SMS marketing works. Response rates run 6–8x higher than email, and 90% of texts are read within 3 minutes of delivery. But the same immediacy that makes SMS so effective also makes compliance failures expensive. One unconsented blast to a list you didn't scrub can generate thousands of violations before anyone hits reply.

SMS compliance means following legal and regulatory standards when sending business text messages - primarily TCPA in the US and GDPR in the EU - to avoid fines and protect consumer privacy. In the United States, the Telephone Consumer Protection Act (TCPA) sets the baseline: express written consent before sending, clear opt-out mechanisms on every message, and no texting before 8am or after 9pm local time. In the EU, GDPR layered on top of the ePrivacy Directive creates a consent framework that's even stricter. Both regimes treat consent as the central question. Get consent right, document it properly, and honor opt-outs immediately - and you're covering the vast majority of your compliance exposure.

This guide covers the core regulations, what they actually require in practice, the most common mistakes businesses make, and how to build a monitoring system that keeps you clean over time.

⚠️

Not legal advice. This guide covers regulatory requirements from an operational standpoint. Consult your legal counsel for guidance specific to your industry, geography, and message types before launching SMS campaigns.

$1,500 Maximum TCPA penalty per willful violation
€20M Maximum GDPR fine - or 4% of global annual turnover
90% Of SMS messages read within 3 minutes

What Is SMS Compliance?

SMS compliance is the set of legal obligations a business must follow when using text messaging to communicate with customers, prospects, or any other recipients. It's not a single law - it's an overlapping framework of federal statutes, industry guidelines, and carrier requirements that vary by geography.

At its core, compliance comes down to three things: who you can text (consent), what you can send (content rules), and how to stop (opt-out requirements). Every major regulation - TCPA, CTIA guidelines, GDPR, ePrivacy - is ultimately enforcing some version of those three principles.

Why SMS Compliance Matters

1. It protects consumers from unwanted messages

Unsolicited texts are intrusive in a way that email isn't. Your phone buzzes. You check it. It's a message you never asked for from a brand you don't know. Compliance rules exist specifically to protect that moment - and the regulators enforcing them take violations seriously.

2. It protects your business from significant liability

TCPA class actions are among the most lucrative in plaintiff-side litigation. There's no minimum harm requirement - a consumer doesn't have to prove damages to collect statutory penalties. Every text to an unconsented number is a separate violation. A 10,000-person blast to a dirty list can mean $5 million to $15 million in exposure before the case is filed.

3. Non-compliance kills deliverability

Mobile carriers actively filter messages from senders with high complaint rates. Getting blocklisted doesn't just stop future campaigns - it can affect your ability to send transactional messages (order confirmations, appointment reminders) through the same number. Compliance and deliverability are the same problem.

4. Compliant programs perform better

A list built on real consent - people who actively opted in to your messages - will always outperform a purchased list or a list that was force-opted-in through buried terms. Compliance forces the discipline that produces high-quality audiences.

5. Trust compounds over time

Consumers who opted in and get messages they actually want become your most responsive channel. The opt-out rate on a well-run compliant program is typically below 2%. That's a list that keeps working for years.

US Regulations: TCPA

What is the TCPA?

The Telephone Consumer Protection Act was enacted in 1991, long before SMS was a marketing channel. Congress passed it to address the wave of unsolicited telemarketing calls hitting consumers' home phones. Over time, the FCC extended its application to text messages - and the courts have largely upheld that extension.

The TCPA matters for three reasons specific to SMS: it requires prior express written consent for marketing messages, it provides a private right of action (meaning any individual consumer can sue, not just regulators), and statutory damages are uncapped per violation. Those three features together make it the primary source of SMS litigation risk in the US.

Key TCPA requirements for business texting

"The TCPA doesn't care how good your offer was. It cares whether you had documented consent before you sent the text."

What's changed since this guide was first published

Three real shifts in TCPA enforcement matter right now:

CTIA Guidelines

The Cellular Telecommunications Industry Association (CTIA) is the industry body that sets standards for commercial SMS programs. While CTIA guidelines aren't law, the major carriers (AT&T, Verizon, T-Mobile) enforce them as a condition of network access. Getting your program rejected by carrier review - or having messages filtered after launch - is a real consequence of CTIA non-compliance.

