Secure SMS
"Secure SMS" is a term that covers methods and technologies for protecting the content of text messages so that sensitive personal or confidential information cannot be read by unauthorized persons. Traditional SMS is not designed to handle sensitive data, and many authorities and experts therefore advise against sending such information via regular SMS.
Background and risks associated with regular SMS
SMS was developed in the 1980s and is based on older telecommunications protocols (including SS7) that do not include modern security mechanisms. Regular SMS messages are sent in plain text and can therefore be read by:
* mobile operators
* other players with access to the telecommunications infrastructure
* criminals who exploit vulnerabilities in the network
This makes traditional SMS unsuitable for sending sensitive personal information such as:
* Social security numbers
* health information
* bank and card details
* passwords
* other confidential personal data
The Danish Data Protection Agency and several European authorities have repeatedly pointed out that ordinary SMS messages do not meet the requirements of the GDPR when processing sensitive personal data.
Data Protection Authority 15-01-2020
SMS messages containing personal data to citizens
Data Protection Authority 27-10-2022:
