ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

How should consent be obtained?

Back to InsightsHow should consent be obtained?

How should consent be obtained?

Key Facts

  • TCPA statutory damages run $500 per violation, trebling to $1,500 for willful violations — each text or call counts as a separate offense per Troutman Pepper analysis.
  • The FCC's one-to-one consent rule takes effect January 27, 2026, requiring consent to be individual, explicit, seller-specific, and clearly connected to the sending business per regulatory coverage.
  • Roughly 35 million phone numbers are disconnected and reassigned annually, meaning old contact lists may reach strangers who never consented per FCC data.
  • Major carriers including AT&T, T-Mobile, and Verizon now block all unregistered A2P business SMS traffic outright as of February 2025 per 10DLC registration guidance.
  • Telemarketing texts require prior express written consent with a signed or ESIGN-compliant electronic agreement — a past purchase or old quote does not qualify per Hunton Andrews Kurth.
  • The FCC identifies seven per se revocation terms — stop, quit, end, revoke, opt out, cancel, unsubscribe — that must be honored within 10 business days per legal analysis.
  • Reactivating a customer costs roughly 5× less than acquiring a new one, while a 5% retention lift can increase profits 25–95% per industry research.

Most service businesses sit on a goldmine of past customers, old quotes, and dormant contacts — and assume that because someone once bought from them, they have permission to reach out. Under the Telephone Consumer Protection Act (TCPA), that assumption is one of the most expensive mistakes in modern marketing.

The distinction matters legally, not just ethically. Legal analysis from Hunton Andrews Kurth draws a hard line between informational communications (appointment reminders, service notifications) and telemarketing (promotional offers, win-back campaigns) — and only the first category can rely on the lower "prior express consent" standard. That seasonal discount text to a customer who bought an HVAC tune-up two years ago? It's telemarketing, and it requires prior express written consent.

A past purchase doesn't create that consent. Neither does an old quote request or a phone number collected at checkout. As compliance guidance on database reactivation makes clear, an old inquiry does not constitute consent for marketing texts — permission must be campaign-specific and sender-specific. The CTIA Messaging Principles state it directly: an opt-in "should apply only to the campaign(s) and specific Message Sender for which it was intended or obtained."

The stakes are about to rise again. The FCC's one-to-one consent rule, effective January 27, 2026, requires that consent be "individual, explicit, seller-specific, and clearly connected to the business sending the message," according to regulatory coverage of the rule. Blanket permission buried in terms and conditions no longer cuts it.

The financial exposure explains why this gap deserves attention:

  • TCPA statutory damages run $500 per violation, up to $1,500 for willful or knowing violations — and each text or call counts separately, per Troutman Pepper's analysis.
  • Roughly 35 million numbers are disconnected and reassigned each year, meaning an old list may reach strangers who never consented to anything.
  • Carriers now block all unregistered A2P business text traffic outright as of February 2025, per 10DLC registration guidance.

This is why any reputable reactivation partner starts with permission, not with the list. CallMyCustomers works only from lists of real customers, honors opt-outs immediately, and collects explicit consent in the booking flow — because a win-back campaign is only worth running if every message behind it can stand up to scrutiny. Consent isn't a formality before outreach; it's the foundation the campaign is built on.

Not all consent is created equal — and treating a promotional text the same as an appointment reminder is one of the fastest ways to land in TCPA litigation. Under the TCPA, legal analysis from Hunton Andrews Kurth identifies two distinct tiers: informational communications require prior express consent, while telemarketing communications demand the stricter prior express written consent.

Informational messages — appointment reminders, fraud alerts, account updates, and service notifications containing no marketing content — sit on the lower tier. Prior express consent can be satisfied when a customer voluntarily provides their phone number in the context of those communications, without limiting the purpose for which the number may be used. That's why a dental patient who leaves a number at booking can reasonably receive a no-show recovery text.

Telemarketing messages — win-back offers, seasonal promotions, referral requests — operate under a much heavier burden. Valid written consent requires a signed agreement (or ESIGN-compliant electronic signature), must be clear and conspicuous, and cannot be a required condition of any purchase. An old inquiry or past purchase alone does not authorize marketing texts; consent must be campaign-specific and sender-specific, per the CTIA Messaging Principles.

The exact opt-in language matters. Compliant wording looks like: "By submitting this form, you agree to receive SMS messages from [Brand Name] about [specific purpose]. Message and data rates may apply. Reply STOP to opt out." Vague, generic permission won't survive scrutiny — especially with the FCC's one-to-one consent rule taking effect January 27, 2026, requiring consent to be individual, explicit, and seller-specific.

The stakes explain the precision required:

  • TCPA statutory damages run $500 per violation, up to $1,500 for willful violations — and each text or call counts separately.
  • FCC penalties may reach $10,000 per violation in certain enforcement contexts.
  • Revocation rules differ by tier: category-specific opt-outs exist for informational calls, but one revocation ends all telemarketing from that sender.

