Sources
- FAQ
Five core compliance requirements for SMS marketing in the UK
Before any campaign goes out, run it against this checklist. Missing even one of these points is what turns an ordinary campaign into a regulatory problem.
- Consent: must be prior, specific and recorded, not inferred from a past purchase or a general sign-up.
- Opt-out: must be immediate, free and simple, such as a reply of "STOP", and it must be honoured across every system that touches that contact.
- Sender identity: never conceal who is messaging; include a contact method or a link to a privacy policy that explains the business behind the text.
- Approved hours: respect what recipients would reasonably expect, avoiding early mornings, late evenings and anything that feels intrusive.
- Short codes and aggregators: if you use a network short code, follow the extra registration and consent rules that come with it.
Most enforcement cases do not start with a mystery. They start with one of these five basics being skipped under time pressure, usually consent or opt-out handling. Treat this list as your pre-flight check every time, not a one-off exercise you did when the business launched.
What counts as valid consent for SMS in the UK
Consent for SMS marketing has to meet the UK GDPR standard: freely given, specific, informed and unambiguous. A vague checkbox buried in a terms-and-conditions block does not meet that bar, and neither does a single tick that covers email, SMS and phone calls all at once. The ICO's guidance on marketing and data protection is clear that "legitimate interests" is not a safe fallback where PECR requires consent, so SMS needs its own, separate opt-in.
In practice, this means:
- Pre-ticked boxes are not valid consent and never have been.
- SMS consent must be collected separately from email or phone consent, not bundled into one general marketing tick.
- The wording shown to the person at the point of sign-up has to say, in plain terms, that they will receive marketing texts.
Capture points vary by business. A web form should say exactly what the person is signing up for, not just "stay in touch". A checkout flow needs its own SMS tick box, separate from the order confirmation. In-person "text JOIN to this number" campaigns need the same clarity, just delivered differently. Our practical steps for capturing UK GDPR consent for SMS go into this in more depth.
Whichever method you use, store four things for every contact: the exact consent text shown, the timestamp, the channel or source where it was collected, and some record of who collected it (a form ID, a till receipt reference, or a staff member's name for in-person sign-ups).
Pro Tip: Screenshot your sign-up form every time you change its wording, and date the screenshot. It is the fastest way to prove what a customer actually saw and agreed to.
Opt-outs, suppression lists and ongoing list hygiene
An opt-out has to be free, immediate and simple. A single-keyword reply like "STOP" is the standard, paired with a confirmation message that tells the person they have been removed. Web-based unsubscribe links work too, provided they do not require a login or multiple steps.
The harder part is what happens after someone opts out. That person needs to land on a suppression list that every system checks before the next send, including your CRM, your SMS platform and any third-party tool a sales team might use separately.
- Confirm every "STOP" reply triggers an automatic, immediate removal, not a manual process someone does later.
- Test the suppression list against your CRM and campaign tool regularly, not just when something goes wrong.
- Re-check suppression after any system migration, since this is the point where people most often get re-added by accident.
Our guide to two-way SMS for service businesses covers how to automate STOP handling without manual intervention, which removes the human error that causes most list hygiene failures.
Sender identity and number types: what you must show and the special short-code rules
You cannot disguise who is sending a marketing text, and you must give recipients a working way to contact you or opt out. That is a plain requirement under PECR and the ICO's business-to-business marketing guidance, which sets out identity obligations alongside the consent rules.
The number type you choose affects how much extra compliance work you take on:
- Long numbers (standard mobile-style numbers) are the simplest to set up and work well for two-way conversations, but they carry lower sending volumes.
- Network short codes support high-volume sending and look more official, but they require separate registration with mobile networks and stricter proof of consent before you are approved to use them.
- Alphanumeric sender IDs (a business name instead of a number) are good for one-way broadcast messages but cannot receive replies, so they are a poor fit if you need STOP handling built into the same thread.
Short codes exist because of the volume and reputational risk involved, so networks demand tighter consent evidence and faster complaint handling before granting access.
Approved sending hours, message content limits and sensitive sectors
UK practice treats marketing texts outside normal daytime hours as a breach of reasonable expectations, so most businesses send only between 9am and 8pm and avoid Sundays and bank holidays for anything promotional. Content also has to stay honest: no misleading claims, no urgency language that cannot be justified, and no promotion of prescription-only medicines to the general public.
Recent MHRA and ASA advertising investigations show that medicinal product promotion gets particular scrutiny, and the same caution applies to financial promotions, which can fall under FCA rules. When your business sits in a regulated sector, check the relevant regulator's current guidance before the campaign goes live, not after a complaint lands.
B2B v B2C: when PECR consent applies and how the soft opt-in works for business contacts
PECR treats "corporate subscribers" differently from individual subscribers. A limited company's generic inbox can often be messaged without prior consent, but a sole trader or many partnerships are treated as individual subscribers, meaning the same consent rules apply as for any consumer. The ICO's business-to-business guidance sets this distinction out directly, and it catches out a lot of businesses that assume "B2B" automatically means "no consent needed".
