Permanent roaming rules are divergent. Most European countries permit permanent roaming for IoT and M2M services, relying on commercial agreements between operators. However, Germany only permits it for services that meet the legal definition of M2M communications, excluding general public internet access. Belgium has the most restrictive framework, generally prohibiting permanent roaming except in specific cases such as eCall or certain “nomadic” services authorised by the minister.
Regarding authorisation and notification, most EU member states apply the general authorisation regime under the European Electronic Communications Code. In 22 countries, notification is required if the IoT or M2M service is made available publicly, typically when there is a direct contractual relationship with end users. Five countries (Estonia, Hungary, Ireland, Italy, and Luxembourg) go further and always require notification, even when services are offered only to closed user groups. In contrast, Denmark, France, and the United Kingdom impose no notification at all.
In the area of SIM card registration, 15 out of 31 countries require the registration of IoT and M2M SIMs. Eleven of these require explicit verification mechanisms, such as Austria’s in-person or video identification, Sweden’s use of BankID, and Switzerland’s retailer-led checks.
By contrast, 16 countries, including Estonia, Finland, Latvia, and the United Kingdom, impose no registration at all or explicitly exempt IoT services. Belgium exempts M2M SIMs but still requires registration for other mobile users, while Greece and Hungary allow exemptions for SIMs that are technically limited to machine-only use.
Cullen International’s new research compares the regulatory approach for IoT and M2M connectivity in all EU member states and associated European markets.
For access to our research, click 'Access full content' – or 'Request access' if you are not yet a subscriber to our IoT service.
Interested in other regions? Check these out:
more news
01 June 26
Privacy in the digital age
Our latest benchmark compares data protection laws across 14 jurisdictions. It covers recent legal updates, lawful bases for processing personal data, and extraterritorial applicability. It also examines privacy rules for location, biometric, and children’s data, as well as enforcement practices involving these data types and big tech groups.
01 June 26
Fewer European countries offer local loop unbundling over copper
29 May 26
How are EU member states transposing NIS2?
Our latest benchmark tracks the progress of the Directive on measures for a high common level of cybersecurity across the EU (NIS2) transposition in the 27 EU member states.