avatar

Jacob Morrow

Updated: 2026-09-11

17 min read

SMS compliance means meeting the laws, carrier requirements, and internal controls that govern who you can text, what you can send, when you can send it, and how recipients can opt out. For global campaigns, start with the recipient's destination and message purpose, then verify consent, sender route, local timing, withdrawal, suppression, and the evidence you will retain.

Part 1: What Is SMS Compliance? The Three Layers You Must Pass

Think of compliance as three separate layers. A campaign can pass a carrier or platform review and still fail the legal test, while a lawful message can still be filtered when the sender or route is not approved.

Compliance layer What it controls Examples Evidence to retain
Law and regulator rules Permission, prohibited conduct, consumer rights, processing deadlines, liability TCPA, CASL, EU ePrivacy rules, PECR, Spam Act, PDPA/DNC rules Consent artefact, disclosure version, withdrawal record, legal review
Industry and carrier controls Network access, sender registration, campaign vetting, throughput, filtering CTIA principles, U.S. 10DLC, local sender-ID registration, DLT onboarding Brand/campaign registration, approved sender, route requirements
Internal operating controls Who may send, approved content, time-zone logic, suppression, monitoring Template approval, launch checklist, access control, incident response Approvals, audience snapshot, send log, delivery status, suppression audit

The distinction cuts both ways: a carrier may accept a message whose consent would not survive a complaint, and a lawful message may still be filtered for an unregistered sender or campaign. Template review catches obvious content and sender problems; it does not establish that each recipient gave valid permission.

1 Classify the message before choosing the rule

A label in your campaign tool cannot decide the legal classification — the recipient-facing content and the surrounding relationship do. A shipping update with only delivery information differs from one that adds “buy another item for 20% off”: the promotional line can change the consent analysis even though the automation still calls the template “transactional.”

  • Marketing or promotional messages encourage a purchase, visit, donation, or renewal. They carry the highest permission and disclosure burden.
  • Transactional or service messages confirm a transaction the recipient initiated, like an order status or appointment reminder. Keep promotions out unless marketing permission covers them.
  • Security and verification messages deliver a code or account alert. Limit them to that security purpose; do not turn a high-trust message into an ad surface.

Decision rule: Classify from the recipient's perspective. If removing the offer would change why the message exists, treat the offer as marketing and verify the corresponding consent path.

Part 2: The Global SMS Compliance Baseline Before You Compare Countries

Country rules vary, but the release process can be managed through six controls. The first two merges keep the scope and evidence together; the withdrawal and suppression controls also belong in the same release check.

Release control What to verify Evidence to retain
1. Scope the campaign Set the destination, state or province, message class, regulated context, and sender route before writing copy. Country record, message purpose, sender type
2. Capture permission and proof Collect channel-specific consent, then store the exact disclosure, source, timestamp, number, programme, and version history. Consent artefact and disclosure version
3. Approve sender and content Confirm registration, identity format, prefixes, prohibited content, template rules, and reply capability. Approved sender, route, and template
4. Schedule locally Apply the recipient's location and state or national send window instead of a single headquarters time zone. Time-zone policy and scheduled send
5. Withdraw and suppress Offer reply keywords where they work or a permitted free alternative, then route requests to the central suppression source before the next send. Opt-out event and suppression result
6. Retain the send record Link the template, sender, audience snapshot, schedule, message ID, delivery status, and suppression result for reconstruction. Send, delivery, and eligibility record

2 The alphanumeric sender-ID trap

Branded sender IDs such as BLOOMCO improve recognition but are often one-way, so “Reply STOP” becomes an instruction the recipient cannot perform. According to ACMA (2026), alphanumeric SMS headers generally cannot receive replies — yet Australia still requires a functional unsubscribe for commercial messages.

Resolve that conflict before launch: a permitted web link, service number, preference center, or provider route may work, depending on country — but it must be easy, accessible, and connected to suppression. Do not assume a link accepted in one market meets another's same-medium or cost rules.

Email opt-in also deserves its own warning. A person who asked for email has selected a different channel. According to the UK ICO (2026), consent must be specific to the type of electronic mail; consent for another communication method does not automatically cover marketing texts.

Evidence chain: Consent artefact → approved sender and template → local-time send policy → suppression result → delivery record. A gap anywhere in this chain should stop the campaign.

