ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

When should we obtain consent?

Back to InsightsWhen should we obtain consent?

When should we obtain consent?

Key Facts

Most service businesses don't ignore consent rules on purpose — they just assume an old invoice or a service call from two years ago covers them today. It doesn't. Consent must be secured before any outbound call or text goes out, not after the phone starts ringing, according to TCPA compliance guidance. The law draws a bright line: prior express consent for informational messages, prior express written consent for marketing outreach using autodialers or texts, and the clock starts before the first dial.

Reactivating a dormant customer list without verifying when and how consent was captured is the compliance equivalent of driving without insurance. TCPA violations carry statutory damages of $500–$1,500 per violation with no cap on total penalties, and lawsuits can reach back four years, as noted by Drips' regulatory overview. The largest TCPA award on record hit $925 million, a figure that should pause any business planning a "quick blast" to old contacts.

  • Informational texts (appointment reminders, service confirmations) require prior express consent — verbal or voluntarily provided number
  • Marketing texts and autodialed calls require prior express written consent with clear disclosure that consent isn't a condition of purchase
  • Manually dialed sales calls may rely on prior express invitation or permission
  • Consent records must be retained for at least four years to match the TCPA statute of limitations

The stakes escalate further on April 11, 2025, when the FCC's new Opt-Out Rule takes effect, requiring businesses to honor revocation requests within 10 business days and accept opt-outs "in any reasonable manner" — not just "Reply STOP," per BCLP's analysis. A single clarification text is permitted within five minutes of an opt-out, but it cannot contain marketing content. CallMyCustomers builds consent verification into every campaign setup, reviewing lists, segmenting by recency and source, and securing client approval on every script before outreach begins — because the cost of getting it wrong isn't theoretical.

Not every message you send to a customer carries the same legal weight — and treating a promotional text like a routine appointment reminder is one of the fastest ways to trigger TCPA liability. The level of consent you need depends on what you're saying and how you're saying it.

For purely informational or transactional messages — appointment reminders, service confirmations, delivery notifications — prior express consent (PEC) is generally sufficient. Verbal consent or a customer voluntarily providing their phone number can qualify. But the moment your message becomes promotional, the bar rises sharply.

Marketing calls and texts made using autodialers or prerecorded voices require prior express written consent (PEWC) — a signed agreement that clearly authorizes telemarketing messages, with disclosure that consent is not a condition of purchase. The same split applies to SMS: marketing texts demand written consent, while informational texts may proceed on PEC under certain conditions. The stakes are real — TCPA violations carry statutory damages of $500 to $1,500 per message, with no cap on total penalties.

Here is the practical framework, matched to message type:

  • Informational messages (reminders, confirmations): PEC — verbal consent or voluntary number provision suffices.
  • Marketing calls and texts (autodialed or prerecorded): PEWC — clear, unambiguous, documented in writing.
  • Manually dialed sales calls: prior express invitation or permission — no written agreement required.
  • SMS marketing: PEWC, with consent language retained as proof.

The landscape grew more complicated when the Fifth Circuit ruled that the TCPA does not require written consent for automated or prerecorded telemarketing calls to cellphones, holding that "prior express consent" may be given orally or in writing. Most circuits still follow the FCC's written-consent standard, creating a fragmented regulatory map where the rules differ depending on where your customer — and your court — sits.

The Fifth Circuit itself cautioned that consent must still be "clear, direct and unequivocal," and that oral consent "should be carefully documented and independently verifiable to withstand future scrutiny." In other words, even where oral consent might survive a challenge, proving it after the fact is the hard part. Independent proof is your strongest defense — and since TCPA lawsuits can reach back four years, consent records should be retained for at least that long.

This fragmentation is why documented written consent remains the safest standard everywhere. It is also why permission-based outreach — the approach CallMyCustomers takes with every reactivation campaign, working only from lists of real customers with consent captured at booking — protects you regardless of which circuit your customers live in. Written consent doesn't just meet the strictest current standard; it future-proofs your outreach against the next ruling.

Getting consent right the first time is only half the job. Since April 11, 2025, the FCC's new TCPA Opt-Out Rule has fundamentally changed what happens when a customer changes their mind — and the penalties for getting it wrong start at $500 per message and climb from there.

Under the new rule, consumers can revoke consent "in any reasonable manner" — a text saying "no more texts," a verbal request on a call, even "I'm not Mary." According to legal analysis from BCLP, businesses can no longer prescribe an exclusive opt-out method, and relying on keyword prompts like "Reply STOP to end" is now risky. Compliance guidance from Drips recommends treating almost any expression of refusal as a valid opt-out.

Once a revocation request arrives, the clock starts ticking. Businesses must honor it within 10 business days, and the rules around follow-up are unusually strict:

  • Only one clarification message is permitted after a revocation request
  • That message must be sent within five minutes of the opt-out
  • It cannot contain any marketing content whatsoever
  • Opt-out records should be retained for at least four years, matching the TCPA's statute of limitations

The stakes are real. TCPA violations carry statutory damages of $500 to $1,500 per violation with no cap on total penalties, and the largest damages award ever reached $925 million, as Drips reports. ActiveProspect's compliance analysis adds that lawsuits can reach back four years — meaning today's sloppy opt-out handling becomes tomorrow's class action.

