AURA

Consent for SMS and email marketing in Poland: how to collect it and keep proof

Promotional SMS and newsletters need consent collected in advance under article 398 PKE. How to tell a service message from an advertising one, where to collect consent, and what proof to record.

Published
13 min read2555 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • Article 398 PKE bans sending commercial information without prior consent; email consent can be given by providing an address specifically for that purpose.
  • Booking confirmations, reminders and invoices are service messages needing no consent; promotions and discounts are advertising that does.
  • Consent is collected separately for SMS and for email — one general "okay to contact me" consent isn't proof of either.
  • Proof of consent means a date, channel, wording version, source and contact — an address just sitting in a database proves nothing on its own.
  • After a consent withdrawal or a marketing objection, data must be deleted without undue delay, at the latest within a month.

A few words that show up in this text

Explained in plain language — you do not need to know the trade to read on.

chatbot
A program that answers questions according to a ready-made scenario.
CRM
One place holding clients and enquiries: who asked, about what, and what happened next.
lead
An enquiry from someone still considering a purchase — not a client yet.
no-show
A booked client who did not turn up and did not cancel.

Sending a promotional SMS or a newsletter to a customer database requires consent collected in advance — this isn't a best-practice suggestion, it's a plainly written prohibition in Poland's electronic communications law. Before you set up your first campaign, it's worth knowing exactly what that consent has to cover, how a service message differs from an advertising one, and how to record proof that someone consented — because it's the business, not the recipient, that has to be able to show it.

This page gives you a concrete set of answers: what the law says about consent for SMS and email, which fields to record as proof, what happens after someone withdraws consent, and why your whole contact database is almost never the same number as the real audience for a campaign.

Four brass toggle switches on a wooden board, two switched on with a green light and two off
Consent works like a switch for each channel separately: SMS can be on while email stays off

When you actually need consent: article 398 of Poland's electronic communications law

There's one core provision here, and it's worth reading closely before setting anything up in a sending system.

Poland's Electronic Communications Law, article 398 section 1, bans the use of automated calling systems and telecommunications terminal equipment — including within interpersonal communication services — for sending commercial information, including direct marketing, to a subscriber or end user, unless they gave prior consent. So the provision covers SMS as much as a voice call or a messenger, as long as it's used to send commercial information. Whether a specific channel or a specific message falls under this ban can be a matter of detail worth disputing — leave the final call to a lawyer or data protection officer (DPO) when the situation isn't clear-cut.

Section 2 of the same article spells out one way consent can be given: it can be expressed by the subscriber or end user providing their identifying electronic address for the purpose of receiving commercial information at that address. That doesn't mean every email address that ends up in your database — say, from an order or a booking — automatically counts as consent for a newsletter. The provision is about providing the address specifically for that purpose, not an address collected for something else entirely.

An old brass mailbox with its flap closed on a wooden garden gate post
An email address given for one purpose isn't the same as one provided for a newsletter

Service message or advertising message — where the line sits

Not every message to a customer is marketing that needs article 398 consent. A booking confirmation, an appointment reminder, or a sent invoice are part of fulfilling a service the customer already ordered. A message about a promotion, a discount, or "we haven't seen you in a while, come back" is a straightforward example of commercial information.

Message contentTypeNeeds article 398 consent
Booking confirmationserviceno
Reminder 24 hours before an appointmentserviceno
Invoice or payment confirmationserviceno
Notice of changed opening hoursdepends on wordingneeds a judgment call
Discount code for the next visitadvertisingyes
"We haven't seen you in a while, come back"advertisingyes

The "depends on wording" row isn't a dodge — it's the most common point of dispute in practice: a plain notice about changed hours with no sales pitch attached is usually a service message, but adding a promotion to it tips the whole thing into advertising. A genuinely borderline message is best checked with a lawyer or DPO rather than guessed at.

Article 398 consent covers the communication channel, but processing personal data for marketing is also governed by GDPR at the same time, and UODO's guidance material points to three principles that matter here specifically. First, if processing relies on consent, the business must be able to show that the person actually gave it — an address just sitting in a table isn't enough; you need a trace of the actual act of consenting.

Second, a request for consent bundled into a statement covering other matters — say, marketing consent tucked into the same box as a booking's terms and conditions — has to be clearly distinguished from them, in an understandable form using plain language. Third, consent can be withdrawn at any moment, and withdrawal doesn't affect the lawfulness of processing carried out before it — so messages already sent don't become unlawful retroactively, but sending after withdrawal does.

A tablet on a wooden desk showing two checkboxes, one ticked in green, with a pen and a mug beside it
A ticked checkbox is a signal the system has to record along with the date and wording version

Consent can be collected in several places at once, and each of them needs the same thing: a separate checkbox per channel, not one general "okay to contact me" tickbox. A website form or an online booking form is the easiest spot — a checkbox next to the phone field and a separate one next to the email field, neither pre-ticked. At reception, where consent gets collected on a tablet or on paper, the same channel split applies, along with the same duty to record the act of consenting, not just the phone number. A chatbot on the site or in a messenger can collect consent through the same mechanism, as long as it logs the moment and the exact wording of the question that was answered "yes."

The whole path from collection to sending runs as one chain:

  1. form
  2. channel checkbox
  3. record with wording version
  4. sending segment
The diagram shows the same process step by step — from the first link to the last.

A sending segment is the group of contacts for whom the database actually shows recorded consent for that channel — not the whole customer list, just the subset you can prove.

A separate practice for SMS

For SMS, the simplest proof ties consent to a specific phone number and records the moment it was given together with the exact checkbox wording the person saw at the time. A number sitting in the database for years with no recorded date and wording isn't proof of anything beyond the fact that someone left it there once.

