SMS marketing compliance is a legal requirement, not a nice-to-have — the rules exist to protect recipients from unwanted messages and to protect your business from significant fines. Because Havari serves UK businesses first, this guide gives UK GDPR and PECR the same depth as the US TCPA rules that most SMS guides default to. Get these fundamentals right once and compliance becomes a background process rather than a recurring headache.
Text messages land directly on a personal device, which is exactly why regulators treat SMS marketing more strictly than email. In the United States, the Telephone Consumer Protection Act (TCPA) governs marketing texts. In the UK, two frameworks apply together: UK GDPR (data protection) and PECR — the Privacy and Electronic Communications Regulations (direct marketing rules). If you send SMS to UK contacts, PECR is the one most people miss, and it's usually the one that gets enforced.
The TCPA requires prior express written consent before sending marketing texts, a clear and easy opt-out mechanism, and immediate honouring of opt-out requests. Violations carry statutory damages of up to $1,500 per message when a court finds a willful violation, which is why US businesses take consent documentation so seriously.
UK GDPR governs how you collect, store and use personal data (including phone numbers) — it requires a lawful basis for processing, transparency about how data is used, and rights for individuals to access or request deletion of their data. PECR sits alongside it and specifically regulates electronic marketing: for SMS marketing to individuals, you generally need specific, informed, opt-in consent before sending — consent gathered for one purpose (e.g. account sign-up) cannot automatically be repurposed for marketing texts. The Information Commissioner's Office (ICO) enforces PECR in the UK and can issue fines separate from UK GDPR penalties, so a single non-compliant campaign can trigger action under both frameworks.
Soft opt-in is narrow — don't over-rely on it
PECR has a limited 'soft opt-in' exception for existing customers marketing similar products, but it comes with strict conditions (the contact details must have been collected during a sale or negotiation, and an opt-out must have been offered at the time). Treat it as an exception, not your default consent strategy.
“Compliance is not just about avoiding fines — it's about building trust and respect with your customers.”
Building a compliant opt-in flow
Use clear, affirmative opt-in
Unchecked web form boxes, SMS keyword sign-ups (text JOIN to a shortcode), or point-of-sale sign-ups with explicit marketing language. Never pre-check a consent box or assume consent from an existing relationship.
Disclose what they're agreeing to
State the business name, the type of messages they'll receive, roughly how often, and that message/data rates may apply. Vague consent language is a common source of disputes on both sides of the Atlantic.
Record the consent event
Log the timestamp, the method of opt-in, and the exact wording shown to the customer at the time. This record is what protects you if consent is ever challenged.
Separate consent by message type where possible
Best practice is to let customers opt in separately to promotions, appointment reminders, and account alerts, rather than bundling everything into one blanket consent.
Every marketing message should include a simple opt-out instruction, typically 'Reply STOP to unsubscribe.' Opt-outs must be processed immediately — not at the end of the day, not after a manual review. A good platform automatically suppresses the number the moment STOP is received and sends a one-time confirmation. Keeping a manually maintained suppression list is one of the most common ways businesses accidentally message someone who has already opted out.
Message timing and content essentials
If your consent practices are ever questioned — by a regulator, a customer complaint, or in litigation — your records are your defence. Keep detailed logs of when, where and how consent was obtained, the full history of messages sent to each contact, and every opt-out request with its timestamp. Manual spreadsheets get out of date quickly; this is exactly the kind of process worth automating rather than tracking by hand.
Let your platform carry the compliance load
A platform like Havari handles consent capture, automatic STOP/opt-out processing, and message history in one place, so your team doesn't have to reconstruct compliance records manually when a question comes up.
Can I text customers who gave me their number in person?
Not for marketing purposes without separate, explicit consent for SMS marketing specifically. A number collected for a delivery update or account setup doesn't automatically authorise promotional texts under TCPA, UK GDPR or PECR.
What's the difference between transactional and marketing SMS?
Transactional messages — order confirmations, appointment reminders, delivery updates — generally face lighter consent requirements than promotional marketing messages, but you still need a lawful basis to message the person and should always offer an opt-out.
Does UK GDPR apply if my customers are only in the UK?
Yes. If you're a UK business messaging UK residents, UK GDPR and PECR both apply directly, regardless of whether you also serve US customers under TCPA.
Do I need separate consent for different message types?
It's best practice. Letting customers opt in and out of promotions, reminders and alerts independently reduces complaints and gives you a defensible, granular consent record.
SMS compliance can feel like a legal maze, but it comes down to a few consistent habits: get clear consent, make opting out effortless, respect timing and content expectations, and keep a paper trail of all of it. Treat compliance as the foundation of trust with your audience rather than a box-ticking exercise, and it stops being a risk and starts being a competitive advantage.