Part 3: SMS Compliance Laws by Country and Region

Global SMS compliance laws share themes, but their legal tests are not interchangeable. Use the matrix below as a launch filter: map the permission rule, identity and opt-out path, route check, and timing deadline for each destination, then confirm the record with local counsel or your provider.

Market Permission baseline Identity and opt-out Route or registration check Processing / timing watch-out
🇺🇸 United States TCPA consent depends on message, relationship, and technology; marketing robotexts commonly need prior express written consent Name the program or sender and support reasonable revocation methods 10DLC brand/campaign registration for A2P long-code traffic; separate processes apply to toll-free and short code Honor revocation within 10 business days; verify federal and state calling windows
🇨🇦 Canada Express or qualifying implied consent for commercial electronic messages Identification information and a readily performed unsubscribe mechanism Confirm sender and carrier requirements for the chosen route Stop commercial messages within 10 business days after unsubscribe
🇪🇺 EU / EEA Prior consent for direct marketing, with a limited existing-customer exception for the sender's own similar products Do not conceal identity; provide a valid, simple objection route National sender-ID, registration, and carrier rules still apply Each member state implements the ePrivacy rules locally; verify national law
🇬🇧 United Kingdom Specific consent or every condition of the PECR soft opt-in for individual subscribers Do not hide identity; give a valid contact address and opt-out in each message Confirm sender type and provider controls Keep a do-not-contact list and stop after withdrawal
🇦🇺 Australia Consent for commercial electronic messages Accurate sender identity/contact details and a functional unsubscribe Register branded sender IDs through the provider; unregistered IDs display as Unverified Honor unsubscribe within five working days
🇸🇬 Singapore Check the DNC Registry unless consent or another exception applies Identify the organisation, provide contact details, and offer an opt-out using the same medium Confirm route and sender requirements with the provider Stop marketing messages within 21 days after an opt-out request
🇮🇳 India Acquire applicable customer consent through the regulated commercial-communication framework Use the registered principal entity, header, and matching content template DLT registration and transmission of PE ID, header, and content ID A content or variable mismatch can block delivery even when the copy is otherwise lawful
🇧🇷 Brazil Document an LGPD legal basis for processing; consent must be provable when used Use transparent purpose and a workable rights/withdrawal process Check provider and route requirements; do not generalize telecom advertising rules to every brand campaign State and consumer-protection considerations need local review
🇦🇪 UAE / 🇸🇦 Saudi Arabia Rules differ by country; UAE promotional SMS requires stored consent UAE requires a free effective opt-out; Saudi promotional sender names use an AD indicator Sender registration and content controls are destination-specific UAE marketing messages are limited to 7 a.m.–9 p.m. UAE time

The U.S. stacks several sources. The TCPA (47 U.S.C. §227, 2023) regulates specified calls and messages with private remedies, and the consent standard depends on technology, content, number type, and relationship — so counsel maps the campaign, not a generic line. A recurring program needs a labelled, unchecked opt-in (Part 6 shows the copy). 10DLC is separate: The Campaign Registry (2026) registers brands and campaigns, but that is not “every sender registers through TCR” and never replaces TCPA consent.

2 Canada, the EU, and the UK: similar themes, different tests

Three regimes share the theme but differ in the test. Canada's CASL (CRTC 2026) requires consent, identification, and unsubscribe, with implied consent limited by category and a cross-channel, 10-business-day unsubscribe. The EU's Article 13 ePrivacy Directive (2002) makes prior consent the baseline, with a narrow existing-customer exception, implemented per member state. The UK's PECR (ICO 2026) needs consent or every condition of the narrow soft opt-in, plus visible identity and a valid opt-out address.

3 Australia and Singapore: deadlines change the workflow

Two APAC markets add hard deadlines. Australia's ACMA (2026) requires consent, accurate sender details, and an unsubscribe honored within five working days, with contact details valid for at least 30 days after the send. Singapore's PDPC (2026) requires DNC-registry screening unless consent or an exception applies, self-identification with a same-medium opt-out, and a 21-day stop window. Screen and suppress before the send, not after.

4 India, Brazil, and the Middle East need destination-level setup

Three destinations need setup or scope work first. India's TRAI (2026) puts route setup in the workflow — Principal Entity, header, and content-template registration — so changing fixed wording can itself fail delivery. Brazil's LGPD (2026 compilation) requires a legal basis with provable consent, and ANATEL's telecom rules are not a universal SMS statute. And “the Middle East” is too broad: the UAE's TDRA (2026) requires prior consent, a free opt-out, and 7 a.m.–9 p.m. sending, while Saudi Arabia's CST (2026) adds a -AD sender prefix.

