Every channel you message customers on in the UK sits under the same broad umbrella of data protection and privacy law, even though the rules feel different from platform to platform. Get consent and opt-outs wrong and you risk complaints, ICO enforcement, and damage to a customer relationship you were trying to strengthen. This guide walks through the basics of UK GDPR and PECR as they apply to SMS, WhatsApp, Email, Instagram and Messenger, and how to build a messaging setup that stays compliant by default.
UK GDPR governs how you collect, store and use personal data — including phone numbers, email addresses and message content. PECR (the Privacy and Electronic Communications Regulations) sits alongside it and specifically covers electronic marketing, including SMS, email, and increasingly the messaging apps businesses now use. In practice, most compliance questions for messaging come back to one or both of these.
The simple version
If a message is transactional (an order update, an appointment reminder, a reply to something the customer asked) you generally have more latitude. If a message is marketing (a promotion, a discount code, a newsletter) you need clear consent and a working opt-out, regardless of which channel it's sent on.
PECR generally requires opt-in consent for marketing messages sent by electronic means, with a narrow exception for existing customers being marketed similar products they've bought before (sometimes called the 'soft opt-in'). Consent needs to be freely given, specific, and recorded — a pre-ticked box or a buried clause in your terms doesn't count. It's worth keeping a record of when and how someone consented, since that's exactly what you'd need to show if a complaint ever reached the ICO.
What good consent looks like
An opt-out that's technically present but practically broken is arguably worse than having none at all, because it creates a paper trail of a customer trying to stop hearing from you and failing. Every channel has its own natural opt-out mechanism, and it needs to be tested, not just assumed to work.
Channel-by-channel opt-out basics
UK GDPR expects you to hold only the personal data you actually need, and to have a clear reason for keeping it. For messaging platforms this usually means thinking about how long conversation history is retained, who inside your business can see it, and whether contact records are being kept up to date rather than accumulating stale, unconsented data over time. A platform that gives you one contact record per customer across channels makes this far easier to manage than five separate exports sitting in different tools.
“The ICO's guidance is consistent across formats: the format changes, the underlying obligation to be fair, lawful and transparent with people's data does not.”
Havari brings SMS, WhatsApp, Email, Instagram and Messenger into a single shared inbox with one contact record per customer, which means consent status and opt-outs are visible in one place rather than scattered across separate tools. STOP replies and channel-level opt-outs are handled automatically, so a customer who opts out on one channel doesn't keep receiving messages because a different tool never got the memo.
Do I need separate consent for each channel?
It's good practice to be specific about which channels you'll use when you collect consent, since a customer who agreed to email updates hasn't necessarily agreed to WhatsApp messages. Being explicit avoids ambiguity later.
Does replying to a customer's own message count as marketing?
Generally no — responding to an enquiry or providing service information the customer has asked for is treated differently from unsolicited marketing, though it's still good practice to keep transactional and promotional content clearly separated.
What happens if someone opts out but I keep messaging them?
This is one of the most common sources of complaints to the ICO. It's a strong reason to use a platform where opt-outs are enforced centrally, rather than relying on manual list management across multiple tools.
None of this needs to be complicated in practice. Get consent properly, make opt-outs genuinely easy, keep one clean record per customer, and treat every channel with the same basic respect for what the customer agreed to. That's most of UK messaging compliance covered — the rest is detail.