The most operationally important CTIA requirements:

Want SMS that handles opt-outs, consent, and STOP flows automatically?

See how Velaro handles it →

EU Regulations: GDPR and ePrivacy

What is GDPR?

The General Data Protection Regulation came into force in May 2018 and applies to any business that processes personal data of EU residents - regardless of where the business is based. For SMS, every mobile number is personal data. Processing it for marketing purposes requires a lawful basis, and for direct marketing to individuals, that lawful basis is almost always consent.

GDPR fines are set at the higher of two figures: up to €20 million, or up to 4% of global annual turnover. Regulators have discretion on the amount and have shown willingness to issue significant fines to mid-size companies, not just tech giants.

Key GDPR requirements for SMS marketing

The ePrivacy Directive

The ePrivacy Directive (sometimes called the "Cookie Directive") predates GDPR and specifically addresses electronic communications including SMS. In most EU member states it requires prior opt-in consent for any direct marketing by electronic means - including text messages. GDPR handles the data protection layer; ePrivacy handles the communication layer. Both apply simultaneously.

Requirement US TCPA EU GDPR / ePrivacy
Consent required before marketing SMS Yes - express written Yes - explicit opt-in
Implied/relational consent acceptable No for marketing No for direct marketing
Opt-out must be honored immediately Yes Yes - without delay
Time-of-day restrictions 8am–9pm local Varies by member state
Per-violation financial penalty $500–$1,500/message Aggregate up to €20M or 4% revenue
Private right of action (consumer can sue) Yes - class actions common Via supervisory authority complaints
Consent records required Yes Yes - burden of proof on sender

Best Practices for SMS Compliance Monitoring

Getting compliant is a one-time project. Staying compliant is an ongoing operational discipline. These seven practices form the minimum monitoring system every business using SMS marketing should have in place.

1. Audit your consent records quarterly

Consent records decay. Numbers get reassigned. Contacts change their mind. Run a quarterly audit of your active SMS list against your consent documentation. Any number you can't match to a documented opt-in event should be removed before the next send.

2. Scrub against the DNC registry monthly

The National Do Not Call Registry is updated continuously. FTC rules require scrubbing at least every 31 days for registered telemarketers - and while SMS programs aren't always technically "telemarketers," operating on that standard is the defensible position.

3. Test your opt-out flow before every campaign

Send yourself a test message and reply STOP. Confirm the opt-out confirmation arrives. Confirm the number is suppressed in your platform before the next send. This takes two minutes and has saved companies from multi-million-dollar exposure.

4. Maintain a suppression list that survives platform changes

If you ever switch SMS platforms or providers, your opt-out list must transfer with you. Keep a platform-agnostic suppression list - a CSV or database record - that you own independently of any vendor. Opt-outs are permanent. They don't expire when you change software.

5. Document consent at the point of collection

Timestamp every opt-in with the date, time, IP address (for web forms), the exact language the consumer saw, and the channel where consent was collected. If that data isn't stored alongside the phone number, you have consent you can't prove.

6. Monitor complaint rates by campaign and list segment

Carrier spam complaint rates above 0.3% are a warning sign. Above 0.5% and you risk having your messages filtered or your short code suspended. Break complaint data down by campaign and list source - a spike in complaints from a specific import is a signal that consent on that segment is questionable.

7. Train everyone who touches the SMS platform

Compliance failures often happen at the operations level, not in legal. Marketing coordinators who upload lists, support agents who manually opt contacts into SMS, campaign managers who schedule sends - all of them need to understand the rules. Annual training is the minimum; quarterly is better.

Common SMS Compliance Mistakes to Avoid

Using email consent to justify SMS sends

This is the single most common mistake. An email opt-in covers email. Full stop. Sending SMS to contacts who opted in for email - even if their phone number is in your CRM - is a TCPA violation. Consent is channel-specific.

Assuming "implied consent" from a purchase or inquiry

A customer buying from you or filling out a contact form is not consenting to marketing texts. There are narrow exceptions for certain transactional messages (order confirmations, shipping notifications), but those exceptions don't extend to promotional content. If in doubt, collect explicit consent.

