Business texting works - and that's exactly why regulators and plaintiffs' attorneys are paying attention to it. Most organizations sending SMS today couldn't produce a defensible consent record in under ten minutes if asked. That's the gap Jeff Pulver's SMS Compliance Masterclass was built to close: a session featuring attorneys Sara Jodka and Glenn Richards of Dickinson Wright on the legal landscape, with our own team joining to walk through what compliance actually looks like inside a texting operation, day to day.
If you missed the live session, you can watch the recording below, along with a recap of the key takeaways and a checklist you can use to evaluate your own program.
(Zoominar hosted on July 22, 2026 by Jeff Pulver)
Consent Fundamentals
Texting is regulated differently than voice calling. The FCC has largely taken a hands-off approach to SMS, leaving much of the day-to-day governance to carrier guidelines (the CTIA messaging guidelines) rather than a dense rulebook like the one that governs robocalls. That doesn't mean texting is unregulated - it means the two laws that do apply carry real weight: the Telephone Consumer Protection Act (TCPA) and the Telemarketing Sales Rule (TSR).
The TCPA draws a critical line between two types of consent:
- Prior Express Consent — the lower bar, sufficient for purely informational messages like shipping updates, appointment reminders, or account alerts. This consent can be oral, written, or even implied simply by a customer providing their phone number.
- Prior Express Written Consent — required for marketing and promotional messages sent via automated technology. This is a meaningfully higher standard: a signed agreement (digital signatures count), specifying the exact number being texted, confirming consent isn't a condition of purchase, and written in clear, conspicuous, plain language.
Under the TCPA, "telemarketing" isn't limited to phone calls - it's a regulatory classification that applies to texts too. If a message mixes informational content with any promotional language, the FCC classifies the entire message as telemarketing, regardless of channel, which triggers the higher written-consent standard.
What a defensible consent record contains:
- What the contact agreed to
- Who the contact is
- How and where they opted in
- A timestamp.
Web forms with clear disclosure language are broadly accepted, and text-to-join (double opt-in) flows have a structural advantage — the opt-in keyword itself functions as a legally recognized signature under e-signature law, so there's less ambiguity to defend later.
Content, Timing, and Targeting Rules
A few operational details separate a compliant texting program from one that's exposed:
Quiet hours: Messages generally can't go out before 8 a.m. or after 9 p.m. in the recipient's local time zone. Area codes are an unreliable proxy for where someone actually is. A New York area code doesn't guarantee the recipient is in New York. Many compliance-conscious teams solve this with a "hyper-restrictive" sending window designed to work across every U.S. time zone at once, rather than trying to track each contact's precise location.
Consent revocation. Opting out isn't limited to the word "STOP." Reasonable revocation now includes "quit," "end," "cancel," "unsubscribe," and similar variations — and reader technology has to be sophisticated enough to catch intent, including misspellings, not just a fixed list of keywords.
Vertical-specific overlays. Debt collection, healthcare, financial services, and nonprofit messaging all carry additional rules layered on top of the baseline TCPA/TSR framework. A compliant approach for one vertical can be a violation in another — treating all messaging as if one-size-fits-all is one of the more common gaps our panel sees.
Why TCPA Litigation Risk Keeps Climbing
As Sara Jodka of Dickinson Wright, whose practice focuses on TCPA litigation, laid out during the session, the dollars-and-cents case for why plaintiff's firms pursue these claims aggressively is stark: a single flawed campaign of 250,000 texts, at $500 in statutory damages per violation, works out to $125 million in exposure before the TCPA's triple-damages provision is even applied. There's no statutory cap, and, notably, no requirement to prove actual harm.
Even a landmark 2021 defense-favorable ruling narrowing what counts as "automated technology" didn't slow claims down, Jodka noted. If anything, claims accelerated afterward, as plaintiff's firms shifted strategy: filing under state-level laws with similar protections, or finding new angles as AI and pre-recorded technology entered the picture.