The soft opt-in exception lets you message existing customers without fresh consent, but only under strict conditions: you collected their details during a sale or sale negotiation, you are marketing similar products or services, and you gave them a clear chance to opt out at the time and in every message since.
If you cannot confirm whether a contact is a genuine corporate subscriber, the safer route is to treat them as an individual and capture consent anyway. Sole traders are the most commonly misclassified group, and the cost of asking for consent is far lower than the cost of an ICO complaint.
Record keeping, lawful basis and how to document compliance
If the ICO ever asks you to justify a campaign, you need to produce evidence quickly, not reconstruct it from memory. Build your recordkeeping around these items:
- The exact wording of the consent request shown to the contact.
- The timestamp of when consent was given.
- The source: web form, checkout, point-of-sale terminal or in-person sign-up.
- Who or what collected it, whether a specific member of staff, a form ID or a till system reference.
- Proof that an opt-out option was visible at the point of collection.
Store these fields inside your CRM or marketing platform so they are searchable by contact, not buried in a spreadsheet nobody updates. Run an internal audit every quarter: pull a random sample of contacts and check that each one has a complete consent record.
Pro Tip: Keep consent records for as long as you keep the contact on your marketing list, plus a reasonable period after removal, in case a complaint arrives after the fact.
If the ICO does request records, having this audit trail ready, rather than assembled under pressure, is usually the difference between a quick resolution and a drawn-out investigation.
Penalties, enforcement examples and director-level risks
The ICO can issue fines and enforcement notices for breaches of PECR, and where a company does not pay, the Insolvency Service can step in. One GOV.UK case describes a director banned after a firm generated tens of thousands of complaints over unlawful high-interest loan text spam. A separate GOV.UK example shows a director disqualified after a company's unsolicited marketing led to fines it failed to pay.
If you receive a complaint or an enforcement notice, pause the campaign immediately, pull every consent record for the affected contacts, and respond to the regulator with your documentation rather than assumptions.
Practical checklist and ready-to-use templates
Here are templates you can adapt directly.
Web form consent example: "Tick here to receive offers and appointment reminders by text from [Business Name]. Reply STOP at any time to opt out. See our privacy policy for details."
In-person text-to-join example: "Text JOIN to [number] to receive offers and updates from [Business Name] by SMS. Msg frequency varies. Reply STOP to unsubscribe at any time."
STOP confirmation example: "You have been unsubscribed from [Business Name] marketing texts and will not receive further messages. Reply JOIN to opt back in."
Before sending any campaign, work through this list:
- Confirm every recipient has a logged, separate SMS consent record.
- Cross-check the send list against your current suppression list.
- Verify the sender ID or number displays correctly and a working contact method is included.
- Review the message content for accuracy and any sector-specific restrictions.
- Confirm the send window falls within acceptable UK hours.
- Log the campaign details (list, content, send time) for your audit trail.
Our compliance checklist for follow-up messaging builds on this with ready-to-use follow-up sequences that stay inside these same rules.
How Talk2Aiva helps service businesses run compliant SMS
Some communication platforms centralise consent capture, STOP handling and suppression list updates across calls, text, web chat and social media, so a reply on one channel propagates everywhere automatically rather than depending on manual checks. Subscriptions often include guided onboarding and ongoing technical support, helping ensure correct set up from the start. For service businesses juggling bookings, follow-ups and enquiries, having consent and opt-out logs built into the platform can reduce the chance of a suppression gap slipping through.
Differences in SMS marketing rules post-Brexit compared to EU regulations
PECR has stayed in force in the UK after Brexit, and it continues to require prior consent for SMS marketing to individual subscribers in broadly the same way it did before. The EU's equivalent framework, the ePrivacy Directive, is implemented separately by each EU member state, so a UK business messaging contacts in the EU may need to check that country's specific transposition rather than assuming PECR's wording applies there too.
The UK GDPR, which sits alongside PECR for lawful basis and data handling, was carried over from the EU GDPR at the point of Brexit and still mirrors it closely, but the UK can now amend it independently through domestic legislation. That means UK and EU rules could diverge further over time, even though they currently align closely on consent standards.
For most UK service businesses marketing to UK recipients only, this divergence is not yet a practical problem: PECR and UK GDPR set the standard, and that standard has not materially changed since EU exit. The risk mainly appears for businesses that market across borders, where assuming "UK rules apply everywhere" is a mistake worth avoiding.

Specific rules for SMS marketing to numbers registered with TPS
The Telephone Preference Service exists primarily for live telephone calls, not SMS text messages, so being registered with TPS does not by itself block marketing texts to that number. PECR's own consent requirement is what actually governs SMS marketing: if you do not have valid consent for a mobile number, the message is non-compliant regardless of TPS registration.
