Skip to content
WebAsk
CRM & Automation

Is Missed Call Text Back Legal in the UK?

Is missed call text back legal in the UK? What an auto reply text to a missed call may say under PECR and UK GDPR, what makes it marketing, and a template.

WebAsk founder Ansar Cheema
Ansar Cheema

Founder · · 17 min read

A plumber is under a sink when her phone rings. By the time her hands are dry, the caller has gone. Her phone system can be set to send a text when a call goes unanswered: sorry we missed you, reply here.

So, is missed call text back legal in the UK? It can be, if the text promotes nothing. The Information Commission (the ICO) says service messages "do not count as direct marketing if they only provide administrative information and do not promote anything". PECR (the UK's e-privacy rules) has a consent rule for direct marketing. It does not reach a text like that. Add an offer or a request for marketing consent, and it becomes marketing.

Checked against the regulations and the ICO's guidance on 5 October 2026. WebAsk is a web and CRM agency, not a law firm. This is not legal advice.

TL;DR

On our reading, a text-back that only names you, says you missed the call and says how to reach you is a service message. An offer or "reply YES for offers" makes it marketing. And a missed call gives you no basis to send marketing to someone on their own phone (our reading).

Why you got a text after a missed call

The business you rang may have set its phone system to send an auto reply text when nobody picks up. If you do not recognise the sender, the ICO's advice to the public is: "Be careful about replying to any messages if you don’t recognise who has sent them to you." It says to report a suspicious message to the 7726 mobile service. For marketing texts, it says to "follow any opt-out instructions within the message".

Is a missed-call text a service message?

The ICO's direct marketing guidance lists service messages, such as messages to "remind people how to contact you in case of a problem". It frames them as information for "your customers", and a first-time caller may not be one. The line from its email guidance quoted above does not mention who receives the message. No ICO page we read on 5 October 2026 mentions a missed call or a text-back. So calling one a service message is our reading.

If a service message has "elements that are direct marketing", the ICO says it "will count as direct marketing", even if that is not its main purpose. The words are not the whole test. If you are unsure, the ICO says you should think about "why you want to communicate with people". It adds that "the context in which you send the message is also important".

Is a reply to someone who just rang unsolicited?

Our reading: a text-back that promotes nothing is a service message, so the question does not arise. One with an offer is unsolicited, because a missed call does not ask for an offer.

PECR, the Privacy and Electronic Communications Regulations 2003, covers "unsolicited communications for the purposes of direct marketing" (regulation 22). Marketing is solicited "when someone specifically asks you to send a particular message or type of information" (ICO). No source we read says whether a missed call is such a request.

If the caller then asks for your prices, sending them is solicited. That needs no consent (ICO). You must still name yourself and give a way to stop.

Our guide to appointment reminders applies the same test to bookings.

What a text-back can say, line by line

"Our reading" below is our view where no source decides; "unsettled" means the sources leave it open.

What the text-back says or doesService message or marketing?Why (sources read 5 October 2026)
"Hi, it's Business Name. Sorry we missed your call."Service message (our reading)ICO: service messages "do not count as direct marketing if they only provide administrative information and do not promote anything"; "general branding or logos" do not count
"Reply here and we'll get back to you"Service message (our reading)ICO example: messages to "remind people how to contact you in case of a problem"
A bare booking link, as one way to reach youUnsettled. Our build standard allows one plain linkICO: a message that "actively promotes or encourages people to make use of a particular service" is "likely to be direct marketing"
"Book today and save 10%"MarketingICO: a service message with "elements that are direct marketing" "will count as direct marketing"
A review linkUnsettled; our standard keeps it outNo ICO page we read names review requests; its test asks if content would "promote you or your interests". Our addition: a missed caller may have nothing to review yet
"Reply YES for offers"MarketingICO, among direct marketing purposes: "contacting people to ask them for consent to direct marketing"
A second automatic text the next dayNeutral chaser: unsettled. With a promotion: marketingICO e-receipt example (our analogy): "the first email was compliant because it didn’t contain any marketing"; the next day's sale email "is not compliant with PECR"
Adding the number to a newsletter or marketing sequenceMarketing, and a new purpose under UK GDPRFor individuals, regulation 22(2) needs consent or the soft opt-in, which a missed call does not give (our reading); UK GDPR Articles 5(1)(b) and 13(3)
A text to a company's line or an employee's work phone at a companyThe consent rule does not apply; regulation 23 still applies to anything marketingICO (under review): an employee's "telephone number" at a corporate body "would constitute a corporate subscriber"; when unsure, you "should treat the details as belonging to an individual subscriber"

Our reminders guide reads "Book your next appointment" as likely marketing, on the ICO's "actively promotes or encourages" line. A text-back link answers someone who has just tried to reach you. Context counts, so we call that link unsettled (our reading).

A template that fits in one text

Hi, it's Business Name. Sorry we missed your call. Reply here and we'll get back to you. Reply STOP to opt out.

That is 111 characters in the 7-bit alphabet, with room for a business name of up to 62 plain characters.

Hi, it's Business Name. Sorry we missed your call. Reply here and we'll get back to you, or book at example.com/book. Reply STOP to opt out.

That is 140 characters, with room for a name of up to 33. Use your own domain, then recount. Each names you, says why, gives a way to reply and to stop, and carries no offer. The link is our build standard, and unsettled under the ICO's test.

A text in the GSM 7-bit alphabet "can consist of up to 160 characters"; in UCS2, "up to 70 UCS2 characters" (ETSI TS 123 038, October 2025).

