Key point: Before sending marketing or promotional text messages, US businesses must obtain prior express written consent from the recipient. That consent must be documented and retrievable. This article covers how consent is typically captured — through web forms, SMS keyword opt-in, and in-store sign-up — what records must be retained, and how marketing SMS differs from one-to-one conversational texting. It does not constitute legal advice.
Business SMS is one of the fastest ways to reach customers, but it is also one of the most legally regulated communication channels in the United States. The Telephone Consumer Protection Act (TCPA) requires prior express written consent before sending marketing or promotional texts using an automated system. Carriers, through CTIA guidelines and 10DLC registration requirements, independently enforce consent and disclosure standards. Getting this wrong carries real risk: TCPA violations can result in per-message penalties, and class action exposure from mass campaigns is well established in case law.
This guide explains the three common consent capture patterns businesses use, shows illustrative examples of consent language (not legal templates), and provides a checklist of what each consent record should contain. It also explains the practical distinction between mass marketing campaigns and one-to-one conversational SMS — because those two scenarios carry different consent requirements.
For a broader overview of business text messaging, see the business SMS guide. For how opt-out handling works once customers are enrolled, see the article on SMS STOP and HELP keywords.
Legal disclaimer: This article provides general educational information about SMS consent practices. It is not legal advice. Requirements vary by jurisdiction, message type, and campaign configuration. Consult qualified legal counsel before designing or deploying SMS campaigns.
Regulatory Framework: TCPA, FCC, and CTIA
Three layers of rules govern business SMS consent in the United States.
The TCPA (Telephone Consumer Protection Act) is the federal law at the center of SMS compliance. It requires prior express written consent before sending marketing or promotional text messages using an automatic telephone dialing system (ATDS). Under FCC rules implementing the TCPA, consent must be clearly disclosed, voluntary, and not bundled as a condition of purchasing goods or services. Violations carry statutory damages per message, which makes class action exposure from non-compliant mass campaigns significant.
The FCC's TCPA rules establish that prior business relationship alone does not constitute consent for marketing SMS. A customer who purchased from you last year and gave you their phone number at checkout has not automatically consented to receive your promotional texts. Consent for marketing SMS must be obtained separately and affirmatively.
CTIA (Cellular Telecommunications Industry Association) publishes Messaging Principles and Guidelines that wireless carriers enforce as a condition of network access. CTIA guidelines require that every A2P (application-to-person) campaign include: clear opt-in language disclosing who is messaging and why; message frequency disclosure; a statement that message and data rates may apply; instructions for opting out (STOP); and HELP keyword support. 10DLC (10-digit long code) registration through The Campaign Registry (TCR) — required as of 2023 for US businesses sending SMS at scale — reinforces these requirements at the campaign level. Carriers use the registered campaign type when evaluating deliverability; a campaign type mismatch can result in filtering.
Businesses with Canadian customers should also be aware of CASL (Canada's Anti-Spam Legislation), which requires express or implied consent for commercial electronic messages and has its own disclosure and unsubscribe requirements. This article focuses on US requirements as the baseline.
Consent Types: What Counts and What Does Not
Not all consent is equal under TCPA and CTIA rules. Understanding the categories helps you match the right consent mechanism to the right message type.
| Consent Type | Description | Sufficient for Marketing SMS? |
|---|---|---|
| Express written consent | Customer affirmatively opts in — checkbox, keyword reply, signed paper form | Yes — required for marketing/promotional SMS |
| Express oral consent | Verbal agreement captured on a recorded call or in person | Generally not sufficient for TCPA marketing purposes — hard to prove and challenged in litigation |
| Implied consent | Customer initiated contact; prior business relationship exists | No for marketing — may apply to one-to-one conversational and certain transactional messages |
| Prior business relationship alone | Customer purchased from you, called you, or provided a number in another context | No — does not constitute TCPA consent for marketing SMS under current FCC rules |
Three Common Opt-In Patterns with Illustrative Language
Most business SMS programs use one or more of the following consent capture methods. Each must include specific disclosures. The language examples below are illustrative patterns only — they are not legal templates and must be reviewed by counsel before use.
1. Web Form Opt-In
A web form opt-in is the most common method for capturing SMS consent digitally. The form collects the customer's phone number and presents a consent checkbox. Several mechanics matter for validity:
- The checkbox must be unchecked by default. A pre-checked checkbox does not constitute valid TCPA express written consent — the customer must take an affirmative action.
- Consent language must appear adjacent to the checkbox, not buried in a linked privacy policy that the customer may not read.
- The phone number field should be separate from the email field. Consent is per channel — collecting both on one form does not mean consent for one carries over to the other.
- The form must capture a timestamp and the source URL at submission time for the consent record.
Illustrative consent language pattern for a web form checkbox (not a legal template):
"By checking this box, I agree to receive promotional text messages from [Business Name] at the number provided. Message frequency varies. Message and data rates may apply. Reply STOP to opt out. Reply HELP for help. View our Privacy Policy and Terms of Service."
The disclosure must name the business, state the purpose of the messages (promotional, appointment reminders, etc.), state message frequency or that frequency varies, include the standard data rates disclaimer, and provide opt-out and help instructions. Linking to a longer privacy policy does not substitute for the adjacent disclosure — both are typically present.
2. SMS Keyword Opt-In
In this pattern, customers text a keyword — commonly "JOIN", "YES", or a campaign-specific word — to a shortcode or 10DLC number that has been promoted in a store, advertisement, or other channel. The act of texting the keyword is the customer's opt-in action.
A critical requirement: the system must immediately auto-reply with a confirmation message that serves as both consent confirmation and campaign disclosure. Sending messages before the confirmation reply, or without sending a confirmation reply at all, is a compliance gap.
Illustrative confirmation reply pattern (not a legal template):
"[Business Name]: You're signed up for [campaign description, e.g., promotional offers]. Msg freq: up to [X] msgs/mo. Msg & data rates may apply. Reply STOP to cancel, HELP for info."
The keyword opt-in method works well for in-store promotions, print advertising, and signage because no internet access is required from the customer. The consent record for each subscriber is the inbound keyword message (logged with timestamp and sending number) plus the outbound confirmation message sent.
The channel where the keyword is promoted (an in-store sign, a website, a social media post) should also include the full disclosure language — business name, campaign description, frequency, data rates, STOP/HELP — before the customer texts the keyword. The confirmation message alone is not sufficient if the customer had no prior disclosure of what they were signing up for.
3. In-Store or Paper Opt-In
Paper-based opt-in is common for retail, healthcare, restaurants, and any business with physical customer interactions. The customer completes a written form that includes the same disclosures required on a web form, writes their phone number, and signs or initials to indicate affirmative consent.
The consent language on the paper form must include the same elements as the web form equivalent: business name, purpose, frequency, data rates disclaimer, and STOP/HELP instructions. A signature line should reference the consent checkbox or language on the form.
After collection, paper forms must be digitized and stored. Scan the form or manually enter the data into your CRM, capturing the date of signature and the store location or form batch ID as the consent source. Retain the original paper forms per your records retention policy.
Paper opt-in is valid consent, but it carries more operational overhead: forms must be stored, consent entry into the SMS platform must be timely and accurate, and the scan or photo of the paper form should be accessible if a consent dispute arises later.
Marketing vs One-to-One Conversational SMS
One of the most commonly misunderstood distinctions in business SMS is the difference between a mass marketing campaign and a one-to-one conversational exchange. These are treated differently under CTIA guidance, and conflating them can lead to either unnecessary consent burden or genuine compliance gaps.
| Message Type | Example | Consent Requirement |
|---|---|---|
| Marketing/promotional campaign | Same or similar message sent to a list — sale announcements, coupons, promotions | Express written consent required |
| One-to-one conversational | Agent responding to a customer who texted in with a question or request | Lighter — implied consent from customer-initiated contact generally applies |
| Transactional | Order confirmation, shipping update, appointment reminder related to a specific transaction | Varies — generally requires a prior business relationship and the message must relate to the transaction; consult counsel |
The key test for whether a message is conversational or campaign-based is not whether it is sent one at a time — it is whether the sender initiated the contact and whether the content is promotional in nature. An agent sending a follow-up promotional offer to a customer who texted in a support question does not convert the interaction into a one-to-one exchange that avoids marketing consent requirements. The promotional nature of the content is what matters.
For more on how compliance works across different campaign types, including interactions with the DNC registry, see the related compliance guides.
Consent Record Checklist
Documenting consent is as important as obtaining it. In the event of a TCPA dispute, a regulatory inquiry, or a carrier audit, you need to produce a record showing that a specific phone number provided consent, when, how, and to what. The following checklist covers what each consent record should contain.
| Field | Required? | Notes |
|---|---|---|
| Phone number that consented | Yes | Store in E.164 format for consistency across systems |
| Date and time of consent (timestamp) | Yes | Include timezone; UTC preferred for consistency |
| Source of consent | Yes | URL of web form, keyword opt-in number, store location name, paper form batch ID |
| Consent language shown at the time | Yes | Exact text or a versioned reference — important when consent language changes over time |
| Campaign type the consent applies to | Yes | Marketing, appointment reminders, transactional — different campaigns require separate consent |
| IP address | Yes, for web forms | Establishes that the submission came from a real session; not applicable to paper or keyword opt-ins |
| Opt-out date and method | Yes, if consent was revoked | Record how the opt-out arrived: STOP keyword, unsubscribe link, manual request, and when it was processed |
| Resubscription record | If applicable | Timestamp and method (START keyword, new form submission) if a previously opted-out subscriber re-enrolled |
Records should be organized so that a given phone number's full consent history — initial opt-in, any opt-out, any resubscription — can be retrieved quickly. A compliance audit or a litigation hold can require producing these records on short notice.
Consent Record Retention
The TCPA statute of limitations for federal court is four years. This establishes a practical minimum: consent records should be retained for at least four years from the date of the last interaction with a given number. If a subscriber opted in three years ago and opted out last month, the clock on the opt-out starts fresh.
Some states have longer statutes of limitations under their own consumer protection laws, and some state-level TCPA analogs have independent retention considerations. Consult legal counsel to determine the appropriate retention period for your jurisdiction mix and message types.
Retention is not just about keeping the data — it is about keeping it retrievable. Records stored in an archived system that takes two weeks to access are less useful in a dispute than records in an indexed database with per-number lookup. Build the retrieval requirement into how you store consent records, not just how long you store them.
Consent records that include personal data (name, phone number, IP address) are also subject to applicable privacy regulations — CCPA in California, for example — which may impose their own deletion rights. Retention and deletion requirements can conflict; this is another area where legal guidance is essential.
Opt-Out Handling: What Happens After Consent
Consent documentation does not end at opt-in. The record of how and when a subscriber opted out is equally important, and the mechanics of opt-out handling are tightly specified.
Under CTIA guidelines, texting STOP to a business SMS number must immediately trigger suppression — no further messages may be sent after the mandatory opt-out confirmation. The HELP keyword must return the sender's contact information. Both requirements apply across number types: 10DLC, shortcodes, and toll-free. See the detailed article on SMS STOP and HELP keywords for how keyword processing works end to end.
Every opt-out event should be written to the consent record for the phone number with a timestamp and the opt-out method (STOP keyword reply, manual unsubscribe request, carrier-reported opt-out). This creates an auditable history. If an opted-out subscriber later resubscribes via START, that event should also be logged — and the consent record should show the sequence: original opt-in, opt-out, resubscription. Each stage has its own timestamp and method.
For campaigns sent to large lists, monitoring SMS delivery receipts alongside opt-out rates helps identify whether messages are being delivered to recipients who may have changed numbers or been reassigned — a separate compliance risk related to number reassignment.
Frequently Asked Questions
SMS consent is not a one-time setup — it is an ongoing operational process: capturing consent correctly, storing records retrievably, honoring opt-outs immediately, and keeping documentation current as consent language or campaign types change. For a full picture of how business SMS programs are structured from number selection to compliance, see the business SMS guide. For how carriers distinguish spam from legitimate traffic and what that means for deliverability, see the article on SMS delivery receipts.
Reminder: This article is educational information about general SMS consent practices, not legal advice. TCPA requirements, FCC rules, and carrier guidelines change. Consult qualified legal counsel before designing or deploying any SMS campaign.