Skip to content

Opt-In and Opt-Out for SMS & RCS Campaigns: A GDPR-Compliant Guide for B2C Brands

Mobile messaging remains one of the most effective channels for reaching consumers, but that reach comes with responsibility. Before a single SMS or RCS message lands in a customer’s inbox, brands need to get consent right, and they need to make it just as easy for customers to leave a list as it was to join one.

For B2C companies running SMS and RCS campaigns across European markets, opt-in and opt-out are legal requirements under the GDPR and the ePrivacy Directive (as implemented in national laws such as Germany’s UWG or France’s “Code des postes et des communications électroniques”). Get them wrong, and you risk fines, blocked sender IDs, and a customer base that no longer trusts your messages.

This guide breaks down what GDPR-compliant opt-in and opt-out actually look like for SMS and RCS marketing, and how to build both into your campaigns from day one.

Why Consent Rules Apply to SMS and RCS Alike

From a data protection standpoint, RCS is treated the same way as SMS. Both are direct marketing channels sending messages to an identifiable individual’s device, which means both fall under:

  • The ePrivacy Directive, which specifically governs unsolicited electronic communications and generally requires prior consent (opt-in) for marketing messages sent to consumers.
  • The GDPR, which governs how you collect, store, and process the personal data (phone number, name, preferences) that makes the campaign possible in the first place.

If your company is expanding from SMS into RCS, it is a mistake to assume the richer format changes the consent bar. RCS’s richer features and data (read receipts, interaction tracking, verified sender profiles) means there is more personal data in play.

What Counts as Valid Consent Under GDPR

GDPR sets a high bar for consent. To be valid for marketing purposes, consent must be:

  • Freely given – no pre-ticked boxes, no consent bundled into terms and conditions the customer cannot decline separately.
  • Specific – consent to receive SMS/RCS marketing should be distinct from consent to receive order updates or use cookies.
  • Informed – customers need to know who is messaging them, what kind of content to expect, how often, and how to unsubscribe.
  • Unambiguous – an affirmative action is required (checking a box, texting a keyword, submitting a signup form), so silence or inactivity is never consent.

In practice, most compliant programs in Europe use double opt-in (even though it is not a GDPR requirement): the customer submits their number (e.g., via a web form or in-store signup), and then confirms via a reply SMS or RCS message before they are added to any marketing list. Double opt-in does two things at once: it satisfies the requirement to be unambiguous and it protects you from fake or mistyped numbers, which also improves the deliverability metrics discussed in our piece on key KPIs in SMS & RCS marketing.

What to capture at the point of opt-in

For GDPR accountability, you need to be able to prove consent was given, not just that it exists. That means logging, for every subscriber:

  • The exact wording of the consent request shown to the customer
  • Timestamp and channel of consent (web form, in-store, keyword reply, etc.)
  • IP address or other verification data, where applicable
  • Confirmation that double opt-in was completed, where applicable

This record becomes essential if a regulator or customer ever asks you to demonstrate that consent was properly obtained.

Building Opt-Out Into Every Campaign

Under GDPR and the ePrivacy rules, customers must be able to withdraw consent at any time, and doing so must be as easy as giving it. A few practical requirements:

  • Every marketing message needs a clear unsubscribe option. For SMS, this is typically a “reply STOP” instruction. For RCS, this can be a dedicated suggested-reply chip (e.g., “Unsubscribe”) built directly into the rich card. This is arguably an even better experience than typing a keyword, since it removes any ambiguity about the correct wording.
  • Opt-out requests must be processed promptly, and the customer should not receive further marketing messages once the request is logged.
  • Opt-out cannot require more effort than opt-in. Making someone call a support line or email a request when they signed up with a single tap on a web form would not meet the “as easy to withdraw as to give” standard.
  • Transactional and service messages are treated differently. Appointment reminders, delivery notifications, and account security alerts generally rely on a different legal basis (contract performance or legitimate interest) rather than marketing consent, but customers should still have a way to manage preferences, and these messages should not be used as a backdoor for promotional content. 

If you’re setting up a new program, our step-by-step walkthrough on how to run an SMS campaign shows exactly where opt-in collection and opt-out handling fit into the campaign lifecycle, from list building to send-time segmentation.

Sender Identity and Transparency

Transparency obligations under GDPR also mean customers should always know who is messaging them. RCS has a natural advantage here: verified sender profiles display your company’s real name, logo, and (where enabled) a verification badge, which reduces confusion and phishing risk compared to a generic short code. For SMS, a registered and consistent sender ID matters just as much, which is something to keep in mind if you operate across multiple European markets, where sender ID registration requirements can vary by country.

Data Minimization and Retention

Beyond consent itself, GDPR requires that you only collect and retain the data you actually need for the campaign:

  • Don’t request data points (age, income bracket, precise location) you don’t have a genuine campaign use for.
  • Define a retention policy: subscriber data should not be retained longer than necessary for the purpose for which it was collected. Periodically review inactive subscribers and consider removing or re-permissioning them where appropriate.
  • If you use a messaging vendor or platform, confirm they act as a GDPR data processor under a signed Data Processing Agreement (DPA), and that any data transferred outside the EU/EEA has appropriate safeguards in place.

A Quick Compliance Checklist

Before launching an SMS or RCS campaign to European customers, confirm you can check off each of the following:

  • Consent was collected through an affirmative, specific action (not a pre-ticked box).
  • Double opt-in confirmation is in place and logged with timestamp and source (where applicable) .
  • Every marketing message includes a working, one-step opt-out.
  • Opt-out requests are processed quickly and reliably suppress future sends.
  • Your sender identity is clear, registered, and consistent across channels.
  • You have a documented retention and data minimization policy.
  • Your messaging provider is contractually bound as a GDPR data processor.

The Bottom Line on Opt-In and Opt-Out

GDPR-compliant opt-in and opt-out are what makes effective SMS and RCS marketing sustainable. A well-permissioned list converts better, complains less, and survives regulatory scrutiny. As RCS adoption grows across Europe, brands that bake consent and easy opt-out into their campaign design from the start will be the ones building long-term trust with their customers, not just short-term reach.

Looking to launch a compliant SMS or RCS program across European markets? Get in touch with the iBASIS Business Messaging team to see how our platform supports verified sender profiles and immediate, reliable opt-out handling.