In practice, though, a number on TPS often belongs to someone who has actively signalled they do not want unsolicited marketing contact, so treating a TPS listing as an extra warning sign is sensible even where it is not a legal bar to texting. If a contact on your list is TPS-registered and you cannot produce a clear, separate SMS consent record for them, the safest move is to remove them rather than rely on an assumption that your consent for calls also covers text.
Businesses that run both call and SMS campaigns should keep TPS checks and SMS consent checks as separate processes, since passing one does not confirm compliance with the other.
Guidance on cross-border SMS marketing targeting UK recipients
If a business based outside the UK sends marketing texts to UK mobile numbers, PECR and UK GDPR still apply because the rules are about where the recipient is, not where the sender is based. An overseas company cannot rely on its home country's lighter rules if the people receiving the texts are in the UK.
This matters for UK businesses too if you use an overseas SMS platform or aggregator: you remain responsible for ensuring the consent, opt-out and identity requirements are met, even if the technical sending happens through infrastructure based elsewhere. Checking that your provider supports the operational basics, a clear STOP flow, suppression list syncing and UK-appropriate sending hours, is part of your own compliance responsibility, not something you can delegate entirely to the vendor.
If you are expanding into markets outside the UK, do not assume your UK consent records or opt-out language are sufficient there. Each market has its own electronic marketing rules, and the safest approach is to treat every country you message into as having its own standard to meet.
Summary of recent legal updates or upcoming changes in UK SMS marketing law
PECR's core consent requirement for SMS marketing has not changed, but enforcement activity has stayed active, with the ICO continuing to pursue fines and the Insolvency Service continuing to cooperate on director disqualifications where penalties go unpaid, as shown in the GOV.UK enforcement case from June 2026. That pattern signals that regulators are treating unpaid fines and large-scale unlawful marketing as a personal risk for directors, not just a company one.
Data protection reform has been under discussion in the UK for several years, and businesses should expect incremental changes to UK GDPR's implementing legislation rather than a wholesale rewrite of PECR's consent standard for electronic marketing. Until any such change is confirmed in legislation, the safest approach remains: assume the current consent, opt-out and recordkeeping obligations will continue to apply, and build your processes to the current standard rather than waiting for a relaxation that may not arrive.
Why compliance deserves priority over campaign volume
The businesses that get burned are rarely the ones that misunderstood the law. They are the ones that understood it and still let a suppression list fall out of sync, or let a sales team send from a tool that was not connected to the main CRM. Fix consent capture and opt-out handling first, because that is where the real risk sits.
Block out fifteen minutes this week and run your current SMS list against the checklist in this guide. It is a small cost against the alternative.
— James Paul
Get compliant SMS marketing set up without the guesswork
Talk2Aiva takes the operational weight off compliance by building consent capture, STOP handling and suppression list management straight into your communications, so you are not relying on separate tools that do not talk to each other.
- Guided onboarding and ongoing technical support included with every subscription, so your setup is checked rather than left to chance.
- Centralised consent and conversation logs across calls, SMS, web chat and social media.
- Automated STOP handling that updates suppression lists across your systems instantly.
- 24/7 support for enquiries, so compliance does not depend on someone manually checking replies.
If you would rather have this built and checked for you than manage it alone, visit the Talk2Aiva plans page to see the Software Suite, Ultimate AI Suite and Elite AI Suite, and get your SMS compliance set up properly from day one.
Where to check the rules yourself
For the primary rules, read PECR Regulation 22 and the ICO's direct marketing guidance. For a messaging-channel GDPR checklist that extends beyond SMS, see SemLocal's WhatsApp GDPR guide.
Sources
- The Privacy and Electronic Communications (EC Directive) Regulations 2003 No. 2426 — Regulation 22
- Marketing and data protection in detail — ICO
FAQ
What are the regulations for SMS marketing in the UK?
SMS marketing to individuals requires prior consent under PECR, alongside UK GDPR requirements for how that consent is collected and recorded. You also need a clear opt-out, honest sender identity and reasonable sending hours.
How do I send bulk SMS in the UK legally?
You need a documented, separate consent record for every contact before sending bulk marketing texts, plus a working suppression list that updates the moment someone opts out. Many businesses use a dedicated platform or short code with built-in consent and STOP handling to manage this at volume.
How does SMS marketing work under UK rules?
A business collects specific consent for text messages, sends marketing content through a long number, short code or alphanumeric sender ID, and must honour any STOP reply immediately. The ICO's guidance on direct marketing sets out how these obligations apply differently to individual and corporate subscribers.
Does registering with TPS stop me receiving marketing texts?
No, the Telephone Preference Service mainly covers live telephone calls, not SMS. SMS marketing is governed separately by PECR's consent requirement, so a number on TPS still needs its own valid SMS consent record before you can text it.
What happens if my business breaches SMS marketing rules?
The ICO can issue fines and enforcement notices, and where fines go unpaid, the Insolvency Service has disqualified directors in cases involving large-scale unlawful marketing, as seen in recent GOV.UK enforcement cases. Keeping clear consent and opt-out records is the main way to defend against a complaint.

