Quantum Automations Quantum Automations
Blog · Portfolio
← Back to Blog
Guide · Lead Systems

SMS Outbound Automation for UK B2B: PECR Rules and Delivery

Published September 2026
Topic Lead Systems · SMS Outreach
Reading time 10 min
For UK SME founders
On this page
  1. PECR consent for B2B SMS in the UK: what soft opt-in covers and where it ends for corporate subscribers
  2. Legitimate interest for B2B SMS: the ICO's three-part test and how UK enforcement has applied it
  3. Sender ID setup for UK SMS outbound: alphanumeric sender IDs, long codes, and UK carrier registration requirements
  4. SMS copy that converts without triggering spam filters: character limits, link handling, and opt-out mechanics
  5. Sequencing SMS with email and LinkedIn: where SMS fits in a multi-touch outbound programme
  6. SMS delivery infrastructure: UK carrier routing, DLR tracking, and what a 94% delivery rate actually requires
  7. Opt-out handling and suppression list management: the PECR obligations that survive campaign end
  8. What changed in 2025–2026: Ofcom messaging regulations and UK network operator spam filtering changes
  9. Good / Bad / Ugly: three SMS outbound programmes and their compliance and delivery outcomes
  10. FAQ

A 15-person UK SaaS team ran an identical 200-contact list through email and SMS in April. The email opened at 6.4% in the first 24 hours. The SMS read rate was 31% within 90 seconds. The SMS side generated 14 booked calls versus 3 from email. They had avoided SMS outbound for two years because a lawyer said it was probably not compliant for B2B — without reading the ICO's guidance on corporate subscribers. That lawyer was cautious, not technically correct. PECR treats SMS to corporate mobile numbers differently from SMS to personal numbers, and legitimate interest applies under conditions the ICO has laid out plainly. Getting those conditions wrong generates complaints. Getting them right opens a channel most competitors have left untouched.

PECR consent for B2B SMS in the UK: what soft opt-in covers and where it ends for corporate subscribers

PECR Regulation 22 requires "prior consent" before sending unsolicited marketing texts to individuals. The definition of "individual" is what most advisers skip over. The ICO draws a firm distinction between sole traders and individual partners — treated as individuals, requiring consent — and employees of limited companies and PLCs, who are corporate subscribers and sit outside that same consent requirement.

In practice: if you are texting a mobile number that belongs to a company account, or is used demonstrably in a corporate capacity by an employee of a limited company, the consent requirement of Regulation 22 does not apply. You still need a legal basis under UK GDPR, but you are not blocked by PECR's consent gate.

The soft opt-in under Regulation 22(3) requires three conditions to be met simultaneously: you obtained the contact's details in the course of a sale or sale negotiations; you are marketing similar products or services; and you gave a clear opt-out opportunity at the point of collection, which they did not take. For cold outbound to contacts who have never interacted with you, soft opt-in does not apply. You need either explicit consent or a legitimate interest basis.

Legitimate interest for B2B SMS: the ICO's three-part test and how UK enforcement has applied it

The ICO's three-part test for legitimate interest as a basis for direct marketing:

  1. Purpose test: Is there a legitimate interest being pursued?
  2. Necessity test: Is processing necessary for that purpose?
  3. Balancing test: Do the individual's interests override the legitimate interest?

For B2B SMS to corporate subscribers, the ICO's direct marketing guidance accepts that commercial communication between businesses can satisfy the purpose test. The necessity test is tighter: you need a reasonable connection between the recipient's role and what you are offering. A UK accountancy software firm texting the finance director of a 50-person manufacturer passes this. A debt collection agency texting that same person about an unrelated financial product does not.

The balancing test is where most B2B SMS programmes fail their legitimate interest assessment (LIA). The ICO expects you to document the assessment, weigh the intrusiveness of the channel — SMS is more intrusive than email — and apply reasonable data minimisation. A written LIA should address three questions: why SMS specifically, why this list, and what the opt-out mechanism is and how quickly it is honoured.

