
Can you provide an example of valid consent?
Key Facts
- TCPA violations carry fines of $500 to $1,500 per call or text message with a four-year statute of limitations for lawsuits according to TCPA compliance specialists
- Carriers began blocking texts from unregistered 10DLC numbers on August 31, 2023, and T-Mobile imposes fines up to $10,000 per non-compliance incident per carrier compliance documentation
- Valid consent requires Prior Express Written Consent with standalone unchecked opt-in, clear autodialer disclosure, and statement that consent isn't a purchase condition according to legal authorities
- Consumers can revoke consent anytime using any reasonable method like STOP or QUIT, and businesses must honor requests within 10 days per telecommunications law analysis
- Businesses must retain consent records including exact language, timestamp, URL, and evidence of human interaction for at least four years according to compliance experts
- A2P 10DLC registration requires verifiable proof of consumer opt-in for every campaign with separate consent flows for transactional and promotional messages per carrier guidelines
- The FCC's one-to-one consent rule was vacated by the Eleventh Circuit Court in January 2025, reinstating broader consent standards for multiple sellers according to regulatory analysis
Why Most Businesses Get Consent Wrong (And Risk Fines)
Most businesses don't ignore consent requirements out of malice — they cut corners because the rules feel abstract until a demand letter arrives. A pre-checked box on a contact form, a vague "I agree" buried in terms of service, or a verbal "sure" noted in a CRM without a timestamp: these are the shortcuts that trigger TCPA violations carrying fines of $500 to $1,500 per call or text message, with a four-year statute of limitations that lets plaintiffs reach back across years of outreach.
The law demands Prior Express Written Consent for any autodialed marketing communication. That consent must be in writing (electronic counts), clearly disclose autodialer use, state that consent isn't a condition of purchase, identify the specific sender, and — critically — use a standalone, unchecked opt-in mechanism. Bundled agreements and pre-ticked boxes do not satisfy this standard, and businesses bear full liability even when purchasing third-party leads.
- Pre-checked checkboxes or default opt-ins on web forms
- Consent buried in terms of service without a separate signature
- Verbal agreement without documented script, timestamp, and disclosure
- Blanket consent covering multiple sellers without individual choice
- Missing opt-out instructions, frequency disclosure, or privacy policy links
For SMS specifically, carriers began blocking texts from unregistered 10DLC numbers on August 31, 2023, and T-Mobile imposes fines up to $10,000 per non-compliance incident for businesses that fail The Campaign Registry approval. Registration requires verifiable proof of consumer opt-in for every campaign — transactional and promotional messages need separate consent flows, each documented with the exact language shown, timestamp, URL, and evidence of human interaction.
CallMyCustomers builds consent into every campaign from the start. Our free list review identifies which contacts have documented, compliant opt-ins and which need re-permissioning before a single message sends. We plan the campaign together, you approve every script and offer, and we run outreach only to contacts who have given clear, specific, documented consent — so reactivation drives revenue, not risk.
What the Law Requires: Clear Standards for Valid Consent
Understanding what constitutes valid consent is essential for businesses engaging in outreach communications, especially under TCPA and A2P 10DLC regulations. Consent must be explicit, documented, and specific to the type of message being sent—whether promotional or transactional. It cannot be inferred from a general relationship or buried in lengthy terms of service. Instead, it requires a clear, affirmative action by the consumer, such as checking an unchecked box or replying with a keyword like "START," that demonstrates informed agreement.
For consent to be valid under TCPA, it must meet the standard of Prior Express Written Consent (PEWC) for marketing communications using autodialing technology. This means the consent must be in writing—including electronic formats compliant with the E-SIGN Act—bear the consumer’s signature or equivalent authentication, clearly disclose the use of autodialing or prerecorded messages, state that consent is not a condition of purchase, and identify the seller. Importantly, the opt-in mechanism must be standalone, meaning it cannot be bundled with other agreements or presented via pre-checked boxes. As noted by compliance experts, businesses bear full liability for ensuring consent validity, even when using third-party leads, and must maintain verifiable proof that each consent event occurred independently and with full disclosure.
