ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Consent for Text Messaging

What is the difference between written and informed consent?

Back to InsightsWhat is the difference between written and informed consent?

What is the difference between written and informed consent?

Key Facts

  • One text sent without proper consent can cost $500, rising to $1,500 per message if a court finds the violation was willful according to TCPA penalty guidelines.
  • The largest TCPA damages award in history reached $925 million, a figure large enough to end most businesses outright per TCPA compliance records.
  • Written consent is only legally valid if it was also informed — meaning clear disclosures that consent isn't a condition of purchase, message rates may apply, and how to opt out as required by TCPA rules.
  • Pre-ticked checkboxes invalidate consent because they are not an express act by the customer per SMS marketing compliance analysis.
  • The FCC's 2024 order requires businesses to honor opt-out requests within 10 business days, effective April 11, 2025, and to accept revocation in any reasonable manner under new revocation rules.
  • After an opt-out, a one-time confirmation text is allowed only if sent within five minutes and contains zero marketing content per FCC confirmation message rules.
  • Marketing texts require prior express written consent, while transactional messages like appointment reminders need only prior express consent if they contain no promotional content under the two-tier consent standard.

One text message sent without proper consent can cost you $500. And if a court decides you knew better, that number jumps to $1,500 — per message, with no ceiling on the total.

That's not a hypothetical risk. Under the Telephone Consumer Protection Act (TCPA), penalties run $500 to $1,500 for every violating text, and customers can sue businesses directly without waiting for a regulator to act. The largest TCPA damages award in history reached $925 million — a number large enough to end most businesses outright.

Here's where the written-versus-informed distinction stops being academic. A signed form sitting in your files doesn't protect you if the person who signed it never actually understood what they were agreeing to. Legal compliance analysis is blunt on this point: "written" consent is only valid if it was also informed, meaning it came with clear disclosures that consent isn't a condition of purchase, that message and data rates may apply, and how to opt out.

The details that sink businesses are usually small ones:

  • A pre-ticked checkbox, which courts don't count as an "express" act by the customer
  • Consent language buried in fine print instead of being clear and conspicuous
  • No record of what the person agreed to receive, or when they agreed
  • Opt-out requests phrased casually — "no more texts!" — that went ignored because they didn't match a keyword

And the rules keep moving. The FCC's 2024 order requires businesses to honor consent revocation requests within 10 business days, effective April 11, 2025, and to accept revocation in "any reasonable manner." Even a single confirmation text after opt-out must go out within five minutes and contain zero marketing content.

For businesses that text leads and customers every day — appointment reminders, follow-ups, booking confirmations — the cost of confusing written and informed consent compounds fast. A hundred marketing texts sent on a technically invalid opt-in is a $50,000 exposure at the low end, before attorney fees.

This is why consent handling can't be an afterthought bolted onto your follow-up process. Services like CallMyLeads treat it as part of the pipeline itself: the booking flow collects explicit consent, opt-outs are honored immediately and automatically, and every plan includes compliance with consent and quiet-hours rules built in. Speed-to-lead only pays off when the texts behind it are legally sound — otherwise every second you save on response time just accelerates your liability.

Many businesses assume that getting a signature or checking a box is enough to legally text customers. But under the TCPA, written consent only holds up if it was also informed — meaning the person truly understood what they were agreeing to before they clicked or signed. This distinction isn’t just semantic; it’s the difference between compliance and costly violations.

Written consent refers to a documented, signature-equivalent act of agreement — such as an unchecked checkbox on a web form, a keyword opt-in via text, or a telephone keypress — that satisfies the E-SIGN Act’s definition of a signature according to legal guidance. Informed consent, by contrast, is the process of ensuring the person knows exactly what they’re opting into: the purpose of the messages, how often they’ll be sent, that consent isn’t a condition of purchase, potential message and data rates, and clear opt-out instructions as noted in healthcare compliance resources. Without this understanding layer, even a perfectly documented signature may not hold up in court.

The TCPA treats these two concepts as interdependent: a “written” consent is legally invalid if it wasn’t preceded by clear and conspicuous disclosures that make it informed per terms of service analyses. For example, a pre-ticked checkbox fails because it’s not an express act by the user, and burying opt-out instructions in fine print undermines informed agreement — both can void consent regardless of how well it’s documented as highlighted in marketing law breakdowns. This is why CallMyLeads builds disclosure and opt-in clarity into every lead response flow, ensuring consent is both captured and understood before any message is sent.