The four fact patterns responsible for the bulk of claims:
- Consent gaps: Having consent for one message type (like order updates) doesn't extend to marketing messages, and proving a vendor sending on your behalf had valid consent is its own burden you carry.
- Missed or mishandled opt-outs: Once someone opts out, every message sent after the grace window closes is treated as a new, separate violation.
- Quiet hours violations: Especially where time zone is inferred from area code rather than verified.
- Evolving "automated technology" theories: As courts extend scrutiny to AI-assisted messaging and pre-recorded content.
The throughline across all four: the burden of proof sits with the business, not the plaintiff. If you can't produce a clean, timestamped consent record when asked, that's the gap a claim will exploit.
Operationalizing Compliance: A Practical Checklist
Understanding the rules is step one. Building a system that enforces them without relying on every employee memorizing every nuance is step two. Here's the operational checklist our panel walked through:
Get and prove consent
Consent records are captured automatically at the point of opt-in, source, method, and timestamp included
Text-to-join or web form workflows are used, not manual spreadsheets
Consent for different message types (informational vs. marketing vs. AI processing) is tracked separately, not bundled together
Honor opt-outs immediately
Broad keyword detection catches "stop," "cancel," "unsubscribe," and reasonable variations, not just an exact-match list
Send restrictions apply the moment an opt-out is received, not after a multi-day delay
Opt-outs received through any channel (call, email, in-thread) flow into one centralized record
Respect timing
Sending windows account for every time zone your contact list touches
Where possible, you're tracking a contact's actual preferred hours rather than inferring from area code alone
Control content by vertical and channel
Marketing templates and automations are built or reviewed by someone current on the relevant rules
Regulated verticals (healthcare, financial services, debt collection) have their own compliance layer, tracked separately from general 10DLC consent
Prove it later
Audit trail records are immutable and can't be edited after the fact
Retention period matches your actual legal exposure window (many compliance teams default to 5 years, given TCPA and TSR statutes of limitations)
Records can be exported or shared with outside counsel if a claim arises
How Beetexting Supports Compliance at Every Layer
Every requirement covered above (consent tracking, opt-out handling, quiet hours, vertical-specific rules, and audit trails) is easier to maintain when your texting platform is built to enforce it automatically, rather than relying on manual processes.
Here's what that looks like inside Beetexting:
- Consent capture and tracking. Every opt-in is logged with source, method, and timestamp, and consent for informational versus marketing messages is tracked separately, so you're never guessing which standard applies to a given contact.
- Automatic opt-out enforcement. Broad keyword detection catches "stop," "cancel," "unsubscribe," and common variations, and enforcement applies immediately.
- Time-zone-aware sending. Messages respect quiet hours across every time zone your contact list touches.
- Vertical-specific compliance tooling. Purpose-built controls for regulated industries like healthcare, home care, financial services, and behavioral health, so your program reflects the overlay rules that apply to your specific vertical, not just a generic baseline.
- Immutable audit trails. Every consent record and message log is retained and exportable, so if a claim ever arises, you can produce documentation quickly instead of scrambling to reconstruct it.
None of this replaces legal counsel, but it does mean the operational side of compliance, the part that's actually enforceable day to day, isn't left to chance. See how Beetexting's AI-powered compliance works.
What Next?
Compliance is also what protects SMS as a channel over the long run. Email lost a lot of its power to spam: average email open rates now hover around 20%, a direct result of inboxes being flooded for years with irrelevant, unwanted messages. SMS still holds a 98% open rate today because it hasn't gone down that same path, and staying that way depends on every business sending texts treating consent and relevance as non-negotiable.
These guidelines are designed to make sure your program can prove it did things right, if it's ever asked to. The businesses that hold up best under scrutiny aren't the ones with perfect knowledge of every rule; they're the ones with systems that don't depend on that knowledge to stay compliant.
Want to see how this works in practice? Schedule a demo with our team to learn how Beetexting's compliance tooling automatically handles consent tracking, quiet hours, and audit trails.
