Arrow Left Back to blog

TCPA Compliance in 2026: What Every SMS/MMS Marketer Needs to Know

Textmunication Team
Calendar September 15, 2026
5 min read
TCPA Compliance in 2026: What Every SMS/MMS Marketer Needs to Know

The Telephone Consumer Protection Act (TCPA) is the law that governs commercial text messaging in the United States. Violate it — even accidentally — and you're looking at $500 per text for negligent violations and $1,500 per text for willful violations.

For a brand sending to 50,000 subscribers without proper consent, that's a $25 million to $75 million exposure. TCPA class actions have hit major retailers, banks, and healthcare companies with eight-figure settlements.

Here's what you need to know to run a compliant SMS/MMS program in 2026.

What Changed in 2026

The FCC's 2024 one-to-one consent rule took full effect in 2026. Under the old rules, a single consent checkbox could authorize messages from multiple companies in a marketing network. That loophole is closed. Now:

Consent must be one-to-one. Each company sending marketing texts needs its own explicit consent from each subscriber. You cannot purchase a list and claim another company's consent covers your messages.

Lead generators must name the seller. If you collect SMS/MMS opt-ins on behalf of a third party, that third party must be specifically identified at the point of consent — not buried in a privacy policy.

Comparison shopping sites face new rules. Sites that collect opt-ins and resell them to multiple vendors must obtain separate consent for each vendor.

The Four Pillars of TCPA Compliance

1. Prior Express Written Consent

For marketing texts (promotional, sales, offers), you need prior express written consent. This means:

The consumer must affirmatively opt in — no pre-checked boxes, no implied consent. The opt-in must clearly disclose that they'll receive recurring automated marketing messages. The opt-in must include your company name, message frequency, "message and data rates may apply," and opt-out instructions. You must retain proof of consent — timestamp, IP address, source URL, and the exact language shown to the subscriber.

2. Proper Identification

Every marketing text must identify who is sending it. "Text STOP to stop" alone is not enough — your brand name must appear in the message or be established by the sending number's context.

3. Opt-Out Honoring

When a subscriber texts STOP, UNSUBSCRIBE, CANCEL, END, or QUIT — you must honor it immediately. Under TCPA, you have one more message allowance: a confirmation that they've been removed. After that, silence. Any message sent to an opted-out subscriber is a violation.

4. Time Restrictions

Marketing texts are only permitted between 8 AM and 9 PM in the recipient's local time zone. If your subscriber list spans time zones, your sending platform must handle time zone-aware scheduling — or you risk violating this rule at scale.

What Counts as an SMS/MMS "Marketing" Message

Transactional messages — order confirmations, shipping alerts, appointment reminders — have a lower consent standard (prior express consent, not written). But the line between transactional and marketing is frequently litigated.

A shipping confirmation is transactional. A shipping confirmation that includes a coupon for your next order is marketing. When in doubt, apply the higher consent standard.

Building a Bulletproof Opt-In Flow

Your opt-in language should look like this: "By entering your phone number and clicking Subscribe, you agree to receive recurring automated marketing SMS/MMS messages from [Brand Name] at the number provided. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe, HELP for help. Privacy Policy: [URL]"

What to avoid: opt-in language that buries the SMS/MMS disclosure in a wall of text, pre-checked consent boxes, consent collected via a third-party form you don't control, and any opt-in flow that doesn't capture the exact disclosure shown to the subscriber.

10DLC and TCPA: How They Interact

10DLC (10-digit long code) registration is a carrier-level requirement separate from TCPA. But they're connected: if your 10DLC campaign description doesn't match your actual message content, carriers may filter your messages. More importantly, carriers can flag non-compliant opt-in practices during the review process.

Running a clean TCPA-compliant opt-in program also helps your 10DLC vetting scores — carriers reward senders who demonstrate proper consent practices.

The Cost of Getting It Wrong

TCPA class actions don't just go after obvious bad actors. They target brands with technical violations: a pre-checked opt-in box, a missing opt-out disclosure, a message sent at 9:05 PM. Plaintiffs' firms specialize in this, and they are actively looking for violations.

The math is brutal: 10,000 subscribers with a technical consent defect × $500 minimum per violation = $5 million floor exposure before litigation costs.

→ Not sure if your current opt-in flow is TCPA-compliant? Book a free compliance review — we'll audit your consent language and list management before it becomes a problem.

Follow Textmunication