SMS marketing in Norway involves both the Marketing Control Act and data protection rules. As a general rule, an organisation needs consent before sending marketing to an identifiable person by SMS. It also needs a valid legal basis for using the mobile number under data protection law.
This article provides general practical guidance, not legal advice. The organisation deciding why the message is sent must assess the particular campaign, recipients and applicable rules.
Two sets of rules need attention
Section 15 of the Norwegian Marketing Control Act governs marketing through electronic methods that allow individual communication, including SMS. The Norwegian Data Protection Authority explains that a mobile number is normally personal data, so the organisation also needs a legal basis for processing it.
The same act of consent may cover both requirements where the information and action meet the relevant standards. Consent must not, however, be hidden in general terms or stretched to purposes that were not explained.
Is consent always required?
Prior consent is the main rule. Norwegian law contains a limited exception for marketing within an existing customer relationship where its conditions are met. It is not enough that a person knows the business, created an account or contacted support. The contact detail must have been obtained in connection with a sale, the marketing must concern the organisation’s own similar products or services, and the customer must have been offered an easy, free opt-out both when the detail was collected and in every later message.
Intellipush applies a stricter contractual rule: customers must be able to document freely given, informed and prior consent before advertising or marketing is sent through the service, even where local law may recognise a narrower exception. Follow the Acceptable Use Policy whenever you use Intellipush.
Does this also apply to B2B marketing?
The rules concern messages directed to natural persons. A work mobile can still identify an individual employee. The fact that the offer is aimed at businesses does not automatically remove the consent requirement for a person-addressed SMS. Generic corporate contacts and other circumstances may require a different assessment, but “B2B” is not by itself a safe exemption.
What makes consent valid?
Valid consent must be freely given, specific, informed, unambiguous, demonstrable and expressed through an active step. It must be as easy to withdraw as it was to give. In practice, the wording should identify:
- the organisation that will send;
- SMS as the channel;
- the type of marketing the person can expect;
- the data used and its purpose;
- the right to withdraw consent.
Use an unticked box or a separate, clearly labelled action. Do not bury marketing consent inside checkout, account acceptance or a privacy notice.
How long does consent last?
There is no single practical expiry period suitable for every consent. Consider what the person reasonably expected, how regularly you communicate, whether the purpose or sender has changed, and how long the relationship has been inactive. An old or ambiguous consent should not be treated as permanent permission. Establish a review routine and ask again when the original consent is no longer clear or current enough.
How to document consent
Your records should show who consented, when and how, the wording and version presented, the purposes and channels selected, and when consent was withdrawn. Retain only what is needed for that purpose, protect the log against unauthorised alteration and ensure the current status follows the recipient across relevant lists.
Opt-out using STOPP, STOP or a link
Marketing needs an easy, free opt-out appropriate to the sender arrangement. Where the SMS route accepts replies, Intellipush supports keywords including STOPP and STOP. A recorded opt-out is added to the blacklist and must prevent later marketing through Intellipush.
An alphanumeric sender name is normally one-way. In that case the organisation must provide another clear route, such as a suitable unsubscribe link. Test it before sending, and ensure that your CRM, commerce and marketing systems respect the same decision. A blacklist in one channel is not permission to circumvent the person’s choice through another.
Marketing message or service message?
An order confirmation, agreed reminder or necessary operational notice may have a different purpose from marketing. However, a “service message” that also promotes an offer, upsell or new service may be wholly or partly marketing. Assess the actual content and purpose, not just the label used internally. Keep operational information neutral where it is intended to remain a service message.
Checklist before a campaign
- Decide whether the message is marketing or necessary service information.
- Confirm documented prior consent for every recipient as required by the Intellipush terms.
- Check the sender, purpose, channel and current consent wording.
- Remove duplicates and respect every recorded opt-out and blacklist.
- Provide an opt-out that genuinely works with the chosen sender.
- Test with a small controlled group before the full send.
See also SMS marketing with Intellipush and the Trust Centre. Where a particular campaign is uncertain, obtain legal advice before sending.
A relevant next step
Make the next campaign more relevant
Plan recipients, wording, timing and follow-up as one coherent journey.



