SMS marketing works. Response rates run 6–8x higher than email, and 90% of texts are read within 3 minutes of delivery. But the same immediacy that makes SMS so effective also makes compliance failures expensive. One unconsented blast to a list you didn't scrub can generate thousands of violations before anyone hits reply.
SMS compliance means following legal and regulatory standards when sending business text messages - primarily TCPA in the US and GDPR in the EU - to avoid fines and protect consumer privacy. In the United States, the Telephone Consumer Protection Act (TCPA) sets the baseline: express written consent before sending, clear opt-out mechanisms on every message, and no texting before 8am or after 9pm local time. In the EU, GDPR layered on top of the ePrivacy Directive creates a consent framework that's even stricter. Both regimes treat consent as the central question. Get consent right, document it properly, and honor opt-outs immediately - and you're covering the vast majority of your compliance exposure.
This guide covers the core regulations, what they actually require in practice, the most common mistakes businesses make, and how to build a monitoring system that keeps you clean over time.
Not legal advice. This guide covers regulatory requirements from an operational standpoint. Consult your legal counsel for guidance specific to your industry, geography, and message types before launching SMS campaigns.
What Is SMS Compliance?
SMS compliance is the set of legal obligations a business must follow when using text messaging to communicate with customers, prospects, or any other recipients. It's not a single law - it's an overlapping framework of federal statutes, industry guidelines, and carrier requirements that vary by geography.
At its core, compliance comes down to three things: who you can text (consent), what you can send (content rules), and how to stop (opt-out requirements). Every major regulation - TCPA, CTIA guidelines, GDPR, ePrivacy - is ultimately enforcing some version of those three principles.
Why SMS Compliance Matters
1. It protects consumers from unwanted messages
Unsolicited texts are intrusive in a way that email isn't. Your phone buzzes. You check it. It's a message you never asked for from a brand you don't know. Compliance rules exist specifically to protect that moment - and the regulators enforcing them take violations seriously.
2. It protects your business from significant liability
TCPA class actions are among the most lucrative in plaintiff-side litigation. There's no minimum harm requirement - a consumer doesn't have to prove damages to collect statutory penalties. Every text to an unconsented number is a separate violation. A 10,000-person blast to a dirty list can mean $5 million to $15 million in exposure before the case is filed.
3. Non-compliance kills deliverability
Mobile carriers actively filter messages from senders with high complaint rates. Getting blocklisted doesn't just stop future campaigns - it can affect your ability to send transactional messages (order confirmations, appointment reminders) through the same number. Compliance and deliverability are the same problem.
4. Compliant programs perform better
A list built on real consent - people who actively opted in to your messages - will always outperform a purchased list or a list that was force-opted-in through buried terms. Compliance forces the discipline that produces high-quality audiences.
5. Trust compounds over time
Consumers who opted in and get messages they actually want become your most responsive channel. The opt-out rate on a well-run compliant program is typically below 2%. That's a list that keeps working for years.
US Regulations: TCPA
What is the TCPA?
The Telephone Consumer Protection Act was enacted in 1991, long before SMS was a marketing channel. Congress passed it to address the wave of unsolicited telemarketing calls hitting consumers' home phones. Over time, the FCC extended its application to text messages - and the courts have largely upheld that extension.
The TCPA matters for three reasons specific to SMS: it requires prior express written consent for marketing messages, it provides a private right of action (meaning any individual consumer can sue, not just regulators), and statutory damages are uncapped per violation. Those three features together make it the primary source of SMS litigation risk in the US.
Key TCPA requirements for business texting
- Express written consent: Before sending any marketing text, you need affirmative consent that clearly describes what the consumer is agreeing to receive. Implied consent from a business relationship is not sufficient for SMS marketing. Consent must be documented and retrievable.
- Do Not Call (DNC) compliance: Check the National Do Not Call Registry before texting any number. Scrub your lists against it at least every 31 days. Individual company-level DNC requests must also be honored permanently.
- Time restrictions: No texts before 8:00am or after 9:00pm in the recipient's local time zone. This applies to the recipient's location, not yours. A marketing automation system sending at 8pm ET is sending at 5pm PT - but if you're targeting recipients in Hawaii, check the math.
