What actually changes when you send OTP, transactional or marketing A2P SMS into Peru — separated into Peruvian law, supplier route policy and what we recommend operationally.
Last reviewed: 1 August 2026 · South America / LATAM
A quick operational read on Peru. Anything marked route-dependent is set by the supplier and operator path your traffic uses, and is confirmed during route assessment.
SMS to mobile
Carrier or route policy
Supported
Number format
Law / regulation
+51 followed by a nine-digit mobile number, normally beginning with 9
Alphanumeric senderID
Carrier or route policy
Common international A2P routes accept submission but overwrite it with a local shortcode or longcode
International numeric / longcode senderID
Carrier or route policy
Commonly overwritten with a local shortcode or longcode — preservation is not promised
Local longcode / two-way sender
Carrier or route policy
Selected services only; not a default international A2P capability
Dedicated or local shortcode
Carrier or route policy
Selected carrier or supplier programmes only
Two-way SMS
Carrier or route policy
Standard international routes are commonly one-way; selected local numeric services may support replies
Number portability
Law / regulation
Available nationwide — never infer the current operator from the original range
Concatenation
Carrier or route policy
Generally supported, but senderID- and route-dependent
MMS
Carrier or route policy
Some provider paths convert MMS to an SMS containing a URL
SMS to fixed line
Carrier or route policy
Not supported on standard routes
Marketing
Law / regulation
Prior, free, informed, express and unequivocal consent; revocation and opposition; sender identification; opt-out and suppression required
Personal-data bank registration
Law / regulation
A separate ANPD legal obligation for holders of personal-data banks — not senderID registration or route provisioning
Last reviewed
Flowstates recommendation
1 August 2026
Route-dependent: “Route-dependent” means the behaviour is decided by the supplier and operator path your traffic takes, not by Peruvian statute. Two providers can behave differently on the same day, and a route can change its policy. Confirm before launch.
Law, route policy and recommendation
Peruvian consumer and personal-data rules, supplier route behaviour and our own operating standard are three different things. Every statement on this page is labelled so the right team can act on it.
Law / regulation
Law and regulation
Binding obligations from Peruvian legislation and regulators: Law 29733 and its current regulation approved by DS 016-2024-JUS, ANPD guidance on unwanted advertising, Law 32323 amending the Consumer Protection and Defence Code, Indecopi enforcement, MTC numbering and OSIPTEL portability. These apply whichever supplier you use.
Carrier or route policy
Carrier or route policy
Rules applied by operators, aggregators or your provider on the specific A2P path your traffic takes — senderID rewriting, whether replies are possible, concatenation behaviour and MMS handling. Route-dependent and subject to change.
Flowstates recommendation
Flowstates operational recommendation
What we ask customers to do because it protects deliverability and keeps you comfortably inside both the law and route policy. Deliberately stricter than the legal minimum.
Numbering and networks
The basics your validation layer and templates need to get right before the first send.
Law / regulationNumber format
Peruvian mobile subscriber numbers use nine national digits and are normally written in E.164 as the country code followed by that nine-digit mobile number, which normally begins with 9.
Law / regulationDialling code
Country dialling code +51. Mobile country code 716.
Law / regulationNumbering administration
The Ministry of Transport and Communications (MTC) publishes and administers numbering resources, including the current mobile numbering directory.
Law / regulationNumber portability
Mobile number portability is available nationwide and is supervised by OSIPTEL. Never infer the current operator from the original number range or prefix.
Carrier or route policyNetworks
The large mobile networks to plan for are Claro, Bitel, Entel and Movistar. The current operator is resolved by live lookup at send time rather than inferred from the number range, and we publish no market shares or route-coverage claims here.
Flowstates recommendationValidation
Validate to E.164 and run mobile validation or lookup before sending. Standard A2P SMS routes target mobile destinations, and fixed-line destinations should be validated out.
Flowstates recommendationPortability handling
Because portability is active, resolve the current operator at send time instead of caching an operator against a contact record.
E.164 example
+51 9XX XXX XXX
Country code 51, then the nine-digit mobile number beginning with 9. This is a masked illustrative pattern, not a real subscriber number.
SenderID options
Both alphanumeric and international numeric senderIDs are commonly rewritten to a route-assigned local shortcode or longcode in Peru. Design the message body so it still identifies your brand when the visible sender changes.
Carrier or route policy
This whole comparison — best for, what the recipient sees and replies — describes carrier or route behaviour on current A2P paths in Peru, not Peruvian statute. Providers differ, it varies by supplier and operator, and it is confirmed before launch rather than guaranteed universally.
Rewritten alphanumeric senderID
Best for
One-way OTP, transactional and permissioned marketing traffic where numeric rewriting is accepted
What the recipient sees
A route-assigned local shortcode or longcode rather than the submitted brand
Replies
No
International longcode
Best for
Selected one-way transactional or service traffic where the route accepts a numeric sender submission
What the recipient sees
Commonly a route-assigned local shortcode or longcode rather than the submitted international number
Replies
Do not assume — only where the selected service explicitly supports inbound SMS
Provider-assigned local longcode / two-way sender
Best for
Selected support, service and conversational use cases
What the recipient sees
The local numeric sender assigned to that service
Replies
Potentially available when explicitly configured
Dedicated or local shortcode
Best for
Selected scale programmes and a stable numeric identity
What the recipient sees
The supported shortcode where the carrier or supplier programme is available
Replies
Route- and programme-dependent
SenderID options
Option
Best for
What the recipient sees
Replies
Rewritten alphanumeric senderID
One-way OTP, transactional and permissioned marketing traffic where numeric rewriting is accepted
A route-assigned local shortcode or longcode rather than the submitted brand
No
International longcode
Selected one-way transactional or service traffic where the route accepts a numeric sender submission
Commonly a route-assigned local shortcode or longcode rather than the submitted international number
Do not assume — only where the selected service explicitly supports inbound SMS
Provider-assigned local longcode / two-way sender
Selected support, service and conversational use cases
The local numeric sender assigned to that service
Potentially available when explicitly configured
Dedicated or local shortcode
Selected scale programmes and a stable numeric identity
The supported shortcode where the carrier or supplier programme is available
Route- and programme-dependent
Put a meaningful brand and the purpose in the message body, because the visible sender may change. Generic sender identifiers can be filtered on some provider paths, so we recommend a recognisable brand — that is route policy and a Flowstates recommendation, not a Peruvian statute.
What changes by traffic type
Peru is not one rulebook. The same destination behaves differently depending on the category you send and the route it takes.
OTP / authentication
Suitable on validated high-quality routes.
Flowstates recommendation
Keep the copy purely transactional and concise, ideally within a single segment.
Flowstates recommendation
Put the brand in the message body, because the senderID is commonly rewritten to a local numeric sender.
Flowstates recommendation
No promotional content in OTP templates.
Flowstates recommendation
Use a branded domain for any link and avoid ambiguous link text.
Flowstates recommendation
Monitor delivery, latency, completed-verification conversion and current-operator performance.
Flowstates recommendation
Configure carrier-grade failover so a degraded path does not become a failed login queue.
Carrier or route policy
Standard international A2P routes into Peru are generally one-way. Do not build a verification flow that depends on replies unless a two-way service is explicitly configured.
Transactional / service
Suitable for alerts, confirmations and account or service updates.
Flowstates recommendation
Identify the brand and state the purpose of the message clearly.
Flowstates recommendation
Use a branded domain for links rather than a public or shared shortener.
Flowstates recommendation
Keep promotional content out of transactional templates.
Flowstates recommendation
Prefer a single segment where practical, and test concatenation on the selected senderID and route.
Carrier or route policy
Enable replies only on an explicitly configured two-way service. Inbound handling is not a default on Peruvian A2P paths.
Marketing / promotional
Free, prior, informed, express and unequivocal consent, a simple free way to revoke it, and prompt suppression.
Law / regulation
Law 32323, published on 9 May 2025, amended article 58 of the Consumer Protection and Defence Code and prohibits calls, mobile text messages and mass electronic communications used to promote products or services unless the consumer has given free, prior, informed, express and unequivocal consent. That consent may be revoked at any time without justification.
Law / regulation
The statutory exception is framed around the consumer directly contacting the provider and giving consent. Indecopi has also clarified that consent can be captured when acquiring a good or service. Do not oversimplify that tension.
Flowstates recommendation
We require a clearly documented consumer-initiated or clearly requested permission journey, and legal review before you rely on any broader interpretation of the exception.
Law / regulation
Current ANPD guidance states that companies need consent to send advertising by email, messages, SMS or WhatsApp, and must provide a simple and free way to oppose or revoke it.
Law / regulation
The special one-time first-contact procedure in the current regulation of Law 29733 is described for telephone calls seeking consent. It is not permission to send an unsolicited marketing SMS asking for consent.
Flowstates recommendation
Provide a simple and free opt-out in every promotional SMS and suppress promptly.
Flowstates recommendation
Support natural Spanish requests such as BAJA, SALIR, CANCELAR and NO. We do not claim any one keyword is universally mandated by statute.
Flowstates recommendation
We do not claim a current national do-not-call registry for SMS. Maintain an internal suppression and do-not-disturb list regardless.
Flowstates recommendation
Schedule in recipient-local daytime as our operating recommendation, not an invented statutory campaign-hours window. A selected route may impose a stricter window, which we confirm privately.
Flowstates recommendation
Do not use purchased lists.
Carrier or route policy
Use the promotional route agreed for the traffic; category acceptance is confirmed privately for the selected route rather than published as a general list.
Peru's consent rules, data protection and unwanted advertising
Peru is often summarised as “you need consent”. The actual framework sits across the personal-data law and its current regulation, ANPD guidance on unwanted advertising and a consumer-protection prohibition introduced by Law 32323 — and the nuance decides whether a campaign is compliant.
Law / regulation
Law 29733 protects personal data. Its current regulation, approved by DS 016-2024-JUS, entered into force on 31 March 2025 and governs how personal data is processed.
Law / regulation
Personal-data processing must be lawful and informed, and where consent is relied on it must be free, prior, express, informed and unequivocal. This is not a blanket rule that every transactional SMS requires marketing consent.
Law / regulation
Current ANPD guidance on unwanted advertising states that advertising sent by email, messages, SMS or WhatsApp requires consent, and that a simple and free channel to oppose or revoke it must be available.
Law / regulation
Law 32323 creates a consumer-protection prohibition on unsolicited commercial calls, text messages and mass electronic messages, with a consent-based exception and consent that is revocable at any time without justification.
Law / regulation
The regulation's special one-time first-contact procedure applies to a telephone call seeking consent. It does not authorise an unsolicited promotional SMS or an unsolicited SMS asking for consent.
Law / regulation
In March 2026 Indecopi confirmed a fine against Claro for 22 promotional SMS sent without prior consumer consent. That is enforcement context showing how the rules are applied, not a separate new rule.
Flowstates recommendation
A direct opt-out or withdrawal must be honoured promptly, whether or not the recipient appears on any external list.
Flowstates recommendation
Do not treat every OTP or service notification as marketing. Keep purpose and template categories separate, and keep promotional copy out of transactional and verification messages.
Law / regulation
Any person or organisation that is the holder of a personal-data bank has a separate obligation to register that bank with the National Register of Personal Data Protection. This is a data-protection obligation — it is not senderID registration and it is not carrier provisioning.
Flowstates recommendation
We deliberately do not reproduce ANPD form particulars or administrative implementation detail. Organisations should verify their current registration obligation and status directly against current ANPD sources.
Flowstates recommendation
Retain the privacy notice and its version, the purpose, the consent record, any revocation or opposition, and evidence of how the data was processed.
Carrier or route policy
Some content or use-case categories, including P2P-style use, can be restricted by provider policy. That is route policy confirmed per campaign, not a published Peruvian statutory category list.
Operational compliance checklist
What we expect to see in place before a Peru route goes live.
Law / regulation
Record the source, the lawful purpose and the permitted use of every recipient record.
Law / regulation
Provide the applicable privacy information and retain the version shown to the recipient.
Flowstates recommendation
For promotions, retain recipient, timestamp, source, exact wording or version, purpose and channel permission.
Law / regulation
Document the consumer-initiated or clearly requested consent journey, and obtain legal review before relying on any alternative interpretation of the statutory exception.
Flowstates recommendation
Identify the brand and the purpose in every message.
Law / regulation
For direct marketing, provide a working, simple and free method to stop the communications.
Flowstates recommendation
Support BAJA, SALIR, CANCELAR and NO without claiming a universal statutory keyword.
Flowstates recommendation
Suppress promptly and maintain an internal suppression and do-not-disturb list across all systems.
Law / regulation
Verify current ANPD personal-data-bank registration obligations separately from messaging sender provisioning.
Flowstates recommendation
Do not use purchased lists.
Flowstates recommendation
Schedule by Peru recipient-local daytime.
Flowstates recommendation
Classify OTP, transactional and marketing templates, and keep promotional copy out of OTP and transactional messages.
Flowstates recommendation
Use a branded short domain rather than a public or shared URL shortener.
Carrier or route policy
Validate the exact senderID, use case and route before launch.
Carrier or route policy
Confirm category acceptance privately for the selected route, rather than relying on a published category list.
Flowstates recommendation
Keep template, privacy, consent, opt-out, campaign, suppression and route-approval records.
Encoding and delivery
Spanish copy makes encoding a real cost and delivery question in Peru, and concatenation support varies by senderID type and route. Test it rather than trusting a generic table.
GSM-7, single segment
160 characters
GSM-7, concatenated
153 characters per segment
Unicode / UCS-2, single segment
70 characters
Unicode / UCS-2, concatenated
67 characters per segment
Flowstates recommendation
Spanish accents, smart punctuation, emoji and formatting pasted from a document can change the encoding, which shortens the segment and changes the segment count. Check the encoding your template actually produces.
Carrier or route policy
Concatenation is generally supported in Peru, but it depends on the senderID and the selected route, so test the actual path before relying on it.
Flowstates recommendation
Recommend single-segment OTP templates and run end-to-end testing across the purchased Claro, Bitel, Entel and Movistar routes.
Flowstates recommendation
Normalise to E.164 as +51 9XX XXX XXX and run mobile validation or lookup before sending — fixed and mobile destinations need different handling, standard routes do not deliver to fixed lines, and portability is active so the original range tells you nothing reliable about the current operator.
Carrier or route policy
Some provider paths convert an MMS into an SMS containing a URL. That is route policy, not a Peruvian rule.
A country guide is only useful when the route follows it.
Knowing Peru's rules is the easy half. Keeping every send inside them, on supplier routes that change their policy, is the operational half — that is the part we run.
Per-country and per-category routing
OTP, transactional and marketing traffic take different Peru routes, with the right policy applied to each category.
SenderID management
We manage sender presentation where a route supports it, and design templates for the common case where the senderID is rewritten to a local numeric sender.
Carrier-grade failover
When a Peru route degrades, traffic moves before your verification funnel does.
Per-route visibility
Delivery, latency and OTP conversion measured per route and per operator, so a route policy change shows up as data rather than complaints.
24/7 vendor escalation
We chase the supplier and the carrier. You get the update, not the ticket queue.
BYOV / BYOG
Keep your existing supplier and contracts and let us operate the routing, or use ours.
Branded short links
Links on your own domain instead of a shared shortener, which route filters treat very differently.
A quick operational read on Peru. Anything marked route-dependent is set by the supplier and operator path your traffic uses, and is confirmed during route assessment. SMS to mobile: Supported. Number format: +51 followed by a nine-digit mobile number, normally beginning with 9. Alphanumeric senderID: Common international A2P routes accept submission but overwrite it with a local shortcode or longcode. International numeric / longcode senderID: Commonly overwritten with a local shortcode or longcode — preservation is not promised.
Which sender ID options work for SMS in Peru?
Both alphanumeric and international numeric senderIDs are commonly rewritten to a route-assigned local shortcode or longcode in Peru. Rewritten alphanumeric senderID — Best for: One-way OTP, transactional and permissioned marketing traffic where numeric rewriting is accepted. International longcode — Best for: Selected one-way transactional or service traffic where the route accepts a numeric sender submission. Provider-assigned local longcode / two-way sender — Best for: Selected support, service and conversational use cases. Dedicated or local shortcode — Best for: Selected scale programmes and a stable numeric identity.
What are the consent and opt-out requirements for SMS in Peru?
Peru is often summarised as “you need consent”. Law 29733 protects personal data. Its current regulation, approved by DS 016-2024-JUS, entered into force on 31 March 2025 and governs how personal data is processed. Personal-data processing must be lawful and informed, and where consent is relied on it must be free, prior, express, informed and unequivocal. This is not a blanket rule that every transactional SMS requires marketing consent. Current ANPD guidance on unwanted advertising states that advertising sent by email, messages, SMS or WhatsApp requires consent, and that a simple and free channel to oppose or revoke it must be available.
How many characters fit in an SMS to Peru?
Spanish copy makes encoding a real cost and delivery question in Peru, and concatenation support varies by senderID type and route. GSM-7, single segment: 160 characters. GSM-7, concatenated: 153 characters per segment. Unicode / UCS-2, single segment: 70 characters. Unicode / UCS-2, concatenated: 67 characters per segment.
Sources and change control
Regulator, statute and provider references behind this guide. Provider documentation reflects a supplier's current route policy, not Peruvian law — official MTC and OSIPTEL sources control numbering and portability, ANPD and official legal sources control personal-data wording, and Law 32323 and Indecopi sources control consumer-protection wording. Where providers disagree, we use route-dependent language rather than picking a winner.
Published 9 May 2025. Prohibits promotional calls, mobile text messages and mass electronic communications without free, prior, informed, express and unequivocal consent, revocable at any time.
The separate legal obligation to register a personal-data bank with the national register. Organisations should verify their own current obligation and status directly.
States that alphanumeric and numeric senders are generally changed to a local number, that numeric senders are only available through selected two-way services, and that generic identifiers can be prohibited on its route.
Describes ordinary Peru coverage as one-way, with senderIDs that may be changed to local numbers on selected operator paths.
Change log
1 August 2026 — Initial draft; separated Peruvian consent, consumer and personal-data obligations from live senderID rewriting and route behaviour.
Last reviewed 1 August 2026
Disclaimer
This is operational guidance, not legal advice. Applicable requirements vary by operator, route, senderID, traffic category, data-bank status and customer configuration. Flowstates confirms the live path during onboarding.