link arrow
Blog
SMS Marketing

Express written consent: TCPA rules and best practices

Inna Shevchenko
9 min read
September 8, 2026
salesmessage xsalesmessage facebooksalesmessage linkedin
Express written consent: TCPA rules and best practices
Start Texting Today

Lets us show you the power of Salesmsg to change your business

Express written consent is proof, not a checkbox. In U.S. marketing, the FCC's 2012 TCPA changes turned consent into a documented, auditable record, not a loose permission someone gave on a phone call or in passing, per CompliancePoint's overview of express written consent. That shift is why revenue teams, not just legal teams, need to care about how consent is captured, stored, versioned, and suppressed across systems. If your workflow can't show the exact disclosure, the signature event, and the phone number tied to the opt-in, you don't really have a defensible consent process.

What express written consent really requires

The biggest mistake teams make is treating express written consent like a vague "yes." It is a written agreement with a consumer's signature or valid electronic equivalent, tied to clear authorization for prerecorded or autodialed marketing calls or texts to a specific number. That is a much higher standard than casual permission, and it is why a sloppy intake form can create more risk than no form at all.

Why the 2012 FCC change matters

The FCC's 2012 amendments tightened the evidentiary standard for marketing outreach, especially for SMS and autodialed voice campaigns. The disclosure must be clear and conspicuous, and it must say that consent is not a condition of purchase. The operational problem is not just writing the words correctly, it is preserving the exact language shown at the moment the consumer opted in.

Many systems still fail here. A CRM field that says "opted in" is not the same thing as a durable consent artifact. A defensible workflow treats consent as evidence, not preference, because the record has to show what the consumer saw, when they saw it, and how they signaled agreement.

Practical rule: if you can't reproduce the disclosure and the signature event later, your consent record is too weak to rely on.

For teams sending texts at scale, the mechanics matter just as much as the wording. The Salesmessage guide on SMS opt-in examples to stay compliant is useful when you need to see how compliant language looks in a real form or message flow.

Required elements for valid express written consent

Valid consent has to do more than look official. It has to give the consumer a real choice, identify who's asking, and make the opt-in easy to prove later. If any one part is vague or bundled, the whole record gets weaker.

A graphic illustration detailing the four key requirements for obtaining valid express written consent from a consumer.

The disclosure has to be clear

The language has to be clear and conspicuous, and it must identify the seller or brand, explain what type of messages the consumer is agreeing to, and say that consent isn't required to buy, per CompliancePoint. If the disclosure is buried below the submit button, wrapped in unrelated terms, or written in legal jargon, you're making proof harder than it needs to be.

The signature has to be active

Electronic consent is acceptable, but only when it behaves like a real signature workflow. That can include checking a box, clicking a button, or typing a name when the process aligns with e-signature rules, per ActiveProspect. A pre-checked box doesn't show affirmative action, and a passive page view doesn't show agreement.

The opt-in has to point to one seller and one interaction

Recent FCC-aligned summaries say consent for marketing calls and texts needs to be obtained one seller at a time and logically tied to the interaction that produced it, per Nelson Mullins. That creates a real compliance burden for lead-gen pages, partner forms, and marketplace experiences where multiple brands might want access to the same consumer. A clean form structure beats a bundled one every time.

For SMS teams, the practical version of this is simple. The SMS compliance for marketing and sales guide shows why the safest opt-in language is the one that names the business, defines the message type, and keeps purchase consent separate from marketing consent.

Implementation test: if a rep, auditor, or regulator can't tell exactly which brand the consumer opted into, the form is too ambiguous.

How consent requirements differ across legal contexts

This phrase looks uniform, but the legal meaning changes by context. A marketing team, a hospital, and a research institution may all talk about "written consent," yet they're solving different problems and answering to different regulators. Reusing one template across those environments is where teams get burned.