- Identification: Every marketing text must identify the sender clearly. "Text STOP to opt out" or an equivalent opt-out instruction is required on every initial message, and best practice on all messages.
- Penalties: $500 per violation for unintentional violations; $1,500 per violation when willful or knowing. Class actions frequently aggregate individual violations into settlements ranging from $3 million to $76 million.
"The TCPA doesn't care how good your offer was. It cares whether you had documented consent before you sent the text."
What's changed since this guide was first published
Three real shifts in TCPA enforcement matter right now:
- The one-to-one consent rule is gone. The FCC's December 2023 rule would have required each individual seller to get its own separate consent, ending the practice of one opt-in covering multiple partners. The 11th Circuit vacated that rule on January 24, 2025 in Insurance Marketing Coalition v. FCC, finding the FCC exceeded its statutory authority. As of this writing, one-to-one consent is not a federal requirement, though broad partner-consent clauses still carry legal risk and should be reviewed with counsel.
- Revocation now has to work through any reasonable channel. Since April 2025, honoring an opt-out only when it arrives as a "STOP" reply is no longer enough. A consumer revoking consent by email, phone call, website form, or a direct conversation with an agent has to be honored too, processed within 10 business days, with real-time handling as the practical standard most compliance teams are building toward.
- The "Revoke-All" rule is delayed, not canceled. A related provision would treat any opt-out on one channel as revocation across every channel and purpose. The FCC pushed its effective date to January 31, 2027. It's coming, just not yet, worth building toward now rather than waiting for the deadline.
CTIA Guidelines
The Cellular Telecommunications Industry Association (CTIA) is the industry body that sets standards for commercial SMS programs. While CTIA guidelines aren't law, the major carriers (AT&T, Verizon, T-Mobile) enforce them as a condition of network access. Getting your program rejected by carrier review - or having messages filtered after launch - is a real consequence of CTIA non-compliance.
The most operationally important CTIA requirements:
- Program disclosure at opt-in: When someone signs up for SMS, they must be told: the program name, message frequency, "Msg & data rates may apply," how to get help (text HELP), and how to stop (text STOP).
- STOP handling: When a recipient texts STOP, your system must immediately send a single confirmation message and never send another marketing message to that number. Failure to honor STOP is both a TCPA violation and a carrier violation.
- HELP handling: Responding to HELP with program information and a contact method is required.
- Age restrictions: Programs targeting minors require parental consent. Programs involving age-restricted products (alcohol, tobacco, gambling) must include age verification at opt-in.
- Short code registration: If you're using a short code for high-volume messaging, it must be registered with the carriers through the Short Code Registry. Unregistered short codes are routinely blocked.
Want SMS that handles opt-outs, consent, and STOP flows automatically?
See how Velaro handles it →EU Regulations: GDPR and ePrivacy
What is GDPR?
The General Data Protection Regulation came into force in May 2018 and applies to any business that processes personal data of EU residents - regardless of where the business is based. For SMS, every mobile number is personal data. Processing it for marketing purposes requires a lawful basis, and for direct marketing to individuals, that lawful basis is almost always consent.
GDPR fines are set at the higher of two figures: up to €20 million, or up to 4% of global annual turnover. Regulators have discretion on the amount and have shown willingness to issue significant fines to mid-size companies, not just tech giants.
Key GDPR requirements for SMS marketing
- Lawful basis for processing: Legitimate interests can sometimes apply to B2B SMS, but for consumer marketing, explicit consent is the safest and most defensible basis.
- Consent specificity: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes don't count. Bundled consent (agreeing to marketing as part of T&Cs) doesn't count. Consent for email doesn't extend to SMS - each channel requires its own consent.
- Right to withdraw: Withdrawing consent must be as easy as giving it. Opt-out requests must be honored without delay and without requiring the individual to give a reason.
- Data minimization: Collect only what you need for the SMS program. If you don't need the recipient's full address to send a delivery notification, don't collect it.
- Records of processing: You must be able to demonstrate consent - who consented, when, to what, and how. If you can't show your consent records in a regulatory investigation, consent is treated as absent.
