Customer decisions
The organization initiating messages commonly decides the recipients, purpose, timing, content, lawful basis and retention needed in its own systems. Record those decisions for each use case.
GDPR and business messaging
A compliant messaging program is not created by adding a consent checkbox or naming a vendor. Map why each data element is used, determine the parties' roles, choose a lawful basis, give required notices, limit access and retention, protect transfers and build a repeatable process for rights and incidents.
Roles and contracts
Under EU guidance, a controller determines why and how personal data is processed, while a processor handles personal data on the controller's behalf. The same organization can have different roles for different activities, so labels in a marketing page cannot replace an assessment of the actual workflow.
The organization initiating messages commonly decides the recipients, purpose, timing, content, lawful basis and retention needed in its own systems. Record those decisions for each use case.
A messaging provider may process recipient and routing data to submit and track messages under written instructions. Exact roles, permitted processing and deletion duties should be stated in the applicable agreement.
Account security, fraud prevention, billing, legal obligations or service analytics may require a separate role analysis. Do not assume every data element is governed by the same purpose or retention period.
Data inventory
Phone numbers and message bodies are obvious, but delivery metadata, account records, logs and support attachments may also be personal data when they relate to an identifiable person.
| Data category | Typical purpose to assess | Control question |
|---|---|---|
| Recipient identifier | Route a verification, notification or permitted campaign message. | Can it be normalized, masked in logs and removed after the required period? |
| Message content | Communicate the event or code requested by the application. | Can sensitive data be omitted and content access be restricted? |
| Routing and delivery metadata | Submit, troubleshoot, reconcile and measure the message lifecycle. | Which fields are necessary, who can access them and when do they expire? |
| Consent or preference records | Demonstrate permission and honor opt-outs where required. | Does the record include source, scope, timestamp and withdrawal history? |
| Account and billing data | Operate the service, secure access, invoice and prevent misuse. | Is this separated from message content and retained under its own schedule? |
| Support evidence | Investigate a specific technical, billing or security issue. | Are secrets redacted, recipients masked and attachments deleted when no longer needed? |
GDPR principles
Identify a lawful basis for each purpose and provide clear information about the controller, purposes, data, recipients, retention, transfers and rights. Consent is one possible basis, not a universal substitute for the full analysis.
Do not reuse a number collected for account security as a marketing audience without separately assessing compatibility, notice, lawful basis and applicable electronic-marketing rules.
Send only what the workflow requires. Avoid secrets, full financial details, health information or other sensitive content when a neutral event message and secure in-app destination can do the job.
Provide correction and suppression paths, stop using stale destinations, and assign a documented retention period to content, delivery metadata, consent records, logs, billing and support evidence.
Use proportionate technical and organizational measures: least privilege, strong authentication, key rotation, encryption, environment separation, monitoring, backups and tested incident procedures.
Keep evidence of decisions, contracts, records of processing, risk reviews, staff access, retention, rights handling, vendor review and incident response. A statement of compliance is not evidence by itself.
Lawful sending
The lawful basis for processing personal data and the rules governing unsolicited electronic communications are related but not identical. Promotional SMS may require consent or meet a narrowly defined exception under the destination's law, while essential service or security messages may follow a different analysis.
Security of processing
A low-risk delivery notification and an authentication code do not create the same threat model. Assess confidentiality, integrity, availability and abuse risk for the complete application, not only the SMS transmission step.
Use unique user accounts, least privilege, strong authentication, scoped credentials where supported, secure secret storage, rotation and immediate revocation after suspected exposure.
Validate inputs, rate-limit requests, prevent enumeration, make OTP values short-lived and single-use, cap guesses and resends, and avoid logging active codes.
Log identifiers and states needed for security and delivery operations while masking recipients and excluding secrets. Monitor unusual volumes, destinations, failure patterns and account changes.
Apply retention by data category, propagate deletion where required, control exports and backups, and verify that support attachments and temporary troubleshooting files do not become permanent archives.
Individual rights
Depending on the facts and legal conditions, individuals may have rights to information, access, rectification, erasure, restriction, portability, objection and protections related to automated decisions. The controller should authenticate requests proportionately and coordinate assistance from processors without disclosing another person's data.
Publish a clear privacy contact path, record the request date and verify identity using information proportionate to the risk.
Search customer systems, messaging records, exports, support cases and relevant providers using documented identifiers and date ranges.
Determine which right applies, preserve information that must lawfully remain, carry out the required action and communicate the result in clear language.
Keep only the evidence needed to demonstrate handling, update suppression or correction records, and review recurring causes of requests.
International transfers
International messaging can involve infrastructure and recipients in several countries. Map storage, remote access, routing partners and support access. Where GDPR Chapter V applies, confirm an appropriate transfer mechanism and any supplementary assessment or safeguards required for the actual countries and data.
Check whether the European Commission currently recognizes the destination as providing an adequate level of protection for the relevant transfer.
Where appropriate, assess current Standard Contractual Clauses, select the correct modules, complete annexes accurately and review the transfer context.
Track subprocessors, data locations, legal changes and technical safeguards. A transfer review is not complete if the real routing or access model later changes.
Incident readiness
Containment, investigation, documentation and notification decisions should run in parallel. A processor should follow its contractual notification duties to the controller, while the controller evaluates risk and any duty to notify a supervisory authority or affected individuals under the GDPR.
Launch checklist
Authoritative resources
These external resources explain the regulation, controller and processor roles, individual rights and international transfer mechanisms. Apply them with qualified advice for your organization and destination markets.
Roles depend on the actual purpose, decisions and processing. A provider may act as a processor for instructed message delivery while having a different role for separate activities. Use the applicable written agreement and a fact-specific assessment.
No single lawful basis fits every activity, and electronic-marketing rules must also be assessed. Consent may be required for promotional traffic in many situations, while essential service or security messages may rely on a different basis. Document the decision for each use case and country.
Cover recipient identifiers, content, delivery metadata, consent and suppression records, application logs, account and billing data, exports, backups and support evidence. Assign a purpose, owner, period and deletion method to each category.
No. It is a planning guide. Compliance depends on the real systems, contracts, instructions, security measures, locations, subprocessors, retention, notices and day-to-day operation of each party.
Review the current privacy policy, applicable DPA, order form, service terms and account documentation. Use the authenticated support channel to resolve missing contractual, security, transfer or deletion details before production.
Connect product requirements, legal decisions, contracts, technical controls, retention and incident response before launching personal-data traffic.