By Tomas Linnik, Deliverability & Compliance Lead · Updated 10 June 2026
SMS marketing in the EU rests on two rules at once. The ePrivacy Directive requires prior consent before you send a marketing text, and the GDPR defines what that consent has to look like. In plain terms: people must actively opt in, you must be able to prove they did, and they must be able to leave as easily as they joined. This guide covers what valid consent means, the one real exception, and how to capture it without crushing sign-ups.
What counts as valid consent under the GDPR?
GDPR Article 4(11) defines consent as a "freely given, specific, informed and unambiguous" indication of the subscriber's wishes, given by a statement or clear affirmative action. Article 6(1)(a) makes that consent the lawful basis for marketing texts. The European Data Protection Board breaks the standard into four parts.
| Element | What it means for SMS |
|---|---|
| Freely given | Real choice. You cannot make a discount conditional on marketing consent the customer does not need to give. |
| Specific | One purpose per opt-in. Bundling "SMS offers" with "share my data with partners" in one tick is invalid. |
| Informed | Name who you are, what they will get, and that they can withdraw, before they agree. |
| Unambiguous | An active motion — a ticked box or a typed keyword. Silence and pre-ticked boxes do not count. |
What does ePrivacy Article 13 add?
The GDPR says what consent is; the ePrivacy Directive (2002/58/EC) says when you need it. Article 13(1) allows direct marketing by electronic mail only to people who have given prior consent, and SMS falls squarely under "electronic mail." The proposed ePrivacy Regulation is not yet in force, so this Directive plus the GDPR remain the binding framework through 2026.
When can you skip opt-in? The soft opt-in
Article 13(2) carves out one exception, the soft opt-in. You may market your own similar products to a person whose contact details you obtained "in the context of the sale of a product or a service," as long as you gave them a free, easy way to object both at collection and in every message. Three conditions all have to hold:
- The details came from your own customer during a sale, not a bought list or a prospect.
- You are marketing your own similar products or services, not a third party's.
- An easy, free objection was offered at sign-up and repeats in every text.
Miss any one and you are back to needing full prior consent. The UK applies the same logic under PECR Regulation 22, and the ICO confirms "electronic mail" there includes SMS.
How do you prove and honour consent?
Article 7(1) puts the burden of proof on you: you must be able to demonstrate that each subscriber consented. The EDPB warns that pointing to "a correctly configured website" is not enough on its own. Record how and when each opt-in was captured and what the person saw at the time. Article 7(3) then requires that withdrawal is as easy as opt-in, free of charge, and that processing stops once someone leaves.
| Obligation | GDPR / ePrivacy basis | In practice |
|---|---|---|
| Active opt-in | Art. 4(11) | Unchecked box or keyword the user actions |
| Proof of consent | Art. 7(1) | Log timestamp, source, and wording shown |
| Easy withdrawal | Art. 7(3) | STOP in every message; suppress immediately |
| Prior consent to send | ePrivacy Art. 13(1) | No send before a valid opt-in exists |
The practical setup
On the ground this means a clear, unbundled opt-in at the popup and checkout, a consent log you can produce on request, STOP and HELP handling that suppresses contacts the moment they reply, and sender IDs registered where countries require them. That last part is country-specific work we cover in compliance and deliverability. Once consent is solid, the next job is growing the list — see how to build an SMS opt-in list.
This guide is general information, not legal advice. Confirm specifics with a qualified adviser for your markets.