Skip to main content
Back to blog

Germany A2P SMS Rules, Decoded: UWG Consent, the Sender-ID Blocking Reality, and the TTDSG/DSGVO Boundary

A Germany-lane deep-dive for Devotel Orbit customers: UWG §7 consent and the Abmahnung enforcement economy, double opt-in as the provable standard, quiet-hours conventions, why dynamic alphanumeric sender IDs get filtered or replaced on German routes, long-number vs short-code economics, NIS2's 2026 message-security posture for enterprises, WhatsApp opt-in evidence under German consumer-protection precedent, and the DE send-gate row.

Orbit Editorial Team

Quick answer: Marketing SMS to German recipients answers to three stacked statutes, not one. UWG §7 (the Unfair Competition Act's spam rule) makes prior express consent the predicate for advertising texts, and it is enforced not only by regulators but by competitors and qualified consumer bodies through the Abmahnung, a formal cease-and-desist with cost recovery. TTDSG (the Telecommunications-Telemedia Data Protection Act) draws the adjacent line for telecom secrecy and device-level consent. DSGVO, the German application of the GDPR, overlays the whole processing with its own consent quality, controller duty, and data-subject rights. Consent that survives a challenge is, in practice, a recorded double opt-in. On the wire, Germany reads permissive on paper — alphanumeric sender IDs are accepted and the DE country row carries no registration requirement at all (none, against France's required) — but German operators actively filter and replace unattributed dynamic alphanumeric traffic, so day-one deliverability and month-six deliverability are different programs. This post walks the consent stack, the sender-ID reality, NIS2's 2026 message-security posture, the WhatsApp opt-in evidence problem, and the DE row of Orbit's send gate.

Everything below is a tenant-owned onboarding playbook, not legal advice and not a delivery guarantee. Orbit carries the controls — consent records, quiet hours, opt-out handling, sender-ID registration — and the German posture on each is yours to set; the final reading of UWG, TTDSG, and DSGVO sits with you and your counsel.

The consent stack: UWG §7, TTDSG, and the DSGVO overlay

UWG §7 treats unsolicited commercial communication as an unfair competitive practice, and §7(2) requires prior express consent for advertising calls and texts to consumers. The enforcement machinery is what makes Germany distinct: a competitor, a qualified industry body such as the Wettbewerbszentrale, or a consumer association can send an Abmahnung and seek an injunction, with the sender carrying the burden to prove consent. The plaintiff pool is wide, so the evidentiary standard matters more than the statutory fine schedule.

TTDSG sits beside the UWG as the telecom and telemedia data-protection layer: telecom secrecy on the transport side, and terminal-equipment and storage access consent on the device side. The boundary worth drawing precisely: TTDSG's device-access consent is triggered by what your campaign does on the recipient's device — tracked links writing identifiers, app-push layers, storage access — while the permission to send the advertising message itself is the UWG §7 question. A program can clear one and miss the other, which is why German reviews list them as separate checklist rows rather than one "consent" item.

DSGVO is the overlay that grades the consent both statutes collect: freely given, specific, informed, unambiguous, and provable, with the controller carrying the record and the processor carrying the instruction. Orbit is the processor at the messaging layer; the controller's consent record is what a German court reads. The sibling Germany UWG/BNetzA docs page walks the statute-by-statute posture, and the consent management docs walk the tenant-owned surface that stores what your collection flow captured.

Double opt-in, in practice. German case law on electronic advertising has made double opt-in the evidentiary standard that survives challenge: the confirmation step converts "someone entered this number" into "the holder of this number confirmed they want these messages." Single opt-in is not void on paper; it is simply the record that loses the Abmahnung. Programs that treat double opt-in as the default for German marketing lists are buying proof, not formality. The mechanics map cleanly onto the double opt-in docs.

Quiet hours. Germany has no statutory SMS clock the way some US states do; the enforceable line is UWG §7(1)'s unreasonable harassment (unzumutbare Belästigung). Enforcement practice reads late-night contact, early-morning contact, and Sunday contact as harassment, which is why the convention German reviewers apply is marketing texts in waking weekday hours and nothing on Sundays. Orbit's quiet hours are a tenant-configured control; a German program sets the window to the convention rather than to the platform default, and the quiet hours docs show the per-tenant surface.