The ePrivacy Directive
The ePrivacy Directive (sometimes called the "Cookie Directive") predates GDPR and specifically addresses electronic communications including SMS. In most EU member states it requires prior opt-in consent for any direct marketing by electronic means - including text messages. GDPR handles the data protection layer; ePrivacy handles the communication layer. Both apply simultaneously.
| Requirement | US TCPA | EU GDPR / ePrivacy |
|---|---|---|
| Consent required before marketing SMS | Yes - express written | Yes - explicit opt-in |
| Implied/relational consent acceptable | No for marketing | No for direct marketing |
| Opt-out must be honored immediately | Yes | Yes - without delay |
| Time-of-day restrictions | 8am–9pm local | Varies by member state |
| Per-violation financial penalty | $500–$1,500/message | Aggregate up to €20M or 4% revenue |
| Private right of action (consumer can sue) | Yes - class actions common | Via supervisory authority complaints |
| Consent records required | Yes | Yes - burden of proof on sender |
Best Practices for SMS Compliance Monitoring
Getting compliant is a one-time project. Staying compliant is an ongoing operational discipline. These seven practices form the minimum monitoring system every business using SMS marketing should have in place.
1. Audit your consent records quarterly
Consent records decay. Numbers get reassigned. Contacts change their mind. Run a quarterly audit of your active SMS list against your consent documentation. Any number you can't match to a documented opt-in event should be removed before the next send.
2. Scrub against the DNC registry monthly
The National Do Not Call Registry is updated continuously. FTC rules require scrubbing at least every 31 days for registered telemarketers - and while SMS programs aren't always technically "telemarketers," operating on that standard is the defensible position.
3. Test your opt-out flow before every campaign
Send yourself a test message and reply STOP. Confirm the opt-out confirmation arrives. Confirm the number is suppressed in your platform before the next send. This takes two minutes and has saved companies from multi-million-dollar exposure.
4. Maintain a suppression list that survives platform changes
If you ever switch SMS platforms or providers, your opt-out list must transfer with you. Keep a platform-agnostic suppression list - a CSV or database record - that you own independently of any vendor. Opt-outs are permanent. They don't expire when you change software.
5. Document consent at the point of collection
Timestamp every opt-in with the date, time, IP address (for web forms), the exact language the consumer saw, and the channel where consent was collected. If that data isn't stored alongside the phone number, you have consent you can't prove.
6. Monitor complaint rates by campaign and list segment
Carrier spam complaint rates above 0.3% are a warning sign. Above 0.5% and you risk having your messages filtered or your short code suspended. Break complaint data down by campaign and list source - a spike in complaints from a specific import is a signal that consent on that segment is questionable.
7. Train everyone who touches the SMS platform
Compliance failures often happen at the operations level, not in legal. Marketing coordinators who upload lists, support agents who manually opt contacts into SMS, campaign managers who schedule sends - all of them need to understand the rules. Annual training is the minimum; quarterly is better.
Common SMS Compliance Mistakes to Avoid
Using email consent to justify SMS sends
This is the single most common mistake. An email opt-in covers email. Full stop. Sending SMS to contacts who opted in for email - even if their phone number is in your CRM - is a TCPA violation. Consent is channel-specific.
Assuming "implied consent" from a purchase or inquiry
A customer buying from you or filling out a contact form is not consenting to marketing texts. There are narrow exceptions for certain transactional messages (order confirmations, shipping notifications), but those exceptions don't extend to promotional content. If in doubt, collect explicit consent.
Neglecting list hygiene when switching platforms
When businesses move from one SMS platform to another, they often re-import their full contact database without checking when consent was collected, whether the opt-out list transfers, or whether numbers have been reassigned since the original opt-in. Number reassignment is particularly dangerous - you can be texting a completely different person who never heard of your business.
Sending outside permitted hours across time zones
A national SMS campaign that goes out at 7pm ET is sending at 4pm PT - fine. But if your list has recipients in Hawaii, that's 1pm. The problem is the other direction: a 9am ET send is 6am in California. Know your list's geographic distribution before scheduling.
Soft opt-outs that don't suppress future sends
Some platforms treat a STOP reply as a campaign-level opt-out rather than a global suppression. The consumer thinks they've opted out. You send another campaign from a different short code or number. That's a violation, even if it was a platform misconfiguration rather than intentional.