But the smartest businesses treat revocation as a last resort rather than a workflow. The better strategy is preventing opt-outs before they happen — reaching out with something the customer actually wants, at a moment when it feels useful rather than pushy. That's the philosophy behind CallMyCustomers' campaign approach: reconnecting past customers around a genuine reason — a seasonal service need, an old quote, a renewal window — so the message lands as a service, not an interruption.

Timing matters here too. Bluecore's customer data shows repeat shoppers spend close to 3x more than new shoppers, and at-risk outreach works best when triggered at intervals that match each customer's natural buying cadence. When outreach is well-timed and permission-based, revocation rarely enters the picture — and the relationship, along with the revenue, stays intact.

Knowing when to obtain consent is only half the equation — the other half is proving you did, long after the conversation ends. With TCPA lawsuits reaching back four years and statutory damages of $500 to $1,500 per violation, your consent records are often the only thing standing between you and a costly claim, according to compliance guidance from ActiveProspect.

A valid consent record needs to tell the full story of how permission was granted. Legal experts recommend documenting five elements for every consent event:

  • The exact consent language shown to the customer at the moment of opt-in
  • A timestamp of when consent was given
  • The URL or platform where collection occurred
  • Evidence of human interaction — bot-submitted leads mean no valid consent
  • The form fields the customer actually submitted

Retain these records for at least four years, aligning with the TCPA's statute of limitations. As one compliance maxim puts it, "independent proof is your strongest defense." A fragmented consent system invites mistakes, so centralize documentation rather than scattering it across booking tools, spreadsheets, and inboxes.

The best moment to obtain consent is when the customer is already engaged — during a booking flow, a quote request, or a service agreement. This is why explicit consent captured during scheduling matters so much: it feels like a natural part of doing business, not a legal hurdle.

Remember that consent type depends on the message. Prior express consent suffices for transactional messages like appointment reminders, while marketing texts demand prior express written consent with clear, conspicuous disclosure — including a statement that consent is not a condition of purchase.

Even well-documented consent can't rescue a campaign the customer never approved. That's why a consent-first process should end with a human gatekeeper: the business owner reviews and signs off on every script, offer, and message before outreach begins. At CallMyCustomers, this sign-off step is built into the process — the campaign is planned together, the owner approves it, and only then does outreach run.

This proactive posture also protects consent itself. As Drips notes, the best strategy is stopping outreach at the right time so customers never feel the need to revoke consent in the first place. And with the FCC's Opt-Out Rule now in effect — requiring opt-outs to be honored within 10 business days and accepted in "any reasonable manner" — respectful, permission-based outreach is the only sustainable approach.

Frequently Asked Questions

Can I text or call customers from an old invoice or service call from a couple of years ago?
Not without verifying when and how consent was originally captured. Consent must be secured before any outbound call or text goes out, and TCPA lawsuits can reach back four years with statutory damages of $500–$1,500 per violation and no cap on total penalties. Before reactivating a dormant list, segment it by recency and confirm how consent was captured at the original booking.
What's the difference between consent for appointment reminders versus marketing texts?
Informational or transactional messages like appointment reminders and service confirmations only require prior express consent — verbal consent or a customer voluntarily providing their number can qualify. Marketing texts and autodialed or prerecorded calls require prior express written consent that clearly authorizes telemarketing, with disclosure that consent is not a condition of purchase.
How much could a TCPA violation actually cost my business?
TCPA violations carry statutory damages of $500–$1,500 per violation with no cap on total penalties, and claimants don't need to prove actual injury. The largest TCPA damages award on record reached $925 million, and lawsuits can reach back four years — so a "quick blast" to an old list can become a class action.
Do customers have to text "STOP" to opt out, or can they revoke consent some other way?
Since April 11, 2025, the FCC's Opt-Out Rule requires businesses to accept revocation "in any reasonable manner" — a text saying "no more texts," a verbal request on a call, even "I'm not Mary." You must honor the request within 10 business days, and relying solely on keyword prompts like "Reply STOP" is now risky.
Can I send a follow-up message after someone opts out to confirm or clarify?
Yes, but only once. A single clarification message is permitted after a revocation request, it must be sent within five minutes of the opt-out, and it cannot contain any marketing content whatsoever. Beyond that, almost any expression of refusal should be treated as a valid opt-out, with records retained for at least four years.
What documentation should I keep to prove consent if we're ever sued?
For every consent event, document the exact consent language shown, a timestamp, the URL or platform where it was collected, evidence of human (not bot) interaction, and the form fields the customer submitted. Retain these records for at least four years to match the TCPA's statute of limitations — independent proof is your strongest defense. Centralize documentation rather than scattering it across booking tools, spreadsheets, and inboxes.

Turn Consent Compliance Into Your Competitive Edge

Getting consent right isn't just about avoiding fines — it's about building trust that turns past customers into reliable revenue. As we've seen, timing, documentation, and message type all determine whether your outreach strengthens relationships or risks costly TCPA violations, especially with the FCC's stricter opt-out rules now in effect. The good news? A permission-first approach doesn't just keep you compliant — it makes your reactivation efforts feel helpful, not pushy, increasing the chance customers actually engage. CallMyCustomers helps service businesses navigate this by reviewing lists, securing proper consent, and running every campaign only after you approve the script — so your outreach lands as a service, not a interruption. Ready to reconnect with customers who already know your business? Start with a free list review to see what your past clients are worth.

Stay in the Loop