Back to Blog
July 16, 20267 min read

SMS to Customers and GDPR: What Applies to Businesses

Consent, opt-out and the crucial difference between transactional and marketing messages — in plain words

Laptop with a security lock icon symbolizing customer data protection
Photo: Dan Nelson · Pexels

GDPR does not ban SMS to customers — it defines when and how you may send them. The basic rule in plain words: appointment reminders are transactional messages serving something the customer themselves requested, while marketing messages require consent and an easy way to unsubscribe. This article explains the basics — it is general information, not legal advice.

Transactional vs Marketing: The Distinction That Matters

Before anything else, separate the two kinds of messages:

  • Transactional messages: appointment reminders, booking confirmations, notice of a time change. They serve the transaction the customer initiated — their appointment.
  • Marketing messages: offers, discounts, promotional greetings, announcements of new services. Their goal is promotion, not serving a specific appointment.

A reminder for an appointment the customer booked themselves is a reasonable, expected message: it relates directly to the service they asked for. A promotional SMS, by contrast, needs its own legal basis — as a rule, the customer's consent.

What Consent Means in Practice

  • Free and specific — the customer actively chooses to receive promotional messages; they are not silently added to a list.
  • Informed — they know who will message them and what kind of content.
  • Revocable — they can withdraw it at any time, as easily as they gave it.
  • Recorded — you must be able to show when and how it was given.

Practically: do not send offers to someone who merely left their phone number for an appointment. The number was given to serve the appointment — not as blanket permission for marketing.

Opt-Out: An Easy Exit, Always

For marketing messages, the customer must be able to stop receiving them easily — with a reply, a link or a phone call. And when they ask, removal from the list must happen promptly and permanently. Note: opting out of marketing does not mean losing appointment reminders — those continue normally, because they serve the bookings the customer makes.

Good Practices for Customer Data

  • Collect only what you need — a name and mobile number are enough for a reminder.
  • Use the details for the purpose they were given.
  • Do not share your client list with third parties without a legal basis.
  • Delete data when asked — the customer has a right to erasure.
  • Choose tools that give the customer a way to cancel and manage their own appointments.

How Wiiz Helps

Wiiz is built around the private-channel principle: your customers are not exposed on a public marketplace and the client list remains yours. SMS reminders (from €0.06 per SMS) are sent only for appointments that exist in your calendar — that is, only as transactional messages — while marketing campaigns are a separate, distinct feature, so the two kinds of communication never get mixed up.

Frequently Asked Questions

Do I need consent to send an SMS appointment reminder?

An appointment reminder is a transactional message: it serves the appointment the customer booked themselves and is something they reasonably expect. Promotional SMS are a different case and as a rule require consent.

Can I send offers to customers who have booked appointments?

Not automatically. Someone giving you their mobile number for an appointment does not mean they consented to marketing messages. For promotional campaigns, make sure you have consent and always an easy way to unsubscribe.

What should a compliant marketing SMS include?

A clear sender identity and an easy way to opt out of future messages — for example an unsubscribe link or number. And of course, it should only go to those who have consented.

If a customer opts out, do they lose reminders too?

No. Opt-out concerns marketing messages. Reminders for the appointments they book continue to be sent, because they serve their own booking.

Do the same rules apply in Greece and Cyprus?

GDPR applies across the EU, so in both countries, alongside national rules on electronic communications. The core principles — consent for marketing, easy opt-out, respect for data — are common. For specific cases, consult a legal professional.

Computer screen with cybersecurity text
Photo: cottonbro studio · Pexels

Communicate with Your Customers the Right Way

With Wiiz, reminders are sent only for real appointments and the client list stays yours — from €0.06 per SMS.

Start Free