Launch rule: Build a country record with legal basis, consent artefact, sender type, registration owner, content restrictions, local window, opt-out route, suppression deadline, and source review date. “MENA,” “EU,” or “APAC” is not a launch-ready destination.

Part 4: SMS Compliance News: 2025–2026 Changes to Act On

A useful SMS compliance news section changes a live control, not just announces a publication. The updates below affect suppression and sender-ID readiness, each with an action for the campaign owner.

Last verified: August 31, 2026. Recheck each linked regulator source before a launch, contract renewal, or material program change.

1 U.S. revocation rules: reasonable methods apply, while one cross-program requirement remains delayed

According to FCC 24-24 (2024), a consumer can revoke consent through any reasonable method — standard reply words, a website, or a sender-supplied phone number — honored within no more than 10 business days. A narrower point runs later: FCC DA 26-12 (2026) extended a waiver until January 31, 2027 for the part of section 64.1200(a)(10) that would treat a revocation to one informational message as covering unrelated future robocalls and robotexts from the same caller. Broader reasonable-revocation rules still apply.

Action: recognize more than the literal word STOP, route requests from every channel into one suppression service, and tag the program and category. Let counsel decide whether a request reaches unrelated programs during the waiver, but keep a global suppression option for a clear "stop everything."

The proposed one-to-one consent rule also changed status: the Eleventh Circuit vacated it in Insurance Marketing Coalition Ltd. v. FCC, and the FCC-hosted 2025 filing confirms the government did not seek review. That still does not make broad or deceptive lead-generation consent safe — the campaign needs consent supporting the caller, content, and method under the applicable law.

2 Australia: the SMS Sender ID Register is live

According to ACMA (2026), Australia's SMS Sender ID Register went live on July 1, 2026: registered IDs keep the organisation's name, unregistered ones are labelled Unverified, and non-participating providers cannot carry sender-ID SMS or MMS. Action: inventory every branded sender for Australian numbers, confirm ownership and registration through the provider (foreign orgs can use an official register or trademark source), and test the delivered label — now, not at the campaign date.

3 Spain: unregistered aliases are now blocked

According to the CNMC (2026), from June 7, 2026 operators must block SMS, MMS, and RCS to Spanish numbers with unregistered aliases, including unregistered foreign senders (subject to exceptions); requirements appear in BOE Circular 1/2026. Action: treat an alias as a registered business asset — confirm who owns it, which provider may use it, and whether the route is registered. A string that rendered last year may not pass current blocking.

Maintenance rule: Give every dated change a named owner, source URL, effective date, affected sender or program, required action, completion evidence, and next review date.

Part 5: TCPA Compliance Checklist for SMS Marketing

Use this TCPA compliance checklist SMS workflow before a U.S. campaign enters production. The owner approving the audience, sender, schedule, and suppression should record the consent standard, exemptions, state “mini-TCPA” rules, calling windows, and retention policy before release.

  • 1. Identify the legal sender and programme. Name the business whose texts the person receives. If lead generation or multiple sellers are involved, map each party and get campaign-specific legal review.
  • 2. Match consent to the message and technology. A recurring automated promotional program commonly needs prior express written consent. Do not reuse transactional, security, or email permission as marketing consent.
  • 3. Preserve the disclosure the person saw. Store the exact text, page or keyword, timestamp, phone number, programme identifier, source, and disclosure version. If the form changes, keep the old version attached to earlier subscribers.
  • 4. Keep consent separate from purchase. Make the marketing choice optional and state that consent is not a condition of buying.
  • 5. State recurring-program mechanics clearly. Cover recurring automated messages, frequency variability, message/data rates, HELP, STOP, and terms/privacy links where applicable.

2 Sender, registration, and content

  • 6. Verify the sender route. Confirm whether the campaign uses 10DLC, toll-free, short code, or another route. Test whether replies reach the suppression workflow.
  • 7. Complete the applicable ecosystem registration. Register the brand and use case for U.S. A2P 10DLC; use the separate process for toll-free or short code. Keep the approved use case aligned with live traffic.
  • 8. Keep each message inside the approved programme. Name the brand, avoid restricted or deceptive content, and do not mix an approved service template with an undisclosed promotion.

