Summary
- Marketing texts count as electronic mail under PECR, so texting individual subscribers needs consent unless the soft opt-in applies.
- Every marketing text must identify your business and carry a working opt-out, including messages sent to corporate subscribers.
- The ICO can fine a business up to £17.5 million or 4% of annual global turnover for breaching PECR.
- This guide explains the legal rules for bulk SMS marketing for startups and growing businesses in the United Kingdom.
- LegalVision’s business lawyers specialise in advising clients on direct marketing and data protection compliance.
Tips for Businesses
Map every number on your list to how it was collected and when, and delete anything you cannot evidence. Put your business name and an opt-out in every message, including business-to-business sends. Ask any data supplier for consent records on 20 sample numbers before you buy. Speak to a data and privacy lawyer at LegalVision about checking consent and supplier arrangements before a bulk SMS campaign.
On this page
- Which Laws Apply to Your SMS Campaign
- Who You Are Texting: Individual and Corporate Subscribers
- Consent and the Soft Opt-In
- What Counts as Your Own Similar Product or Service
- What Every Marketing Text Must Show
- Buying Data and Using Third-Party SMS Providers
- What Happens If You Get It Wrong
- Key Takeaways
- Frequently Asked Questions
Bulk SMS marketing in the UK is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR. The Information Commissioner’s Office enforces it. Under PECR, a marketing text counts as electronic mail. You need consent before texting individual subscribers, a group that includes consumers, sole traders and certain partnerships, unless the soft opt-in applies. You do not need consent to text corporate subscribers. Every marketing text must identify your business and carry a working opt-out. Bulk SMS is cheap to run and quick to set up. Growth teams reach for it to clear stock, fill a launch list or bring lapsed customers back. The rules on who you may text, and on what basis, are tighter than most founders expect. This article explores key legal rules to be aware of if your business plans to send large-scale marketing texts.
Which Laws Apply to Your SMS Campaign
There are two sets of rules that apply to a bulk SMS campaign. One is the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR.
PECR: The Main Rules for Marketing Texts
PECR is the main law for SMS marketing in the UK. It controls the sending of electronic marketing messages and protects people from unwanted texts and spam.
Under PECR, marketing text messages are treated as electronic mail. The electronic mail rules therefore apply to messages sent by SMS.
Where the UK GDPR Also Applies
If your business stores or uses personal data that identifies individuals as part of SMS campaigns, you are processing personal data. In that situation, you must comply with UK GDPR requirements when handling that data.
In practice you follow both. Review how you collect phone numbers, and how your messages will be sent, before any campaign starts. Fixing a consent problem in a list of 5,000 numbers takes an afternoon. Fixing it after 500,000 texts have landed does not.
Who You Are Texting: Individual and Corporate Subscribers
PECR separates recipients into two groups for marketing messages: individual subscribers and corporate subscribers. Which group someone falls into changes what you must do before you press send.
Here are the four differences that matter before you send a marketing email or sms:
| What the rule covers | Individual subscribers | Corporate subscribers |
| Who is in the group | Consumers, sole traders, certain partnerships | Limited companies, limited liability partnerships, public bodies |
| Consent before texting | Required in most cases, unless the soft opt-in applies | Not required under PECR |
| Identifying your business | Required in every message | Required in every message |
| Opt-out in every message | Required | Required |
A list of business numbers is not automatically a corporate list. Sole traders sit on the individual side. A database of tradespeople, freelance designers or single-operator clinics needs consent in the same way a consumer list does.
Continue reading this article below the formCall 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.
Consent and the Soft Opt-In
What Valid Consent Looks Like
The rules are stricter when sending marketing messages to individuals. In most cases, your business must obtain valid consent before sending marketing texts to individual recipients. Consent must be freely given, specific, informed and unambiguous. The individual must take a clear positive action to demonstrate consent, such as ticking an opt-in box confirming they agree to receive marketing messages.
Record the wording that was on screen and the date the person agreed. A screenshot of your current sign-up form tells the ICO nothing about a number collected 18 months ago on a different form. Keeping consent records and a suppression list belongs inside the process, not in a clean-up job later.
The Soft Opt-In Exception
There is a limited exception called the soft opt-in. This allows your business to send marketing texts to existing customers who have bought from you or discussed buying, if certain rules are met:
- you must have collected their contact details directly;
- the details must have been obtained during a sale or negotiation;
- the marketing must be about your own similar products or services;
- you must give them a clear and simple way to opt out both when you collect their details and in every message.
In practice, this means giving people a clear opt-out option when you collect their details and including simple opt-out instructions in every text message.
What Counts as Your Own Similar Product or Service
Two parts of the soft opt-in catch growing businesses. The marketing must cover your own similar products or services, and you must have collected the number directly from the person you are texting.
The Similarity Test
On similarity, the ICO applies a reasonable expectation test. The question is whether, based on previous interactions, people reasonably expect direct marketing about your product or service. Someone who bought running shoes from you will expect a text about trainers. That same person will not expect a text about your new insurance product, even where both sit under one company.
UK data protection law is complicated. This free guide covers UK GDPR,and explains lawful basis, data rights and staying compliant.
Whose Products, and Whose Data
The words “your own” rule out more than most teams assume. You cannot use the soft opt-in for messages about other organisations or their products and services. It does not stretch across a group structure either. The ICO says the soft opt-in does not apply where someone else obtained the contact details for you, even another organisation inside your own group.
