Europe Sending restrictions

UK SMS Guidance Update Pending

This matters to growth, compliance, and messaging operations teams sending marketing SMS, account prompts, and cross-channel campaigns into the UK because the ICO is actively aligning PECR guidance with changes introduced by the Data (Use and Access) Act. Companies can no longer assume that legacy consent logic is enough. The ICO updated its direct marketing guidance on April 28, 2026 to reflect the Act’s commencement timetable, and it still lists updated PECR guidance for Summer 2026, which makes message classification, soft opt-in use, and opt-out mechanics immediate review items.

Published:07/21/2026 Updated:07/21/2026

1. Regulatory focus

This is not a fresh enforcement action but a reset of the UK compliance baseline for SMS programs. On April 28, 2026, the ICO updated its direct marketing guidance to reflect the six-month commencement schedule of the Data (Use and Access) Act, and its guidance development page still says an updated PECR version for small organisations is due in Summer 2026. For messaging teams, the practical issue is no longer only whether consent exists. The harder question is which messages will be treated as direct marketing, when soft opt-in can still be used, and whether objections and opt-outs are applied consistently across SMS, email, and CRM workflows.

2. Business impact

For many UK messaging programs, the real exposure sits in mixed-purpose traffic: renewal reminders with promotional copy, billing texts that upsell, or service follow-ups that push an offer. The ICO’s current guidance already stresses that direct marketing is broader than pure product sales and can include promoting an organisation’s aims. That means legacy templates labeled as “service messages” may still create risk in complaints, opt-out disputes, or vendor audits. For CPaaS providers, SaaS operators, and cross-border brands, the impact is immediate: template libraries, consent evidence, preference centres, and outsourced sending controls all need tighter classification and governance.

3. Operating recommendations

The practical move is to rebuild UK message taxonomy now instead of waiting for the final PECR update. A workable structure is to classify all UK SMS templates into five buckets: OTP, pure service notice, contract-performance message, customer care, and promotional marketing. For each template, document the legal basis, whether PECR consent is required, whether soft opt-in is being relied on, and whether an opt-out must be included. Then connect CRM timestamps, capture-page screenshots, source channel data, language variants, and unsubscribe write-back logs into a defensible audit trail. If an aggregator or agency sends on your behalf, contracts should assign consent checks, suppression-list handling, and complaint stop-send SLAs explicitly.

Frequently Asked Questions

If a renewal reminder includes a discount code, is it service traffic or marketing?
In the UK, mixed-purpose texts should not automatically be treated as pure service messages. If the SMS includes promotional content, purchase encouragement, or broader organisational promotion, it may fall within direct marketing. The safer approach is to review the service copy and promotional add-on separately, then confirm whether you have provable PECR consent or a valid soft opt-in basis for that user.
What evidence should a UK SMS program prioritise right now?
Focus on three evidence layers. First, capture how consent or soft opt-in was obtained, including form wording, checkbox state, and timestamp. Second, retain template classification records showing why a message was treated as service or marketing. Third, preserve opt-out execution logs, including STOP handling, CRM write-back, and suppression-list syncing. Without those, complaint defence becomes weak very quickly.
Can a brand shift responsibility to a local UK messaging vendor?
Not fully. Outsourcing delivery does not remove the brand’s core responsibility for consent basis, message classification, and opt-out compliance. Vendors usually carry execution and logging duties, not the whole legal burden. Contracts should spell out source-data validation, suppression-list sync frequency, complaint escalation windows, and stop-send SLAs, otherwise both the brand and the messaging provider may face scrutiny.
This article is for informational purposes only and does not constitute legal advice.

Related products

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch