TPS and CTPS compliance: a corporate responsibility for every sales and marketing team

Content authorBy Claire ConnorPublished onReading time14 min read
A businessperson holds a glossy smartphone displaying a glowing SMS compliance process flow in a warm-toned office setting.

Screening against the Telephone Preference Service (TPS) and its corporate counterpart, the Corporate TPS (CTPS), is one of the few UK marketing compliance checks that sits entirely within a sales and marketing team's own control. Here's a repeatable process for building TPS and CTPS screening into every outbound programme, with SMS-specific consent and message controls run alongside it as a separate, complementary track.

Why every text needs its own check

Most UK sales and marketing teams treat TPS and CTPS screening as a list problem: run the numbers once, load the campaign, move on. But MCP Online Ltd was fined £55,000 in September 2023 for 20,939 calls to TPS or CTPS registered numbers, on top of 92,265 texts sent without consent. This is what happens when registry checks are treated as an afterthought rather than an owned process.

Registry screening is one control among several, and it carries particular weight because an objection on TPS or CTPS is set directly by the individual or business, not inferred from anywhere else. Responsibility for clearing that check sits with the sales and marketing team running the campaign, not with a vendor further up the supply chain. What follows is a review sequence that puts TPS and CTPS screening first, with SMS consent and message controls run alongside it.

Run it before each campaign.

Set the legal baseline

The Privacy and Electronic Communications Regulations 2003 (PECR) treat a text message as electronic mail, which puts it under Regulation 22 alongside email. You need prior consent, or you need to satisfy the soft opt-in conditions under which the number was collected during a sale or negotiations for one, and the marketing covers similar products, with a simple refusal route offered at collection and repeated in every message.

There's no fallback basis written into PECR itself. Bratby Law's data protection practice puts it plainly: "If you cannot satisfy regulation 22, you cannot send the marketing", full stop. Argentum Data Solutions tried arguing an alternative basis applied, and the ICO rejected it.

For teams running both phone and text programmes, the Telephone Preference Service (TPS) and its corporate counterpart (CTPS) govern live marketing calls under Regulation 21. They don't govern texts. A number's absence from either register tells you nothing about whether you have permission to send an SMS, and the ICO's own business-to-business marketing guidance keeps the two rule sets in separate rows of the same table.

Screen TPS and CTPS

Registry screening against TPS and CTPS is a standing corporate responsibility for sales and marketing teams. It clears a different question from SMS consent: consent asks whether this person agreed to hear from you by text; screening asks whether the number sits on a statutory objection register, which matters directly wherever that number is used for calls, and indirectly wherever the same CRM record feeds both calling and texting programmes.

The registers behind TPS compliance data are large, and they move. The TPS held 17,251,346 numbers in August 2026, with additions running between roughly 500 and 2,400 on a typical working day and almost no removals, since consumer registrations don't expire. CTPS entries do expire because corporate subscribers have to re-register annually. A file screened six weeks ago is not a file screened today.

Both gates have to clear, and TPS compliance data feeds only one of them. Your consent check runs against your own records, and your screening policy runs against the registers. Passing one does not excuse failing the other, and the ICO has investigated both together: MCP Online Ltd was fined £55,000 in September 2023 for 20,939 calls to TPS or CTPS registered numbers alongside 92,265 texts sent without consent.

Check TPS compliance data

A checking service returns a flag against each number before the list is loaded into your sending or dialling platform. Acudo, which brought together HLR Lookup and TPS Unlimited under one platform, runs TPS and CTPS checks through an application programming interface (API) or bulk upload, at an illustrative £0.029 per number for a combined lookup. This turns registry compliance from a periodic project into a standing part of how a sales or marketing team builds every list.

Two operational habits make TPS compliance data useful. Screen the file that's actually going out, because the extract and the send are days apart. And store the screening result with a timestamp next to the number, so a later query about a specific send can be answered from the record instead of reconstructed.

The 28-day rule matters here too. A registration takes effect 28 days after it's made, which means numbers added last week will start clearing as objections next month. Refreshing TPS compliance data on a fixed cycle, weekly for active outreach files, keeps that lag from turning into a complaint.

Screening is what a checking service does. It is not what your SMS compliance programme is.

Acudo's role stops at telling you whether a number appears on TPS or CTPS and whether it's valid. Everything else stays with you:

  • Consent records and the channel-level fields described earlier

  • The retention and lawful-basis decisions that stay your organisation's responsibility under PECR

  • Your suppression list and the workflow that feeds it

  • Send timing and frequency caps

  • Message copy and opt-out routing

If your TPS compliance data is clean and your consent evidence is thin, you still have a Regulation 22 problem. The registry check answers one narrow question well, and treating it as a general permission signal is the mistake the ICO keeps writing into penalty notices.

Validate every number. Deliver every message.

Talk to our team about real-time phone number validation, fraud prevention, and high-deliverability SMS for your business.

Collect clear SMS consent

Consent under PECR must be freely given, specific, informed, and given by clear affirmative action. For text, "specific" means the word SMS or text appears in the wording the person actually read. HelloFresh's statement asked customers to agree to "sample gifts (including alcohol) and other offers, competitions and news via email" and then used it for texts, which is why the ICO found it neither specific nor informed.

A compliant web form checkbox starts unticked and reads something close to this:

  • "Tick this box to receive marketing text messages from [Business Name] about new products and offers. You can stop them any time by replying STOP. Ticking this box is not required to complete your order."

  • For text-to-join: "Text JOIN to XXXXX to get offers from [Business Name] by SMS. Message and data rates apply. Reply STOP to unsubscribe. Consent is not a condition of purchase."

Both name the sender and the channel, and both require the person to do something. Neither bundles the marketing permission with age confirmation or terms acceptance. When SAGA was fined in September 2021, the ICO rejected consent wording that referred to "similar organisations" and "selected third parties" because the customer couldn't tell who would actually contact them.

Store consent by channel

Bold infographic with orange and black icons for communication channels, compliance symbols, and a consent icon on a white background.

An email opt-in and an SMS opt-in are different permissions, so they need different fields. Practical Law's summary of ICO direct marketing guidance is unambiguous on this: "Consent to receive phone calls cannot be extended to cover texts or e-mails and vice versa." Copying a value from one column into another destroys the evidential trail even when the underlying customer genuinely wanted both.

Your SMS consent record should hold six things:

  1. The mobile number in E.164 format

  2. The exact wording displayed at the moment of capture, stored as text rather than a version reference that can be edited later

  3. What the person did (ticked box, sent keyword, ticked box in app preference centre)

  4. The source: which form, which landing page, which store, which campaign

  5. Date and time

  6. The channel scope the consent covers

That last field is the one teams skip. Without it, a migration that merges three CRM instances will happily populate the SMS flag from whatever permission column looks closest. ZMLUK was fined £105,000 for relying on third-party data where, in the ICO's finding, the trail back to the individuals had broken. The regulator doesn't accept "our vendor said so" and neither should your data team.

Build compliant message copy

You can hold perfect consent for every number in the file and still breach PECR through the wording, because Regulation 23 attaches to the message itself. It prohibits sending marketing by electronic mail where the sender's identity has been disguised or concealed, or where no valid address for opt-out requests has been provided.

So build a template your team reviews as copy for SMS compliance. A workable structure for a UK marketing text:

  1. Sender name, at the start, in a form your customers would recognise

  2. The offer or message, written so nothing in it pretends to be something else

  3. A link, where the destination matches what the text promised

  4. The opt-out instruction, in the same message, in the same register of language as the rest

Every campaign gets reviewed against those four slots for SMS compliance before it's scheduled. When a slot is empty, the send doesn't go.

Validate every number. Deliver every message.

Talk to our team about real-time phone number validation, fraud prevention, and high-deliverability SMS for your business.

Name the sending business

The recognisable trading name goes in the text. Not an abbreviation the marketing team uses internally or a bare short code the recipient has never seen. Argentum Data Solutions was found in breach of Regulation 23 partly because none of the SMS messages it sent identified who they came from.

Alphanumeric sender IDs help, but they aren't sufficient on their own if the ID doesn't match anything the customer recognises from their relationship with you. The test for SMS compliance is whether someone reading the message on a lock screen can tell who is contacting them.

Add texting compliance wording

"Reply STOP to unsubscribe" works because it's short, universally understood, and it costs the recipient nothing to act on. Your texting compliance wording should sit in the body of the message, and it must connect to a route somebody actually monitors.

That last condition is where teams fail quietly. A STOP keyword that arrives at an unmonitored inbound number is functionally the same as no opt-out at all, and PECR requires a valid address to which the recipient may send a request that communications cease. Test the route the way you'd test a payment flow: send a real STOP from a real handset on each network you use and confirm the suppression fired.

Keep the texting compliance wording identical across campaigns. Rotating between STOP and UNSUBSCRIBE gives your recipients something to think about at the exact moment you want the process to be effortless, and it multiplies the keyword handling your platform has to get right.

Separate transactional messages

A service message becomes a marketing message the moment it starts selling. Remove the promotional element and ask whether what remains is something the customer still needs. A delivery notification survives that test, while an order confirmation with a "customers also bought" block fails it, since the whole message needs consent and an opt-out.

Process every STOP request

Suppression has to be immediate and permanent, and it also has to be unavoidable. Those three properties describe different failure modes, and the HelloFresh case involved all of them: the ICO found the company continued contacting people after they'd asked it to stop, and it "was taking too long to respond, or sometimes not responding" to opt-outs at all.

The texting compliance workflow runs in four steps:

  1. Inbound STOP hits the messaging platform and writes to the suppression table in the same transaction. No batch job, no overnight sync, no queue.

  2. A confirmation reply goes back, and it confirms only that the person has been removed. It carries no offer and no win-back.

  3. The number moves to a permanent do-not-text record that survives deletion requests, because the ICO's guidance on suppression lists treats retaining that minimum data as a legal obligation.

  4. Every import and every campaign build checks against that record before it can produce an audience.

Step four is the one that saves you. Suppression that lives inside a single sending tool gets wiped the first time someone loads a fresh CSV from the warehouse or migrates to a new platform. Make the do-not-text record a source of truth in your own systems and treat the sending tool as a consumer of it, so a reactivated number needs a deliberate human decision.

Control sending times

The ICO's direct marketing guidance says organisations "must not go beyond what someone would reasonably expect in the circumstances" and should avoid contact at antisocial hours.

Schedule against the recipient's local time. For a UK-only programme that's straightforward. For anything crossing borders, it means storing a timezone against each number and holding messages that would land outside the window. Number validation returns the issuing country, which gives you a starting point, though a UK number held by someone living abroad will still need a preference on file.

This is your SMS compliance control, which sits in your scheduler and your campaign approval process. A screening provider tells you what's on a register. Send timing and frequency cap decisions belong in the systems your team operates.

Audit SMS compliance failures

Run this SMS compliance audit quarterly and after every data migration. Each item below caused a real enforcement outcome, so treat a positive finding as a reason to pause sends.

  • Email opt-ins transferred into SMS fields. Query for numbers where the consent source references an email form or the consent wording contains no reference to text. Fix by re-permissioning.

  • Purchased or migrated lists without appropriate screening. Ask the questions the ICO recommends about who collected the data and what wording was shown. If the answers aren't documented, the list isn't usable.

  • STOP wording for texting compliance pushed past the truncation point or written in smaller-signal language. Render every template on a real handset and check the opt-out is visible without expanding the message.

  • Suppression updates that failed silently. Reconcile the do-not-text record against the last three campaign audiences and count the overlap. It should be zero.

  • Unidentified senders. Pull a sample of sent messages and confirm the trading name appears in the body or in a sender ID your customers would recognise.

  • Promotional content inside transactional texts. Apply the strip test to your automated service templates for delivery updates and security alerts, because those flows get edited by people who don't attend the SMS compliance review.

The stakes changed in February 2026, when Commencement No. 6 Regulations brought the Data (Use and Access) Act 2025 provisions into force and lifted the PECR penalty ceiling from £500,000 to £17.5 million or 4% of global turnover. Texting compliance now carries exposure at that scale in its own right, on a regime with a lower evidential threshold and a faster enforcement cycle than most sales and marketing teams are used to. The ICO issued 49 PECR penalties totalling £4.63 million between March 2022 and mid-2025, and marketing texts feature in a large share of them.

Bringing the checks together

The sequence runs from TPS and CTPS screening through to SMS consent, message copy, and timing. Run the checks in order before each campaign, and treat registry screening as the check your sales and marketing team owns outright, not the one you assume someone else has already covered. None of them is difficult on its own, and the enforcement record shows that failures cluster where nobody owns the handoff between them.

Registry screening is the gate every sales and marketing team owns directly, and it works best when the underlying number data is accurate. Acudo validates UK mobile numbers and checks them, through TPS Unlimited, against the TPS and CTPS registers before a list is used, which keeps your files current without adding CPaaS complexity. Speak to Acudo about building TPS and CTPS screening into your team's standing compliance responsibilities.

Validate every number. Deliver every message.

Talk to our team about real-time phone number validation, fraud prevention, and high-deliverability SMS for your business.

Keep SMS consent evidence for as long as you rely on it to send marketing and for a documented period afterward to handle complaints. Retain the captured wording, source, action, timestamp and channel scope. Review the retention period against your data-retention policy and delete records when that purpose ends.

Use third-party SMS consent only when you can document exactly who collected it, what the person saw and how your business was named. Consent that refers vaguely to partners or selected organisations doesn't identify the sender clearly enough. If that evidence is unavailable, obtain fresh permission before texting.

Treat a changed mobile number as a new contact point and don't automatically copy SMS permission from the old number. Ask the customer to confirm their marketing choice for the replacement number, then store the new consent event. Check the old number against suppression records before it leaves your systems.

Keep a campaign record that ties each recipient to their consent evidence, suppression status and send time. Save the final message copy, sender identity, opt-out route and TPS or CTPS screening timestamp where relevant. These records let you show what checks applied to a specific send.

Acudo can validate mobile numbers and return TPS or CTPS screening results before a file is used for outreach. It doesn't create consent or process opt-outs for your business. Store each result with its timestamp, then apply your own consent and suppression checks before sending.

Get in touch

Talk to our team about phone number validation, fraud prevention, and reliable SMS communications.

You Might Also Like

Discover more insights and articles

Title:
How to create phone number validator rules that catch common errors

Meta description:
Learn how a phone number validator lets you clean input and check whether numbers can receive messages.

A

How to create phone number validator rules that catch common errors

Turning messy phone input into stored numbers you can actually message means building a validation pipeline, not a single regex. From cleaning through to a live network lookup, then what to return to the caller and how to test the whole thing end to end.

A realistic smartphone in a hand displays a phone number entry UI, glowing network overlay, and a secure checkmark, with warm bokeh background.

Phone verification for trust & safety teams

Fake accounts are rarely stopped by adding another verification step. The better approach is to use phone intelligence to decide which signups need more friction and which can pass with minimal interruption.

For trust & safety teams, the goal is not to verify every phone number in the same way. It is to identify numbers that look risky, validate legitimate ones quickly, and reserve stronger verification for accounts that show other signs of abuse.

A close-up of a realistic hand holding a smartphone displaying a UK phone number signup interface with a glowing network overlay.

How to set up UK phone number verification

A UK mobile number can look perfectly valid and still be unsuitable for an OTP, onboarding check, or critical customer message. The problem is what happens between accepting the number and sending the message: format validation can confirm that the number follows UK numbering rules, but it cannot tell you everything about the line itself. A stronger verification flow puts number validation and intelligence before the OTP send, so product, engineering, and trust & safety teams can make a better decision about whether to proceed.

A realistic hand holds a glossy smartphone displaying an SMS campaign dashboard, with glowing network icons and warm bokeh background.

How to build a bulk SMS messaging campaign that drives results

A first bulk SMS messaging campaign either sets the pattern for every one that follows, or teaches an expensive lesson in consent and list hygiene before a single message goes out. Getting it right comes down to sequence: one measurable goal, defensible consent, a validated list, and a message worth reading, built on the UK rules that decide whether a text lands or gets filtered.