For service businesses running reactivation or retention campaigns, this distinction shapes everything. CallMyCustomers builds this tier separation into every campaign plan — a missed-appointment recovery text and a seasonal win-back offer are treated as legally different animals, because they are. Before any outreach begins, scripts and consent language are reviewed and approved so each message matches the consent tier it actually sits in.

Building a Compliant Opt-In Process That Converts

A single text message sent without proper consent can cost $500 — and up to $1,500 if the violation is willful or knowing, since each message counts as a separate violation under the TCPA. That makes your opt-in process the most valuable piece of paperwork in your entire outreach program.

The good news: building a compliant opt-in that still converts follows a clear, repeatable framework. Here's how to do it step by step.

Step 1: Match the consent tier to the message type. Not all messages require the same standard. Informational communications like appointment reminders and service notifications require prior express consent, while telemarketing — promotional offers, seasonal campaigns, win-back messages — requires prior express written consent with a signed agreement or ESIGN-compliant electronic signature, as legal analysts at Hunton Andrews Kurth explain. Critically, that consent cannot be a condition of purchase.

Step 2: Make the disclosure clear, conspicuous, and specific. The FCC's one-to-one consent rule, effective January 27, 2026, requires consent to be individual, explicit, and seller-specific — clearly connected to the business sending the message, per A2P 10DLC compliance guidance. An old inquiry or past purchase does not constitute consent for marketing texts; the CTIA Messaging Principles state an opt-in "should apply only to the campaign(s) and specific Message Sender for which it was intended."

A compliant opt-in statement should include:

  • The sender's exact business name — no vague branding or third-party ambiguity
  • The specific campaign purpose, e.g., "seasonal HVAC maintenance reminders" rather than generic marketing language
  • Rate disclosure: "Message and data rates may apply"
  • A working opt-out mechanism: "Reply STOP to opt out"

Step 3: Document everything centrally. Experts at Greenspoon Marder recommend centralized, auditable consent records — when, where, and how consent was obtained for each campaign. Siloed systems across brands or vendors create real operational risk under the evolving TCPA framework.

Step 4: Keep opt-out promises honest. The FCC has identified seven per se revocation terms — "stop," "quit," "end," "revoke," "opt out," "cancel," and "unsubscribe" — and revocations must be honored within 10 business days, with a proposed reduction to seven, according to Troutman Pepper's analysis. For telemarketing, one revocation ends all future promotional contact from that caller.

This is why done-for-you services like CallMyCustomers build consent capture directly into the booking flow and honor opt-outs immediately — the framework has to be operational, not theoretical. Get the opt-in right, and every message that follows starts on solid ground.

List Hygiene and Revocation: The Ongoing Compliance Engine

Maintaining compliance doesn't end when consent is obtained; it requires continuous, proactive list hygiene and robust revocation processes. For CallMyCustomers' clients, this means implementing mandatory protocols to scrub lists against the FCC Reassigned Numbers Database and the National Do Not Call Registry before every campaign, addressing the approximately 35 million numbers disconnected and reassigned annually that could lead to contacting the wrong party or violating DNC rules. Industry research confirms this step is critical to prevent inadvertent TCPA violations stemming from number recycling.

Centralized consent management across all campaigns and communication channels is essential for operational compliance and audit readiness. Businesses must maintain clear, accessible records detailing when, how, and for what specific purpose consent was obtained, particularly important given the FCC's one-to-one consent rule requiring campaign-specific permission effective January 27, 2026. Expert guidance emphasizes that siloed systems create significant risk, whereas centralized processes ensure consistency and provide the auditable trail regulators increasingly demand. This approach supports compliance whether sending service reminders (informational) or win-back offers (telemarketing).

Honoring revocation requests promptly remains a non-negotiable obligation, with the current maximum timeframe set at 10 business days to cease all telemarketing communications upon receiving a valid opt-out via any reasonable method. Recent FCC proposals indicate this window may be reduced to seven business days under a Further Notice of Proposed Rulemaking, requiring businesses to prepare for faster response times. Implementing systems that immediately flag and act on revocation requests across voice, text, and email channels ensures adherence to these evolving standards and minimizes exposure to statutory damages of $500-$1,500 per violation. This ongoing engine of list hygiene and revocation management transforms compliance from a one-time checklist into a sustainable operational practice.

Infrastructure Checklist: A2P 10DLC Registration and Carrier Compliance

Infrastructure Checklist: A2P 10DLC Registration and Carrier Compliance

Since February 2025, A2P 10DLC registration has shifted from a best practice to a mandatory requirement, with major carriers including AT&T, T-Mobile, and Verizon blocking all unregistered business SMS traffic outright. This infrastructure layer is now foundational to ensuring messages reach customers rather than being filtered at the carrier level. For CallMyCustomers’ clients in home services, wellness clinics, and other repeat-revenue businesses, compliance begins with proper brand vetting through The Campaign Registry (TCR), where standard brand vetting fees increased to $41.50 as of August 2025, and each additional campaign submission now costs $15.00.