The German sender-ID reality: filtered alphanumerics and long-number economics

On paper, Germany accepts alphanumeric sender IDs with the DE registration row at none: a dynamic alphanumeric sender can go on day one, and the send-time gate does not hold DE traffic for a missing registration. The paper reading understates the wire reality. German mobile network operators run spam filtering that replaces or filters dynamic alphanumeric senders they cannot attribute to a registered brand, so unregistered alphanumeric traffic delivers less reliably over time — the same pattern as France and the UK, with German filters among the stricter of the three.

Two structural facts shape the economics:

  • Alphanumeric is one-way. An alphanumeric sender ID cannot receive a mobile-originated reply, so any program that needs replies — opt-out keywords included, unless handled out-of-band — runs on a numeric long code. Two-way on a German route means a long number.
  • Short codes are the scarce, expensive lane. Germany never developed the cheap shared short-code market the US did; dedicated short codes carry long lead times and rental cost, while long numbers are the everyday workhorse for two-way traffic and the cheaper of the two numeric options.

The carrier-consolidation context explains why filter policy moves in lockstep. The D1 (Telekom) and D2 (Vodafone) networks and the E-Plus/O2 merger into Telefónica Deutschland left three incumbent MNO groups, with 1&1 entering as the fourth MNO — a small set of filter-policy decision makers covering essentially the whole market. When one group tightens alphanumeric filtering, the practice converges across the others, which is exactly why registering your sender ID is the stable-program move even though the DE gate does not hold your traffic — registration for stability, not because the row demands it.

NIS2 in 2026: message-content security as a tenant policy posture

NIS2 (Directive (EU) 2022/2555), transposed in Germany through the BSI Act amendments, is in enforcement force by 2026, and its scope is the point for messaging teams: it captures essential and important entities by size and sector — energy, transport, health, digital infrastructure, parts of manufacturing, food, waste, postal — which puts a large share of German enterprise senders inside it.

For an in-scope enterprise, NIS2 reaches the messaging program through two doors. Supply-chain security means the communications vendors and the sending surface are part of the risk-management record; incident notification means a compromised messaging channel — a hijacked sender, a breached campaign store — is reportable on the NIS2 clock, not just the GDPR 72-hour one. The operational posture is content discipline as much as transport security: keep personal and sensitive data out of message bodies, keep API credentials and console access inside named controls, and name the messaging channel in the incident runbook.

Frame it precisely: this is a tenant policy posture, not a platform guarantee. Orbit supplies the tenant-owned surfaces an NIS2-scoped sender leans on — audit logging, access control, data-residency pinning for where records land — and the data residency overview documents the residency classes. Whether your entity is in scope, and what your risk-management record must say about the messaging channel, is a question for your compliance function, with BSI and BNetzA among the German authorities administering the regime.

WhatsApp in Germany: WABA rules meet German consumer-protection precedent

WhatsApp to German recipients answers first to Meta's global WABA rules: opt-in evidence per Meta policy, template categories, display-name review, and the quality rating. The German addition is the enforcement history. German consumer-protection bodies, notably the vzbv, have repeatedly taken WhatsApp and Meta to court over consent and data practices, and German data-protection authorities have acted against Meta's data-processing posture, including the 2021 Hamburg commissioner's order over cross-platform data sharing. The practical consequence for a sender is evidentiary: German reviewers treat the channel's own reputation as a reason to scrutinize opt-in provenance more closely, not less.

The operational rule is that Meta's in-app opt-in is the floor, not the ceiling. A German program keeps its own consent record — who opted in, when, through which wording, confirmed by which step — independent of what Meta's flows captured, because under UWG and DSGVO the controller's record is what carries the burden. That is the tenant-owned consent-receipt posture, and it is the same discipline the SMS lane applies: the channel differs, the proof standard does not. The WhatsApp content policy docs cover the channel-side rules; the consent record is yours.

