
What information is required for informed consent?
Key Facts
- GDPR enforcement has produced €5.88 billion in cumulative fines across Europe according to privacy compliance research
- 75% of people say they've lost control over how companies use their data according to Ethyca's analysis
- The Fifth Circuit's February 2026 Bradford ruling held the TCPA requires only prior express consent — oral or written — for automated telemarketing calls per Holland & Knight's legal analysis
- Carrier-mandated 10DLC rules require six specific disclosures at every opt-in touchpoint including message receipt, sender identity, opt-out instructions, rate notice, and policy links per carrier compliance guidance
- Best practice pairs every disclosure with an affirmative action like a required checkbox so consent is explicit and documented rather than implied per carrier compliance guidance
- Enforcement focus has shifted from "did you collect consent?" to "can you prove how it was applied downstream?" according to consent management analysis
- The Bradford ruling applies only within the Fifth Circuit (Texas, Louisiana, Mississippi); other circuits and state statutes may still require written consent per Holland & Knight's analysis
The Consent Gap: Why 'They Gave Me Their Number' Isn't Enough
Many service-business owners assume that a phone number collected on a booking form or quote request gives them a green light to reach out. It doesn't. That number is contact information — not consent — and the gap between the two is where enforcement actions, carrier blocks, and lawsuits live.
The regulatory environment has sharpened fast. TCPA litigation remains a constant threat, carriers now screen every 10DLC registration for proper opt-in language, and privacy regulators have levied €5.88 billion in cumulative GDPR fines across Europe. Even small local operators are exposed: a single complaint can trigger a carrier takedown, and a class action can cost far more than the campaign that sparked it. Research on consent enforcement trends shows that 75% of people say they've lost control over how companies use their data — a sentiment that fuels both regulatory pressure and consumer complaints.
Carrier-mandated 10DLC rules make the required disclosures explicit. Every opt-in touchpoint must tell the consumer: that they may receive text messages, the identity of the business sending them, how to opt out (e.g., "Reply STOP"), that message and data rates may apply, and where to find the Privacy Policy and Terms & Conditions. Carrier compliance guidance treats these as non-negotiable, and best practice pairs each disclosure with an affirmative action such as a required checkbox so consent is explicit and documented.
- Clear disclosure that texts may be received
- Business identity and message purpose
- Opt-out instructions in every message
- Message and data rates notice
- Links to Privacy Policy and Terms & Conditions
The legal ground is also shifting underfoot. The Fifth Circuit's February 2026 ruling in Bradford v. Sovereign Pest Control held that the TCPA requires only "prior express consent" — which may be oral — for automated telemarketing calls, rejecting the FCC's written-consent rule. Holland & Knight's analysis notes this applies only within the Fifth Circuit; other circuits and many state statutes still expect written consent. For any business texting across state lines, the conservative, defensible standard remains a documented, checkbox-based opt-in.
Consent management analysis underscores the operational reality: enforcement is moving from "did you collect consent?" to "can you prove how it was applied downstream?" A consent record that doesn't travel with the data into your CRM, analytics, and outreach tools is just a record — not a control. CallMyCustomers builds explicit consent collection into the booking flow and honors opt-outs immediately across every channel, so the consent you gather stays enforceable wherever the conversation goes.
The Six Disclosures Every Consent Form Must Include
A consent form that leaves out a single required disclosure can undermine every message you send afterward. Under carrier-mandated 10DLC rules and the TCPA framework, informed consent for business texting rests on six specific pieces of information — and every opt-in touchpoint, from a website form to a booking flow, needs all of them.
According to carrier compliance guidance, these disclosures are not optional polish; they are the conditions under which your messaging program gets registered and stays deliverable. Here is the checklist:
- Message receipt disclosure: a clear statement that the individual may receive text messages from your business.
- Sender identification: the name of the business actually sending the messages — no ambiguity about who is contacting them.
- Opt-out instructions: simple, immediate language such as "Reply STOP to unsubscribe," included at opt-in and in applicable messages.
- Rate disclosure: a note that message and data rates may apply.
- Policy links: references to your Privacy Policy and Terms & Conditions, both of which carriers require to be publicly accessible.
The Privacy Policy must describe what data you collect, how you use it, any third-party sharing, and how individuals can request updates or deletion. The Terms & Conditions page should cover your business name, message types, opt-in and opt-out instructions, message frequency, a support contact, and the message/data rate statement.
One distinction shapes everything else: the TCPA treats informational messages and marketing messages differently, and each may require a different form of consent. A service reminder about an upcoming appointment is not the same, legally, as a promotional win-back offer — and businesses are responsible for classifying their own use cases and collecting the appropriate consent type for each. For marketing texts specifically, the conservative standard remains prior express written consent with clear opt-in disclosures.
