Skip to main content

GDPR and business messaging

Plan GDPR-ready SMS data flows from collection to deletion

A compliant messaging program is not created by adding a consent checkbox or naming a vendor. Map why each data element is used, determine the parties' roles, choose a lawful basis, give required notices, limit access and retention, protect transfers and build a repeatable process for rights and incidents.

This page is operational guidance, not legal advice or a certification. The GDPR role and obligations of each party depend on the actual processing and applicable written agreement.

Roles and contracts

Determine controller and processor roles from the real activity

Under EU guidance, a controller determines why and how personal data is processed, while a processor handles personal data on the controller's behalf. The same organization can have different roles for different activities, so labels in a marketing page cannot replace an assessment of the actual workflow.

Customer decisions

The organization initiating messages commonly decides the recipients, purpose, timing, content, lawful basis and retention needed in its own systems. Record those decisions for each use case.

Service processing

A messaging provider may process recipient and routing data to submit and track messages under written instructions. Exact roles, permitted processing and deletion duties should be stated in the applicable agreement.

Separate purposes

Account security, fraud prevention, billing, legal obligations or service analytics may require a separate role analysis. Do not assume every data element is governed by the same purpose or retention period.

Contract check: Where Article 28 applies, the controller-processor arrangement should address subject matter, duration, nature and purpose, data types, data subjects, instructions, confidentiality, security, subprocessors, rights assistance, deletion or return and audit information.

Data inventory

Map every data category that crosses the workflow

Phone numbers and message bodies are obvious, but delivery metadata, account records, logs and support attachments may also be personal data when they relate to an identifiable person.

Data categoryTypical purpose to assessControl question
Recipient identifierRoute a verification, notification or permitted campaign message.Can it be normalized, masked in logs and removed after the required period?
Message contentCommunicate the event or code requested by the application.Can sensitive data be omitted and content access be restricted?
Routing and delivery metadataSubmit, troubleshoot, reconcile and measure the message lifecycle.Which fields are necessary, who can access them and when do they expire?
Consent or preference recordsDemonstrate permission and honor opt-outs where required.Does the record include source, scope, timestamp and withdrawal history?
Account and billing dataOperate the service, secure access, invoice and prevent misuse.Is this separated from message content and retained under its own schedule?
Support evidenceInvestigate a specific technical, billing or security issue.Are secrets redacted, recipients masked and attachments deleted when no longer needed?

GDPR principles

Turn data-protection principles into engineering decisions

01

Lawfulness and transparency

Identify a lawful basis for each purpose and provide clear information about the controller, purposes, data, recipients, retention, transfers and rights. Consent is one possible basis, not a universal substitute for the full analysis.

02

Purpose limitation

Do not reuse a number collected for account security as a marketing audience without separately assessing compatibility, notice, lawful basis and applicable electronic-marketing rules.

03

Data minimization

Send only what the workflow requires. Avoid secrets, full financial details, health information or other sensitive content when a neutral event message and secure in-app destination can do the job.

04

Accuracy and storage limitation

Provide correction and suppression paths, stop using stale destinations, and assign a documented retention period to content, delivery metadata, consent records, logs, billing and support evidence.

05

Integrity and confidentiality

Use proportionate technical and organizational measures: least privilege, strong authentication, key rotation, encryption, environment separation, monitoring, backups and tested incident procedures.

06

Accountability

Keep evidence of decisions, contracts, records of processing, risk reviews, staff access, retention, rights handling, vendor review and incident response. A statement of compliance is not evidence by itself.

Lawful sending

Separate GDPR analysis from electronic-marketing rules

The lawful basis for processing personal data and the rules governing unsolicited electronic communications are related but not identical. Promotional SMS may require consent or meet a narrowly defined exception under the destination's law, while essential service or security messages may follow a different analysis.

For transactional and security traffic

  • Define the service event that triggers the message
  • Keep the content necessary and non-promotional
  • Prevent the number from silently entering a marketing list
  • Apply expiry and rate limits to verification codes
  • Document the lawful basis and retention period

For promotional traffic

  • Verify permission requirements in each destination
  • Record the source, wording, scope and time of consent where used
  • Identify the sender and purpose clearly
  • Provide an effective opt-out and maintain suppression
  • Respect local content, timing and registration rules

Security of processing

Match controls to the risk of the messaging use case

A low-risk delivery notification and an authentication code do not create the same threat model. Assess confidentiality, integrity, availability and abuse risk for the complete application, not only the SMS transmission step.

Access and credentials

Use unique user accounts, least privilege, strong authentication, scoped credentials where supported, secure secret storage, rotation and immediate revocation after suspected exposure.

