Texting your five-a-side team needs no paperwork. Texting 400 customers about a promotion is regulated activity in most of the world, and the penalties are not trivial.
This is a plain-language overview to help you ask the right questions. It is not legal advice — the rules differ by country and change, and if you are texting at scale commercially you should get advice specific to your situation.
The one principle underneath all of it
Across jurisdictions the same idea recurs: you may send commercial messages to people who agreed to receive them, and you must stop when they ask.
Everything else is detail about what “agreed” means, how you prove it, and how quickly you must stop.
Europe: GDPR and ePrivacy
For marketing texts to individuals in the EU and UK, consent must be:
- Freely given — not a condition of buying something.
- Specific — to SMS marketing, not buried in a general acceptance of terms.
- Informed — they knew who you are and what you would send.
- Unambiguous — an affirmative action. Pre-ticked boxes do not count, and neither does silence.
- Documented — you must be able to show when and how consent was obtained.
The main exception is soft opt-in: you may market to existing customers about similar products to what they bought, provided they were offered an opt-out at the point of collection and in every message since. The scope is narrower than people assume — an existing customer is not a blanket permission for anything.
Separately, the numbers themselves are personal data, so the usual GDPR obligations apply: a lawful basis, a retention period, and the ability to honour a deletion request. This is also why putting 60 customers in one group thread, where they all see each other’s numbers, is a data disclosure and not merely awkward.
United States: TCPA and the 10DLC layer
The TCPA governs commercial texting, and its notable feature is a private right of action with statutory damages per message — $500, or $1,500 for wilful violations. Multiply by a list of a thousand and the exposure is not theoretical; TCPA class actions are an established industry.
Requirements in outline: prior express consent for marketing, prior express written consent for autodialed marketing, sender identification, honouring opt-outs promptly, and respecting quiet hours (commonly 8am–9pm in the recipient’s local time).
There is also a carrier layer independent of the law. US carriers require business messaging over standard numbers to be registered through 10DLC, with brand and campaign vetting. Unregistered commercial traffic is increasingly filtered regardless of whether you have consent. This applies to messaging routed through gateways rather than to a personal phone texting its own contacts, but it is worth knowing the environment.
Elsewhere
Canada’s CASL is strict, with consent requirements and significant penalties. Australia’s Spam Act requires consent, sender identification and a functional unsubscribe. Most other countries have adopted something recognisably similar. The safe assumption travelling anywhere: consent, identification, opt-out.
What an opt-out has to be
Common ground everywhere:
- Present in the message, or at minimum in the first message and periodically after.
- Free — no premium number, no charge.
- Simple — replying STOP is the convention because it works with no effort.
- Fast — immediate in practice; some regimes allow a short window, but “before the next send” is the only safe standard.
- Permanent. Someone who opted out stays out. Re-adding them because they bought something later is the most common way a well-meaning business ends up in trouble.
Practically: keep a suppression list, and check it before every send. An opt-out that is honoured manually and inconsistently is worse than none, because you have documented that you knew.
The awkward part: replies come to your phone
Sending from your own phone with your own number has real privacy advantages — your contacts never leave the device, no third party holds your list. It also means opt-out requests arrive as ordinary text messages in your inbox, and it is on you to act on them.
There is no automated STOP handling, because there is no server in the middle to do it. If someone replies STOP, you must remove them from the list yourself before the next send. On a list of a few hundred this is entirely manageable. It is a genuine responsibility rather than a footnote.
When you should not use a personal phone at all
Be honest with yourself about which side of this line you are on:
Fine from your own phone: your own customers, who gave you their number for this, in the low hundreds, at a frequency they would expect.
Not fine from your own phone: purchased or scraped lists (illegal nearly everywhere, and no tool makes it legal), tens of thousands of recipients, anything requiring audited consent records or automated compliance. That is a job for a compliant platform with proper opt-out handling — see bulk SMS services versus your own phone.
Step by step
- Establish where consent came from for every number on the list, and whether it covers what you are about to send.
- Discard anything you cannot account for. A number of unknown origin is a liability, not an asset.
- Identify yourself in the first line of every message.
- Include a free, simple opt-out and keep a suppression list.
- Check the suppression list before every send, since nothing does it for you.
- Respect quiet hours in the recipient’s local time, not yours.
- Get advice if you are texting commercially at scale — this page is orientation, not a legal opinion.
Questions people ask
Do I need consent to text my own customers?
For marketing, generally yes. Some regimes allow a narrow soft opt-in for existing customers about similar products, provided an opt-out was offered at collection and appears in every message. Transactional messages — an appointment reminder they asked for — are treated differently from marketing.
Is “reply STOP to opt out” enough?
It is the standard mechanism and it satisfies the “free and simple” requirement. What matters is that you actually honour it, immediately and permanently.
Can I text a list I bought?
No. Purchased lists fail the consent requirement essentially everywhere, and they also carry high failure rates that get your number flagged by carriers.
What if someone replies STOP and I text them again?
That is the clearest possible violation and the easiest to prove. Keep a suppression list and check it before every send.
Does this apply to a school parents’ group or a sports team?
Non-commercial messages to people who gave you their number for that purpose are a different situation from marketing. The data protection obligations still apply — do not put everyone in one thread where they see each other’s numbers.
Who is responsible, me or the app?
You are. The app is a tool that composes messages on your device; you choose the recipients and the content. This is true of any texting tool.