That written standard is worth holding onto even as the law shifts. In February 2026, the Fifth Circuit ruled in Bradford v. Sovereign Pest Control that the TCPA requires only "prior express consent" — oral or written — for automated telemarketing calls, rejecting the FCC's 2012 written-consent rule. But as Holland & Knight's legal analysis notes, the ruling applies only within the Fifth Circuit, other circuits may still follow the FCC framework, and state statutes may independently require written consent. Interstate businesses should proceed with caution.
Disclosure alone is only half the equation. Best practice pairs every disclosure with an affirmative action, such as a required checkbox, so consent becomes explicit and documented rather than implied. This matters more than ever because enforcement is shifting from "did you collect consent?" to "can you prove how it was applied?" — privacy compliance research finds that defensible records must show when consent was given, what the user agreed to, and the context of collection. The stakes are real: GDPR enforcement alone has produced €5.88 billion in cumulative fines, and 75% of people say they have lost control over how companies use their data.
This is exactly why CallMyCustomers builds explicit consent collection directly into the booking flow — every message approved by the business owner before it sends, every opt-out honored immediately, and every consent decision documented from the first touchpoint.
Consent Is a Record, Not a Checkbox: Proving You Complied
Getting a "yes" at the point of collection is only half the job — regulators increasingly want to know whether you can prove that yes was honored everywhere it mattered. Enforcement focus has shifted from "did you collect consent?" to "can you prove how it was applied?"
That shift changes what a consent record needs to contain. A checkbox timestamp alone won't survive scrutiny; under GDPR and CCPA-style standards, a defensible record captures the full picture of the agreement.
A defensible consent record includes:
- When consent was given — a verifiable timestamp, not just a date field
- What the person agreed to — versioned consent states showing the exact disclosure language they saw
- The legal basis — why you're permitted to contact them under the applicable law
- The collection context — the interface, purpose, and jurisdiction where consent occurred
Attorneys at Holland & Knight put it plainly: companies must demonstrate that consent was "clear, direct and unequivocal," and where consent is obtained orally, it should be "carefully documented and independently verifiable to withstand future scrutiny." Even after the Fifth Circuit's February 2026 ruling relaxed the written-consent requirement within that circuit, documentation remains the conservative standard everywhere else.
The harder problem is what happens after collection. Consent that never reaches your downstream systems — your CRM, outreach tools, analytics, booking flow — "becomes a record, not an enforceable control." Consent must travel with the data and be checked at the point of use, not just at the point of capture.
Opt-outs raise the stakes further. Withdrawals must reach every connected system in real time; one-directional sync creates lag and audit inconsistencies. If a customer texts STOP and your booking tool sends a reminder three days later, the record of that opt-out exists — but it wasn't enforced where it counted. TCPA compliance guidance is explicit: honor opt-out requests immediately and include opt-out instructions in all applicable messages.
The cost of getting this wrong is real. GDPR enforcement alone has produced €5.88 billion in cumulative fines, and a recent German court ruling found that even having consent banners in place doesn't protect you if consent isn't actually enforced downstream.
Meanwhile, 75% of people say they've lost control over how companies use their data, according to Ethyca's analysis. That trust deficit means customers are watching how businesses handle their preferences — and a single unwanted message after an opt-out can end a relationship permanently.
This is why permission-based outreach has to be operational, not aspirational. At CallMyCustomers, every campaign runs only from lists of real customers, opt-outs are honored immediately, and the booking flow collects explicit consent — so the record and the practice match. Whether you run outreach in-house or through a partner, the standard is the same: consent isn't a checkbox you tick once. It's a living record you can defend.
The Legal Landscape Is Shifting: What the Fifth Circuit Ruling Means for Your Outreach
For over a decade, businesses running automated calling campaigns have treated written consent as non-negotiable. A February 2026 federal court ruling just cracked that assumption — but only in one corner of the country.
On February 25, 2026, the Fifth Circuit decided Bradford v. Sovereign Pest Control of TX, Inc., holding that the TCPA requires only "prior express consent" — oral or written — for automated or prerecorded telemarketing calls to cellphones. The court rejected the FCC's 2012 written-consent rule, relying on traditional statutory interpretation following the Supreme Court's 2024 Loper Bright decision.
What makes the case instructive is how consent was proven without a signature. The plaintiff had supplied his cellphone number in his service plan agreement, expressly authorized contact, engaged with the calls by scheduling inspections, and renewed his plan four times. That conduct was enough to establish consent, even absent any written opt-in.
Before you loosen your consent standards, though, consider the limits:
- The ruling binds only the Fifth Circuit — Texas, Louisiana, and Mississippi. Other circuits may still follow the FCC's written-consent framework.
- State telemarketing statutes may independently require written consent regardless of what the federal TCPA demands.
- The court also rejected the FCC's distinction between telemarketing and informational calls on the form of consent — but that, too, is circuit-limited.
- The FCC's global revocation rule has already been extended to January 31, 2027, signaling continued regulatory flux.
Holland & Knight attorneys caution that companies must still demonstrate "clear, direct and unequivocal consent," and that oral consent "should be carefully documented and independently verifiable to withstand future scrutiny." In other words, the ruling raises the bar on documentation even as it lowers it on format.
