Sending a promotional SMS or a newsletter to a customer database requires consent collected in advance — this isn't a best-practice suggestion, it's a plainly written prohibition in Poland's electronic communications law. Before you set up your first campaign, it's worth knowing exactly what that consent has to cover, how a service message differs from an advertising one, and how to record proof that someone consented — because it's the business, not the recipient, that has to be able to show it.
This page gives you a concrete set of answers: what the law says about consent for SMS and email, which fields to record as proof, what happens after someone withdraws consent, and why your whole contact database is almost never the same number as the real audience for a campaign.

When you actually need consent: article 398 of Poland's electronic communications law
There's one core provision here, and it's worth reading closely before setting anything up in a sending system.
The ban without prior consent
Poland's Electronic Communications Law, article 398 section 1, bans the use of automated calling systems and telecommunications terminal equipment — including within interpersonal communication services — for sending commercial information, including direct marketing, to a subscriber or end user, unless they gave prior consent. So the provision covers SMS as much as a voice call or a messenger, as long as it's used to send commercial information. Whether a specific channel or a specific message falls under this ban can be a matter of detail worth disputing — leave the final call to a lawyer or data protection officer (DPO) when the situation isn't clear-cut.
Consent given by providing an email address
Section 2 of the same article spells out one way consent can be given: it can be expressed by the subscriber or end user providing their identifying electronic address for the purpose of receiving commercial information at that address. That doesn't mean every email address that ends up in your database — say, from an order or a booking — automatically counts as consent for a newsletter. The provision is about providing the address specifically for that purpose, not an address collected for something else entirely.

Service message or advertising message — where the line sits
Not every message to a customer is marketing that needs article 398 consent. A booking confirmation, an appointment reminder, or a sent invoice are part of fulfilling a service the customer already ordered. A message about a promotion, a discount, or "we haven't seen you in a while, come back" is a straightforward example of commercial information.
| Message content | Type | Needs article 398 consent |
|---|---|---|
| Booking confirmation | service | no |
| Reminder 24 hours before an appointment | service | no |
| Invoice or payment confirmation | service | no |
| Notice of changed opening hours | depends on wording | needs a judgment call |
| Discount code for the next visit | advertising | yes |
| "We haven't seen you in a while, come back" | advertising | yes |
The "depends on wording" row isn't a dodge — it's the most common point of dispute in practice: a plain notice about changed hours with no sales pitch attached is usually a service message, but adding a promotion to it tips the whole thing into advertising. A genuinely borderline message is best checked with a lawyer or DPO rather than guessed at.
What GDPR requires alongside channel consent
Article 398 consent covers the communication channel, but processing personal data for marketing is also governed by GDPR at the same time, and UODO's guidance material points to three principles that matter here specifically. First, if processing relies on consent, the business must be able to show that the person actually gave it — an address just sitting in a table isn't enough; you need a trace of the actual act of consenting.
Second, a request for consent bundled into a statement covering other matters — say, marketing consent tucked into the same box as a booking's terms and conditions — has to be clearly distinguished from them, in an understandable form using plain language. Third, consent can be withdrawn at any moment, and withdrawal doesn't affect the lawfulness of processing carried out before it — so messages already sent don't become unlawful retroactively, but sending after withdrawal does.
Where to collect consent: forms, bookings, reception, chatbots