CTIA and carrier requirements belong in these checks, but keep their legal status clear. According to CTIA (2026), its Messaging Principles and Best Practices are voluntary — carriers and providers can still use them to vet or filter traffic. Passing a carrier check does not answer whether the TCPA or a state law permits the message.

3 Timing, revocation, and evidence

  • 9. Schedule in the recipient's local time. Apply the federal window and any stricter state rule from counsel. Resolve unknown or conflicting time zones before release.
  • 10. Accept reasonable revocation and suppress fast. Recognize standard reply words and other reasonable methods. Send only the permitted one-time confirmation, then stop; treat 10 business days as a ceiling and suppress as soon as the request is processed.
  • 11. Retain a complaint-ready record. Link the consent artefact, approved sender and campaign, exact message, audience snapshot, send time, message ID, delivery status, opt-out event, and suppression result.
Hard stop Why the campaign must pause Release condition
No provable permission The team cannot connect the recipient to the required consent and disclosure Exclude the record or obtain new valid permission
No functional revocation route STOP replies or the advertised alternative do not reach suppression End-to-end opt-out test passes
Unknown local time or state The scheduler cannot apply the approved contact window Resolve location or exclude the recipient
Sender or use case not approved The live traffic does not match the registered route or campaign Approval and provider confirmation are stored
Restricted or mixed-purpose content The message exceeds the consented and approved programme Remove the content or obtain the required permission and approval
Test the control path before you test the copy

Create a sandbox audience, run the sender and template review, then prove scheduling, delivery status, and suppression handoffs.

Start Free

Part 6: Compliant SMS Examples You Can Copy and Adapt

These examples turn the controls into usable copy. Replace the brand, URLs, and sender route, then verify under the law and carrier rules for your audience. A template cannot cure missing permission, and words that work on a replyable U.S. number may fail on a one-way sender.

For more collection methods, see SMS opt-in examples and the companion guide to opt-in and opt-out text messages.

1 Recurring-program opt-in disclosure

Use when: a U.S. consumer joins a recurring promotional text programme via a web or mobile form. Start the checkbox unchecked, with terms and privacy links available before submission.

By checking this box and entering your phone number, you agree to receive recurring automated marketing texts from Bloom Co at the number provided. Consent is not a condition of purchase. Msg & data rates may apply. Message frequency varies. Reply STOP to opt out and HELP for help. View Terms and Privacy Policy.

Copy disclosure Add Terms + Privacy links
Mobile form with recurring SMS programme disclosure and unchecked consent box
A consent record should preserve the wording, source, timestamp, programme and subscriber event together.
  • Swap: brand, programme description, frequency statement, HELP route, terms and privacy URLs, and required campaign disclosures.
  • Verify locally: written-consent requirements, electronic-signature evidence, disclosure placement, lead-generator roles, and state-law language.

2 Ongoing marketing message

Use when: the offer falls within the programme joined and the number can process replies. Keep the commercial purpose obvious and the withdrawal instruction functional.

Bloom Co: 20% off denim ends tonight. Shop: blm.co/denim. Reply STOP to opt out.

Copy message Test STOP end to end
iPhone promotional SMS with brand, offer, link and STOP instruction
The footer is useful only because the number accepts the reply and the request reaches suppression.
  • Swap: brand, offer, truthful deadline, destination page, and locally accepted opt-out instruction.
  • Verify locally: consent scope, quiet hours, restricted content, link domain, frequency, and route registration.

3 Opt-out confirmation and a non-replyable sender alternative

Use the confirmation when: a replyable U.S. programme gets a clear stop request. FCC rules permit a one-time confirmation in defined circumstances — confirm the action, no promotion.

Bloom Co: You've been unsubscribed and will receive no more marketing texts. No reply needed.

Copy confirmation No promotion

Use the alternative when: local rules permit a link-based withdrawal and the alphanumeric sender cannot receive replies. The link must be trustworthy, accessible without account friction, and tied to the same suppression source as other channels.

Bloom Co: 20% off ends tonight. Shop: blm.co/sale. Opt out free: blm.co/stop

Copy alternative Non-reply sender
Comparison of opt-out confirmation on a replyable number and link opt-out on a branded sender ID
The opt-out instruction must match what the sender route can actually do.
  • Swap: brand, suppression scope, approved confirmation wording, opt-out domain, and customer-service route.
  • Verify locally: whether a confirmation is allowed, whether a web link satisfies the destination's unsubscribe rule, and whether a cost or authentication barrier invalidates the path.

