1. Regulatory focus
This is not a fresh enforcement action but a reset of the UK compliance baseline for SMS programs. On April 28, 2026, the ICO updated its direct marketing guidance to reflect the six-month commencement schedule of the Data (Use and Access) Act, and its guidance development page still says an updated PECR version for small organisations is due in Summer 2026. For messaging teams, the practical issue is no longer only whether consent exists. The harder question is which messages will be treated as direct marketing, when soft opt-in can still be used, and whether objections and opt-outs are applied consistently across SMS, email, and CRM workflows.
2. Business impact
For many UK messaging programs, the real exposure sits in mixed-purpose traffic: renewal reminders with promotional copy, billing texts that upsell, or service follow-ups that push an offer. The ICO’s current guidance already stresses that direct marketing is broader than pure product sales and can include promoting an organisation’s aims. That means legacy templates labeled as “service messages” may still create risk in complaints, opt-out disputes, or vendor audits. For CPaaS providers, SaaS operators, and cross-border brands, the impact is immediate: template libraries, consent evidence, preference centres, and outsourced sending controls all need tighter classification and governance.
3. Operating recommendations
The practical move is to rebuild UK message taxonomy now instead of waiting for the final PECR update. A workable structure is to classify all UK SMS templates into five buckets: OTP, pure service notice, contract-performance message, customer care, and promotional marketing. For each template, document the legal basis, whether PECR consent is required, whether soft opt-in is being relied on, and whether an opt-out must be included. Then connect CRM timestamps, capture-page screenshots, source channel data, language variants, and unsubscribe write-back logs into a defensible audit trail. If an aggregator or agency sends on your behalf, contracts should assign consent checks, suppression-list handling, and complaint stop-send SLAs explicitly.