Consent can be collected in several places at once, and each of them needs the same thing: a separate checkbox per channel, not one general "okay to contact me" tickbox. A website form or an online booking form is the easiest spot — a checkbox next to the phone field and a separate one next to the email field, neither pre-ticked. At reception, where consent gets collected on a tablet or on paper, the same channel split applies, along with the same duty to record the act of consenting, not just the phone number. A chatbot on the site or in a messenger can collect consent through the same mechanism, as long as it logs the moment and the exact wording of the question that was answered "yes."
The whole path from collection to sending runs as one chain:
- 01form
- →02channel checkbox
- →03record with wording version
- →04sending segment
A sending segment is the group of contacts for whom the database actually shows recorded consent for that channel — not the whole customer list, just the subset you can prove.
A separate practice for SMS
For SMS, the simplest proof ties consent to a specific phone number and records the moment it was given together with the exact checkbox wording the person saw at the time. A number sitting in the database for years with no recorded date and wording isn't proof of anything beyond the fact that someone left it there once.
A separate practice for email
For email, proof is usually easier to automate, since the sign-up form can send a confirmation to the address itself — not getting a reply to that confirmation doesn't invalidate the consent on its own, but having that record makes it easier to show the address genuinely belongs to the person who provided it.
What to record as proof of consent
Proof of consent isn't just a "consent: yes" column in the database — it's a full set of fields that together reconstruct when, how, and exactly what someone agreed to.
| Proof field | What it holds |
|---|---|
| Date and time | the moment consent was given |
| Channel | SMS, email, or both separately |
| Wording version | the exact checkbox text or question at that moment |
| Source | website form, reception, chatbot |
| Contact | the phone number or email address the consent covers |
| Recorded by | the person or system that logged the consent |
The exact set of fields and how to store them is worth settling with a DPO or the lawyer handling the business — the table shows the skeleton, not a form ready to copy. We cover a similar way of thinking about where customer data physically ends up in automated processes in our article on automation and GDPR.
Withdrawing consent and objecting to marketing
UODO's guide on the right to erasure states it plainly: a business must delete personal data among other cases when a person has withdrawn consent to its processing for marketing purposes and there's no other legal basis to keep processing it, and when the person has objected to processing for direct marketing purposes. In both cases, the response and the action should happen without undue delay, at the latest within one month; if the matter is complex, that deadline can be extended by another two months, provided the person is told about it before the first month is up, with the reason given.
In practice this means "stop" has to take effect everywhere the data lives — in the CRM and in the SMS gateway or email sending system — not in just one of those places. Someone who unsubscribed from the newsletter but keeps getting SMS messages, because both channels have separate consent and separate unsubscribe mechanisms, is experiencing exactly what the guidance warns against: an objection raised in one place has to produce a real effect, not just an entry in a single system.
How many people in the database can actually be reached
A contact database and a campaign's actual audience are almost never the same number — the difference comes down to how many contacts have recorded, provable consent for that specific channel. The relationship is simple: real_audience = contacts_in_database × share_with_recorded_channel_consent.
The rest of the database — 780 contacts in this example — may well have a phone number recorded for an entirely different reason (a booking, an invoice), and sending to them would be sending without consent, not "wider reach."
Old and purchased contact databases
A database collected years ago with no recorded marketing consent, or a database bought or taken over from another business, falls under exactly the same article 398 ban — how old a contact is in the table, or how it ended up there, doesn't change the fact that sending to it without recorded consent means sending without a legal basis. This applies to each contact individually, not the database as a whole: part of an old database might have consent recorded correctly at the time of a booking, and part might not have any at all — separating those two groups is exactly what a consent map does, not the assumption that "since they're in our database, it's fine."
Do it yourself tonight: check your own database
Export the contact database from whichever system holds it. For each contact, mark whether there's recorded consent separately for SMS and separately for email — not a general "consent: yes," but a specific channel with a date. Find the exact wording of the form or checkbox the customer saw at the moment they consented — if the form has changed over time, different people may have agreed to different versions of the text. Check the unsubscribe link in the most recently sent newsletter and SMS: does it work, where does it lead, and does unsubscribing from one channel actually stop sending on just that channel — or on both, if that's how it's supposed to work.
What a system-run consent process looks like
Manually tracking who consented to what in a spreadsheet works up to a few dozen contacts — beyond that it drifts out of sync with reality at the first form change, or the first unsubscribe someone forgot to log in a second system. When a system runs the process, a checkbox on a form or at reception gets recorded straight away as consent with a date, channel, and wording version on the customer's card:
- 01checkbox
- →02consent in CRM
- →03segment with consent
- →04unsubscribe removes the mark
This doesn't replace a legal review of a specific consent wording or a specific message — that stays with the business's lawyer or DPO.
Recording consent and tying it to a contact is handled by Customer Data — one customer card instead of columns drifting apart across several systems. The sends that only go to the consenting segment are handled by Automatic messages for SMS and Email integrations for newsletters and email sequences. A website form with separate, clearly labelled checkboxes for each channel is built by Lead forms, and tying all of it into one pipeline is CRM and automations. A similar mechanism for consent and reminders holds up outside marketing too — see our article on hair salon automation and our article on follow-up automation after the first conversation. We also cover a confirmation chain that protects against a no-show in our article on no-shows — the same consent-recording principle for reminders applies there.
Frequently asked questions
Does signing up for a newsletter during a purchase count as article 398 consent?
Only if the email address was provided specifically for the purpose of receiving commercial information — meaning a separate, deliberate checkbox at checkout, not just the fact that an address was given to send an invoice or an order confirmation. An address collected purely to fulfil an order doesn't automatically become marketing consent.
Does an SMS appointment reminder need the same consent as a promotional SMS?
Not to the same extent — a reminder about an already-booked appointment is part of fulfilling a service the customer ordered, and usually doesn't need separate article 398 consent. An SMS about a promotion or discount is commercial information and needs prior consent for that channel.
What counts as proof of consent if a customer ticked a box on a tablet at reception?
The same as with an online form: the date and time it was ticked, the exact wording the customer saw at that moment, and which contact — which number or address — it applies to. A phone number just sitting in a booking system without that record isn't proof of marketing consent.
Do you need to collect SMS and email consent separately?
Yes — article 398 applies to the communication channel, so consent for one doesn't automatically extend to the other. One general "okay to market to me" consent with no channel split makes it harder later to show exactly what a person agreed to.
What happens to data after someone withdraws marketing consent?
The business should delete the data processed on the basis of that consent, provided there's no other legal basis to keep processing it, and do so without undue delay, at the latest within a month. Messages sent before the withdrawal stay lawful — it's sending after the withdrawal that becomes a problem.
Can an old contact database with no recorded consent be fixed by adding consent retroactively?
No — consent has to be given before sending, not reconstructed after the fact. The only lawful path is collecting genuine new consent from each contact individually, for example at the next interaction with the customer, rather than marking the whole old database as consenting in bulk.