SMS complianceCyprus and Greece

SMS Marketing Consent and Opt-Out Rules in Greece and Cyprus

A practical guide to lawful SMS lists, consent records, the existing-customer exception, STOP and suppression lists.

Reading time: 11 minutesUpdated:
Διαβάστε τον οδηγό στα Ελληνικά

Identify direct marketing first

An SMS containing a discount, offer, package, referral or purchase prompt is normally direct marketing even when bundled with useful information. Calling it “informational” in software does not decide its legal character.

Article 13 of the EU ePrivacy Directive sets prior consent as the general rule for electronic marketing. National rules and guidance, including those of the Greek and Cypriot data-protection authorities, implement that framework.

Collect consent you can prove

The marketing choice should be optional, specific, clear and separate from accepting booking terms. Avoid pre-ticked boxes or making service conditional on unrelated permission.

Store the number, timestamp, source, exact statement and privacy-notice version. Double opt-in is not automatically mandatory in every case, but can strengthen evidence that the person controls the number.

  • Who agreed, when and through which form
  • Which brand and message type they accepted
  • When they withdrew and how suppression was applied

Use the customer exception cautiously

ePrivacy contains a narrow exception where details were obtained through a sale, marketing concerns the same company’s own similar products or services, and an easy, free objection was offered at collection and in every message.

An old appointment is not unlimited permission, and the exception does not automatically transfer to partners. Document why it applies and obtain local legal advice for uncertain lists.

Make opting out genuinely easy

Each marketing SMS needs a clear, easy objection mechanism without cost beyond the ordinary channel. If the sender cannot receive replies, provide a working link or comparably simple method and test it.

On STOP or another clear objection, update a central suppression list before the next campaign. Retain only the minimum identifier needed to prevent accidental re-import rather than erasing all evidence of the objection.

Audit lists, vendors and purpose

Do not buy a list because a seller labels it “GDPR compliant.” Request origin, consent wording, named recipients, dates and audit rights; broad third-party permission rarely names your brand adequately.

Audit consent logs, suppression, access roles and retention regularly. This is general information, not legal advice; obtain a local review for the actual campaign, audience and content.

Frequently asked questions

Can I send offers to everyone who booked?

Not automatically. Confirm valid consent or document that every condition of the narrow existing-customer exception is met.

Is the word STOP enough?

It is familiar where replies work. Otherwise provide an equally easy functioning method and honour every clear objection.

Can I message a number after opt-out?

Not for the marketing refused unless fresh valid permission is given. Keep a minimal suppression record to prevent accidental re-import.

Sources and methodology

Prices and features can change. Verify the official source before making a decision.

Related guides