Skip to content
+370 5 212 1506 info@dat.lt

Direct marketing by email and SMS: when consent is needed

24 September 2026 · Good to know

You may send advertising by email or SMS to a natural person only with their prior consent. There is one exception for your own customers. If you obtained an email address when selling goods or a service to a customer who is a natural person, you may offer them your own similar goods or services, provided they can opt out both when the address is collected and in every message. For legal persons, prior consent is no longer needed, but they must be given a clear, easy opt-out at no cost.

The last rule is new, and its limits are not yet settled. It is especially unclear how it applies to a named employee’s work address. Below: what the law says now, where things can go wrong, and when it is worth taking advice.

What Article 81 of the Law on Electronic Communications says now

Article 81 of the Law on Electronic Communications (ERĮ) was amended by Law No XV-815 of 16 April 2026, published in the Register of Legal Acts on 21 April 2026. Most of that law entered into force on 1 July 2026, but Article 10, which amended Article 81, is excluded from that date (Article 14(1) XV-815). No other date is set for it, so the new wording of Article 81 entered into force after official publication, on 22 April 2026.

The article has three parts:

  • Paragraph 1. Direct marketing using electronic communications services, including email, requires the prior consent of the subscriber or registered recipient of public electronic communications services. A new second sentence: no consent is needed where that subscriber or registered recipient is a legal person, but they must be given the option to opt out (Article 81(1) ERĮ).
  • Paragraph 2. The own-customer exception, now expressly for a customer who is a natural person (Article 81(2) ERĮ).
  • Paragraph 3. It is prohibited to conceal the sender’s identity, to omit a valid address at which the recipient can ask for the messages to stop, and to send messages that encourage recipients to visit websites that do not meet the requirements of the Law on Information Society Services (Article 81(3) ERĮ).

Natural persons: consent you must be able to prove

You may send advertising to a natural person only with prior consent (Article 81(1) ERĮ). The fact that an address or phone number is published does not replace consent.

You must be able to demonstrate consent (Article 7(1) GDPR). In practice this means a record: when, in which form and what text the person saw. Withdrawing consent must be as easy as giving it (Article 7(3) GDPR). When consent is valid, and when it is not, is covered in Consent under the GDPR: when you need it and when it is invalid.

The own-customer exception

You may write to your own customer without separate consent when all the conditions are met (Article 81(2) ERĮ):

  • you lawfully obtained the email address, in compliance with the GDPR, from your own customer, who is a natural person, when selling goods or providing a service;
  • you offer only your own similar goods or services;
  • the customer can object clearly, easily and at no cost – both when the address is collected and in every message.

The exception does not cover addresses from event lists, partners or purchased databases. How to apply the exception to a newsletter step by step is described on the Privacio page on newsletters to existing customers (in Lithuanian).

SMS raises a separate doubt. The paragraph 2 exception in the text of the law speaks of email contact details. Whether it covers a phone number, the text does not directly say. ERĮ defines an “electronic mail message” broadly – as a text, voice, sound, image or other message that can be stored in the network or in the recipient’s terminal equipment until the recipient collects it (Article 3(12) ERĮ). So there are arguments that the exception covers SMS too. Until this is clarified, it is safest to have consent for SMS advertising.

Legal persons: what changed and what remains unclear

The new rule in the second sentence of Article 81(1) ERĮ works most clearly for a company’s general addresses, such as info@ or sales@. Such a recipient does not need to give prior consent. The legal person must be given a clear, easy opt-out at no cost (Article 81(1) ERĮ), and every email must include a valid address at which the recipient can ask for the messages to stop (Article 81(3) ERĮ). In practice this means an opt-out link in every message and an opt-out that is acted on.

A named employee’s address, such as firstname.lastname@company.lt, is harder. The law defines a subscriber as a person who has concluded a contract for public electronic communications services with a provider of those services (Article 3(1) ERĮ). A registered recipient is a person who is not a subscriber, is identified by a user identification code and registers the information provided (Article 3(61) ERĮ). But the law has a third term. An actual recipient of public electronic communications services is a natural person using those services for personal or business purposes, who need not be a subscriber (Article 3(23) ERĮ). An employee using a company mailbox fits this term, and Article 81 does not mention it.

So two literal readings are possible. If the employee is treated only as an actual recipient, the status of the subscriber, that is the company, decides. But an employee who logs in to their mailbox with a personal user name may also count as a registered recipient, and that is a natural person. On that reading the literal text also makes the employee the recipient. Until the State Data Protection Inspectorate (VDAI) or the courts clarify this, it is an open point of interpretation. If the second reading prevails, the first sentence of Article 81(1) ERĮ applies to a named address: advertising may be sent only with prior consent. A legitimate interest assessment under the GDPR does not replace that consent, because a specific law requires consent. Sending without consent would then breach Article 81(1) ERĮ, and compliance with that provision is supervised by the State Data Protection Inspectorate (Article 5(2)(1) ERĮ).

So the safe course for named addresses is one of two: obtain the person’s consent, or do not send them advertising. If you still decide to write without consent, that is a risk you take knowingly, and all the GDPR requirements remain, because a first name and surname in an address are personal data:

  • You need a legal basis. Usually this is legitimate interest (Article 6(1)(f) GDPR). Recital 47 GDPR says that direct marketing may be regarded as carried out for a legitimate interest. This is a possibility, not an automatic permission: the balancing of interests must be done and written down. How this is done is covered in our article when legitimate interest is enough.
  • The person may object to direct marketing at any time (Article 21(2) GDPR). Their data are then no longer processed for that purpose (Article 21(3) GDPR). They must be told of this right at the latest at the first communication, clearly and separately from any other information (Article 21(4) GDPR).
  • If you found the address on a website or in a register, information about the processing must be given to the person at the latest at the first contact (Article 14(3)(b) GDPR).
  • Send only what relates to the person’s role. An offer of accounting software to a finance director is clearly linked to their work. An offer of a personal nature is not.

SMS and the opt-out method

The phrase “you can unsubscribe in your account settings” is risky. To change settings the person must log in and be online, while the law requires opting out to be easy:

  • if you send with consent, withdrawing it must be as easy as giving it (Article 7(3) GDPR);
  • if you rely on the own-customer exception, the option to object must be in every message (Article 81(2) ERĮ);
  • an email must include a valid address at which the recipient can ask for the messages to stop (Article 81(3) ERĮ).

So every SMS should have an opt-out in the same channel: a reply with the word “STOP” or a short link. This is market practice, not the wording of the law. Account settings can remain as an additional route.

Customer emails and advertising platforms

Uploading customer addresses to an advertising platform, for example to build an audience, is not prohibited, but it needs preparation:

  • have a legal basis for this use (Article 6(1) GDPR);
  • state the purpose, its legal basis and the recipients in the privacy policy (Article 13(1) GDPR);
  • check that there is a proper contract with the platform (Article 28(3) GDPR). Whether the platform is a processor or a separate controller depends on its terms;
  • do not upload people who have objected to direct marketing (Article 21(3) GDPR).

Where things can go wrong

  • A purchased list or one received from a partner. Such a list may not come with consent you could prove. The burden of proof falls on the sender.
  • “The address is public, so we may.” Not for a natural person.
  • The new legal-person rule is applied to every address on a company domain. It may not fit named addresses.
  • The opt-out does not work. The link leads to a login page, or the opt-out is not passed on to another mailing system, and the person gets mail again.
  • Consent cannot be proved. There is no date, no form and no record of the text the person saw.

Consequences. A recipient who opted out but keeps receiving messages may complain to the State Data Protection Inspectorate. A breach of the personal data and privacy rules in the Law on Electronic Communications is itself an administrative offence. This includes Article 81, which sits in the chapter of that law on data processing and privacy protection. The Code of Administrative Offences provides for fines on individuals and on managers or other responsible persons of legal persons (Article 83(1) ANK), higher for a repeat offence (Article 83(2) ANK). Such offences are investigated, and the reports drawn up, by the Inspectorate’s officials (Article 589(29) ANK), and the Inspectorate itself decides the case out of court (Article 615(1) ANK). For breaches of the conditions for consent and of data subjects’ rights, including the right to object, the GDPR provides for administrative fines of up to 20 million euros or, in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5) GDPR).

When to call a lawyer

  • when you plan a campaign to named employees of legal persons and need to assess the risk and prepare a legitimate interest assessment;
  • when you have received a complaint or an Inspectorate inquiry about marketing messages;
  • when you buy or take over a contact database, for example together with a business;
  • when you want to pass customer data to an advertising platform or a partner.

Frequently asked questions

May we send advertising to company email addresses without consent?

A legal person no longer needs to give prior consent, but there must be a clear, easy opt-out at no cost. For named employee addresses this is unclear: if the employee is the recipient, their consent is needed, and a legitimate interest assessment does not replace it. The safest course is to obtain consent or not to send.

May we write to a private person’s publicly listed email address?

No. A natural person must give prior consent, and a public address does not replace it. The exception is your own customer under the own-customer exception.

Is a link to account settings enough in an SMS advert?

It is risky to rely on it. Opting out must be easy, so every message should include an opt-out in the same channel, such as a “STOP” reply.

Does an order notification need consent?

No, if it only gives information about the order or service. If you insert an offer or advertising into such a message, the marketing rules apply to it.

How to start

Send us your consent form and a description of your newsletter opt-out mechanism, and tell us where your contacts come from. We will tell you where consent is needed, where an opt-out is enough and what to change.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and advice.

Get a free assessment

Related articles