Skip to content

Legal Considerations for Bulk SMS Marketing in the UK

Summary

  • Marketing texts count as electronic mail under PECR, so texting individual subscribers needs consent unless the soft opt-in applies.
  • Every marketing text must identify your business and carry a working opt-out, including messages sent to corporate subscribers.
  • The ICO can fine a business up to £17.5 million or 4% of annual global turnover for breaching PECR.
  • This guide explains the legal rules for bulk SMS marketing for startups and growing businesses in the United Kingdom.
  • LegalVision’s business lawyers specialise in advising clients on direct marketing and data protection compliance.

Tips for Businesses

Map every number on your list to how it was collected and when, and delete anything you cannot evidence. Put your business name and an opt-out in every message, including business-to-business sends. Ask any data supplier for consent records on 20 sample numbers before you buy. Speak to a data and privacy lawyer at LegalVision about checking consent and supplier arrangements before a bulk SMS campaign.

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

Bulk SMS marketing in the UK is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR. The Information Commissioner’s Office enforces it. Under PECR, a marketing text counts as electronic mail. You need consent before texting individual subscribers, a group that includes consumers, sole traders and certain partnerships, unless the soft opt-in applies. You do not need consent to text corporate subscribers. Every marketing text must identify your business and carry a working opt-out. Bulk SMS is cheap to run and quick to set up. Growth teams reach for it to clear stock, fill a launch list or bring lapsed customers back. The rules on who you may text, and on what basis, are tighter than most founders expect. This article explores key legal rules to be aware of if your business plans to send large-scale marketing texts.

Which Laws Apply to Your SMS Campaign

There are two sets of rules that apply to a bulk SMS campaign. One is the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR.

You may also need to follow the UK General Data Protection Regulation (UK GDPR) if your campaign uses personal data.

PECR: The Main Rules for Marketing Texts

PECR is the main law for SMS marketing in the UK. It controls the sending of electronic marketing messages and protects people from unwanted texts and spam.

Under PECR, marketing text messages are treated as electronic mail. The electronic mail rules therefore apply to messages sent by SMS.

Where the UK GDPR Also Applies

If your business stores or uses personal data that identifies individuals as part of SMS campaigns, you are processing personal data. In that situation, you must comply with UK GDPR requirements when handling that data.

In practice you follow both. Review how you collect phone numbers, and how your messages will be sent, before any campaign starts. Fixing a consent problem in a list of 5,000 numbers takes an afternoon. Fixing it after 500,000 texts have landed does not.

Who You Are Texting: Individual and Corporate Subscribers

PECR separates recipients into two groups for marketing messages: individual subscribers and corporate subscribers. Which group someone falls into changes what you must do before you press send.

Individual subscribers include consumers, sole traders and certain partnerships. Corporate subscribers include limited companies, limited liability partnerships and public bodies.

Here are the four differences that matter before you send a marketing email or sms:

What the rule coversIndividual subscribersCorporate subscribers
Who is in the groupConsumers, sole traders, certain partnershipsLimited companies, limited liability partnerships, public bodies
Consent before textingRequired in most cases, unless the soft opt-in appliesNot required under PECR
Identifying your businessRequired in every messageRequired in every message
Opt-out in every messageRequiredRequired

A list of business numbers is not automatically a corporate list. Sole traders sit on the individual side. A database of tradespeople, freelance designers or single-operator clinics needs consent in the same way a consumer list does.

Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.

What Valid Consent Looks Like

The rules are stricter when sending marketing messages to individuals. In most cases, your business must obtain valid consent before sending marketing texts to individual recipients. Consent must be freely given, specific, informed and unambiguous. The individual must take a clear positive action to demonstrate consent, such as ticking an opt-in box confirming they agree to receive marketing messages.

You cannot use pre-ticked boxes or unclear wording. Keep clear records of when and how each person gave consent and what they agreed to receive.

Record the wording that was on screen and the date the person agreed. A screenshot of your current sign-up form tells the ICO nothing about a number collected 18 months ago on a different form. Keeping consent records and a suppression list belongs inside the process, not in a clean-up job later.

