- Resources
- >>
- FAQ Category
- >>
- UK SMS Compliance
UK SMS Compliance
The main UK rules for SMS marketing
In the UK, SMS marketing is mainly governed by UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, consumer protection rules and any sector-specific rules that apply.
Businesses in regulated sectors, such as finance, insurance, claims, health, legal services, credit, investments, mortgages or funeral plans, may need extra approval or compliance checks before sending messages.
Consent for SMS Marketing
For SMS marketing to individuals, businesses usually need valid consent unless a specific exception applies.
Consent should be freely given, specific, informed, unambiguous, actively given, recorded and easy to withdraw.
A good consent record should show who consented, when they consented, how they consented, what wording they saw, what they agreed to receive, which business they agreed to hear from and how they can opt out.
Pre-ticked boxes, hidden consent, unclear wording or bundled consent should not be relied on.
Bought-in data and third-party lists
Businesses should be extremely careful with bought-in data, third-party lists or scraped contact data.
Before using third-party data for SMS, a business should be able to prove that the data was collected lawfully, the recipient agreed to receive SMS marketing from that business or a clearly defined category of business, the consent covers the intended campaign, the consent is recent enough to remain valid, privacy information was provided and opt-outs have been respected.
WeAreSMS may refuse campaigns using third-party or purchased data where the compliance position is unclear.
Opt-outs
Every marketing SMS should include a clear and simple way to opt out.
When someone opts out, the business should stop sending marketing messages covered by that opt-out.
Privacy Information
Before using someone’s personal data, businesses should provide clear privacy information.
This should explain who is using the data, what data is being used, why it is being used, the lawful basis, how long it will be kept, who it may be shared with, how the person can exercise their rights and how they can complain.
For SMS campaigns, privacy information may be provided through a privacy policy, data collection notice, form wording, campaign landing page or other clear route.
Message Content
SMS messages should be clear, honest and not misleading.
A compliant message should usually make clear who the message is from, why the recipient is being contacted, what action is being requested, whether the message is marketing and how the recipient can opt out.
Businesses should avoid pressure tactics, misleading urgency, fake personalisation, unclear sender identity, overstated claims, regulated claims without approval and excessive follow-up messages.
Regulated Sectors
Some sectors require extra care, including financial services, insurance, claims management, debt or credit, healthcare, legal services, funeral plans, investments, mortgages, gambling and high-risk offers.
Campaigns in regulated sectors may require review by a compliance officer, authorised person or legal adviser before launch. We Are SMS may ask for confirmation that regulated-sector messages have been reviewed and approved before sending.
Client Responsibilities
Before launching an SMS campaign, clients should confirm that the data was collected lawfully, the campaign has a valid lawful basis, consent is available where required, soft opt-in is only used where the rules are met, privacy information has been provided, message content is accurate and approved, opt-out wording is included, suppression lists have been checked and regulated-sector approval has been obtained where needed.
We Are SMS may refuse, pause or stop any campaign where compliance information is incomplete or where the campaign may create legal, regulatory, consumer or reputational risk.
Marketing SMS and service SMS
A marketing SMS promotes, advertises or encourages someone to buy, enquire, apply, book, renew or engage with a product or service. Marketing SMS usually requires the correct consent or another valid compliant route before sending.
A service SMS provides necessary information about an existing service, booking, order, account or appointment. Service messages should not be used to hide marketing content. If a service message includes promotional wording, it may be treated as marketing.
Soft Opt-in
Soft opt-in is a limited exception that may allow a business to send marketing texts to existing customers without fresh consent, but only where specific conditions are met.
A business should only rely on soft opt-in where the contact details were collected directly from the person during a sale or negotiation for a sale, the marketing relates to similar products or services, the person was given a clear chance to opt out when details were collected, and the person is given a clear chance to opt out in every later message.
Soft opt-in should not normally be used for cold prospects, bought-in lists, scraped data or third-party data.
B2B SMS marketing
Business-to-business marketing can still involve personal data, especially when contacting sole traders, partnerships, individual employees or named business contacts.
Businesses should consider whether PECR applies, whether the number belongs to an individual, sole trader or corporate subscriber, whether the person would reasonably expect the message, whether the message is relevant to their role, whether there is a lawful basis under UK GDPR and whether there is a clear opt-out.
Even where consent is not required, it is good practice to respect objections and maintain a do-not-contact list.
Suppression Lists
A suppression list is a record of people who should not be contacted for certain marketing purposes.
Suppression lists help businesses avoid contacting people who have opted out, objected or withdrawn consent.
Suppression records should be used carefully. The purpose is not to continue marketing to someone, but to make sure they are not contacted again in error
Data Accuracy
Businesses should take reasonable steps to make sure the data they use is accurate and up to date.
Before sending a campaign, businesses should check duplicate numbers, invalid numbers, suppression lists, existing opt-outs, contact source, consent status, campaign relevance and data age.
AI-assisted SMS
We Are SMS may use AI-assisted tools to support message drafting, lead qualification, routing, replies, testing or campaign workflows.
Businesses should ensure AI-assisted SMS uses approved wording, does not mislead recipients, does not dishonestly pretend to be a person, does not pressure vulnerable people, does not make regulated claims without approval, routes sensitive replies to a human and respects opt-outs.
WeAreSMS compliance controls
WeAreSMS can support responsible campaign management through opt-out handling, suppression list support, campaign review, message templates, consent checks, data source checks, reply tracking, lead routing, audit trail support, approval steps and campaign reporting.
These controls are designed to support compliance, but clients remain responsible for the lawful use of their own data and campaign content.
Our Position
WeAreSMS is built for responsible messaging.
We support businesses that want to create genuine conversations with people who can lawfully be contacted.
We do not support spam, misleading outreach, unlawful data use or campaigns that ignore opt-outs.