Legal framework
Primary use case
Required elements
Key differences
TCPA
Marketing calls and texts
Written agreement, signature, clear disclosure, specific seller, purchase not required
Focuses on telemarketing and autodialed or prerecorded outreach
HHS Common Rule
Federally regulated research
Legally effective informed consent, IRB waiver possible, form includes approximate number of subjects, per HHS
Centers on voluntary participation and research disclosure
GDPR
Personal data processing
Controller identity, purpose, data type, withdrawal rights, automated decision-making info, transfer-risk info when relevant, per EDPB guidelines
Consent must be specific to each processing purpose
CASL
Canadian express consent requests
Clear purpose, requester identity, third-party identification, other prescribed info, per CASL
Emphasizes requester transparency and plain-language purpose
FERPA
Education record disclosure
Signed and dated consent, records specified, purpose stated, recipient identified, per FERPA
Protects education records, not marketing outreach

Why one template fails in practice

The marketing version has to be specific about the seller and the message class. The research version has to support voluntary participation and disclosure of study details. The GDPR version has to spell out purpose and withdrawal rights. Those are not interchangeable requirements, even when a vendor tries to package them as one consent screen.

Healthcare teams feel this most acutely. The health care SMS guide is relevant because patient messaging can involve operational reminders, privacy-sensitive data, and different consent expectations than marketing.

The safest cross-border approach is to design separate workflows for SMS, clinical intake, research enrollment, and education-record access, then keep each proof set in its own compliance lane.

Examples of acceptable expressed written consent

Compliant consent usually looks boring, and that's a good thing. The best examples are plain, traceable, and hard to misread later. They don't depend on someone remembering what they meant, they leave an auditable trail.

Web forms with an unchecked box

A well-built web form puts the disclosure near the submit action, uses an unchecked checkbox, and names the sender clearly. The consumer has to actively select the box, which gives you a record of affirmative action. A passive visit to the page doesn't count.

Text-based opt-ins with confirmation

Text-to-join flows can work when the first message is paired with a clear disclosure and the consumer then confirms the subscription. That second step matters because it produces a stronger event trail than a loose keyword alone. It's especially useful when you want the record to show a deliberate reply tied to a specific number.

E-signature and checkout flows

For higher-stakes transactions, e-signature platforms and checkout pages can capture written consent cleanly if they keep the disclosure separate from unrelated terms. The record should show who agreed, what they saw, and when they acted. That's the difference between a legally useful artifact and a noisy form submission.

The one thing these examples share is specificity. The platform, message type, number, and timestamp all matter. If any of those are missing, the record becomes harder to defend.

Building consent as an auditable data workflow

Consent stops being a compliance headache when it's treated like data engineering. The right structure is a versioned event log, not a single CRM checkbox, because the business needs to know what was agreed to, when it changed, and when outreach must stop. That mindset also helps when legal or marketing teams update the language later.

A diagram illustrating a four-step auditable consent workflow from data capture to final audit for compliance.

What to store

At minimum, consent records should separate the lawful basis, the purpose, the withdrawal status, and the proof-of-consent metadata. You also want the exact disclosure text shown at capture time, the signatory's phone number, and evidence of the signature event. Without those fields, your team can't show what the consumer agreed to.

How the workflow should behave

The record should be durable enough to support disputes and suppression decisions. If a consumer revokes consent, downstream systems need to stop outreach immediately and keep that revocation visible across sales and marketing tools. That's where a static field fails and an event log wins.

For archive and traceability, sales teams often pair capture with retrieval workflows. The Salesmessage article on search and archive text messages is a helpful model for thinking about how messaging evidence should remain searchable and reviewable.

What makes the audit trail useful

A good audit trail makes it easy to answer three questions fast. What did the consumer see, what did they do, and what happened after that? If your team can't answer those without digging through screenshots and inbox threads, the workflow isn't mature enough.

Operational takeaway: consent should move like any other governed record, captured once, versioned over time, and accessible when a dispute lands.

How messaging platforms automate consent capture and storage

The operational problem is not getting a yes once. It is capturing that yes in a form a team can prove later, then keeping it attached to the contact record as messages move through sales and service. Messaging platforms help by logging the disclosure shown at capture time, tying it to the phone number and signature event, and syncing the result into CRM timelines so reps are not reconciling opt-ins by hand. That reduces the number of places where consent can drift out of sync, which matters when one missed field can turn a clean record into a weak one.