  • TCPA violations carry penalties of $500–$1,500 per text message, with no cap on total liability — the largest award ever was $925 million according to TCPA compliance guides.
  • Valid consent requires upfront disclosure that signing up is not a condition of purchase, that message/data rates apply, and how to opt out — such as “Text STOP to opt-out” per SMS marketing legal resources.
  • Written consent can be collected electronically via web forms, text messages, or keypresses under the E-SIGN Act, but voice recordings alone are often insufficient without supporting documentation as clarified in compliance analyses.

For businesses using automated texting — whether for lead follow-up, appointment reminders, or missed call recovery — treating written and informed consent as separate steps creates risk. The safest approach is to combine them: document the agreement with a signature-equivalent action, but only after delivering the disclosures needed for true understanding. This two-part standard isn’t just legally sound; it builds trust by showing leads you respect their autonomy from the very first interaction.

What makes a written consent actually informed is the presence of clear, upfront disclosures that ensure the individual truly understands what they’re agreeing to. Under the TCPA, consent is not legally valid unless it includes specific information presented before the opt-in occurs. This includes stating clearly that consent is not a condition of purchase, disclosing that message and data rates may apply, specifying the expected frequency of messages, and providing straightforward opt-out instructions such as “Text STOP to opt-out” according to industry guidance. These elements transform a simple signature or checkbox into a meaningful, informed agreement.

Without these disclosures, even a documented consent can be deemed invalid, exposing businesses to significant risk. TCPA violations carry penalties of $500 to $1,500 per text message, with no cap on total liability, and the largest damages award in TCPA history reached $925 million based on legal analyses. For businesses using automated texting — such as those relying on AI-driven lead response and appointment setting — ensuring informed consent isn’t just ethical; it’s a critical safeguard against costly litigation and reputational harm.

Several common practices undermine the validity of consent, even when a form or signature is present. Pre-ticked checkboxes, for example, do not constitute express consent because they reflect no active choice by the user as compliance experts note. Similarly, relying solely on voice recordings without accompanying disclosures and a retainable record fails to meet the E-SIGN Act standards required for written consent per regulatory interpretations. Additionally, businesses must recognize the two-tier consent standard: marketing texts require prior express written consent, while transactional messages like appointment reminders and confirmations need only prior express consent, provided they contain no promotional content as clarified in TCPA guidance.

For services like CallMyLeads, which automate lead response and booking workflows via text, this distinction is operational. While appointment confirmations and reminders may operate under the lower threshold of prior express consent, any promotional follow-up or upsell message triggered by lead engagement demands the full informed written consent process. Getting this right means building trust from the first interaction — ensuring every message sent is not only compliant but welcomed.

Opt-Outs, Revocation, and the Rules That Changed in 2025

Opting out of business texts just got simpler—and stricter—under new FCC rules taking effect April 11, 2025. Companies must now honor any reasonable revocation request within 10 business days, whether it’s a standard “STOP” reply or a phrase like “no more texts!” or “I’m not Mary.” Industry guidance confirms that relying solely on keyword prompts is risky; businesses should treat varied opt-out language as valid to avoid TCPA penalties of $500–$1,500 per violating message. This shift means consent management systems need flexibility to interpret intent, not just match exact words.

After an opt-out, businesses may send a one-time confirmation text—but only if it meets strict criteria. The message must be delivered within five minutes, contain zero promotional content, and serve solely to confirm the opt-out was processed. Legal analyses note this narrow allowance prevents abuse while giving consumers clarity. For a service like CallMyLeads, which handles appointment booking and lead nurture via SMS, this means configuring automated flows to respect revocation instantly while staying compliant with confirmation-message limits.

  • Honor revocation requests across all systems within 10 business days
  • Accept any reasonable opt-out phrasing—not just predefined keywords
  • Send one confirmation text max, within five minutes, with no marketing content

Meanwhile, the FCC’s controversial one-to-one consent rule—originally set to require consent for only one identified seller at a time—faces a contested legal status. While it was slated to take effect January 27, 2025, one source reports the Eleventh Circuit Court of Appeals struck it down before implementation. Despite this, bundled consent obtained through lead generators remains high-risk unless the specific brand is clearly named at opt-in. Businesses using multi-seller lead sources should proceed cautiously, as regulatory uncertainty doesn’t erase liability for improper consent collection under the TCPA.