The Soft Opt-In Exception

There is a limited exception called the soft opt-in. This allows your business to send marketing texts to existing customers who have bought from you or discussed buying, if certain rules are met:

  • you must have collected their contact details directly;
  • the details must have been obtained during a sale or negotiation;
  • the marketing must be about your own similar products or services;
  • you must give them a clear and simple way to opt out both when you collect their details and in every message.

In practice, this means giving people a clear opt-out option when you collect their details and including simple opt-out instructions in every text message.

What Counts as Your Own Similar Product or Service

Two parts of the soft opt-in catch growing businesses. The marketing must cover your own similar products or services, and you must have collected the number directly from the person you are texting.

The Similarity Test

On similarity, the ICO applies a reasonable expectation test. The question is whether, based on previous interactions, people reasonably expect direct marketing about your product or service. Someone who bought running shoes from you will expect a text about trainers. That same person will not expect a text about your new insurance product, even where both sit under one company.

Front page of publication
UK Data Protection and Privacy: A Legal Guide for Businesses

UK data protection law is complicated. This free guide covers UK GDPR,and explains lawful basis, data rights and staying compliant.

Download Now

Whose Products, and Whose Data

The words “your own” rule out more than most teams assume. You cannot use the soft opt-in for messages about other organisations or their products and services. It does not stretch across a group structure either. The ICO says the soft opt-in does not apply where someone else obtained the contact details for you, even another organisation inside your own group.

The word “directly” rules out bought data. Numbers from a partner, an affiliate, a lead generator or an acquisition were not collected during a sale or negotiation with that person. The soft opt-in is not available. You are back to consent, and generic consent covering any third party will not be enough.

You must watch three situations closely:

  • a second product line unrelated to the first;
  • an acquisition that brings you a customer database; and
  • a partner collecting sign-ups on your behalf.

In each case, split the list by what the person actually bought and by how the number reached you. Text the group that fits the soft opt-in, then run a consent campaign for the rest. Sending to the whole list because most of it is fine is how a compliant database turns into an unlawful send.

“Before a bulk send, pull 20 numbers off your list at random and try to produce the consent record for each one. If you cannot produce them, the list is not ready, and you have found that out for the cost of an hour rather than the cost of an ICO investigation.”

Kieran Ram
Kieran Ram Associate, LegalVision

What Every Marketing Text Must Show

Two requirements apply to every marketing text you send, whoever receives it. You must not disguise or conceal who you are. And you must give a valid contact address the recipient can use to opt out. The ICO applies both rules to individual and corporate subscribers, and to solicited as well as unsolicited messages.

The rules are generally more relaxed when sending marketing communications to corporate subscribers. Businesses can often send marketing messages to companies without obtaining consent.

There is one further point on business lists. Where a message identifies a specific person, the UK GDPR applies to that data, and that person has an absolute right to object to direct marketing. You stop when they object, whether they are a consumer or a procurement manager.

Buying Data and Using Third-Party SMS Providers

Most bulk SMS campaigns run through a third-party platform, and many use data the business did not collect itself. Neither arrangement moves the legal risk off your business.

Who the ICO Holds Responsible

PECR catches the business that sends an unlawful marketing message and the business that instigates it, meaning whoever arranged for it to go out. If you commissioned the campaign, you instigated it. The platform pressed send, and the ICO still comes to you.

What to Check Before You Buy a List

Bought data is where this usually goes wrong. The ICO expects you to check that any list is accurate, that the details were collected fairly, and that the consent is specific and recent enough. In practice that means seeing the consent record itself, not a warranty buried in the supplier’s terms.

KRA Consultancy Ltd is the case to look at. In June 2026 the ICO fined the company £300,000 for sending 5,575,715 texts to people who had been declined for loans. The data came from a third party and was up to three years old. KRA made no attempt to check whether it was accurate or whether anyone had consented. More than 60,000 people complained.

Before you sign with a supplier or buy a list, get three things in writing:

  • the exact consent wording each person saw, plus the date and source of that consent;
  • confirmation that your business was named at the point of collection, not described as a carefully selected partner;
  • who maintains the suppression list, how opt-outs flow back to you, and how quickly.

Then sample it. Ask for the consent record behind 20 numbers picked at random. A supplier who cannot produce records for 20 will not produce them for 200,000, and that is the request the ICO makes.

