ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Consent for Text Messaging

How should consent be obtained?

Back to InsightsHow should consent be obtained?

How should consent be obtained?

Key Facts

  • TCPA violations can cost $500 to $1,500 per message, per class member, with no need to prove injury according to BCLP legal analysis
  • Using purchased lead lists assumes consent that doesn't transfer, as consent is single-use and cannot be shared across businesses or campaigns per Forbes Tech Council
  • Pre-checked opt-in boxes are invalid; valid consent requires an unchecked box and an affirmative action like checking it or texting a keyword as stated by TermsFeed
  • Businesses must disclose message frequency (typically 2–4 promotional texts per month) at opt-in for compliance per Text-Em-All guidance
  • Consent records must be kept for at least four years, even after a customer opts out, to defend against TCPA claims per Quo's consent framework
  • Adding promotional content to a service text converts the entire message into marketing, requiring separate marketing consent as clarified by Quo
  • Double opt-in strengthens proof of consent by requiring two separate actions, reducing errors and accidental signups per TermsFeed best practices

A single promotional text sent to the wrong person can cost you $1,500. Multiply that by a few hundred messages on a purchased lead list, and an "efficient" marketing shortcut becomes a lawsuit that threatens the business itself.

The most common trap is assuming transactional consent covers marketing. If a customer gave you their number for an order confirmation, delivery update, or appointment reminder, that's transactional consent only — it does not extend to promotional messages, according to compliance guidance from Text-Em-All. Worse, A2P 10DLC analysis shows that adding even a line of promotional content to a service text converts the entire message into marketing — which then requires marketing consent you never collected.

Purchased lead lists create the same liability at scale. As Textdrip founder Phil Portman puts it, "Purchased lead lists inherit every consent defect of whoever collected them." The person on that list agreed to hear from someone else — not from you — and consent is single-use only, meaning it cannot be transferred to different campaigns, phone numbers, or businesses, per Quo's consent guidance.

Pre-checked boxes fail for the same reason. The checkbox must be unchecked by default; valid consent requires an affirmative action like checking the box or texting a keyword. Anything inferred from passive behavior doesn't count.

The financial stakes are steep. TCPA violations carry $500 to $1,500 per violation, per class member, with no requirement to prove actual injury, as BCLP's legal analysis explains. Willful or knowing violations draw the higher fines. And the burden of proof sits entirely with the business: if you can't document when, how, and what the customer agreed to, you lose by default.

Three habits create immediate TCPA exposure:

  • Texting promotions to customers who only consented to order or appointment updates
  • Buying lead lists and assuming the original collector's consent transfers to you
  • Using pre-checked opt-in boxes instead of affirmative, documented sign-ups

The fix is unglamorous but simple: collect explicit consent at the moment of contact, document it with timestamps and the exact disclosure language shown, and keep records for at least four years. That's why systems like CallMyLeads build consent collection directly into the booking flow — every lead that comes in gets a fast response, and that response starts from a documented, affirmative opt-in rather than an assumption. A smaller list of people who actually want your texts beats a huge list of people who never asked.

Getting consent right isn't a formality — it's the difference between a compliant text program and fines of $500 to $1,500 per message under the TCPA. Here's what valid consent actually looks like.

For promotional texts sent using automated technology, the legal standard is prior express written consent, obtained in advance through an explicit act of agreement, as TermsFeed explains. Electronic signatures count — a website form, email, text message, or telephone keypress all qualify under the E-SIGN Act. But courts have found voice recordings no longer sufficient for "written" consent, so paper trails matter.

Consent cannot be inferred from passive behavior. Pre-checked boxes are invalid: the checkbox must be unchecked by default, and the customer must take an affirmative action — checking the box or texting a keyword — to opt in. Text-Em-All's guidance is blunt on this point: "The checkbox must be unchecked by default. Customers must take an affirmative action to opt in."

At the point of opt-in, the law requires clear and conspicuous disclosures. Quo's consent framework and TermsFeed agree on the core elements:

  • Message frequency — tell people roughly how often texts will arrive (2–4 promotional texts per month is a typical benchmark).
  • A "message and data rates may apply" disclosure.
  • A statement that consent is not a condition of purchase — making opt-in mandatory to buy is illegal.
  • Clear opt-out instructions, such as "Reply STOP to cancel" and "Text HELP for help."

Consent must also be channel- and campaign-specific. Implied consent — say, from a delivery update or a live conversation — covers only that context, and adding promotional content to a service text converts the entire message into marketing that requires marketing consent. As Quo puts it, "You cannot transfer customer consent to different SMS campaigns or phone numbers."

