A client asked us last year why her appointment reminders had stopped going out. Nothing had changed on her end. No error message, no bounce, no billing problem. The texts simply were not arriving, and nobody on her staff could explain it. She had assumed texting worked like email: type, send, done.
It does not. Business texting runs on private infrastructure owned by the wireless carriers, and it is governed by both carrier rules and federal regulators. This article is general information, not legal advice. We are an IT company, not a law firm, and nothing here is a substitute for talking to your own attorney. What we can do is explain the landscape in plain terms so you know what questions to ask your messaging provider and your counsel.
This Is a Real, Enforced Area
Think of email as a public sidewalk and text messaging as a shopping mall. Both are places you can talk to customers. Only one of them is privately owned, and the owner sets the rules about who can set up a booth.
Two groups have a say here. The wireless carriers run the network and decide what traffic they carry. Federal regulators, principally the Federal Communications Commission, set consumer protection rules covering calls and texts. Neither side is theoretical. The carrier side is quieter and faster: your messages just stop arriving, often with no explanation, which is exactly what happened to our client.
The industry association CTIA publishes guidance for message senders, and its Messaging Principles and Best Practices, updated in 2023, is a useful window into how carriers think. It notes that individual service providers “may adopt additional Consumer protection measures for Non-Consumer Message Senders, which may include, for example, campaign pre-approval, Service Provider vetting, in-market audits, or Unwanted Message filtering practices.”
Registration Generally Comes Before Sending
Here is the concept that catches most small businesses off guard. Before you send business texts from a standard phone number, you are generally expected to register: to tell the ecosystem who your business is and what kind of messages you intend to send. Your provider may call this brand and campaign registration, or use shorthand for it in their documentation.
The point of registration is accountability. Unregistered traffic is the easiest thing for a carrier to filter, because it looks like the traffic everyone wants blocked. Registering does not make you immune from filtering. It makes you identifiable, which is a prerequisite for being trusted.
We are deliberately not printing specific requirements, timelines, or fees, because carriers and vendors set those and they change. Ask your provider directly: what registration do we need, what information will you need from us, what does it cost, and how long does approval take. Get it in writing. Then ask your attorney whether your particular use case needs a closer look.
What Consent Actually Means
This is where good faith businesses get into trouble, because the intuitive answer is wrong. Having someone’s phone number is not consent. An existing customer relationship is not automatically consent to text them whatever you like.
CTIA’s 2023 guidance describes tiers rather than a single yes or no. It states that message senders are expected to “obtain a Consumer’s consent to receive messages generally” and to “obtain a Consumer’s express written consent to specifically receive marketing messages.” It treats a consumer who starts the conversation differently: “if the Consumer initiates the text message exchange and the Non-Consumer only responds with relevant information, then no verbal or written permission is expected.”
Translated into how a business actually operates:
- A customer texting you first is a conversation. Replying with relevant information is the easy case.
- Operational messages sit in the middle. Appointment reminders and service notifications generally call for the customer to have agreed to receive them.
- Marketing is the strictest tier. Promotions and offers sit at the express written consent end of the scale.
- Consent is specific, not general. CTIA’s guidance says a consumer opt-in “should not be transferable or assignable” and “should apply only to the campaign(s) and specific Message Sender for which it was intended or obtained.” Agreeing to reminders is not agreeing to a monthly newsletter.
- Borrowed lists are a dead end. The same guidance states senders “should not use opt-in lists that have been rented, sold, or shared” and “should create and vet their own opt-in lists.”
Opt-Outs Are the Bright Line
If you take one operational lesson from this article, make it this one. Honoring opt-outs is the least ambiguous obligation in the space, and the easiest to fail by accident.
The FCC announced in January 2024 that it had adopted rules confirming consumers may revoke consent in “any reasonable manner that clearly expresses a desire not to receive further calls or text messages,” including reply words such as stop, quit, end, revoke, opt out, cancel, and unsubscribe. The Commission stated that “the consumer is not limited to using only a revocation method that the caller has established,” and that senders “may not designate an exclusive means to request revocation of consents.” It also said revocation requests must be honored as soon as practicable and no longer than ten business days from receipt.
CTIA’s 2023 guidance makes a related point, noting that while standardized STOP wording should be used in opt-out instructions, requests using normal language such as end, unsubscribe, cancel, quit, or “please opt me out” should also be read and acted upon. In practice, someone needs to watch the inbox, because customers do not type the magic word. They type “take me off this list please.”
Keep the Receipts
Consent you cannot prove is consent you do not have, at least not in any conversation that matters later. CTIA’s 2023 guidance lists what to retain, including the timestamp of consent, the medium used to capture it, the specific campaign it was provided for, the phone number, and the identity of the person who consented.
None of that requires special software. It requires that consent be captured through a system rather than a conversation, so the record exists without anyone remembering to create it. Building the process once beats reconstructing it under pressure, the same argument we make in why saving time takes priority over saving money.
The Personal Phone Problem
Somewhere in your business, an employee is texting customers from their own phone. It started because it was convenient. It is now a business process nobody designed.
That creates two problems. The compliance one: no record of consent, no reliable way to honor an opt-out across the company, no visibility into what was promised to whom. The continuity one is just as serious. When that employee leaves, the relationship leaves with them. The history is gone, customers keep texting a number you do not control, and a former employee walks out with a live channel to your client list. This is exactly the kind of predictable failure we argue for planning around in the cloud can go down and what that means for your business.
The Bottom Line
Business texting works well when it is set up deliberately: registered with your provider, consent captured through a system, opt-outs honored quickly and broadly, and messages sent from a business-owned number rather than somebody’s personal phone. Done that way it is one of the best channels a small business has. Done casually, it quietly stops working and creates exposure nobody was tracking.
To repeat what we said at the top: this article is general information, not legal advice. Requirements in this area are set by carriers and regulators and they change. Confirm the current requirements with your messaging provider, and talk to your own attorney about how they apply to your business.
We help small and mid-sized businesses across Denton County choose messaging platforms, get texting off personal phones, and build consent capture into the systems they already use. Contact us today.
Sources:
Comments are closed