Skip to content
smsrocket
Menu ▾

Guide · Compliance

GDPR & SMS marketing consent: the practical rules

Consent is the foundation of every legal SMS program in the EU. Get it right and the rest is marketing; get it wrong and it is a liability.

By Tomas Linnik, Deliverability & Compliance Lead · Updated 10 June 2026

SMS marketing in the EU rests on two rules at once. The ePrivacy Directive requires prior consent before you send a marketing text, and the GDPR defines what that consent has to look like. In plain terms: people must actively opt in, you must be able to prove they did, and they must be able to leave as easily as they joined. This guide covers what valid consent means, the one real exception, and how to capture it without crushing sign-ups.

What counts as valid consent under the GDPR?

GDPR Article 4(11) defines consent as a "freely given, specific, informed and unambiguous" indication of the subscriber's wishes, given by a statement or clear affirmative action. Article 6(1)(a) makes that consent the lawful basis for marketing texts. The European Data Protection Board breaks the standard into four parts.

ElementWhat it means for SMS
Freely givenReal choice. You cannot make a discount conditional on marketing consent the customer does not need to give.
SpecificOne purpose per opt-in. Bundling "SMS offers" with "share my data with partners" in one tick is invalid.
InformedName who you are, what they will get, and that they can withdraw, before they agree.
UnambiguousAn active motion — a ticked box or a typed keyword. Silence and pre-ticked boxes do not count.

What does ePrivacy Article 13 add?

The GDPR says what consent is; the ePrivacy Directive (2002/58/EC) says when you need it. Article 13(1) allows direct marketing by electronic mail only to people who have given prior consent, and SMS falls squarely under "electronic mail." The proposed ePrivacy Regulation is not yet in force, so this Directive plus the GDPR remain the binding framework through 2026.

When can you skip opt-in? The soft opt-in

Article 13(2) carves out one exception, the soft opt-in. You may market your own similar products to a person whose contact details you obtained "in the context of the sale of a product or a service," as long as you gave them a free, easy way to object both at collection and in every message. Three conditions all have to hold:

  • The details came from your own customer during a sale, not a bought list or a prospect.
  • You are marketing your own similar products or services, not a third party's.
  • An easy, free objection was offered at sign-up and repeats in every text.

Miss any one and you are back to needing full prior consent. The UK applies the same logic under PECR Regulation 22, and the ICO confirms "electronic mail" there includes SMS.

How do you prove and honour consent?

Article 7(1) puts the burden of proof on you: you must be able to demonstrate that each subscriber consented. The EDPB warns that pointing to "a correctly configured website" is not enough on its own. Record how and when each opt-in was captured and what the person saw at the time. Article 7(3) then requires that withdrawal is as easy as opt-in, free of charge, and that processing stops once someone leaves.

ObligationGDPR / ePrivacy basisIn practice
Active opt-inArt. 4(11)Unchecked box or keyword the user actions
Proof of consentArt. 7(1)Log timestamp, source, and wording shown
Easy withdrawalArt. 7(3)STOP in every message; suppress immediately
Prior consent to sendePrivacy Art. 13(1)No send before a valid opt-in exists

The practical setup

On the ground this means a clear, unbundled opt-in at the popup and checkout, a consent log you can produce on request, STOP and HELP handling that suppresses contacts the moment they reply, and sender IDs registered where countries require them. That last part is country-specific work we cover in compliance and deliverability. Once consent is solid, the next job is growing the list — see how to build an SMS opt-in list.

This guide is general information, not legal advice. Confirm specifics with a qualified adviser for your markets.

FAQ

GDPR & SMS consent FAQ

Do I always need opt-in consent for marketing SMS in the EU?+
Almost always. ePrivacy Directive Article 13(1) requires prior consent for marketing by electronic mail, which includes SMS. The main exception is the soft opt-in: you may text your own existing customers about similar products if you offered an easy refusal at collection and in every message.
Is a pre-ticked box valid consent?+
No. The EDPB is explicit that pre-ticked boxes, silence, and inactivity do not count. GDPR Article 4(11) requires a clear affirmative action, so the subscriber has to actively opt in — an unchecked box they tick themselves, not one you tick for them.
How long can I keep someone on my SMS list?+
Consent does not have a fixed expiry in the GDPR, but it must stay valid. If a contact has gone cold for a long time or the purpose changed, re-confirm. You must also stop immediately when someone withdraws, because Article 7(3) makes withdrawal as easy as opt-in.
Does the soft opt-in let me text bought-in lists?+
No. The soft opt-in only covers your own customers whose details you collected during a sale of your own similar products. Purchased lists, rented data, and prospects who never bought from you all need full prior consent before you send.

★ FREE SMS AUDIT ★

Want your consent setup audited before you send?

Book a free 20-minute audit. We will look at your list, your flows, and your consent setup, then tell you the three changes worth making first.