BulkSMSRates

SMS Compliance Guide

Sending bulk SMS requires compliance with data protection and electronic communications regulations. This guide covers GDPR, UK DPA 2018, PECR, opt-in requirements, STOP handling, and data retention.

GDPR (General Data Protection Regulation)

The GDPR is the EU's comprehensive data protection regulation, retained in UK law post-Brexit as the UK GDPR. It applies to any organisation processing personal data of UK/EU residents.

Key requirements for SMS:

  • Lawful basis: You need a lawful basis for processing phone numbers — typically consent (marketing) or contract performance (transactional).
  • Transparency: Recipients must be informed about how their data is used, who processes it, and their rights — typically via a privacy notice.
  • Data minimisation: Only collect and retain data necessary for your stated purpose. Don't keep numbers “just in case”.
  • Right to erasure: Recipients can request deletion of their data at any time. You must comply within 30 days.
  • Data processing records: Maintain records of processing activities (Article 30). Document what data you hold, why, and how long.
  • Data breach notification: Report breaches to the ICO within 72 hours if they pose a risk to individuals.

UK Data Protection Act 2018

The UK DPA 2018 supplements the UK GDPR with additional provisions specific to UK law. It sets out the framework enforced by the Information Commissioner's Office (ICO).

  • • Applies to all organisations processing personal data in the UK, regardless of where they're based.
  • • Establishes the ICO as the supervisory authority with enforcement powers.
  • • Sets rules for direct marketing, including electronic communications.
  • • Penalties align with GDPR: up to £17.5M or 4% of global annual turnover.
  • • Organisations processing personal data must pay an annual data protection fee to the ICO.

PECR (Privacy and Electronic Communications Regulations)

PECR is the UK regulation that specifically governs electronic marketing, including SMS. It sits alongside GDPR and adds extra rules for direct marketing messages.

Requirements:

  • Prior consent: You must have opt-in consent before sending marketing SMS to individuals (not just legitimate interest).
  • Soft opt-in exception: You may message existing customers about similar products/services if: (a) you obtained the number during a sale or negotiation, (b) you only market similar products, and (c) you gave them a simple opt-out opportunity at collection and in every message.
  • Sender identification: Every marketing SMS must identify who you are. Anonymous marketing messages are prohibited.
  • Opt-out mechanism: Every message must include a way to opt out (e.g. “Reply STOP”).
  • Enforcement: The ICO can fine up to £500,000 for PECR violations. They regularly take enforcement action against SMS spammers.

Opt-in Requirements

What constitutes valid opt-in:

  • ✅ Unticked checkbox with clear description of what they're consenting to
  • ✅ SMS keyword opt-in (e.g. “Text JOIN to 88000”)
  • ✅ Web form with explicit SMS marketing consent separate from T&Cs
  • ✅ Double opt-in (recommended): send a confirmation SMS asking them to reply YES

What does NOT count as valid opt-in:

  • ❌ Pre-ticked checkboxes
  • ❌ Consent bundled into Terms & Conditions
  • ❌ Purchasing a phone number list
  • ❌ Business card collection at events (without explicit SMS consent)
  • ❌ “By providing your number you agree to receive SMS” buried in fine print

STOP Handling & Opt-out

Every marketing SMS must include an opt-out mechanism. BulkSMSRates automatically processes opt-out keywords for you.

Recognised keywords:

STOPSTOP ALLUNSUBSCRIBECANCELENDQUITOPTOUTOPT OUT

How BulkSMSRates handles opt-outs:

  • 1. Recipient replies with a STOP keyword
  • 2. We immediately add the number to your account suppression list
  • 3. We send an automatic confirmation: “You have been unsubscribed. You will not receive further messages.”
  • 4. Future sends to that number are automatically blocked
  • 5. You can view and export your suppression list from the dashboard

Data Retention

GDPR requires you to retain personal data only as long as necessary. Here are recommended retention periods for SMS-related data:

Data typeRecommended retentionNotes
Consent recordsDuration of relationship + 6 yearsKeep as evidence of lawful basis
Message logs90 daysFor troubleshooting and DLR reconciliation
Phone numbers (active)Review annuallyRemove unengaged contacts after 12-24 months
Suppression listIndefinitelyMust keep to prevent re-messaging opted-out numbers
Delivery reports90 daysAvailable via API for 90 days, then archived
Webhook logs30 daysFor debugging failed webhook deliveries

Quick Compliance Checklist

  • Valid opt-in consent obtained and recorded for every recipient
  • Privacy notice updated to cover SMS marketing
  • Every marketing SMS identifies your organisation
  • Every marketing SMS includes opt-out mechanism (Reply STOP)
  • Opt-outs processed immediately (automated via BulkSMSRates)
  • Suppression list maintained and checked before every send
  • Data retention policy documented and enforced
  • ICO data protection fee paid (if applicable)
  • Data processing records maintained (Article 30)
  • Staff trained on SMS compliance requirements

Frequently Asked Questions

Send compliant SMS with confidence

BulkSMSRates includes built-in compliance tools: automatic STOP handling, consent tracking, suppression lists, and audit logs.

Get Started Free