The Orbit send gate for DE: registration row at none

Orbit's send-time gate reads one field per country and channel: registration. The DE row for SMS is documented as none — sitting one step below the UK's recommended and well clear of France's required: a send to a German destination is not held for lack of a registration, and the gate does not flag DE on a missing registration at all. The per-country row, with sender_types (alphanumeric and long code), two_way, and content restrictions, is published on the country requirements page; the gate that reads it is described on the send gates page.

Two honest readings of that row. First, none is a gate posture, not a deliverability promise: German operator filtering makes registration the difference between a sender that stays stable and one that gets replaced or filtered, so a sustained program registers the sender ID through the same POST /api/v1/compliance/sender-id-registrations flow every market uses — as a deliverability posture, not a gate requirement. Second, the gate is a conduit, not a compliance warranty: content restrictions on the DE row follow GDPR-era prior opt-in for marketing, and a German opt-out keyword is expected on the traffic — the alias table that carries it is tenant-owned and additive, and the opt-out keyword alias table docs show where you extend it. Orbit does not guarantee GDPR or UWG compliance for any program; it carries the controls and the per-country reference data, and the posture is tenant-owned.

Launch checklist for a German program

The country-by-country launch loop lives in the sender-ID registration country playbook; the Germany lane adds these rows to its five steps:

  1. Read the DE row live. Call the country-rules reference for DE on the sms channel and read registration, sender_types, and content_restrictions — the row is data, and it is what the gate reads.
  2. Pick the sender for the job. Long code for anything two-way; alphanumeric for one-way brand display, registered through the sender-ID registration flow before the program scales.
  3. Build the consent stack. Double opt-in as the default record for marketing lists; controller entity named; DSGVO grading applied to the collection wording.
  4. Set the conventions. Quiet hours to the German waking-weekday convention, and a German opt-out keyword in the tenant alias table.
  5. Scope NIS2 before launch. If the sending entity is an essential or important entity, name the messaging channel in the risk-management and incident-notification record.
  6. Carry WhatsApp opt-in evidence separately. If the program includes WhatsApp, keep the controller-held consent record alongside Meta's WABA opt-in.

Run those against the live country-rules reference, and the German program stops being a statute reading and becomes a checklist.

Frequently asked questions

Handy-Werbe-SMS Einwilligung: does a marketing text to a German mobile number need prior consent?

Yes, in practice. UWG §7 requires prior express consent for advertising texts to consumers, and the Abmahnung economy — competitors and qualified bodies enforcing with the burden of proof on the sender — makes provable consent, recorded double opt-in, the operational standard.

UWG SMS Werbung 2026: what does the UWG require of SMS advertising this year?

Prior express consent for consumer marketing texts, an identifiable sender, and a working opt-out. A violation is an unfair competitive practice that competitors, industry bodies, and consumer associations can pursue, which is why the evidentiary record, not the fine schedule, drives German program design.

Why does my alphanumeric sender ID get replaced on German routes?

German operators filter and replace dynamic alphanumeric senders they cannot attribute. Registration through the sender-ID flow stabilizes the sender; a numeric long code is the alternative that also carries replies.

Does NIS2 make my platform responsible for my message content?

No. NIS2 obligations sit with the in-scope enterprise. The platform supplies tenant-owned surfaces — audit logging, access control, residency pinning — and the security posture statement for the messaging channel is the tenant's, reviewed with its compliance function.

Is WhatsApp marketing to Germany legal with Meta's opt-in alone?

Meta's WABA opt-in is the channel floor, not the German ceiling. Given the German consumer-protection and DPA enforcement history against Meta, reviewers look for controller-held opt-in evidence; keep your own consent record for the WhatsApp lane as you do for SMS.

Does Devotel Orbit guarantee GDPR or UWG compliance for my German program?

No. Orbit carries the controls — consent records, quiet hours, opt-out handling, sender-ID registration, and the DE send-gate row — and the compliance posture is tenant-owned. Statutory interpretation stays with you and your counsel.

The levels are hard gates where they are hard; in Germany they are not. What Germany enforces is the consent record and the sender's provenance, and both are checklist rows a program clears before the launch calendar moves.

Published 11 October 2026.

Germany A2P SMS Rules, Decoded: UWG Consent, the Sender-ID Blocking Reality, and the TTDSG/DSGVO Boundary — Orbit by Devotel