A separate practice for email

For email, proof is usually easier to automate, since the sign-up form can send a confirmation to the address itself — not getting a reply to that confirmation doesn't invalidate the consent on its own, but having that record makes it easier to show the address genuinely belongs to the person who provided it.

Proof of consent isn't just a "consent: yes" column in the database — it's a full set of fields that together reconstruct when, how, and exactly what someone agreed to.

Proof fieldWhat it holds
Date and timethe moment consent was given
ChannelSMS, email, or both separately
Wording versionthe exact checkbox text or question at that moment
Sourcewebsite form, reception, chatbot
Contactthe phone number or email address the consent covers
Recorded bythe person or system that logged the consent

The exact set of fields and how to store them is worth settling with a DPO or the lawyer handling the business — the table shows the skeleton, not a form ready to copy. We cover a similar way of thinking about where customer data physically ends up in automated processes in our article on automation and GDPR.

UODO's guide on the right to erasure states it plainly: a business must delete personal data among other cases when a person has withdrawn consent to its processing for marketing purposes and there's no other legal basis to keep processing it, and when the person has objected to processing for direct marketing purposes. In both cases, the response and the action should happen without undue delay, at the latest within one month; if the matter is complex, that deadline can be extended by another two months, provided the person is told about it before the first month is up, with the reason given.

In practice this means "stop" has to take effect everywhere the data lives — in the CRM and in the SMS gateway or email sending system — not in just one of those places. Someone who unsubscribed from the newsletter but keeps getting SMS messages, because both channels have separate consent and separate unsubscribe mechanisms, is experiencing exactly what the guidance warns against: an objection raised in one place has to produce a real effect, not just an entry in a single system.

How many people in the database can actually be reached

A contact database and a campaign's actual audience are almost never the same number — the difference comes down to how many contacts have recorded, provable consent for that specific channel. The relationship is simple: real_audience = contacts_in_database × share_with_recorded_channel_consent.

35%
This is an illustrative example with assumed figures — substitute your own: with a database of 1,200 contacts and a 35% share with recorded SMS consent, that's 1,200 × 0.35 = 420 people forming the real audience for that specific campaign.

The rest of the database — 780 contacts in this example — may well have a phone number recorded for an entirely different reason (a booking, an invoice), and sending to them would be sending without consent, not "wider reach."

Old and purchased contact databases

A database collected years ago with no recorded marketing consent, or a database bought or taken over from another business, falls under exactly the same article 398 ban — how old a contact is in the table, or how it ended up there, doesn't change the fact that sending to it without recorded consent means sending without a legal basis. This applies to each contact individually, not the database as a whole: part of an old database might have consent recorded correctly at the time of a booking, and part might not have any at all — separating those two groups is exactly what a consent map does, not the assumption that "since they're in our database, it's fine."

Do it yourself tonight: check your own database

Export the contact database from whichever system holds it. For each contact, mark whether there's recorded consent separately for SMS and separately for email — not a general "consent: yes," but a specific channel with a date. Find the exact wording of the form or checkbox the customer saw at the moment they consented — if the form has changed over time, different people may have agreed to different versions of the text. Check the unsubscribe link in the most recently sent newsletter and SMS: does it work, where does it lead, and does unsubscribing from one channel actually stop sending on just that channel — or on both, if that's how it's supposed to work.

Manually tracking who consented to what in a spreadsheet works up to a few dozen contacts — beyond that it drifts out of sync with reality at the first form change, or the first unsubscribe someone forgot to log in a second system. When a system runs the process, a checkbox on a form or at reception gets recorded straight away as consent with a date, channel, and wording version on the customer's card:

  1. checkbox
  2. consent in CRM
  3. segment with consent
  4. unsubscribe removes the mark
The diagram shows the same process step by step — from the first link to the last.

This doesn't replace a legal review of a specific consent wording or a specific message — that stays with the business's lawyer or DPO.

Recording consent and tying it to a contact is handled by Customer Data — one customer card instead of columns drifting apart across several systems. The sends that only go to the consenting segment are handled by Automatic messages for SMS and Email integrations for newsletters and email sequences. A website form with separate, clearly labelled checkboxes for each channel is built by Lead forms, and tying all of it into one pipeline is CRM and automations. A similar mechanism for consent and reminders holds up outside marketing too — see our article on hair salon automation and our article on follow-up automation after the first conversation. We also cover a confirmation chain that protects against a no-show in our article on no-shows — the same consent-recording principle for reminders applies there.

Frequently asked questions

Does signing up for a newsletter during a purchase count as article 398 consent?

Only if the email address was provided specifically for the purpose of receiving commercial information — meaning a separate, deliberate checkbox at checkout, not just the fact that an address was given to send an invoice or an order confirmation. An address collected purely to fulfil an order doesn't automatically become marketing consent.

Not to the same extent — a reminder about an already-booked appointment is part of fulfilling a service the customer ordered, and usually doesn't need separate article 398 consent. An SMS about a promotion or discount is commercial information and needs prior consent for that channel.

The same as with an online form: the date and time it was ticked, the exact wording the customer saw at that moment, and which contact — which number or address — it applies to. A phone number just sitting in a booking system without that record isn't proof of marketing consent.

Yes — article 398 applies to the communication channel, so consent for one doesn't automatically extend to the other. One general "okay to market to me" consent with no channel split makes it harder later to show exactly what a person agreed to.

The business should delete the data processed on the basis of that consent, provided there's no other legal basis to keep processing it, and do so without undue delay, at the latest within a month. Messages sent before the withdrawal stay lawful — it's sending after the withdrawal that becomes a problem.

No — consent has to be given before sending, not reconstructed after the fact. The only lawful path is collecting genuine new consent from each contact individually, for example at the next interaction with the customer, rather than marking the whole old database as consenting in bulk.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →