TCPA Texting Rules and Consent Requirements

You send a quick text to fifty customers about a weekend sale. One recipient forwards your message to a class-action attorney. Three months later, you're facing a lawsuit that could cost more than your annual revenue. The Telephone Consumer Protection Act—TCPA—is the federal law that governs how businesses communicate with customers by text message, and it applies to every text you send—shipping alerts, promotional discounts, appointment reminders. Congress passed TCPA in 1991 to protect consumers from unwanted calls and messages, and the Federal Communications Commission has updated the rules repeatedly to cover modern SMS marketing and transactional messaging.

The penalties for violating TCPA are blunt and expensive: $500 to $1,500 per text. And those fines multiply fast when you're sending bulk messages.
A single campaign to three hundred customers without proper consent can become a six-figure liability overnight. TCPA violations are one of the most frequently litigated areas of consumer protection law, and class-action lawsuits are common because the statutory damages add up quickly across large recipient lists.

Small businesses face the same exposure as national brands. The statute doesn't distinguish between a mailbox center sending fifty texts and a retailer sending fifty thousand—the per-message penalty is identical, and a single plaintiff's attorney can turn a compliance mistake into a lawsuit that threatens your business. Understanding TCPA text message compliance requirements isn't optional paperwork; it's the foundation of legally texting your customers.

Written Consent Requirements

Before you send a single promotional text, TCPA requires that you collect prior express written consent from the customer. That's not a suggestion or a best practice—it's a federal requirement, and it's more specific than most business owners realize. How to get TCPA consent for texting starts with written documentation: a signature, a web form submission, or an email record that clearly shows the customer agreed to receive text messages from your business.

Here's where many small centers stumble. A customer who bought something from you has not given consent to text them. A phone number in your point-of-sale system is not permission to send updates. Even verbal consent—"Sure, text me when it arrives"—falls short of TCPA's standard.

The law requires consent to be specific, voluntary, and documented in a way that proves the customer knew what they were agreeing to and did so affirmatively.

What Compliant Consent Looks Like

Compliant consent language is clear and separate, not buried in the fine print of your terms of service. A good example: "By checking this box and submitting this form, I agree to receive promotional and transactional text messages from [Your Business Name] at the mobile number provided. Message and data rates may apply. I can opt out at any time by replying STOP." That checkbox or signature field must be unchecked by default—pre-checked boxes don't count as affirmative consent.

You can collect this consent on paper (a sign-up sheet at the counter with the language printed above the signature line), through a web form on your site, or via email confirmation. What matters is that the record is clear, dated, and tied to the specific phone number. If a regulator or plaintiff's lawyer asks for proof three years from now, you need to produce it.

Why Documentation Protects You

Documentation is your proof that consent was freely given. Without it, you're defending a TCPA claim with nothing but your memory of a conversation. Each undocumented text is a separate violation, and at hundreds or thousands of dollars per message, the risk compounds quickly. Proper written consent—collected upfront, stored systematically—stops violations before they start.

Smartphone on desk beside notepad representing professional customer text messaging
Getting written consent means documenting customer permission before your first text message.

Consent Collection Mechanics

Now that you understand what consent is, here's where to collect it and how to phrase it. The most practical points are your checkout counter, online signup forms, printed invoices with an opt-in box, and customer account creation screens. Each of these moments is a natural place to ask for permission before you hit send on that first promotional text.

Your consent language should call out texting by name and state why you're messaging. A compliant example: "I agree to receive text messages from [Your Business Name] at this phone number, including promotional offers, order confirmations, and service alerts. Message frequency varies. Reply STOP to opt out. Message and data rates may apply." That sentence covers purpose, frequency, and opt-out—everything TCPA texting rules and consent standards require.

Store each consent record alongside the customer's phone number and timestamp in your CRM or spreadsheet. This audit trail proves you had permission if a complaint ever arrives, turning consent from an abstract legal concept into a retrievable, dated file you can pull in five seconds.

Consent Documentation Gaps

A handshake and a "sure, you can text me" at the counter feel like consent—but in court, verbal-only agreements leave you without proof. Text confirmations of verbal consent are marginally better, but plaintiffs' attorneys still attack them as after-the-fact constructions. Written consent captured at the moment of agreement is what holds up under scrutiny.

The simplest path is to screenshot consent forms or store them in a system tied directly to the customer record—your point-of-sale platform, CRM, or contact database. If a regulator or attorney requests proof, you need to produce the exact consent language the customer saw, along with metadata.

For each customer, document the date consent was granted, the method (web form, paper signature, email reply), and the exact wording the customer agreed to. This metadata is what regulators and legal teams inspect first when auditing TCPA consent best practices.

Opt-Out Mechanisms and Handling

Once you have consent to text a customer, the law gives them an absolute right to revoke it—and your obligation to honor that request immediately. TCPA requires every marketing or informational text to include clear, easy opt-out instructions, almost always in the form of "Reply STOP to unsubscribe" or similar language. Text message opt-out handling requirements are non-negotiable: if a customer sends STOP, END, CANCEL, UNSUBSCRIBE, or any other recognized opt-out keyword, you must remove them from all future texting campaigns on the spot.