Not renewing stale consent
There's no universal statute of limitations on SMS consent, but regulators and courts look unfavorably at consent collected years ago with language that didn't specifically mention texting. If your list contains contacts who opted in before your current consent language was implemented, consider a re-permission campaign before resuming sends to that segment.
Velaro's SMS channel includes built-in opt-out management and consent tracking - TCPA-compliant flows out of the box.
See a demo →How Velaro Handles SMS Compliance
Most businesses running SMS today are operating on a patchwork: one tool for opt-in collection, a separate CRM for suppression lists, a different platform for sending, and a spreadsheet for documentation. Every seam in that stack is a compliance gap.
Velaro's SMS channel was built as part of a unified customer engagement platform, which means opt-out management, consent tracking, and suppression are handled in the same system that sends the messages - not bolted on after the fact.
- Built-in opt-out management: STOP replies are processed automatically, suppression is immediate, and the opt-out is stored against the contact record across all channels. There's no manual list reconciliation.
- Consent tracking at the contact level: When consent is collected - via web form, chat widget, or in-conversation - the timestamp, channel, and consent language version are stored with the phone number. Consent documentation is auditable on demand.
- TCPA-compliant message flows out of the box: Pre-built flows include required STOP/HELP handling, sender identification, and message frequency disclosure. You're not building compliance logic from scratch.
- Works alongside live chat and AI from one platform: SMS isn't a separate tool with a separate contact database. It's a channel in the same platform where your agents handle chat, your AI handles initial responses, and your suppression lists are unified. When a contact opts out of SMS, that's reflected everywhere.
If you're running SMS marketing today and you're not certain your opt-out flow is working, your consent records are complete, or your list was properly permissioned - that's the right starting point for a conversation. We're happy to walk through your current setup.
The Bottom Line
SMS compliance is not complicated in principle. You need documented consent before you send, a working opt-out flow, and a suppression list you actually maintain. Where businesses get into trouble is in the operational details: consent that wasn't specific enough, opt-outs that didn't propagate, lists that weren't scrubbed.
The financial stakes are real. A single TCPA class action - even one you eventually settle - will cost more than several years of running a properly compliant SMS program. The monitoring practices in this guide aren't overhead. They're insurance.
And if you want a platform that handles the compliance infrastructure automatically - so your team focuses on the messages rather than the mechanics - Velaro's SMS channel is built for exactly that.
Frequently Asked Questions
What is SMS compliance?
SMS compliance means following the legal and regulatory requirements that govern business text messaging. In the US, that's primarily the Telephone Consumer Protection Act (TCPA), which requires express written consent before sending marketing texts and mandates immediate opt-out processing. In the EU, GDPR and the ePrivacy Directive impose similar consent requirements with penalties up to €20 million or 4% of global annual turnover.
What are the TCPA requirements for business texting?
The TCPA requires businesses to obtain prior express written consent before sending marketing texts, honor opt-out requests immediately and permanently, avoid texting before 8am or after 9pm in the recipient's local time zone, check against the National Do Not Call Registry, and identify the sender in every message. Violations carry statutory penalties of $500 to $1,500 per text message.
How do I get consent for SMS marketing?
Collect express written consent through a web form, in-store sign-up, or other method where the consumer actively agrees to receive texts. The consent language must clearly identify the sender, describe the type of messages to expect, state the approximate message frequency, disclose that message and data rates may apply, and explain how to opt out (text STOP). Email opt-ins do not cover SMS - you need channel-specific consent.
What happens if you violate the TCPA?
TCPA violations expose businesses to statutory damages of $500 per violation for unintentional violations and $1,500 per violation for willful violations. Because each individual text message is a separate violation, a large unconsented campaign can generate enormous aggregate liability. TCPA cases are frequently brought as class actions - settlements commonly range from $3 million to over $75 million. Regulators can also bring enforcement actions independently of private litigation.
What are the SMS opt-out requirements?
When a recipient texts STOP (or any standard opt-out keyword: STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT), your system must immediately send a single confirmation message and permanently suppress that number from all future marketing sends. The opt-out must be honored without requiring any further action from the consumer. Sending another marketing text to an opted-out number - even from a different short code - is a separate TCPA violation.