UK enforcement has cited absence of a documented LIA rather than the channel choice itself. It is worth noting that the Data & Marketing Association takes a more conservative position in its Code of Practice: consent-first even where legitimate interest is technically available. That is the counterpoint. Our view: document the LIA properly and the risk is manageable; skip it and you have no defence.

Sender ID setup for UK SMS outbound: alphanumeric sender IDs, long codes, and UK carrier registration requirements

UK carriers present a harder technical environment for SMS than most US-built tooling assumes.

Alphanumeric sender IDs replace the sending number with a text string, e.g. "QuantumAuto". They are one-way and require pre-registration through your SMS provider's UK carrier registration workflow. Unregistered sender IDs are increasingly blocked outright. Registration involves submitting the sender ID string, company registration number, and use case description. Timelines run 3–10 business days.

Long codes — standard 07 mobile numbers — are two-way and support inbound replies. They require a UK virtual number from a licensed operator. UK carrier spam scoring applies to long codes even without a formal registration framework; carriers run their own scoring models.

Short codes (5–6 digit numbers) are registered through the Phone-paid Services Authority and produce the highest deliverability. They require 6–8 weeks for approval and higher monthly costs. Right for a high-volume ongoing programme; not suitable for a quick-start test.

Type Reply-capable Registration required Typical UK delivery rate
Alphanumeric sender ID No Yes (carrier, 3–10 days) 90–94% if registered
Long code (07 number) Yes Virtual number purchase 85–92%
Short code Yes Phone-paid Services Authority 95–98%

SMS copy that converts without triggering spam filters: character limits, link handling, and opt-out mechanics

A standard UK SMS is 160 characters using GSM-7 encoding. One character outside the GSM-7 set — a curly quote, a non-breaking space, an emoji — splits the message into 153-character segments that arrive as two separate messages on many handsets.

Practical character budget for a single-segment cold message: - Message body: ~130 characters - Opt-out instruction: "Reply STOP to opt out" = 22 characters - 8-character buffer for personalisation variables

Do not use shortened URLs. UK carrier spam filters score bit.ly, t.co, and similar shorteners heavily against you. Use a branded domain redirect (e.g. go.yourcompany.co.uk/demo) and track clicks server-side on your own redirect endpoint.

For the opt-out mechanic, include "Reply STOP" in every message. Your receiving infrastructure must process inbound STOP replies and write to a suppression list within one working day. If you are using a Twilio long code for inbound, the inbound webhook payload looks like this:

{
  "From": "+447911123456",
  "To": "+447700900123",
  "Body": "STOP",
  "MessageSid": "SMxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
  "AccountSid": "ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
}

Write the From number to your suppression table on receipt. Do not route this through a batch job that runs at midnight — the ICO expects same-day processing.

Sequencing SMS with email and LinkedIn: where SMS fits in a multi-touch outbound programme

SMS works as a third or fourth touch in a multi-channel sequence, not as the opener. A cold SMS from an unrecognised sender to a corporate number reads as spam regardless of your PECR basis. Use it after at least one email and one LinkedIn touchpoint have established context.

A sequence structure that produced the results from the opening example:

  1. Day 0: Personalised email referencing a specific company detail or trigger event
  2. Day 3: LinkedIn connection request
  3. Day 6: LinkedIn message (if accepted) or second email
  4. Day 10: SMS — reference the previous email, include a direct booking link
  5. Day 14: Voicemail drop or AI voice agent call

The SMS at step 4 is short: "Hi [First name], emailed you about [topic] last week. Happy to send the deck — reply here or grab 15 mins: [link]." 140 characters. One segment.

See our multi-channel outbound sequence guide for the full automation flow. LinkedIn DM automation has its own compliance considerations — the safe patterns are in LinkedIn DM automation for UK B2B.

SMS delivery infrastructure: UK carrier routing, DLR tracking, and what a 94% delivery rate actually requires

A 94% delivery rate for UK B2B SMS requires attention to three distinct variables: routing quality, list hygiene, and delivery receipt (DLR) tracking.

Routing quality means your provider is using direct connections to UK operators, not grey routes through international aggregators. Grey routes are cheaper and are consistently filtered during UK carrier sweep events. Twilio, Bird (formerly MessageBird), and Vonage all operate direct UK carrier connections. Test a 50-contact pilot and monitor DLR statuses — not just sent counts.