Application safeguards

Validate inputs, rate-limit requests, prevent enumeration, make OTP values short-lived and single-use, cap guesses and resends, and avoid logging active codes.

Logging and monitoring

Log identifiers and states needed for security and delivery operations while masking recipients and excluding secrets. Monitor unusual volumes, destinations, failure patterns and account changes.

Lifecycle and deletion

Apply retention by data category, propagate deletion where required, control exports and backups, and verify that support attachments and temporary troubleshooting files do not become permanent archives.

Individual rights

Build a request process before the first request arrives

Depending on the facts and legal conditions, individuals may have rights to information, access, rectification, erasure, restriction, portability, objection and protections related to automated decisions. The controller should authenticate requests proportionately and coordinate assistance from processors without disclosing another person's data.

01

Receive and verify

Publish a clear privacy contact path, record the request date and verify identity using information proportionate to the risk.

02

Locate the data

Search customer systems, messaging records, exports, support cases and relevant providers using documented identifiers and date ranges.

03

Assess and act

Determine which right applies, preserve information that must lawfully remain, carry out the required action and communicate the result in clear language.

04

Record completion

Keep only the evidence needed to demonstrate handling, update suppression or correction records, and review recurring causes of requests.

International transfers

Identify where data becomes available outside the EEA

International messaging can involve infrastructure and recipients in several countries. Map storage, remote access, routing partners and support access. Where GDPR Chapter V applies, confirm an appropriate transfer mechanism and any supplementary assessment or safeguards required for the actual countries and data.

Adequacy

Check whether the European Commission currently recognizes the destination as providing an adequate level of protection for the relevant transfer.

Contractual safeguards

Where appropriate, assess current Standard Contractual Clauses, select the correct modules, complete annexes accurately and review the transfer context.

Ongoing review

Track subprocessors, data locations, legal changes and technical safeguards. A transfer review is not complete if the real routing or access model later changes.

Incident readiness

Connect technical response with legal assessment

Containment, investigation, documentation and notification decisions should run in parallel. A processor should follow its contractual notification duties to the controller, while the controller evaluates risk and any duty to notify a supervisory authority or affected individuals under the GDPR.

Operational evidence

  • What happened and when it was detected
  • Systems, accounts and credentials affected
  • Data categories and approximate scope
  • Countries and individuals potentially affected
  • Containment, recovery and preservation steps

Governance decisions

  • Controller and processor contacts
  • Risk to individuals and likely consequences
  • Contractual and regulatory notification deadlines
  • Information still unknown and follow-up cadence
  • Corrective actions and retained incident record

Launch checklist

Complete the evidence before production traffic

Legal and data review

  • Document purposes, data categories and lawful bases
  • Confirm controller, processor and subprocessor roles
  • Review notices, consent and opt-out requirements
  • Confirm the applicable DPA and service terms
  • Assess international transfers and data locations

Technical and operational review

  • Minimize content, logs and support evidence
  • Configure access, credentials and environment separation
  • Set retention and deletion by data category
  • Test rights, incident and vendor-change workflows
  • Record owners, approval date and next review date

Authoritative resources

Use official EU sources for the legal baseline

These external resources explain the regulation, controller and processor roles, individual rights and international transfer mechanisms. Apply them with qualified advice for your organization and destination markets.

GDPR and SMS questions

Is TextPulse always a processor for customer messages?

Roles depend on the actual purpose, decisions and processing. A provider may act as a processor for instructed message delivery while having a different role for separate activities. Use the applicable written agreement and a fact-specific assessment.

Does GDPR always require consent before an SMS?

No single lawful basis fits every activity, and electronic-marketing rules must also be assessed. Consent may be required for promotional traffic in many situations, while essential service or security messages may rely on a different basis. Document the decision for each use case and country.

What should an SMS data-retention schedule cover?

Cover recipient identifiers, content, delivery metadata, consent and suppression records, application logs, account and billing data, exports, backups and support evidence. Assign a purpose, owner, period and deletion method to each category.

Does this page prove GDPR compliance or certification?

No. It is a planning guide. Compliance depends on the real systems, contracts, instructions, security measures, locations, subprocessors, retention, notices and day-to-day operation of each party.

Where should account-specific privacy details be confirmed?

Review the current privacy policy, applicable DPA, order form, service terms and account documentation. Use the authenticated support channel to resolve missing contractual, security, transfer or deletion details before production.

Review the complete SMS data lifecycle

Connect product requirements, legal decisions, contracts, technical controls, retention and incident response before launching personal-data traffic.