Mass text messaging in the European Union is governed by a combination of EU-wide regulations and national laws. The two primary frameworks are the General Data Protection Regulation (GDPR) and the ePrivacy Directive. Understanding these regulations is essential for any organization sending SMS campaigns to EU residents.

EU mass messaging laws and regulations

GDPR (General Data Protection Regulation)

GDPR, which took effect in May 2018, governs how personal data — including mobile phone numbers — is collected, stored, and used across the EU. Key GDPR requirements for SMS messaging include:

  • Lawful Basis for Processing: You must have a valid legal basis for processing phone numbers. For marketing SMS, this is typically explicit consent.
  • Clear Consent: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes or bundled consent are not sufficient.
  • Right to Withdraw Consent: Recipients must be able to easily withdraw consent at any time, and withdrawals must be honored promptly.
  • Data Minimization: Collect only the data you need and retain it only as long as necessary.
  • Transparency: Inform contacts at the time of collection what their data will be used for, including SMS marketing.

ePrivacy Directive

The ePrivacy Directive (sometimes called the "Cookie Law") specifically addresses electronic communications, including SMS. For marketing texts, it requires:

  • Prior explicit consent before sending marketing SMS to individuals
  • Clear identification of the sender in every message
  • A valid address or opt-out mechanism so recipients can object to future messages

National Variations

While GDPR is directly applicable across all EU member states, each country may implement additional requirements under the ePrivacy Directive. Germany, France, and other member states have national laws that may impose stricter rules. Always check the specific requirements of each country where your recipients are located.

Penalties for Non-Compliance

GDPR violations can result in fines of up to €20 million or 4% of global annual turnover — whichever is higher. National data protection authorities in each EU country can also impose their own penalties for ePrivacy violations.

Best Practices for EU Compliance

  • Obtain documented, explicit consent with a clear description of what recipients are signing up for
  • Maintain consent records with timestamps and evidence of the opt-in mechanism used
  • Honor opt-out requests immediately
  • Appoint a Data Protection Officer (DPO) if required by GDPR
  • Conduct a Data Protection Impact Assessment (DPIA) for large-scale SMS processing

Note: This article provides general information and is not legal advice. Consult a legal expert familiar with EU data protection law for guidance specific to your situation.