The word “directly” rules out bought data. Numbers from a partner, an affiliate, a lead generator or an acquisition were not collected during a sale or negotiation with that person. The soft opt-in is not available. You are back to consent, and generic consent covering any third party will not be enough.
You must watch three situations closely:
- a second product line unrelated to the first;
- an acquisition that brings you a customer database; and
- a partner collecting sign-ups on your behalf.
In each case, split the list by what the person actually bought and by how the number reached you. Text the group that fits the soft opt-in, then run a consent campaign for the rest. Sending to the whole list because most of it is fine is how a compliant database turns into an unlawful send.
“Before a bulk send, pull 20 numbers off your list at random and try to produce the consent record for each one. If you cannot produce them, the list is not ready, and you have found that out for the cost of an hour rather than the cost of an ICO investigation.”
What Every Marketing Text Must Show
Two requirements apply to every marketing text you send, whoever receives it. You must not disguise or conceal who you are. And you must give a valid contact address the recipient can use to opt out. The ICO applies both rules to individual and corporate subscribers, and to solicited as well as unsolicited messages.
There is one further point on business lists. Where a message identifies a specific person, the UK GDPR applies to that data, and that person has an absolute right to object to direct marketing. You stop when they object, whether they are a consumer or a procurement manager.
Buying Data and Using Third-Party SMS Providers
Most bulk SMS campaigns run through a third-party platform, and many use data the business did not collect itself. Neither arrangement moves the legal risk off your business.
Who the ICO Holds Responsible
PECR catches the business that sends an unlawful marketing message and the business that instigates it, meaning whoever arranged for it to go out. If you commissioned the campaign, you instigated it. The platform pressed send, and the ICO still comes to you.
What to Check Before You Buy a List
Bought data is where this usually goes wrong. The ICO expects you to check that any list is accurate, that the details were collected fairly, and that the consent is specific and recent enough. In practice that means seeing the consent record itself, not a warranty buried in the supplier’s terms.
KRA Consultancy Ltd is the case to look at. In June 2026 the ICO fined the company £300,000 for sending 5,575,715 texts to people who had been declined for loans. The data came from a third party and was up to three years old. KRA made no attempt to check whether it was accurate or whether anyone had consented. More than 60,000 people complained.
Before you sign with a supplier or buy a list, get three things in writing:
- the exact consent wording each person saw, plus the date and source of that consent;
- confirmation that your business was named at the point of collection, not described as a carefully selected partner;
- who maintains the suppression list, how opt-outs flow back to you, and how quickly.
Then sample it. Ask for the consent record behind 20 numbers picked at random. A supplier who cannot produce records for 20 will not produce them for 200,000, and that is the request the ICO makes.
What Happens If You Get It Wrong
The Information Commissioner’s Office (ICO) regulates compliance with PECR and UK data protection law in the United Kingdom. If you do not follow these rules, it can lead to complaints, enforcement action and harm to your business’ reputation.
How the ICO Finds Out
Individuals who receive unwanted marketing messages can complain directly to the ICO, or report a message by forwarding it to 7726. Even a relatively small number of complaints can bring a company’s marketing practices to the regulator’s attention.
If a business breaks the rules, the ICO may investigate and take action. This can include heavy fines or orders to stop unlawful marketing.
The Fines and the ICO’s Powers
The maximum fine has gone up since that case. The enforcement provisions of the Data (Use and Access) Act 2025 commenced on 5 February 2026, and lifted PECR penalties to the UK GDPR level.
Businesses that fail to comply with electronic marketing rules may now face fines of up to £17.5 million or 4% of annual global turnover, whichever is higher.
The same Act made a broader set of changes to UK privacy law. It also gave the ICO new investigatory powers. Those include compelling a witness to attend an interview and requiring reports from approved persons. The Act creates a new body, the Information Commission, to take over the Information Commissioner’s functions. That changes who enforces the rules, not the rules you follow.
Do this before the campaign rather than after the first complaint. A short review of your consent records, your opt-out handling and your sender ID holds for every campaign that follows it.
Key Takeaways
Businesses planning to use bulk SMS marketing in the UK should ensure they understand the legal rules before sending any messages. Compliance with PECR and, where relevant, UK GDPR is essential to avoid complaints, regulatory action and financial penalties. Businesses should ensure they comply with the relevant consent rules, provide clear opt-out options, and keep appropriate records. Taking a careful approach to SMS marketing is vital for compliance and to help reduce legal and reputational risk.
LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced data and privacy lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.
Frequently Asked Questions
Can my business send marketing texts to companies without consent?
The rules are less strict for corporate subscribers. Consent is not required for limited companies, limited liability partnerships and public bodies. You must still identify your business and give a simple opt-out in every message. Sole traders count as individuals, so they need consent.
When can we rely on the soft opt-in for marketing texts?
Only where you collected the number directly during a sale or negotiation, the marketing covers your own similar products or services, and you gave a clear opt-out at collection and in every message. It does not cover bought lists.
What penalties can the ICO issue for breaching PECR?
The ICO can fine a business up to £17.5 million or 4% of annual global turnover, whichever is higher. It can also order a business to stop unlawful marketing. People affected by a breach may separately bring a claim for compensation.
Why should a business get legal advice before starting an SMS campaign?
Legal advice helps you confirm which PECR rules apply to your list, set consent wording that holds up, handle opt-outs correctly and check your UK GDPR position. It also covers higher-risk areas such as the soft opt-in and third-party data.
We appreciate your feedback! Request your free consultation now.