That documentation burden is where many businesses stumble. Enforcement is shifting from "did you collect consent?" to "can you prove how it was applied?" — with defensible records requiring when consent was given, what the user agreed to, and the context of collection, according to consent management analysis. GDPR enforcement alone has produced €5.88 billion in cumulative fines, a reminder of what weak consent records can cost.
For interstate marketers — which describes nearly every US service business with a customer list — the prudent path hasn't changed. Written, checkbox-based consent paired with clear disclosures remains the conservative, defensible standard. Carrier rules for business texting still expect explicit opt-in disclosures, opt-out instructions like "Reply STOP," and links to your Privacy Policy and Terms, as outlined in texting compliance guidance.
This is exactly why CallMyCustomers builds explicit consent collection into the booking flow and works only from lists of real customers. When every message is approved by the business owner before it sends and every opt-out is honored immediately, a shifting legal landscape becomes manageable rather than threatening.
The Bradford ruling could invite further challenges to FCC consent rules and may prompt the agency to reconsider its approach. Until the law settles nationally, treat oral consent as a fallback to document rigorously — not a strategy to build on.
Your Consent Compliance Playbook: Five Steps to Implement Today
Knowing the rules is only half the battle — the other half is building them into your daily operations. Here's a practical five-step playbook to turn consent requirements into a working system.
Step 1: Audit every opt-in touchpoint against the six-disclosure checklist. Walk through every place a customer hands you their phone number — booking forms, quote requests, intake paperwork, website pop-ups. Each one should disclose that the individual may receive texts, identify your business as the sender, include opt-out instructions like "Reply STOP," note that message and data rates may apply, and link to your Privacy Policy and Terms & Conditions, according to carrier-mandated texting compliance guidance.
Step 2: Add required checkboxes to booking and quote forms. Disclosure alone isn't enough. Best practice pairs every disclosure with an affirmative action, such as a required checkbox, so consent is explicit and documented rather than implied. An unchecked box that must be ticked before submission creates a clear record that the customer actively agreed.
Step 3: Document how and when each consent was obtained — and retain those records. Enforcement is shifting from "did you collect consent?" to "can you prove how it was applied?" As consent management research notes, defensible records include versioned consent states, the legal basis, and the context of collection. The stakes are real: GDPR enforcement alone has produced €5.88 billion in cumulative fines, and 75% of people say they've lost control over how companies use their data.
Step 4: Honor opt-outs immediately across all systems. A withdrawal that lives in one spreadsheet but not your CRM is a liability waiting to happen. Consent withdrawals must reach every connected system in real time — one-directional sync creates lag and audit inconsistencies. Build a single opt-out process that updates every list, tool, and pipeline the moment someone says stop.
Step 5: Keep written consent as your default standard. The Fifth Circuit's February 2026 ruling in Bradford v. Sovereign Pest Control held that the TCPA requires only "prior express consent" — oral or written — for telemarketing calls. But as Holland & Knight's legal analysis explains, the ruling applies only within that circuit, other courts may still follow the FCC's written-consent framework, and state statutes may still require written consent. Written, checkbox-based consent remains the conservative, defensible standard for any business operating across state lines.
Your quick-start checklist:
- Map every form, page, and script where customers share contact details
- Add the six required disclosures plus a mandatory checkbox to each
- Log the date, method, and exact language of every consent
- Sync opt-outs instantly across your CRM, booking, and messaging tools
- Re-audit quarterly as laws and carrier rules evolve
This is the same discipline CallMyCustomers builds into every reactivation campaign: explicit consent is collected in the booking flow before outreach begins, and opt-outs are honored immediately on every campaign — so your list stays clean, your customers stay respected, and your follow-up stays compliant.
Frequently Asked Questions
Isn't a customer's phone number on my booking form enough consent to text them?
What exactly has to be in my consent form or opt-in disclosure?
Can I just get verbal consent now that a court ruled written consent isn't required?
Do I need different consent for appointment reminders versus promotional texts?
What kind of consent records do I need to keep, and for how long should I track them?
What happens if a customer opts out but my other systems still message them?
Consent Done Right Is Revenue You Can Defend
Informed consent comes down to six disclosures at every opt-in touchpoint, an affirmative checkbox to make it explicit, and records detailed enough to prove what was agreed, when, and where — with opt-outs honored instantly across every system. Even as the Fifth Circuit relaxes the written-consent rule in its corner of the country, documented, checkbox-based consent remains the defensible standard for any business texting across state lines. And the stakes justify the discipline: GDPR enforcement alone has produced €5.88 billion in cumulative fines. The good news is that compliance and customer trust point the same direction — permissioned customers are the ones most likely to book again. Start by auditing your forms against the checklist, then re-audit quarterly. If you'd rather have it handled, CallMyCustomers builds explicit consent collection into the booking flow and honors every opt-out immediately — and the free list review shows you exactly what your customer list can produce before you spend a dollar.