Processing opt-outs manually is where many small businesses run into trouble. A customer texts STOP at 3 p.m. on a Friday, and the owner forgets to pull them from the weekend promotion list. One more text goes out Saturday morning, and that single message is a separate TCPA violation—one that regularly triggers class-action lawsuits.

The legal standard is strict: immediate means immediate, not "when we get to it."
If your texting system doesn't automatically remove opt-outs and suppress future sends, you're relying on perfect human memory under deadline pressure, and that's a liability waiting to happen.

Tracking opt-outs is just as important as collecting consent in the first place. Your customer database should flag opted-out contacts so they never receive another text, even if a staff member rebuilds a campaign list from scratch months later. Automated platforms handle this by maintaining a suppression list that cross-checks every outbound message; manual systems require a clear process—spreadsheet flags, CRM tags, whatever works—and regular audits. The consequence for missing an opt-out isn't a warning or a do-over. It's $500 to $1,500 per message, and when one plaintiff's attorney finds a pattern, it becomes a class action that can include hundreds of customers who opted out and were texted again. Maintaining clear opt-out mechanisms is the second core practice that protects businesses from the most common, most preventable TCPA violation.

Smartphone resting face-down on desk beside laptop in minimalist workspace with natural lighting
Respecting customer preferences means building opt-out processes that are just as easy as opting in.

Documentation and Audit Trail

Consent and opt-outs mean very little if you cannot prove they happened. In any TCPA dispute—whether a customer complaint, a regulatory inquiry, or a class-action lawsuit—the burden of proof rests on the business. Without documentation, violations are presumed, and defenses collapse. A paper trail is not administrative overhead; it's your legal shield.

Build that trail by keeping three categories of records tied to each customer:

  • consent records (the signed form, web checkbox, or email where the customer agreed to receive texts)
  • opt-out logs (the date, time, and method of every opt-out request you receive)
  • texting activity (send dates, times, message content, and recipient phone numbers)
Store these records in a way that links them to the individual customer—spreadsheets work, but a purpose-built CRM or compliance platform is safer and searchable. Every text you send should have a matching record you can retrieve in under a minute.

Run a September 2026 Audit

Before the Q4 sales push begins, conduct a compliance audit to catch gaps while you still have time to fix them. Set aside an hour in mid-September and work through this checklist: verify that every customer in your texting list has a dated, retrievable consent record; confirm that your opt-out mechanism is functioning and that opt-out requests are logged with timestamps; review a sample of recent messages to confirm opt-out language appears in every text; and test your opt-out process by sending a STOP reply from a test number to confirm it processes immediately.

Quarterly audits—or at minimum, a pre-season review—turn compliance from a hope into a habit. If a regulator or plaintiff's attorney asks for your records, you hand them over with confidence, not panic.

Workspace desk with coffee cup, blank papers, and office supplies in soft natural lighting
Proper documentation practices protect your business when customer communication questions arise.

September Compliance Checklist

Before the Q4 rush begins, spend an hour or two this September auditing your text-message compliance systems. Small gaps caught now are easier to fix than lawsuits filed later. Here's a simple five-step checklist to safeguard your business before holiday volume hits.

  1. Step 1: Audit consent records. Pull a sample of customer files and verify that consent is documented in writing with dates. If you find verbal agreements or missing records, those customers need re-consent before you send another text.
  2. Step 2: Test your opt-out system. Send a STOP request to your own business number and confirm removal from send lists within minutes. If the system requires manual action or takes hours, fix that process.
  3. Step 3: Review message templates. Check that every text includes opt-out language and clearly identifies your business and message purpose. Ambiguous or missing language is a violation waiting to happen.
  4. Step 4: Verify record storage. Confirm that consent forms, opt-out logs, and message history are stored together by customer and backed up.
  5. Step 5: Document gaps. Write down what's missing or broken, assign owners, and set a fix-by date before October.

How PortPuffin Protects Your Business

Manual consent tracking and opt-out management work until they don't—and the moment they fail, you're exposed to per-message penalties that can end your business. PortPuffin's AI receptionist handles TCPA compliance automatically, from logging consent with timestamps to processing opt-outs in real time and suppressing contacts across every message you send.

Every customer interaction flows into a single record that includes consent status, opt-out history, and message logs. You don't hunt through spreadsheets or worry that a staff member forgot to update the list. PortPuffin's system flags non-compliant sends before they go out, maintains audit-ready documentation, and gives you one-click access to proof of consent for any customer, any time.

If you're running text campaigns manually or patching together tools that weren't built for compliance, you're taking on risk that doesn't scale. PortPuffin was built to handle the compliance burden so you can focus on running your business—not defending it in court.

Start your free trial today and protect your business from TCPA liability. Visit PortPuffin.com to see how automated compliance works in practice, or schedule a demo to walk through consent tracking, opt-out handling, and audit trails built for small businesses that text customers.