What automation should do

The workflow has to record the opt-in artifact, timestamp the event, and preserve the message context that produced it. It also has to attach the exact disclosure text, because a consent record without version history leaves your team guessing about what the consumer saw. When revocation happens, the platform should suppress outreach immediately and keep that suppression visible across campaigns, inboxes, and sequences. Salesmsg SMS workflows are relevant here because automation only helps when consent capture, routing, and suppression stay in the same path.

Where Salesmsg fits

Salesmsg is one platform that embeds two-way SMS, MMS, and voice into CRM workflows, with automatic logging, double opt-in support, and opt-out handling. That matters because consent evidence and message history stay in the same operational path instead of being split across spreadsheets and separate databases.

The practical trade-off is simple. If your stack records the conversation but not the consent event, your team still has to reconstruct the record later. If it records both and keeps them searchable, review gets faster and suppression decisions are easier to defend. Without that capability, the tool functions only as a messaging layer rather than compliance infrastructure.

Common consent mistakes and how to avoid them

Most consent failures are predictable. Teams either make the opt-in too passive, make the disclosure too vague, or fail to keep the evidence in a form they can retrieve later. Those are process problems, not mystery events.

  • Pre-checked boxes: they don't show affirmative action. Use an unchecked box or a deliberate click instead.
  • Bundled disclosures: if consent sits inside unrelated terms, the opt-in becomes harder to defend. Separate the marketing language from the purchase flow.
  • Missing disclosure versioning: if you don't store the exact text shown at capture time, you can't prove what the consumer saw.
  • No revocation tracking: consent has to be reversible in the workflow, not just in policy language.
  • One template for every legal regime: TCPA, GDPR, FERPA, CASL, and research consent each ask for different information.

The fix is usually structural, not cosmetic. Put consent in a dedicated workflow, keep the artifacts attached to the contact record, and make suppression immediate when a revocation lands. That's what turns consent from a checkbox into an operational control.

FAQ

Is it "express" or "expressed" written consent? The legally correct term under TCPA is "express written consent." "Expressed" is a common variation people search and say, but the FCC's own rule language uses "express."

What makes written consent "express" instead of implied? Express consent requires an affirmative, documented action, a signature or clear electronic equivalent, tied to a specific disclosure. Implied consent is inferred from context and does not meet the TCPA bar for marketing calls or texts.

Does a pre-checked box count as express written consent? No. A pre-checked box does not show affirmative action from the consumer, which is a core requirement.

Can one consent form cover multiple brands or sellers? No. Consent must be tied to one seller and one interaction at a time under current FCC guidance.

How long should a business keep consent records? There is no single federal retention period specified in TCPA itself, so businesses should retain records for as long as they might need to defend a complaint, and align with their platform's audit log retention.

Does Salesmsg store proof of consent? Salesmsg logs opt-in and opt-out events alongside message history, so consent evidence and conversation history stay in the same record.

Is express written consent required for every text message? It is required specifically for marketing calls and texts sent using an autodialer or prerecorded voice. Purely transactional or informational messages have different, often lighter requirements.

Salesmsg helps teams capture, log, and act on consent inside the same messaging workflow they already use for sales and service. If you need SMS and calling that keep opt-ins, opt-outs, and conversation history tied together, visit Salesmsg and see how it fits into a compliance-minded revenue operation.

Hey! I’m Inna, Marketing Lead at Salesmsg. Content is my focus, I dive into the strategies and stories that help businesses connect with their audience. From SMS campaigns to messaging that resonates, I share insights that drive engagement and results.

Inna Shevchenko
Hey! I’m Inna, Marketing Lead at Salesmsg. Content is my focus, I dive into the strategies and stories that help businesses connect with their audience. From SMS campaigns to messaging that resonates, I share insights that drive engagement and results.

What text leads around the world

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

5-star rating
1,500+ reviews with an average of 4.7/5 stars

Experience Seamless Business Texting & Calling

Get started today and see how Salesmsg can transform your business and bring you closer to your customers.