Under A2P 10DLC frameworks, valid consent requires an explicit opt-in before any SMS is sent, including transactional messages. Consent must be obtained through specific, traceable methods such as web forms with unchecked checkboxes, booking links with clear consent language, verbal scripts (limited to transactional use), or keyword opt-in (e.g., texting "START"). Each method must include clear disclosures about message type, frequency, pricing (if applicable), opt-out instructions, and links to the sender’s Privacy Policy and Terms of Service. Carriers and The Campaign Registry (TCR) require proof of this consent during campaign registration, and businesses with higher trust scores—based on verified consent practices—benefit from improved message deliverability and throughput.
Consumers retain the right to revoke consent at any time using any reasonable method, including keywords like "STOP," "QUIT," "END," "REVOKE," "OPT OUT," "CANCEL," or "UNSUBSCRIBE." Businesses must honor these requests as soon as possible but no later than 10 days after receipt. Even messages lacking exact opt-out language may constitute a valid revocation if a reasonable person would interpret them as a request to stop messaging, particularly if technical limitations prevent standard responses. In such cases, businesses must disclose those limitations and provide alternative opt-out methods to remain compliant.
Proper documentation is critical for defending against TCPA claims, given the statute of limitations allows lawsuits to reach back up to four years from the alleged violation. Businesses should retain records of each consent event—including the exact language presented, timestamp, URL or platform, and evidence of human interaction—for at least four years. This documentation becomes essential when demonstrating compliance during audits or legal challenges. For CallMyCustomers, this means ensuring every client campaign begins with verified, documented consent that aligns with both TCPA and A2P 10DLC standards, protecting both the business and its clients from regulatory risk while enabling effective, permission-based outreach.
Real Examples of Valid Consent in Action (Like CallMyCustomers Uses)
Valid consent isn't just a legal box to check—it's the foundation of trust in customer outreach. For service businesses, getting permission right means respecting the relationship while staying compliant with evolving regulations like TCPA and A2P 10DLC. Real-world examples show exactly how this works in practice, turning permission into a competitive advantage rather than a hurdle.
One of the most reliable methods is using unchecked checkboxes on service intake or booking forms. When a customer actively checks a box to opt in for appointment reminders or service updates—rather than having it pre-selected—they provide clear, unambiguous agreement. This standalone opt-in must include specific disclosures about message type, frequency, and how to opt out, meeting both TCPA and A2P 10DLC standards for Prior Express Written Consent (PEWC) according to TCPA compliance specialists. CallMyCustomers integrates this approach directly into client workflows, ensuring every message sent aligns with the exact permission granted.
Keyword opt-ins like texting "START" to a business number also constitute valid consent when paired with upfront transparency. Before the first message, customers must receive clear details about what they’re signing up for—including potential message frequency, any associated costs (though most service reminders are free), and how to stop receiving texts by replying "STOP" or similar phrases. This method works especially well for transactional SMS, such as post-service follow-ups or missed-call text-backs, where the opt-in happens naturally during a service interaction per A2P 10DLC carrier guidelines. Documentation of these exchanges—including timestamps and the exact language shown—is critical, as businesses must retain consent records for at least four years to match the TCPA statute of limitations legal experts emphasize.
Verbal consent can also be valid, but only for transactional texts under strict conditions. For example, if a customer verbally agrees during a service call to receive a text confirmation for their appointment, that agreement may suffice—but only if the business clearly states the purpose, uses a compliant script, and documents the interaction thoroughly. However, verbal consent does not cover promotional messages, which require PEWC. Businesses must also honor revocation requests immediately, accepting any reasonable method like "STOP," "QUIT," or even a direct reply asking to be removed, and act on them within 10 days per recent telecommunications law analysis.
Ultimately, valid consent thrives when it’s specific, documented, and respectful of customer choice. Whether through web forms, keyword triggers, or verified verbal agreements, the goal isn’t just compliance—it’s building outreach that customers expect and appreciate. For businesses reactivating past clients, this means every message feels like a helpful nudge, not an intrusion, because it’s rooted in permission they freely gave.
How to Implement and Protect Consent in Your Campaigns
Getting consent right on paper is one thing — keeping it defensible years later is where most businesses stumble. TCPA lawsuits can reach back up to four years from the date of an alleged violation, so your consent practices need to hold up long after the campaign ends.
The good news is that protecting consent comes down to a handful of disciplined habits. Here's what every service business running outreach should have in place:
- Keep consent records for at least four years. Document the exact consent language shown, the timestamp, the URL or platform where consent was collected, and evidence of human interaction. These records are your first line of defense if a claim ever surfaces.
- Honor revocation requests immediately. Consumers can revoke consent by any reasonable method — "STOP," "QUIT," "CANCEL," or even a plain-language reply a reasonable person would read as opting out. Requests must be honored as soon as possible, and no later than 10 days after receipt.
- Separate transactional and promotional opt-ins. Under A2P 10DLC rules, SMS consent requires a clear, explicit opt-in before any messages are sent — with no exceptions, even for transactional texts.
- Verify third-party leads include proof of consent. Businesses bear the liability for consent validity even when purchasing leads, so confirm that leads carry independent, traceable proof of consent rather than blanket agreements covering multiple sellers.
The stakes are real. TCPA violations carry fines of $500 to $1,500 per call or text, and carriers began blocking texts from unregistered 10DLC numbers in August 2023 — meaning poor consent hygiene can quietly kill your deliverability before a regulator ever calls. T-Mobile alone imposes fines of up to $10,000 per non-compliance incident for businesses that skip proper registration.
This is also where a done-for-you partner earns its keep. At CallMyCustomers, the booking flow collects explicit consent, opt-outs are honored immediately, and every script, offer, and message is approved by the business owner before anything goes out — so nothing reaches a customer that the business hasn't explicitly signed off on. For dental, med spa, and clinic clients, outreach runs under the required privacy agreements, including BAA/HIPAA and TCPA compliance in practice.
The pattern across all of these habits is simple: consent should be clear, specific, and documented at every step. When your opt-in mechanisms use unchecked checkboxes, disclose message frequency and opt-out instructions, and link to your Privacy Policy and Terms of Service, you're not just complying — you're building outreach that customers actually trust. And trust is what turns a dormant list into booked work.
Frequently Asked Questions
What does valid consent look like for a service business sending appointment reminders via text?
Can I use a pre-checked box on my website form to get consent for texting customers?
How long do I need to keep records of customer consent for text or call campaigns?
What happens if a customer texts something like 'Please stop' instead of 'STOP'—do I still have to honor it?
Do I need separate consent for transactional texts (like appointment confirmations) versus promotional texts?
If I buy a lead list from a third party, am I responsible for verifying that the contacts gave proper consent?
Turning Consent Into Your Competitive Edge
Valid consent isn’t just about avoiding fines—it’s the foundation of trust that turns outreach into real results. When you document clear, specific permission through unchecked checkboxes, keyword opt-ins, or compliant verbal agreements, you’re not only meeting TCPA and A2P 10DLC standards, you’re building campaigns that customers actually welcome. The stakes are high: violations can cost $500 to $1,500 per message, and poor consent hygiene can sink your deliverability before a regulator even calls. But done right, consent becomes a reactivation superpower—especially when paired with a partner who handles the complexity while you keep full control. Every script, offer, and message stays yours to approve, ensuring outreach feels helpful, not intrusive. If you’re ready to reactivate your list with confidence, start with a free list review to see which contacts are already compliant and which need re-permissioning—so your next campaign drives booked work, not risk.