Template rule: Copy the structure, then validate the law, programme, sender and suppression path. Do not copy a U.S. STOP footer onto a non-replyable global route.

Part 7: Build Compliance Into Your SMS Workflow

engagelab sms messaging service

The key features of EngageLab SMS include:

  • Global direct-carrier delivery across 190+ countries and regions.
  • Separate marketing, notification, and verification (OTP) message types, each with built-in signature and template review.
  • A single outbound send API plus SMPP, with delivery-status callbacks for every message.
  • Real-time character, encoding, and price checks shown before you send.
  • Scheduled sends, plus message analysis by template, country, sender, and delivery state.
  • Transparent pay-as-you-go, per-segment pricing with no monthly minimum.
Get Started For Free
SMS service overview with setup status and message controls
Use the SMS overview to confirm the setup path before moving into message review, scheduling, and delivery checks.

Use the source system to determine which law applies, validate consent, and manage suppression. EngageLab sits in the workflow as the outbound control point, while your CRM, consent platform, or another source system remains authoritative for permission and suppression.

1 Make market and message type required campaign fields

Start every request with the destination, message class, owner, lawful basis or consent programme, and proposed sender — and never allow “global” as a destination. A campaign reaching five countries needs five launch records (or one record with five complete country rows), approved by a legal owner. Export only recipients already cleared for permission and suppression: a successful upload proves a number was accepted, not that permission exists.

SMS template creation screen with Notification, Marketing and Verification type tabs and an intended-market field
Message type (marketing, notification, verification) sets the review path; the intended-market field is research-only, so enforce destination rules in your intake.

2 Review the signature and template before the launch window

In EngageLab SMS, a new or edited signature enters review before use, and templates (marketing, notification, verification) enter review too — build that lead time into the schedule. The review checks the asset; the business still confirms consent, destination rules, and eligibility.

SMS console creating a marketing template with message preview and character count
Create the correct message type, attach the approved signature where required, and submit the template before the campaign deadline.

Keep variables narrow and typed: a discount field should not accept arbitrary text, and a URL should be restricted to approved domains. Preview realistic maximum-length values, since fixed text can mislead or exceed route limits after personalisation.

3 Preview, schedule, and run a controlled test

The console shows a sending preview, estimated price, and real-time character stats — catching a broken link, unexpected Unicode, or a variable that expands too far. These are content and cost controls; legal eligibility remains an upstream decision.

Choose immediate or scheduled sending only after converting the approved window to the recipient's time zone (the EngageLab SMS API supports scheduled sends too). Test one small controlled audience first, verifying the rendered sender, link, personalisation, opt-out, and delivery record.

SMS send screen with recipient upload, message type, preview and scheduled-send option
Release the audience only after the approved template, recipient source and local-time schedule agree.

4 Preserve delivery evidence and investigate anomalies

Message-status callbacks expose sent, delivered, and failure states. Retain the message ID with the campaign, template version, and eligibility decision; a delivered status supports reconstruction but does not prove the content was lawful or seen. Monitor by template, country, sender, and route: a drop in valid targets points to formatting or audience issues, a delivery-rate change to registration or carrier, an opt-out spike to frequency or copy. Keep these separate so the team does not “fix” a consent problem by rewriting copy.

SMS analytics screen with planned, valid, sent and delivered metrics
Separate audience validity, sending, and delivery so the team can investigate the control that actually changed.

Ready-to-send test: A campaign is ready when the team can produce the permission record, applicable rule set, approved sender and template, local-time schedule, working withdrawal test, clean suppression result, and message-status record.

Effective SMS compliance gives a repeatable release decision. Start with destination and purpose. Prove permission. Match the sender and opt-out route. Apply local timing. Suppress fast. Keep enough evidence to explain the send later.

For regulated sectors, lead generation, or multi-market programmes, have counsel review the launch record and every material change. For the outbound controls, explore the EngageLab SMS service and validate one real workflow in a test environment first.

Turn the checklist into a controlled SMS launch

Use EngageLab to review sender and template assets, schedule approved messages, and retain delivery-status evidence. Keep legal approval, consent and suppression in your source of truth.

Legal note: This guide is for operational education, not legal advice. Recheck the controlling source for each destination before launch; time-sensitive sources were last reviewed on August 31, 2026.