List hygiene: UK mobile numbers inactive for 12+ months are frequently reassigned. Sending to a reassigned number is a PECR compliance risk and a delivery quality signal to carriers. Run your list through an HLR (Home Location Register) lookup API before each campaign. This step recovers 2–4 percentage points of delivery rate on lists older than six months.

DLR tracking: UK carrier DLRs arrive within 30 seconds for on-network delivery. A message in "sent" status without a DLR after 5 minutes has almost certainly failed silently. Build a DLR timeout handler:

def handle_dlr_timeout(message_sid: str, timeout_seconds: int = 300):
    """Flag messages that have not received delivery confirmation."""
    if time_since_sent(message_sid) > timeout_seconds:
        update_message_status(message_sid, "delivery_failed")
        log_failed_delivery(message_sid)
        trigger_carrier_debug_alert(message_sid)

Track delivery rate by carrier and sender ID separately. A drop below 88% on any single carrier signals your sending pattern is being filtered. See our phone number warmup and spam flag recovery guide for recovery steps once a long code is flagged.

Opt-out handling and suppression list management: the PECR obligations that survive campaign end

PECR opt-out obligations do not expire. An opt-out of SMS from your organisation does not reset when you change CRM, change provider, change the sender ID, or run a new campaign under a different product name.

Minimum suppression list requirements under PECR: - Written record of each opt-out with timestamp and channel - Opt-out honoured within one working day of receipt - Suppression applied to all future campaigns from the organisation - Suppression list not reset or overwritten without specific legal basis

Maintain a sms_suppressions table outside any single campaign tool. Your campaign automation queries this table before generating send lists. An n8n workflow that checks suppression state before producing each SMS batch is more reliable than a CRM filter that can be overridden by a list import.

Cross-check your SMS suppression list against your email suppression list quarterly. A contact who opted out of SMS is signalling channel preference — sending harder elsewhere is not the answer.

What changed in 2025–2026: Ofcom messaging regulations and UK network operator spam filtering changes

In early 2025, Ofcom published updated guidance on tackling scam texts, which accelerated UK mobile operators implementing enhanced sender filtering at the network layer. EE and Vodafone UK deployed SMS scoring models in Q1 2025 that assess messages in real time — URL patterns, content similarity across a batch, and sending frequency from a given sender.

The practical consequence for legitimate B2B senders: personalisation is now a deliverability requirement. A batch of 500 identical messages will trigger carrier filtering even with a registered sender ID and a clean PECR basis. Introduce at least three content variations across any batch over 200 messages.

The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, did not overhaul the PECR framework for SMS, but it clarified that legitimate interest assessments must be reviewed at least annually. The ICO updated its direct marketing guidance accordingly in Q3 2025. If you ran an LIA in 2024 and have not revisited it, review it before your next campaign. For broader PECR and TPS compliance, our PECR and TPS compliance guide for UK AI outreach covers the updated framework.

Good / Bad / Ugly: three SMS outbound programmes and their compliance and delivery outcomes

Good: UK SaaS company, ICP-matched list, four-touch sequence

A 12-person B2B SaaS company targeting UK HR teams. 180 contacts, all limited company employees from LinkedIn Sales Navigator. Documented LIA on file. Registered alphanumeric sender ID. Four-touch sequence with SMS at touch four, referencing previous email. Message personalised to role and company. "Reply STOP" included. DLR tracking active. Suppression list in Postgres, queried before each batch. Result: 29% read rate, 8 booked demos from 180 contacts. Zero opt-out complaints. Zero ICO enquiries. Total cost including registration: £340.

Bad: Fintech startup, purchased list, undocumented basis

A 6-person fintech bought a "B2B decision-maker" list of 1,200 UK mobile numbers from a data broker. No documented LIA. No segmentation of corporate versus individual subscribers — the list included sole traders. No prior email or LinkedIn touch. Unregistered alphanumeric sender ID, silently replaced with a generic number by two carriers. Delivery rate: 61%. Two ICO complaints from sole traders who required explicit consent. One complaint from a contact who had previously opted out via the broker's licence holder. Campaigns paused for compliance review. Leads generated: three, none of whom booked.

