A Practical Guide to UK SMS Marketing Rules: Navigating PECR
SMS marketing in the UK is primarily governed by the Privacy and Electronic Communications Regulations (PECR), which work alongside the UK GDPR to protect individual privacy. Complying with these regulations is not just a legal necessity but a cornerstone of building trust and running effective campaigns. This guide breaks down the key rules for businesses. While compliance is vital, so is performance. A transparent provider is key, which is why at TextVolley we publish our carrier routes, pricing, and latency data for 18 countries, including the UK.
What is PECR and Why Does it Matter for SMS?
The Privacy and Electronic Communications Regulations (PECR) are UK laws that set specific privacy rights for electronic communications, making them the primary rulebook for SMS marketing.
PECR sits alongside the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. While UK GDPR governs the overall processing of personal data, PECR provides specific rules for marketing by phone, email, and, crucially, text message.
The Golden Rule: Explicit 'Opt-In' Consent
For unsolicited marketing text messages, you must have specific, freely given, informed, and unambiguous consent from an individual before you can message them.
This means you cannot rely on pre-ticked boxes, silence, or inactivity as consent. The person must take a positive action to opt in, such as ticking an unchecked box, to agree to receive marketing texts from your organisation. The consent request must be separate from other terms and conditions and clearly state what the person is agreeing to.
- Consent must be a positive 'opt-in', not an assumed 'opt-out'.
- Clearly explain that the user is agreeing to receive SMS marketing messages.
- Keep detailed, timestamped, and auditable records of every consent obtained.
The Limited Exception: 'Soft Opt-In' for Existing Customers
The 'soft opt-in' is a narrow exception that allows you to send marketing texts to existing customers about similar products or services without prior explicit consent, under very strict conditions.
This is not a loophole for general marketing. To use the soft opt-in, you must be able to satisfy all of its conditions meticulously. If even one condition is not met, you must fall back on obtaining explicit opt-in consent. Misusing the soft opt-in is a common cause of complaints and ICO enforcement action.
- You must have obtained the contact details in the course of a sale (or negotiations for a sale) of a product or service.
- The marketing you send must be for your own similar products and services only.
- The person must have been given a simple way to opt out, both at the time their details were collected and in every subsequent message.
Essential Mechanics: Sender Identification and Mandatory Opt-Outs
Every marketing SMS you send must clearly identify your business and provide a simple, free, and straightforward method for the recipient to opt out of future messages.
Your company's name or brand must be stated within the message. While using an Alphanumeric Sender ID (e.g., 'YourBrand') is great for branding, it doesn't allow for replies. Therefore, the body of the message must still contain your name so the recipient knows who is contacting them.
- Always state your company or brand name clearly in the message.
- Provide a clear and simple opt-out mechanism like 'Text STOP to #####'.
- Ensure the opt-out process is automated and reliable to honour requests immediately.
- Failure to honour an opt-out request is a serious breach of PECR.
How UK GDPR and PECR Work Together
PECR provides the specific rules for electronic marketing, while the UK GDPR sets the overarching data protection standards, including the high bar for what constitutes valid consent.
A mobile phone number is considered personal data. Therefore, whenever you collect, store, or use a phone number for marketing, you are processing personal data and must comply with UK GDPR. The very definition of 'consent' used in PECR is taken directly from the UK GDPR, meaning it must always meet that high standard of agreement.
- The UK GDPR defines the high standard of 'consent' that PECR requires.
- A phone number is personal data, so its processing is fully subject to UK GDPR.
- You must have a lawful basis under UK GDPR for processing the data (consent is one such basis).
- Core data protection principles like transparency and security apply to your contact lists.
Consequences of Non-Compliance: The ICO
The Information Commissioner's Office (ICO) is the UK's regulator that enforces PECR and has the power to issue significant fines and other sanctions for breaches.
The ICO investigates complaints from the public about nuisance marketing. If they find an organisation has been sending unsolicited marketing texts in breach of PECR, they can take formal enforcement action. This can include information notices (forcing you to provide information), undertakings (committing you to a course of action), and monetary penalty notices.
- The ICO investigates complaints from the public and can conduct its own audits.
- Monetary penalties for breaching PECR can reach up to ยฃ500,000 per infringement.
- Reputational damage from a public enforcement notice can be severe and long-lasting.
- The ICO is particularly focused on organisations that cause widespread nuisance through high volumes of complaints.
Beyond Compliance: Best Practices for Great SMS Marketing
Adopting best practices like respecting 'quiet hours' and choosing a transparent provider will improve customer relations, boost campaign ROI, and future-proof your strategy.
While not a legal rule in PECR, sending messages at sociable hours is crucial. Avoid texting customers late at night, on public holidays, or very early in the morning. This common-sense courtesy shows respect for their privacy and prevents your brand from being perceived as a nuisance.
- Do not send messages during unsociable 'quiet hours' (e.g., 9pm to 8am).
- Regularly clean your marketing lists to remove invalid numbers and maintain data hygiene.
- Ensure every message provides clear value and is relevant to the recipient.
- Partner with a provider that is transparent about its network, routing, and pricing.
FAQ
Do these rules apply to B2B SMS marketing?
Yes, in most cases. PECR's marketing rules apply to individuals, which includes sole traders and some partnerships. While rules for corporate subscribers (limited companies) can differ, the ICO recommends obtaining explicit consent for all B2B marketing as best practice to avoid any issues.
What is the difference between marketing and service messages?
Service messages are transactional and contain essential information about a product or service a customer is using (e.g., appointment reminders, delivery updates). Marketing messages aim to promote products or services. PECR's strict consent rules apply to marketing messages, not purely transactional ones.
How long does SMS marketing consent last?
Neither PECR nor UK GDPR specify a fixed expiry time for consent. However, consent is not indefinite and can degrade over time. It is good practice to regularly review your contact lists, monitor engagement, and consider setting your own reasonable time limit (e.g., 12-24 months) to refresh consent.
Can I use a purchased list of phone numbers for SMS marketing?
No, you should not use purchased or third-party lists. The specific, informed consent required by PECR must be given directly to your organisation for your marketing. A third party cannot give consent on an individual's behalf for your specific marketing messages. This is a high-risk practice.
What must I do when a customer texts 'STOP'?
You must immediately and automatically add their number to a suppression list and permanently stop sending them any further marketing messages. This process should be automated. Failure to honour an opt-out request is a clear and serious breach of PECR and a major source of complaints to the ICO.
Are messages from charities considered marketing under PECR?
Yes. Messages sent by a charity, political party, or other non-profit organisation that promote their aims and ideals are considered 'for the purposes of direct marketing' under PECR. Therefore, they must follow the same rules regarding consent as commercial businesses.