Neglecting list hygiene when switching platforms

When businesses move from one SMS platform to another, they often re-import their full contact database without checking when consent was collected, whether the opt-out list transfers, or whether numbers have been reassigned since the original opt-in. Number reassignment is particularly dangerous - you can be texting a completely different person who never heard of your business.

Sending outside permitted hours across time zones

A national SMS campaign that goes out at 7pm ET is sending at 4pm PT - fine. But if your list has recipients in Hawaii, that's 1pm. The problem is the other direction: a 9am ET send is 6am in California. Know your list's geographic distribution before scheduling.

Soft opt-outs that don't suppress future sends

Some platforms treat a STOP reply as a campaign-level opt-out rather than a global suppression. The consumer thinks they've opted out. You send another campaign from a different short code or number. That's a violation, even if it was a platform misconfiguration rather than intentional.

Not renewing stale consent

There's no universal statute of limitations on SMS consent, but regulators and courts look unfavorably at consent collected years ago with language that didn't specifically mention texting. If your list contains contacts who opted in before your current consent language was implemented, consider a re-permission campaign before resuming sends to that segment.

Velaro's SMS channel includes built-in opt-out management and consent tracking - TCPA-compliant flows out of the box.

See a demo →

How Velaro Handles SMS Compliance

Most businesses running SMS today are operating on a patchwork: one tool for opt-in collection, a separate CRM for suppression lists, a different platform for sending, and a spreadsheet for documentation. Every seam in that stack is a compliance gap.

Velaro's SMS channel was built as part of a unified customer engagement platform, which means opt-out management, consent tracking, and suppression are handled in the same system that sends the messages - not bolted on after the fact.

If you're running SMS marketing today and you're not certain your opt-out flow is working, your consent records are complete, or your list was properly permissioned - that's the right starting point for a conversation. We're happy to walk through your current setup.

The Bottom Line

SMS compliance is not complicated in principle. You need documented consent before you send, a working opt-out flow, and a suppression list you actually maintain. Where businesses get into trouble is in the operational details: consent that wasn't specific enough, opt-outs that didn't propagate, lists that weren't scrubbed.

The financial stakes are real. A single TCPA class action - even one you eventually settle - will cost more than several years of running a properly compliant SMS program. The monitoring practices in this guide aren't overhead. They're insurance.

And if you want a platform that handles the compliance infrastructure automatically - so your team focuses on the messages rather than the mechanics - Velaro's SMS channel is built for exactly that.

Frequently Asked Questions

What is SMS compliance?

SMS compliance means following the legal and regulatory requirements that govern business text messaging. In the US, that's primarily the Telephone Consumer Protection Act (TCPA), which requires express written consent before sending marketing texts and mandates immediate opt-out processing. In the EU, GDPR and the ePrivacy Directive impose similar consent requirements with penalties up to €20 million or 4% of global annual turnover.

What are the TCPA requirements for business texting?

The TCPA requires businesses to obtain prior express written consent before sending marketing texts, honor opt-out requests immediately and permanently, avoid texting before 8am or after 9pm in the recipient's local time zone, check against the National Do Not Call Registry, and identify the sender in every message. Violations carry statutory penalties of $500 to $1,500 per text message.

How do I get consent for SMS marketing?

Collect express written consent through a web form, in-store sign-up, or other method where the consumer actively agrees to receive texts. The consent language must clearly identify the sender, describe the type of messages to expect, state the approximate message frequency, disclose that message and data rates may apply, and explain how to opt out (text STOP). Email opt-ins do not cover SMS - you need channel-specific consent.

What happens if you violate the TCPA?

TCPA violations expose businesses to statutory damages of $500 per violation for unintentional violations and $1,500 per violation for willful violations. Because each individual text message is a separate violation, a large unconsented campaign can generate enormous aggregate liability. TCPA cases are frequently brought as class actions - settlements commonly range from $3 million to over $75 million. Regulators can also bring enforcement actions independently of private litigation.

What are the SMS opt-out requirements?

When a recipient texts STOP (or any standard opt-out keyword: STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT), your system must immediately send a single confirmation message and permanently suppress that number from all future marketing sends. The opt-out must be honored without requiring any further action from the consumer. Sending another marketing text to an opted-out number - even from a different short code - is a separate TCPA violation.