Using Mobile Numbers for Marketing and Transactions

Phone numbers are powerful for customer and event communication, but the rules are stricter than email. This guide explains what you can send without consent, where marketing crosses the line, and how to stay compliant.

If you use mobile numbers to contact people about your events, services, or orders, and any of those people are in the UK or EU, you need to care about GDPR and PECR. This applies whether you are sending SMS, WhatsApp messages, or using any other messaging platform. Like email, this is not just a box-ticking exercise. It affects how you collect phone numbers, what you send, and whether you are allowed to send it at all. This is a plain English guide to what you can and cannot do when it comes to using mobile numbers for both transactional messages and marketing.

What GDPR actually covers

A mobile number is personal data if it can identify an individual, which in most cases it can. If you are storing it, messaging it, or linking it to a profile, you are processing personal data. That means GDPR applies. However, with phone numbers, there is an additional layer: the Privacy and Electronic Communications Regulations (PECR) in the UK (and equivalent ePrivacy rules in the EU). These set stricter rules for electronic marketing, particularly for SMS and messaging apps.

Transactional vs marketing messages

This is the most important distinction. Transactional (or service) messages are those necessary to deliver a service or fulfil a contract. For example:

  • Sending an order confirmation, delivery update, or ticket
  • Providing instructions or account-related information
  • Sharing event updates, schedule changes, or delivery notifications
  • Notifying of cancellations or issues

Marketing messages are anything that promotes your business beyond that specific service. For example:

  • Inviting someone to a future event
  • Promoting products, offers, or services
  • Sending discount codes or sales campaigns
  • Adding them to ongoing messaging campaigns

The rules for these two categories are very different.

Using mobile numbers for transactional messages

You can usually send transactional messages without explicit consent, as long as there is a clear expectation. For example, if someone has bought from you or is attending your event, it is reasonable for them to receive:

  • “Here is your ticket”
  • “Your order has been dispatched”
  • “Your event starts at 7pm, here are the details”

This can be justified under legitimate interest, provided the messaging is strictly related to the service and does not stray into marketing. You should still:

  • Clearly identify who you are
  • Explain why they are receiving the message
  • Keep messages limited and relevant

Where data is collected indirectly, for example via a sponsor, marketplace, or third party, you should be especially careful to make the context clear in your first message.

Using mobile numbers for marketing

This is where the rules tighten significantly. Under PECR, you generally need prior consent to send marketing via SMS or messaging apps such as WhatsApp. Consent must be:

  • Freely given
  • Specific
  • Informed
  • Unambiguous

In practice, that means:

  • A clear opt-in (no pre-ticked boxes)
  • Clear wording about what messages will be sent
  • A record of when and how consent was obtained

Simply having someone’s phone number does not mean you can market to them. Even if they gave it to you directly during a purchase or registration, you still need to be clear about how it will be used. If the number was provided by a third party, such as a sponsor or partner, you are in an even weaker position, as the individual has not interacted with you directly.

There is no equivalent to the “soft opt-in” for SMS and WhatsApp that works as broadly or as safely as email. You should assume that consent is required.

What you definitely cannot do

  • Add phone numbers to marketing campaigns without consent. This is one of the most common mistakes.
  • Send a message asking for consent via SMS or WhatsApp if you do not already have permission to use that channel. That message itself may be considered unsolicited marketing.
  • Assume that because someone has purchased from you or is attending your event, you can market to them via phone afterwards. You cannot, unless they have opted in.
  • Hide who you are or why you are contacting them. Transparency still applies.

Privacy and transparency

As with email, you need to be clear about how you use personal data. Your privacy notice should explain:

  • What data you collect (including phone numbers)
  • Why you collect it
  • How you will use it (including messaging)
  • Your lawful basis
  • How long you keep it
  • How people can exercise their rights

If you are collecting phone numbers at checkout, registration, or account creation, this is the moment to be clear about whether they will be used for messaging, and whether that includes marketing.

Data minimisation and retention

Only collect phone numbers if you actually need them. If your entire communication strategy works via email, do not collect mobile numbers “just in case”. If you do collect them, make sure you have a clear purpose. For example:

  • Order or service updates
  • Event communication or emergency notifications
  • Optional marketing (with consent)

Do not keep them indefinitely without reason. If someone has not engaged or no longer has a relationship with you, consider whether you still need their data.

Security

Phone numbers are personal data and should be protected accordingly. Use secure systems, limit access internally, and avoid exporting and sharing lists unnecessarily. If a list is compromised, the same breach rules apply as with email.

People’s rights

Individuals have the same rights over their phone number as they do over their email address. This includes:

  • The right to access their data
  • The right to rectification
  • The right to erasure
  • The right to object to direct marketing

If someone objects to marketing via phone, you must stop. There is no balancing test.

A practical, low-drama approach

If you want to use mobile numbers without creating risk:

  • Use them for transactional messages where there is a clear expectation
  • Keep those messages focused and limited
  • Do not use them for marketing unless you have explicit consent
  • Offer a clear opt-in if you want to build a messaging audience
  • Be transparent about how numbers are used
  • Keep email as your primary, lower-risk channel

Mobile messaging can be a powerful tool, particularly for time-sensitive communication such as deliveries, bookings, and events. But it comes with a higher compliance bar than email. Used correctly, it improves the customer or attendee experience. Used carelessly, it creates unnecessary risk.

As with email, the safest and most effective approach is the same: communicate with people who actually want to hear from you.


The information provided in this article is for general guidance and informational purposes only. It does not constitute legal advice, and should not be relied upon as such. While every effort has been made to ensure accuracy at the time of writing, laws and best practices can change, and interpretations may vary depending on your specific circumstances.

If you are collecting, storing or processing personal data – particularly special category data – you should seek professional legal advice to ensure you are meeting your obligations under the UK GDPR or other applicable data protection laws. This is especially important if you work in a regulated industry such as healthcare, legal services or finance, where the handling of sensitive information carries additional responsibilities and risks.

Neither the author nor the publisher accepts any liability for loss or damage arising from reliance on the information contained in this post. Always consult a qualified solicitor or data protection professional if in doubt.