Throughput limits and per-message fees vary significantly by carrier and business structure, directly impacting campaign scalability. Sole proprietors face daily caps of 1,000 messages on T-Mobile networks, while AT&T restricts throughput to 15 messages per minute for similar entities. Outbound SMS fees from carriers like AT&T and Verizon average $0.003 per message, a cost that accumulates quickly at scale but remains negligible compared to the risk of non-delivery or regulatory penalties. These technical constraints must be aligned with campaign design to avoid throttling or blocking during peak outreach windows.

Successful registration depends on precise, campaign-specific use case descriptions that clearly define audience, purpose, and consent mechanism. Generic labels such as “Insurance leads marketing texts” are routinely rejected, whereas detailed explanations like “Renewal reminder notifications sent to active policyholders who opted in during policy binding” meet TCR review standards. This specificity ensures alignment with both carrier policies and the FCC’s evolving one-to-one consent rule, which requires consent to be individually tied to a specific sender and campaign purpose effective January 27, 2026. Maintaining this infrastructure as an ongoing governance process—not a one-time task—is essential for sustained deliverability and compliance. Carrier blocking policies and TCR fee updates underscore the operational reality that compliance is continuous, not episodic. For businesses relying on reactivation campaigns, this infrastructure directly supports the ability to re-engage past customers without interruption, turning dormant lists into booked work through carrier-approved channels.

Frequently Asked Questions

Can I text my past customers just because they bought from me before?
No — under the TCPA, a past purchase, old quote request, or number collected at checkout does not constitute consent for marketing texts. Consent must be campaign-specific and sender-specific; the CTIA Messaging Principles state an opt-in "should apply only to the campaign(s) and specific Message Sender for which it was intended or obtained," per compliance guidance on database reactivation.
What's the difference between an appointment reminder and a promotional text under the TCPA?
Appointment reminders and service notifications are informational and only require prior express consent, while promotional offers and win-back campaigns are telemarketing requiring prior express written consent with a signed (or ESIGN-compliant) agreement that isn't a condition of purchase, per legal analysis from Hunton Andrews Kurth.
What does compliant opt-in language actually look like?
A compliant opt-in names the exact business, the specific campaign purpose, and includes rate disclosure plus an opt-out — e.g., "By submitting this form, you agree to receive SMS messages from [Brand Name] about [specific purpose]. Message and data rates may apply. Reply STOP to opt out." Vague or generic permission won't survive scrutiny, especially under the FCC's one-to-one consent rule effective January 27, 2026.
How much can texting without consent actually cost my business?
TCPA statutory damages run $500 per violation, up to $1,500 for willful or knowing violations — and each text or call counts separately, so a 1,000-message campaign can quickly mean six-figure exposure, per Troutman Pepper's analysis. FCC penalties may also reach $10,000 per violation in certain enforcement contexts.
How quickly do I have to honor a STOP request?
The FCC has identified seven per se revocation terms — "stop," "quit," "end," "revoke," "opt out," "cancel," and "unsubscribe" — and revocations must be honored within 10 business days, with a proposed reduction to seven. For telemarketing, one revocation ends all future promotional contact from that sender, per Troutman Pepper's analysis.
Do I need to register with carriers before sending business texts?
Yes — as of February 2025, AT&T, T-Mobile, and Verizon block all unregistered A2P business SMS traffic outright, so registration through The Campaign Registry is mandatory for deliverability, per 10DLC registration guidance. Use case descriptions must be specific (generic labels like "marketing texts" get rejected), and CallMyCustomers handles this registration as part of running compliant campaigns for you.

Consent First, Revenue Second — The Order That Protects Both

Consent isn't a box to check before your win-back campaign launches — it's the architecture the campaign stands on. The rules are only getting sharper: the FCC's one-to-one consent requirement arrives January 27, 2026, carriers now block unregistered business texts outright, and every message sent without proper permission carries statutory damages of $500 to $1,500, per Troutman Pepper's TCPA analysis. The practical takeaway: separate your informational messages from your telemarketing, capture campaign-specific written consent in your booking flow, scrub lists against the Reassigned Numbers Database before every send, and honor opt-outs immediately. If that sounds like a lot to operationalize alongside running your business, it doesn't have to sit on your plate alone. CallMyCustomers builds consent capture, list hygiene, and message approval into every reactivation campaign — and you sign off on every script before anything goes out. Start with a free list review to see what your past customers could produce, with no obligation and no spend until you know the numbers.

Stay in the Loop