SMS is one of the most direct ways to reach a customer. A text lands on the one device people keep within arm's reach all day. That directness is exactly why UK law sets clear rules on when and how you can send marketing messages. Get the rules right and SMS becomes a powerful, trusted channel. Get them wrong and you risk complaints and enforcement.

This is a plain-English guide to sending marketing texts legally in the UK. It is not formal legal advice, but it will help you understand what PECR and UK GDPR expect so you can run campaigns with confidence.

The two rulebooks: PECR and UK GDPR

Two sets of rules govern marketing texts. PECR, the Privacy and Electronic Communications Regulations, deals specifically with electronic marketing including SMS. UK GDPR governs how you handle personal data, including the phone numbers on your list. They work together: GDPR covers how you store and use the data, PECR covers whether you are allowed to send the message at all.

Consent is the default

The starting point is simple. Before you send a marketing text to an individual, you generally need their consent. Valid consent under UK GDPR is a clear, affirmative action: someone ticking an unticked box or entering their number specifically to receive offers. It cannot be buried in terms and conditions or assumed from silence.

Good consent records matter. If someone questions why they received a text, you should be able to show when and how they agreed.

The soft opt-in, explained

There is one important exception, often called the soft opt-in. You may text your existing customers about your own similar products or services without separate consent, as long as all of these are true:

The soft opt-in does not cover people who only enquired but never bought, and it does not let you promote unrelated products. When in doubt, get consent.

Build a compliant SMS campaign, free

ClientRoots SMS Builder includes a character counter, cost calculator and a built-in opt-out, so your UK campaigns start on the right side of the rules.

Try the free SMS Builder →

Every message needs an easy opt-out

Whether you rely on consent or the soft opt-in, every marketing text must give people a free and simple way to stop receiving them, typically by replying STOP. You must act on opt-outs promptly and keep a suppression list so that person is never messaged again. Ignoring an opt-out is one of the fastest ways to attract a complaint.

Identify yourself

Recipients should be able to tell instantly who a message is from. Do not disguise or conceal your identity as the sender, and make sure your business name is clear. A text that hides who sent it erodes trust and breaches the rules.

A simple compliance checklist

  1. Lawful basis: do you have consent, or does the soft opt-in genuinely apply?
  2. Clean data: is your number list accurate and up to date, with opt-outs removed?
  3. Clear sender: can the recipient tell the message is from you?
  4. Opt-out in every send: is there a free, easy way to stop?
  5. Records: can you show consent and honour opt-outs quickly?

Keeping your list clean supports all of this. Running your contacts through the Email Cleaner and keeping opt-outs suppressed means you are only messaging people you are allowed to reach.

Business and consumer contacts follow different rules

PECR treats individual subscribers and corporate subscribers slightly differently. Texts to individuals, which includes sole traders and most partnerships, need consent or the soft opt-in. Texts to corporate bodies such as limited companies are treated a little more leniently, though UK GDPR still applies to any personal data and best practice is to offer an opt-out regardless. When you are unsure which category a contact falls into, the safest approach is to treat them as an individual and get consent.

Timing and frequency matter

Just because a message is legal does not mean it is welcome. Bombarding people leads to opt-outs and complaints, which undermines the whole channel. Send at sensible hours, keep your frequency reasonable, and make every message worth the interruption. A text that offers something genuinely useful will always outperform one sent just to stay visible.

How to write a marketing text people act on

Keep your consent records

If a complaint is ever raised, the burden is on you to show that the person agreed or that the soft opt-in applied. Keep a record of when and how each contact opted in, and maintain a suppression list of everyone who has opted out. Clean, well-documented data is not just good compliance, it also means you are only spending your budget on people who actually want to hear from you.

Frequently asked questions

Do I need consent to send marketing texts in the UK?

In almost all cases, yes. PECR requires prior consent before sending marketing SMS to individuals. The main exception is the soft opt-in for existing customers.

What is the soft opt-in?

It lets you text existing customers about your own similar products without separate consent, provided you got their number during a sale, offered an easy opt-out then, and include an opt-out in every message. It does not apply to people who only enquired.

Do marketing texts need an opt-out?

Yes. Every marketing message must give a simple, free way to opt out, such as replying STOP, and you must honour it promptly and keep that person suppressed.

Who enforces SMS marketing rules in the UK?

The Information Commissioner's Office (ICO) enforces PECR and UK GDPR. Breaches can lead to enforcement action and fines.

The takeaway

Compliant SMS marketing comes down to a few habits: send to people who agreed or genuinely qualify under the soft opt-in, always identify yourself, always offer an easy opt-out, and keep good records. Do that and texting becomes a channel your customers welcome rather than report.

The ClientRoots SMS Builder is built for UK rules, with a compliant opt-out and the tools to plan a campaign in minutes. Reach your customers where they actually look, the right way.