Rules for UK texting

Send UK SMS with consent handled properly

UK text messaging is governed by PECR and UK GDPR rather than a US-style registration regime. WorldText lays out the boundaries: marketing consent and the soft opt-in, sender ID reserved lists, Ofcom anti-spoofing work and the distinction that keeps transactional messages outside marketing consent.

Last reviewed: 11 September 2026

What rules apply to business SMS in the UK?

UK electronic marketing, including text marketing, is governed by PECR (the Privacy and Electronic Communications Regulations) together with UK GDPR for data protection. Marketing texts need consent or the soft opt-in exception, which applies to your own customers for similar products or services where a clear opt-out was given at collection; the exception covers email and text. Transactional or service messages are not marketing and do not need marketing consent, although privacy law still applies to the data. Sender IDs are subject to UK network reserved lists, and Ofcom's CLI authentication programme continues to roll out to counter spoofed calls and messages. This is an overview, not legal advice: see our compliance guide.

The UK rulebook in outline

UK business texting is governed by two overlapping regimes, neither of which is a registration scheme. PECR, the Privacy and Electronic Communications Regulations, governs electronic marketing: it restricts unsolicited marketing by text and email unless the recipient has consented or a narrow exception applies. UK GDPR governs the personal data behind every message, lawful basis, transparency, retention and the rights individuals can exercise. The two interact, and a messaging programme has to satisfy both rather than either.

We deliberately do not present our word as law. Our compliance guide is the general reference: it is explicitly not legal advice, it was recently updated, and it is honest that service-provider and carrier rules may require pre-registration of message originators and that customers remain responsible for consent. The anti-spam policy covers the sending side, including how we treat sender IDs and originator registration. For the infrastructure side, the service level agreement sets out what we commit to operationally rather than legally.

Marketing texts: consent and the soft opt-in

Direct marketing by text message requires consent in the UK, or the soft opt-in exception. The soft opt-in is specific and limited: it applies to your own customer, for similar products or services, where a clear opt-out was offered at the point their details were collected. It applies to email and text, and it does not cover third-party offers or unrelated promotions. Where the soft opt-in does not apply, positive consent is the safe route, and it should be recorded with evidence: what was offered, when, and how it was withdrawn.

Consent is not the only obligation. UK GDPR requires a lawful basis for processing personal data, and marketing typically needs explicit consent or legitimate interests, depending on the traffic. Every marketing message needs a working opt-out, and the opt-out needs to be respected across channels rather than only the channel it came from. The transactional versus marketing comparison lays out where the line sits in practice, because the boundary is where most UK compliance problems start.

Transactional messages sit outside marketing consent

Service messages are a different category. A one-time code, an order update, an appointment reminder or a system alert is information the recipient needs because an event happened. It is not marketing, it does not need marketing consent, and it would be odd to ask for consent before sending a delivery confirmation. Privacy law still applies to the data, so lawful basis, retention and subject access are all still live obligations.

The category boundary should be drawn by trigger and content, not by intent. A confirmation with a promotional footer can drift into marketing territory depending on the assessment, so many UK senders keep promotional material out of transactional messages entirely, or tag message types so consent state is queryable. Our UK transactional SMS page and UK business SMS page cover the practical side, and the compliance guide gives the fuller legal context.

If you cannot tell a compliance officer whether a given message was transactional or marketing, treat that as a system gap rather than a lawyer's problem: the tag should exist in the data, attached at creation, and audit should be a query rather than an archaeology project.

Sender IDs and network reserved lists

Sender identity is regulated by default in the UK, not by registration. An alphanumeric sender ID can contain up to 11 characters using letters, digits and spaces, and it is what the recipient sees in the inbox. UK mobile networks, including BT/EE, O2, Vodafone, Three and others, maintain reserved or restricted sender IDs. If your ID is on a reserved list, a network may substitute another sender or reject the message; BT/EE publish restricted lists, and some networks support or require sender-ID registration via the aggregator before the ID can be used at all.

Because there is no US-style national registry in the common case, the discipline is per-network and quiet: check the lists, and register where a network requires it. That is exactly what we offer. Where a network requires it, we can check and register your sender ID before you launch, which is the practical equivalent of 10DLC registration without the schedule. The UK SMS gateway page covers the operational handling, and our US compliance page shows how the comparable US regime differs.

Anti-spoofing context and UK short codes

The UK messaging ecosystem has been tightening identity for reasons beyond marketing consent. Ofcom, the UK communications regulator, introduced a CLI authentication framework after a 2024 consultation, and the rollout continues: the framework is aimed primarily at spoofed caller IDs, but it sits alongside anti-spoofing and whitelisting work that affects messaging originators too, including the MEF UK whitelist register and Do-Not-Originate lists. The practical implication for a sender-ID-based market is that legitimate, registered originators become easier to distinguish from impersonated ones, which is good news for the majority and a reason not to skip list checks.

Short codes have their own regulatory shape. UK text short codes are Ofcom-allocated, commonly 5-6 digits in the 7000 series, and several ranges such as the familiar 80xxx, 84xxx, 86xxx and 87xxx family remain in use (several ranges are in use; check with us for current allocations). Our inbound SMS page covers the short code options, and the policy pages on data protection, data retention and terms and conditions complete the picture if you need the contractual side.

PECR consent guidance

The UK electronic marketing regime, explained as rules you can implement rather than a legal lecture.

Soft opt-in explained

When the exception applies: your own customer, similar products or services, and a clear opt-out at collection.

Sender ID reserved lists

Network-level identity checks and registration where a network requires it, with the honest caveats.

Ofcom anti-spoofing context

The CLI authentication rollout and whitelisting work that makes registered originators stand out.

Frequently asked questions

Does transactional SMS need marketing consent in the UK?

No. Transactional or service messages are not marketing, so they do not need marketing consent under PECR. UK GDPR still applies to the data, so keep lawful basis, retention and subject access in order.

What is the soft opt-in?

The soft opt-in applies when you market to your own customer, about similar products or services, having offered a clear opt-out when their details were collected. It covers email and text. It does not cover third-party offers or unrelated products, which need consent.

Who is responsible for consent in a UK SMS setup?

Customers remain responsible for consent, as our compliance guide states. WorldText handles the platform side: delivery, sender-ID checks and registration where a network requires it, plus the policy pages that set out how we process data.

Do I need to register my alphanumeric sender ID?

There is no US-style mandatory national registration for the common case. UK networks maintain reserved sender ID lists, and where a network requires pre-registration we can check and register your ID with the networks before launch.

What is Ofcom's CLI authentication framework?

Ofcom introduced an authentication framework for CLI (caller line identity) after a 2024 consultation; the rollout continues. It targets spoofed caller IDs and works alongside the MEF UK whitelist register and Do-Not-Originate lists, which is part of the anti-spoofing context around UK messaging originators.

Is this page legal advice?

No. It is an overview. Our compliance guide is not legal advice either, but it is the general reference, and it points clearly at where the law sits and where responsibility lives. Check it and the policy pages before you launch.

Keep UK SMS on the right side of the rules

Review our compliance guide and policy pages, then let us check your sender ID against network reserved lists before you launch.