Finally, document everything. Keep records of the date, time, method, phone number, and exact disclosure language shown — for at least four years, and even after someone opts out. For businesses like CallMyLeads that handle lead response and appointment booking at scale, building consent capture into the booking flow itself is the simplest way to make proof automatic rather than an afterthought.

One caveat: a February 2026 Fifth Circuit ruling held that oral consent can suffice within that jurisdiction. But legal analysis of the decision urges caution — other circuits and state statutes may still require written consent, so documented written consent remains the safest nationwide standard.

Getting consent right isn't just about checking a legal box — it's about being able to prove, years later, exactly what a customer agreed to and when. TCPA violations run $500 to $1,500 per message, and compliance experts are blunt about why documentation matters: if you can't prove a customer agreed to hear from you, you can't defend yourself.

The most reliable collection methods fall into three categories, each with its own proof requirements:

  • Web form opt-in — Use an unchecked checkbox (pre-checked boxes are invalid), display all required disclosures, and consider double opt-in, where the customer confirms with a "YES" reply before messages begin.
  • Text-to-join keywords — Advertise a keyword (e.g., "Text HVAC to 55555"), state where customers will see it, and include legal disclosures in the confirmation message.
  • Paper forms — Best for brick-and-mortar businesses; photograph or scan each signed form so you have a digital record.

Double opt-in deserves special attention. As SMS compliance guidance explains, it reduces typos, wrong numbers, and accidental signups — and it gives you stronger proof because the customer took two separate actions. It may lower conversion slightly, but the trade-off is worth it in higher-risk industries.

Whatever method you use, proper documentation means recording the timestamp, the method of consent, and the exact disclosure language the customer saw. CTIA guidelines go further, recommending you log the campaign type, phone number, customer name, and IP address where applicable.

Retain those records for at least four years — even after someone opts out. Consent records should outlast the relationship, and consent itself is single-use: you can't transfer it to a different campaign or phone number without fresh permission.

This is why a compliance-first approach to lead response matters. When every booking flow collects explicit consent before automated follow-up begins — the way CallMyLeads builds it into each response sequence — speed and legality stop competing with each other. Your leads get answered in seconds, and every message traces back to a documented, provable yes.

Frequently Asked Questions

Can I text promotions to customers who gave me their phone number for order updates?
No — that's transactional consent only, and it doesn't extend to promotional messages. Even adding one line of promotional content to a service text converts the entire message into marketing, which requires marketing consent you never collected, per Text-Em-All's compliance guidance.
Can I use a pre-checked opt-in box on my web form?
No. The checkbox must be unchecked by default, and the customer must take an affirmative action — checking the box or texting a keyword — for consent to be valid. Anything inferred from passive behavior doesn't count under TCPA rules.
Is it legal to buy a lead list and text everyone on it?
No. Purchased lead lists inherit every consent defect of whoever collected them — the person agreed to hear from someone else, not from you. Consent is single-use only and cannot be transferred to different campaigns, phone numbers, or businesses, per Quo's consent guidance.
What disclosures do I need to show when someone opts in to my texts?
You need message frequency (2–4 promotional texts per month is a typical benchmark), a "message and data rates may apply" disclosure, a statement that consent is not a condition of purchase, and clear opt-out instructions like "Reply STOP to cancel." Making opt-in mandatory to buy from you is illegal, per TermsFeed's consent guide.
How much can texting someone without proper consent actually cost me?
TCPA violations carry $500 to $1,500 per violation, per class member, with no requirement to prove actual injury — and willful or knowing violations draw the higher fines, according to BCLP's legal analysis. The burden of proof sits entirely with you, so if you can't document what the customer agreed to, you lose by default.
How long do I need to keep consent records, and what should they include?
Keep records for at least four years — even after someone opts out. CTIA guidelines recommend logging the date, time, method of opt-in, campaign type, phone number, customer name, and IP address where applicable, per Quo's consent guidance. This is why CallMyLeads builds consent capture directly into the booking flow, so every message traces back to a documented, provable yes.

The Cheapest Insurance Your Text Program Will Ever Buy

Consent isn't paperwork — it's the difference between a text program that grows your business and one that costs you $500 to $1,500 per message under the TCPA. The rules are clear: get an affirmative opt-in with an unchecked box or keyword, show the required disclosures up front, never assume a transactional text covers promotions, skip purchased lists, and document the date, method, and exact language shown — for at least four years, as SMS compliance guidance recommends. A smaller list of people who actually want your texts will always beat a huge list of people who never asked. Your next step: audit your current opt-in forms against the disclosure checklist above, then make proof automatic — CallMyLeads builds consent capture into every booking flow, so every fast response starts from a documented, provable yes. Stop paying for leads you never get to talk to, and start texting people who actually want to hear from you.

Build My Lead Response Plan

Get lead response tips that actually work