Ugly: Agency, multiple clients, shared sender infrastructure

A digital agency ran SMS campaigns for five clients from a single shared long code. Each client's suppression list lived in a separate spreadsheet. During a manual list merge, one client's suppression list overwrote another's. 340 previously opted-out contacts received messages. The agency required a formal ICO undertaking and remediation report. The technical fix — a shared suppression service in Postgres that all client workflows query via API — took one engineer six hours to build. The compliance event it could have prevented took six months to resolve.

The pattern across all three: technical setup is straightforward. Compliance failure is almost always in suppression management and LIA documentation. For a sense of how these systems are built at the portfolio level, see our LinkedIn AI SDR case study — the suppression and enrichment architecture transfers directly to SMS programmes.

FAQ

Is B2B SMS outreach legal in the UK without explicit consent from the recipient?

Yes, for corporate subscribers — employees of limited companies and PLCs — PECR does not require prior explicit consent if you have a documented legitimate interest basis or an existing commercial relationship that satisfies the soft opt-in rule. The corporate subscriber distinction is the critical legal gateway: sole traders and individual partners are treated as individuals under PECR and do require consent. A legitimate interest assessment must be documented before you send, weighing the intrusiveness of SMS against the business purpose. You must include an opt-out mechanism in every message and honour opt-outs within one working day. The ICO has confirmed this position in its direct marketing guidance, but notes that SMS is treated as more intrusive than email when applying the balancing test.

Does PECR treat corporate mobile numbers differently from personal mobile numbers?

Yes, explicitly. PECR Regulation 22 applies its consent requirement to 'individual subscribers', which the ICO defines as sole traders, individual partners, and private individuals — not employees acting in a corporate capacity. A number on a company's account is a corporate subscriber. In practice, if the mobile number was sourced from professional data (LinkedIn, Companies House, trade directories) and belongs to an employee of a limited company, UK enforcement has treated it as a corporate subscriber. Numbers sourced from consumer databases retain individual subscriber status regardless of the holder's employment. Document the source and the corporate status of each number in your list before sending — this record is what you produce if an ICO complaint lands.

How do UK carriers handle alphanumeric sender IDs and what registration is required?

As of 2024, all four major UK mobile operators — EE/BT, Vodafone UK, O2, and Three — require alphanumeric sender IDs to be pre-registered or they replace the sender ID with a generic number, or filter the message entirely. Registration happens through your SMS provider's UK carrier registration process: you submit the sender ID string, company name, and a use case description. Unregistered sender IDs are increasingly blocked outright rather than substituted. Registration takes 3–10 business days depending on the provider. Alphanumeric sender IDs are one-way only — recipients cannot reply — so if your campaign needs inbound STOP processing, you need a UK long code or short code alongside it.

What must a UK B2B SMS opt-out mechanism include to satisfy ICO requirements?

Every marketing SMS must include a clear, free opt-out method in every message — not just the first one. The standard wording is 'Reply STOP to opt out'. Your receiving infrastructure must process STOP replies and add the number to a suppression list within one working day; the ICO treats delayed processing as a breach of PECR. The suppression list must persist across campaigns, CRM migrations, and provider changes — it is the organisation's obligation, not any single tool's. Where you use an alphanumeric sender ID (which cannot receive replies), provide an alternative opt-out channel such as an email address or web form within the message body.

Related Reading

WhatsApp Business API for UK B2B Lead Nurture in 2026

WhatsApp Business API setup, template approval, and GDPR-compliant nurture sequences for UK B2B — with the send rules th

PECR TPS Compliance for UK AI Cold Calling Campaigns

The TPS/CTPS screening stack and PECR rules for UK AI cold calling: who you can legally call, how to screen the list, an

Need a compliant SMS outbound programme set up?

30-minute audit. We map your stack, your constraints, and where AI will pay back fastest.

Take the Quantum Leap →
© 2026 Quantum Automations Group Ltd
Home Blog Portfolio Privacy Terms Security