Your sender ID and message content work the same way. Anything sent under your brand is your message, even where an agency wrote the template.

What Happens If You Get It Wrong

The Information Commissioner’s Office (ICO) regulates compliance with PECR and UK data protection law in the United Kingdom. If you do not follow these rules, it can lead to complaints, enforcement action and harm to your business’ reputation.

How the ICO Finds Out

Individuals who receive unwanted marketing messages can complain directly to the ICO, or report a message by forwarding it to 7726. Even a relatively small number of complaints can bring a company’s marketing practices to the regulator’s attention.

If a business breaks the rules, the ICO may investigate and take action. This can include heavy fines or orders to stop unlawful marketing.

A recent case shows what that looks like. In January 2026 the ICO fined Allay Claims Ltd £120,000 for sending 4,046,947 marketing texts without valid consent, after more than 46,000 complaints.

The Fines and the ICO’s Powers

The maximum fine has gone up since that case. The enforcement provisions of the Data (Use and Access) Act 2025 commenced on 5 February 2026, and lifted PECR penalties to the UK GDPR level.

Businesses that fail to comply with electronic marketing rules may now face fines of up to £17.5 million or 4% of annual global turnover, whichever is higher.

The same Act made a broader set of changes to UK privacy law. It also gave the ICO new investigatory powers. Those include compelling a witness to attend an interview and requiring reports from approved persons. The Act creates a new body, the Information Commission, to take over the Information Commissioner’s functions. That changes who enforces the rules, not the rules you follow.

Do this before the campaign rather than after the first complaint. A short review of your consent records, your opt-out handling and your sender ID holds for every campaign that follows it.

Key Takeaways

Businesses planning to use bulk SMS marketing in the UK should ensure they understand the legal rules before sending any messages. Compliance with PECR and, where relevant, UK GDPR is essential to avoid complaints, regulatory action and financial penalties. Businesses should ensure they comply with the relevant consent rules, provide clear opt-out options, and keep appropriate records. Taking a careful approach to SMS marketing is vital for compliance and to help reduce legal and reputational risk.

LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced data and privacy lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.

Frequently Asked Questions

Can my business send marketing texts to companies without consent?

The rules are less strict for corporate subscribers. Consent is not required for limited companies, limited liability partnerships and public bodies. You must still identify your business and give a simple opt-out in every message. Sole traders count as individuals, so they need consent.

When can we rely on the soft opt-in for marketing texts?

Only where you collected the number directly during a sale or negotiation, the marketing covers your own similar products or services, and you gave a clear opt-out at collection and in every message. It does not cover bought lists.

What penalties can the ICO issue for breaching PECR?

The ICO can fine a business up to £17.5 million or 4% of annual global turnover, whichever is higher. It can also order a business to stop unlawful marketing. People affected by a breach may separately bring a claim for compensation.

Why should a business get legal advice before starting an SMS campaign?

Legal advice helps you confirm which PECR rules apply to your list, set consent wording that holds up, handle opt-outs correctly and check your UK GDPR position. It also covers higher-risk areas such as the soft opt-in and third-party data.

Register for our free webinars

When AI Is Misused: How One Business Responded Without Runaway Legal Fees

Online
How one business recovered its IP without incurring high legal costs after relying on an AI-drafted contract. Register for our free webinar.
Register Now

Ask A Lawyer: Terminations and Restructures After Fire and Rehire

Online
Fire and rehire rules change from January 2027. Join our free live Q&A webinar with an employment practice leader on managing terminations and restructures.
Register Now

Sponsoring Overseas Talent: What Your Business Needs to Know

Online
Learn what UK businesses need to know before sponsoring overseas workers. Register for our free webinar.
Register Now

Before You Sell Your Business: The Legal Steps That Make You Attractive To Buyers

Online
Get your business sale ready before buyers start due diligence. Register for our free webinar.
Register Now
See more webinars >

Kieran Ram

Associate | View profile

Kieran is an associate in LegalVision’s Corporate and Commercial team. He has completed a Law Degree, the Legal Practice Course and a Masters in Sports Law, specialising in Football Law.

Qualifications: Bachelor of Laws (Hons), Master of Laws, Legal Practice Course.

Read all articles by Kieran

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards