Permanent roaming rules are divergent. Most European countries permit permanent roaming for IoT and M2M services, relying on commercial agreements between operators. However, Germany only permits it for services that meet the legal definition of M2M communications, excluding general public internet access. Belgium has the most restrictive framework, generally prohibiting permanent roaming except in specific cases such as eCall or certain “nomadic” services authorised by the minister.
Regarding authorisation and notification, most EU member states apply the general authorisation regime under the European Electronic Communications Code. In 22 countries, notification is required if the IoT or M2M service is made available publicly, typically when there is a direct contractual relationship with end users. Five countries (Estonia, Hungary, Ireland, Italy, and Luxembourg) go further and always require notification, even when services are offered only to closed user groups. In contrast, Denmark, France, and the United Kingdom impose no notification at all.
In the area of SIM card registration, 15 out of 31 countries require the registration of IoT and M2M SIMs. Eleven of these require explicit verification mechanisms, such as Austria’s in-person or video identification, Sweden’s use of BankID, and Switzerland’s retailer-led checks.
By contrast, 16 countries, including Estonia, Finland, Latvia, and the United Kingdom, impose no registration at all or explicitly exempt IoT services. Belgium exempts M2M SIMs but still requires registration for other mobile users, while Greece and Hungary allow exemptions for SIMs that are technically limited to machine-only use.
Cullen International’s new research compares the regulatory approach for IoT and M2M connectivity in all EU member states and associated European markets.
For access to our research, click 'Access full content' – or 'Request access' if you are not yet a subscriber to our IoT service.
Interested in other regions? Check these out:
more news
25 February 26
Protection of minors: overview of national initiatives on banning access to social media
Our latest benchmark shows that an increasing number of European countries are discussing a potential social media ban on children.
23 February 26
The DNA explained: universal service to serve the same goals under a revised approach
Cullen International is issuing a series of analyses on different aspects of the Digital Networks Act (DNA) proposal. This report covers universal service.
20 February 26
Revised Cybersecurity Act (CSA2) - Changes to the EU cybersecurity certification framework
Cullen International published an analysis of the proposed changes to the EU cybersecurity certification framework under the draft Cybersecurity Act 2 (CSA2) delivered by the European Commission on 20 January 2026.