
What is an example of written consent?
Key Facts
- Each individual text message can now count as a separate TCPA violation, with statutory damages of $500 per violation and up to $1,500 for willful violations according to recent research
- Consent records must be stored for at least four years after a subscriber’s last message or opt-out to comply with TCPA statute of limitations as stated in the research
- Under the FCC's 2025 'one-to-one' consent rule, businesses must obtain prior express written consent separately for each seller, invalidating broad pre-checked agreements per legal alerts
- A legally compliant written consent form must include sender identity, message types and frequency, cost disclaimer, opt-out instructions, and terms/privacy policy links based on Wonders & Worries' production-grade example
- Consent must be obtained voluntarily through an affirmative action like an unchecked checkbox, as pre-checked boxes fail TCPA scrutiny and 10DLC carrier vetting per SMS compliance best practices
- For dental, med spa, and clinic clients, CallMyCustomers operates under required privacy agreements including BAA/HIPAA, ensuring patient outreach meets clinical standards from the company's compliance section
- CallMyCustomers captures consent during booking or list review through unchecked checkboxes, ensuring voluntary agreement without pre-selection as described in their workflow
Why Generic Consent Forms Fail Under New TCPA Rules
Generic consent forms no longer meet the legal and carrier standards required for SMS marketing under updated TCPA rules, putting service businesses at significant risk. The FCC’s 2025 “one-to-one” consent rule now requires that prior express written consent be obtained separately for each seller, meaning businesses can no longer rely on broad, pre-checked agreements that cover multiple brands or lead generators. This change directly targets the resale of consumer data and invalidates vague consent methods that fail to specify exactly who is sending the message and for what purpose. As a result, service businesses using outdated forms may find their 10DLC registrations rejected or suspended by carriers during vetting, effectively blocking campaigns before they begin.
Each individual text message can now count as a separate TCPA violation, with statutory damages of $500 per violation and up to $1,500 for willful violations. Given that consent records must be stored for at least four years after a subscriber’s last message or opt-out, businesses using non-compliant methods face prolonged liability exposure. The burden of proof falls entirely on the sender—if a business cannot produce clear records showing what the consumer agreed to, when, and under what disclosures, courts and regulators treat consent as if it never existed. This message-by-message liability transforms what might have been a minor oversight into a potentially costly legal issue, especially for reactivation campaigns that rely on high-volume outreach.
To remain compliant, service businesses must upgrade their consent practices to include specific, unambiguous disclosures: sender identity, message types, frequency, cost disclaimer, opt-out instructions, and links to terms and privacy policies. Consent must be obtained voluntarily, without being tied to a purchase or service condition, and captured through an affirmative action like an unchecked checkbox or signature. CallMyCustomers integrates this standard into its booking flow for clients, ensuring explicit consent is collected before any outreach begins. By aligning with 10DLC carrier requirements and maintaining granular opt-out management per conversation, businesses can avoid campaign blocks, reduce legal risk, and build trust through permission-based messaging that respects customer preferences.
What a Legally Compliant Written Consent Form Must Include
A consent form that misses even one required disclosure can invalidate every message built on it. With TCPA statutory damages running $500 per violation—and up to $1,500 for willful violations, with each individual text counting separately—compliance analysts treat incomplete disclosure language as an existential risk, not a paperwork nitpick.
Seven elements make a written consent form legally compliant. Drawing on the production-grade Wonders & Worries SMS consent form and the Fransis.ai consent template, here is what each one requires:
- Sender identity — the exact business name the messages come from, so the consumer knows who is texting.
- Message types and frequency — what will be sent (reminders, promotions, follow-ups) and how often, or a statement that frequency varies.
- Cost disclaimer — the standard "message and data rates may apply" language, plus whether the business charges for messages.
- Opt-out and HELP instructions — accepted keywords like STOP, CANCEL, and UNSUBSCRIBE, plus a HELP keyword for assistance.
- Terms and privacy policy links — carriers actually read these before approving campaigns and reject those that disclose data selling.
The final two elements are voluntary agreement and record-keeping. Consent must be genuinely voluntary—never a condition of purchase—and captured through an affirmative action, since pre-checked boxes fail both TCPA scrutiny and 10DLC carrier vetting. Records must be retained for at least four years after a subscriber's last message, matching the federal statute of limitations for TCPA claims.
In practice, this is how a service like CallMyCustomers structures consent language when running reactivation campaigns for HVAC companies, dental spas, and med spas. A typical form for a dental spa client reads: "I agree to receive appointment reminders, treatment follow-ups, and occasional offers from [Business Name] at the number provided. Message frequency varies. Message and data rates may apply. Reply STOP to opt out; reply HELP for assistance. Terms and privacy policy at [link]. Consent is not a condition of purchase."
Two nuances matter for service businesses. Purely informational appointment reminders require only prior express consent, but the moment a reminder includes promotional content, written consent becomes mandatory. And under the FCC's 1-to-1 consent rule effective January 27, 2025, consent must name a single seller at a time—so the form must identify the client business specifically, not a lead generator or marketing partner.
The burden of proof always sits with the sender. If you cannot produce records showing what the person agreed to and when, regulators treat the consent as if it never existed.
How CallMyCustomers Builds Consent Into Its Reactivation Workflow
CallMyCustomers builds consent into every step of its reactivation workflow to ensure compliance and trust. The process begins with the client approving all scripts, offers, and messages before any outreach occurs, maintaining full control over what is communicated to their customers. This aligns with the company’s promise that clients "plan the campaign together, you sign off, we run it."
Consent is captured during booking or list review through unchecked checkboxes, ensuring voluntary agreement without pre-selection—a practice required under TCPA guidelines and 10DLC carrier vetting. For marketing messages, a double opt-in confirms the customer’s choice via text message, meeting the express written consent standard for SMS campaigns. This approach satisfies both legal requirements and carrier expectations, reducing the risk of campaign suspension due to unclear disclosure language.
All consent records are stored for at least four years after the subscriber’s last message or opt-out, in line with the TCPA statute of limitations. For dental, med spa, and clinic clients, this process operates under required privacy agreements including BAA/HIPAA, ensuring patient outreach meets clinical standards. The booking flow collects explicit consent, and opt-outs are honored immediately, reinforcing the permission-based, relationship-first approach that defines CallMyCustomers’ service.
Frequently Asked Questions
What makes a written consent form legally compliant for SMS marketing under TCPA rules?
Does CallMyCustomers use a specific written consent form example for clients like dental spas or HVAC businesses?
Why can't I use pre-checked boxes for SMS consent under the new TCPA rules?
How long must I keep records of customer consent for SMS messaging?
What happens if I send promotional texts without proper written consent?
Is verbal consent enough for sending marketing texts to customers?
Consent Done Right Is Revenue Done Safely
Written consent under the new TCPA rules comes down to a simple standard: name your business, disclose what you'll send and how often, include the cost disclaimer and opt-out instructions, link your terms and privacy policy, and capture a genuinely voluntary, affirmative opt-in—then keep the records for at least four years. Miss one element, and every message built on that form carries $500 in potential statutory damages, or up to $1,500 per willful violation, with each text counted separately. The good news is that compliance and good customer relationships point in the same direction: permission-based outreach to people who already know your business is both the safest and the most effective way to generate repeat revenue. Before your next reactivation campaign, audit your current consent language against the seven elements covered here—or skip the guesswork entirely. CallMyCustomers builds compliant consent collection into every campaign, with you approving every script, offer, and message before anything goes out. Start with a free list review to see what your customer list can produce—before you spend a dollar.