A compliant consent flow isn’t just about checking a box—it’s about timing, transparency, and trust. Start by ensuring consent is collected with an unchecked checkbox or clear opt-in action during your booking flow, never pre-ticked, because a pre-populated box invalidates express consent under TCPA rules. Pair that action with conspicuous disclosures: state the purpose of messaging, frequency, that consent isn’t a condition of purchase, and include opt-out instructions like “Text STOP to opt-out”—this satisfies both the written and informed consent requirements, as valid consent must be both documented and understood.

Timestamp every consent record with the date, time, and specifics of what the lead agreed to receive, creating an auditable trail that supports both compliance and 10DLC registration, which requires organizations to detail how phone numbers and consent were obtained. Store these records securely and accessibly, as they’re your defense if consent is ever challenged—TCPA violations can carry penalties of $500–$1,500 per message, with no cap on total liability, making documentation non-negotiable.

Honor opt-outs immediately and automatically across all systems, accepting non-standard phrases like “no more texts!” as valid revocation requests, and if you send a confirmation message after opt-out, ensure it’s delivered within five minutes and contains zero marketing content. This aligns with the FCC’s 2024 revocation rules effective April 11, 2025, which require honoring consent withdrawal within 10 business days.

  • Use unchecked checkboxes or web forms during lead capture to collect express written consent
  • Precede opt-in with clear disclosures on purpose, frequency, costs, and opt-out methods
  • Store timestamped consent details including what was agreed to and when
  • Honor opt-outs automatically within 10 business days, accepting varied phrasing
  • Ensure 10DLC registration reflects your actual consent collection process

CallMyLeads builds this compliance into its done-for-you flow: explicit consent is gathered in the booking process, opt-outs are honored instantly and automatically, and first replies happen in seconds—keeping you fast, compliant, and in control of your lead data.

Frequently Asked Questions

Is a signed consent form enough to legally text my customers?
No. Under the TCPA, written consent is only legally valid if it was also informed — meaning the person saw clear disclosures before opting in, including that consent isn't a condition of purchase, that message and data rates may apply, and how to opt out. A signature without that understanding can still expose you to $500–$1,500 in penalties per text message.
Does written consent have to be on paper, or can it be electronic?
Electronic works. Under the E-SIGN Act, a "signature" can include a website form, text message opt-in, or telephone keypress. However, voice recordings alone are often insufficient for written consent — they can only serve as supporting evidence if the process included proper disclosures and a retainable record.
Why is a pre-ticked checkbox considered invalid consent?
Courts don't count a pre-populated box as an "express" act by the customer, since it requires no active choice. To be valid, the checkbox must be unchecked and paired with clear, conspicuous disclosures about what the person is agreeing to receive, according to legal compliance guidance.
Do appointment reminders need the same consent as marketing texts?
No — there's a two-tier standard. Marketing texts sent via automated systems require prior express written consent, while transactional messages like appointment reminders and confirmations need only prior express consent, as long as they contain no promotional content. The catch: any upsell or promotional follow-up triggered by a booking demands the full informed written consent process.
If someone texts "no more texts!" instead of "STOP," do I have to honor it?
Yes, treat it as a valid opt-out. Under FCC rules effective April 11, 2025, businesses must honor revocation requests made in "any reasonable manner" within 10 business days — not just exact keywords. Relying solely on keyword matching is risky because each violating text carries $500–$1,500 in penalties with no cap on total liability.
Can I send a confirmation text after someone opts out?
Yes, but only one — and it must be sent within five minutes of the opt-out and contain zero marketing content. This narrow allowance exists to confirm the opt-out was processed, and anything promotional in that message can trigger TCPA penalties of $500–$1,500 per message.

The Bottom Line: A Signature Isn't a Shield

The difference between written and informed consent comes down to this: a documented agreement only protects you if the person signing it actually understood what they were agreeing to. Under the TCPA, a checkbox without clear disclosures — purpose, frequency, costs, and how to opt out — isn't valid consent, and penalties run $500 to $1,500 per text with no cap on total liability. Add the FCC's 2025 revocation rules, and the margin for error keeps shrinking. Your next steps are straightforward: audit your opt-in forms for pre-ticked boxes and buried fine print, timestamp every consent record, and make sure opt-outs are honored instantly — even when phrased casually. If your team texts leads daily and this feels like a lot to manage, CallMyLeads builds consent collection, instant opt-out handling, and quiet-hours compliance directly into its lead response and booking flows. Want to see how fast, compliant lead follow-up works? Book a free 15-minute scoping call and find out how every lead gets answered in seconds — legally.

Build My Lead Response Plan

Get lead response tips that actually work