As we read the standard, curly apostrophes, emoji and long dashes are outside the 7-bit alphabet. With curly apostrophes, neither template fits in one text. GoHighLevel says its SMS compliance settings (modified 1 September 2026) add opt-out wording and "sender identification" "when those elements are missing". So test on your own phone and count what arrives. It also advises: "Avoid spammy formatting, excessive emojis, URL shorteners, and vague brand references." That is its advice, not law, and why the link is on your own domain.

Regulation 22 covers unsolicited electronic mail "to individual subscribers". Electronic mail "includes messages sent using a short message service" (regulation 2). For individual subscribers, an unsolicited marketing text needs consent, unless the soft opt-in applies.

Whose number it is decides. An employee's work phone at a company "would constitute a corporate subscriber" (ICO, under review), outside the consent rule. A sole trader, a partnership outside Scotland that is not an LLP, or anyone on their own mobile is an individual subscriber. When unsure, the ICO says you "should treat the details as belonging to an individual subscriber" (under review). Our PECR guide to B2B outreach covers companies.

Why a missed call is not the soft opt-in

For the soft opt-in in regulation 22(3), you must have got the person's details yourself "in the course of the sale or negotiations for the sale" of a product or service to them. The ICO says "A person doesn’t need to actually buy anything from you. It’s enough if ‘negotiations for the sale’ took place." It also sets a limit: "You must have some form of express communication from the person and it must involve them buying your products or services." It adds: "You must offer the opt-out when you collect the contact details. Including an opt-out in an order confirmation email is not sufficient."

Our reading, as in our database reactivation guide: a missed call, nothing more, is no "express communication" about buying. And nobody offered a way to refuse when the number arrived. So it gives no soft opt-in. A STOP line in the text-back comes too late, like that order confirmation.

One line that turns it into marketing

Add "book today and save" and the text becomes marketing. Sent to someone who rang from their own phone and gave you nothing more, it is, on our reading, unsolicited marketing with no consent and no soft opt-in. Regulation 22(2) forbids that.

Naming yourself and a way to stop

Regulation 23 covers "a communication for the purposes of direct marketing by means of electronic mail". Among other things, the sender's identity must not be "disguised or concealed". There must also be "a valid address" to ask for the messages to stop. The ICO says this applies "regardless of whether the message is solicited or unsolicited".

A service message is not bound by regulation 23. Our build standard follows it anyway. Then a text that tips into marketing already names you and gives a way to stop.

What the caller's number may be used for

Our build standard: the number is used to reply to that call, and for nothing else unless the caller asks.

Where you use personal information, "data protection law also applies" (ICO). UK GDPR Article 5(1)(b) says personal data must be collected "for specified, explicit and legitimate purposes". It must not then be used in a way that is "incompatible" with them. If you gave no privacy information because the use is "an obvious purpose that people already know about", the ICO says that is "the ‘specified purpose’" (purpose limitation, updated 23 March 2026). Our reading: for a missed call, that is returning the call.

In general, the ICO says, a new use is likely to be incompatible if it "is very different from the original purpose", "would be unexpected" or "would have an unjustified impact on the people involved". It adds: "You must have a lawful basis for any new purpose." People must be told of it "prior to that further processing" (Article 13(3)), unless they already know.

Privacy information includes "your purposes for processing their personal data, your retention periods for that personal data, and who it will be shared with" (ICO, under review).

Whose number the text comes from

Our build standard: a number registered to your business, not to whoever set it up, with the business named first.

GoHighLevel's UK guidance (modified 4 September 2026) says: "UK Long Code: Requires applicable KYC information and an approved Regulatory Compliance bundle." An "Alphanumeric Sender ID" is "Suitable for supported one-way branded messaging use cases." Our reading: a text that asks for replies, or says "Reply STOP", needs a number that takes them. GoHighLevel's text-back help page (modified 7 September 2026) says the text "may come from a different number than the one they originally called". That is one more reason to name yourself first.

On a divert, check which number the text goes from. Our guide to AI receptionists explains diverts.

Penalties since 5 February 2026

A higher maximum penalty applies to breaches on or after 5 February 2026 (SI 2026/82, reg 11(2)). The maximum for breaking regulations including 22 and 23 is the "higher maximum amount" (PECR Schedule 1, para 18). For an undertaking, the Data Protection Act 2018, s.157(5) sets that amount at:

"£17,500,000 or 4% of the undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher"

In any other case, it is £17,500,000. If someone else sends for you, the ICO says "you are still responsible" (Guide to PECR).

Questions to ask of any text-back software

"Ours" marks our build standard, not the law.

  1. Can we edit every word, and does it add lines of its own?
  2. Can we keep out offers, "reply YES" and review links (review links: ours)?
  3. Is any link a single plain link on our own domain (ours)?
  4. Does it send from a number registered to us, take replies and obey STOP (ours)?
  5. Can callers' numbers be kept out of newsletters, sequences and review requests?
  6. Does our privacy information cover callers' numbers?
  7. Does the text as sent fit 160 characters in the 7-bit alphabet?

Where to start

  1. Write the text against the table above, test it on your phone, and keep callers' numbers out of your marketing. Who you may contact later is in our database reactivation guide.
  2. Build the checks in. Our CRM and automation service is built on GoHighLevel first and HubSpot where it fits. Its sequences "check before they send".
  3. Get in touch with what your phone does now when nobody answers.

Ready to put this into practice?

Book a 30-minute discovery call — we'll map the highest-leverage moves for your business and send a written scope within three working days.

Book a discovery call