Legalify shield logoLegalify
Free CheckerGDPR GuideBlogFeaturesHow it worksPricing
Log inSign up
Guides/SMS & WhatsApp Marketing

SMS and WhatsApp Marketing GDPR Compliance Guide

Direct messaging is governed by the ePrivacy Directive first and GDPR second, which makes it stricter than most advertisers expect: consent is the default rule, and the soft opt-in exception is narrower than it looks. This guide covers what that means for your message copy.

Updated 13 August 2026

SMS and WhatsApp marketing sit under Art. 13 of the ePrivacy Directive, which requires prior consent for unsolicited commercial messages sent by automated means to individual subscribers. GDPR then governs how the underlying phone number is collected, stored, and erased. The result is a two-layer regime where a lawful basis under GDPR does not by itself make the message lawful. National implementations differ, particularly on whether the rules extend to business subscribers. This guide covers the obligations that shape the message itself.

Consent as the default rule (ePrivacy Art. 13)

Prior consent is required for marketing SMS and messaging-app broadcasts to individuals. That consent must meet the GDPR standard: freely given, specific, informed, unambiguous, and separately obtainable from other terms. Bundling SMS consent into a checkout tick-box that also covers terms and conditions fails the test. Ticking a box to receive order updates does not extend to promotional broadcasts, because the purpose is different.

The soft opt-in exception and its limits

Where you obtained the number in the course of a sale of your own similar products or services, and gave a clear opt-out opportunity at that point and in every message since, you may market similar products without separate consent. Three constraints trip advertisers up: the sale must be your own, the products must be genuinely similar, and negotiations that did not result in a sale count only in some member states. The exception never covers third-party products or purchased lists.

Sender identity and opt-out in every message (Art. 13 and GDPR Art. 21)

Every marketing message must identify the sender and provide a free, simple opt-out in the message itself. 'STOP to unsubscribe' satisfies the mechanism, but the sender must also be identifiable from the message, which an unbranded short code is not. Opt-outs must be actioned promptly across every channel, since Art. 21 objection applies to the person and not the channel.

WhatsApp template messages and claim rules

WhatsApp Business marketing templates are pre-approved for format, not for legality. Approval says nothing about whether your claim complies with the UCPD or whether you hold consent. Urgency framing works especially poorly here: a countdown in a message that arrives on the recipient's personal phone amplifies both the aggressive-practice risk under UCPD Art. 8-9 and the volume of complaints.

Common violations to avoid

  • Bundled consent — SMS opt-in combined with terms acceptance or newsletter signup
  • Purchased lists — messaging numbers you did not collect through your own sale or consent
  • Soft opt-in overreach — marketing unrelated products under an exception limited to similar ones
  • Unidentifiable sender — an unbranded short code with no sender name in the message body
  • Opt-out actioned in one channel only, leaving the recipient on email or push lists
  • Aggressive urgency framing in personal messaging, engaging UCPD Art. 8-9
Free resource

Get the GDPR Ad Copy Checklist

12 pre-launch compliance checks for EU campaigns. Free, instant delivery.

No spam. Unsubscribe any time.

Frequently asked questions

Do I need consent for SMS marketing under GDPR?

You need consent under the ePrivacy Directive in most cases, which is the stricter and controlling rule for direct messages. Legitimate interests can support related processing but does not replace the ePrivacy consent requirement for the message itself.

Does the soft opt-in apply to WhatsApp broadcasts?

The exception is drafted for electronic mail, and most regulators treat messaging-app broadcasts within scope. It still requires that you obtained the number during your own sale, that products are similar, and that an opt-out was offered at collection and in every message.

Is B2B SMS marketing covered by the same rules?

It depends on the member state. Some implementations apply Art. 13 only to individual subscribers, leaving corporate subscribers under a lighter regime, while others cover both. For a multi-country campaign, the practical approach is to apply the stricter standard.

How do I check my SMS or WhatsApp copy for compliance?

Paste the message body and any consent wording into Legalify's free GDPR Ad Copy Checker. It flags consent-language failures, missing opt-out signals, misleading claims, and aggressive urgency, and returns compliant rewrites.

Check your SMS & WhatsApp Marketing ad copy now

Paste your ad copy into the free GDPR Ad Copy Checker and get article-level findings in seconds — no login, no card required.

Run a free scanRead the full GDPR guide
LLegalify

AI-powered GDPR and ad risk scanning for EU marketing agencies. Catch compliance issues before campaigns go live.

Designed for GDPR risk reviewSubprocessors listed in privacy policyDPA available on request

Product

  • Free GDPR Checker
  • Meta Ad Rejected?
  • Google Ad Disapproved?
  • GDPR Ad Compliance Guide
  • Compare tools
  • How it works
  • Features
  • Pricing

Company

  • Blog
  • GDPR Guides
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA
  • Security
© 2026 Legalify · Y-tunnus: 3610308-7 · Not a substitute for legal advice.
PrivacyTermsCookiesSecurity