SMS Marketing Compliance in 2026: Consent, Opt-Out, TCPA & GDPR

Share

If you send marketing texts in 2026, the rulebook looks different from what it did two years ago, and not in the direction most compliance teams expected. The FCC killed its own one-to-one consent rule before it ever took effect. A separate opt-out rule quietly became one of the most consequential changes to hit SMS marketing in a decade. And in Europe, regulators walked away from the one law that was supposed to simplify everything, leaving 27 member states to keep interpreting electronic marketing consent their own way.

None of this means the pressure is off. TCPA class action filings are still climbing, GDPR enforcement is still active at the member-state level, and carriers are filtering more aggressively than ever through 10DLC and CTIA vetting. The rules just moved to different places. This is where they actually stand right now, and what a marketing or compliance team needs to do about it.

Where SMS compliance actually stands in 2026

Three things define the current landscape. First, the FCC's one-to-one consent rule, which would have required a separate opt-in for every company sharing a lead, was vacated by the Eleventh Circuit days before it was set to take effect, and the commission has since reinstated the older consent standard. Second, the TCPA's revocation-of-consent rule, which forces businesses to honor an opt-out through any reasonable channel, has been fully enforceable since April 11, 2025, even though its toughest provision (a single "stop" wiping out consent for every program a company runs) has been pushed back to January 31, 2027. Third, the European Commission formally withdrew its proposed ePrivacy Regulation on February 11, 2026, which means the patchwork of GDPR plus national ePrivacy implementations is now the permanent state of play in the EU, not a placeholder waiting for something cleaner.

For a fintech or enterprise team sending OTPs, alerts, or promotional texts across US and EU numbers, that combination matters. US lead generation got a little easier. US opt-out handling got meaningfully harder. And EU compliance stopped waiting for harmonization and needs to be built for permanent fragmentation instead.

TCPA in 2026: what actually changed and what didn't

The one-to-one consent saga is worth understanding because so much 2024-era compliance advice was written around a rule that never survived contact with the courts. The FCC adopted the rule in December 2023 to close what it called the lead generator loophole, the practice of a single consent checkbox authorizing calls and texts from dozens of undisclosed marketing partners. The rule was delayed twice, then the Eleventh Circuit vacated it entirely in January 2025, ruling that the FCC had exceeded its statutory authority by redefining "prior express consent" beyond what Congress wrote into the law. The FCC subsequently deleted the vacated language from its rules as part of a broader deregulatory push. As of 2026, the pre-2023 standard governs: consent must be in writing, it must include a signature, and it must clearly disclose what the consumer is agreeing to, but it does not need to name every seller who might contact them.

That is a genuine reprieve for lead generators and the buyers of shared leads, and it means the aggressive multi-seller consent architecture many platforms built in 2024 to prepare for one-to-one was, in hindsight, unnecessary defensive work. It is not, however, a green light to relax consent practices generally. Statutory damages under the TCPA still run $500 to $1,500 per violation with no cap, and a single non-compliant campaign sent to a large list can still produce existential exposure through a class action.

The rule that actually deserves the most attention right now is the opt-out side, not the consent side.

Opt-out mechanics you need to support today

Since April 11, 2025, the FCC has required that businesses honor a consumer's revocation of consent through any reasonable method, not just a specific keyword or a specific channel. That sounds like a small wording change, but it restructures how opt-out handling has to work. A handful of practical requirements follow directly from it:

  • No exclusive opt-out channel. A terms-of-service clause that says texting "STOP" is the only valid way to opt out is no longer enforceable as an exclusive method. Consumers can revoke consent by replying with other clear language, calling a listed number, or using a designated web form, and the business has to honor it regardless of channel.
  • Recognized keywords, but not an exhaustive list. STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL, and UNSUBSCRIBE are treated as per se reasonable, but the FCC explicitly left room for other phrasing. If a consumer texts something like "please stop messaging me," a keyword-only filter that only catches the seven standard words is legally insufficient, which is why natural-language opt-out detection has quietly become a compliance requirement rather than a nice-to-have.
  • A ten-business-day compliance window. Down from the old thirty-day standard, businesses now have to stop messaging across the affected program within ten business days of a valid revocation.
  • One clarification message, and only one. If a business needs to confirm the scope of an opt-out (for example, distinguishing a marketing opt-out from a transactional one), it gets exactly one follow-up message to do that, with no marketing content in it.
  • Disclosure if replies aren't supported. If a sender can't technically process inbound replies on a given number, it has to say so clearly in the message and provide another reasonable way to opt out.

The provision that has not yet taken effect is the "revoke-all" requirement, which would treat a single opt-out as canceling consent across every program a company runs, not just the one that sent the message. That piece has been granted limited waivers twice and is now delayed until January 31, 2027. It's worth building toward now anyway, since suppression architecture that only works program-by-program is expensive to retrofit later.

GDPR and the EU: the picture got more fragmented, not less

GDPR itself hasn't changed its core requirements for SMS marketing. Article 6 still requires a lawful basis for processing personal data, phone numbers still count as personal data, and consent under Article 6(1)(a) is still the basis nearly every SMS marketing program has to rely on, because legitimate interest under Article 6(1)(f) is difficult to defend for unsolicited direct marketing and most data protection authorities treat it skeptically in this context.

What changed is the layer sitting on top of GDPR. Electronic marketing in the EU has always required a second, more specific legal basis under the ePrivacy Directive (or its national implementations), which generally demands opt-in consent for SMS marketing independent of whatever GDPR basis a company claims. The European Commission spent years trying to replace that directive with a single ePrivacy Regulation that would apply uniformly across the bloc. On February 11, 2026, it gave up on that project and formally withdrew the proposal, which means marketing compliance authority reverts fully to individual member states rather than converging toward one EU-wide standard. Practically, that means a business texting customers in France, Germany, and Spain has to keep tracking three sets of national rules on top of GDPR, not one harmonized framework, and that gap is likely to widen rather than close as national regulators move at different speeds.

GDPR also applies extraterritorially: if the recipient is in the EU or EEA, GDPR governs the message regardless of where the sending business is incorporated. For a CPaaS or OTP provider serving global fintech customers, that means EU consent, documentation, and deletion-request handling can't be an afterthought bolted onto a US-first compliance program.

TCPA vs GDPR at a glance

TCPA (US)GDPR + national ePrivacy rules (EU)
Applies toAutodialed/prerecorded calls and texts to US numbersProcessing personal data of anyone in the EU/EEA
Legal basis for marketing SMSPrior express written consentConsent (Art. 6(1)(a)), plus opt-in under national ePrivacy law
Opt-out standardAny reasonable method; 10-business-day compliance windowWithdrawal must be as easy as giving consent
Consent sharing across brandsOne-to-one rule vacated; pre-2023 standard appliesEach processing purpose needs its own specific consent
Penalty structure$500–$1,500 per violation, no cap, private right of actionUp to €20M or 4% of global annual turnover
Regulatory trend in 2026Deregulatory at the federal level; state laws filling the gapHarmonization effort abandoned; enforcement stays national

Carrier-level compliance: CTIA, 10DLC and the delivery layer

Even a program that satisfies TCPA and GDPR on paper can still fail to deliver, because US carriers enforce a separate, non-statutory layer of rules through The Campaign Registry and the CTIA's messaging principles. (If A2P registration itself is new territory, our primer on what A2P messaging is and how it's priced covers the mechanics this section assumes.) Since February 1, 2025, unregistered A2P traffic on 10-digit long codes is blocked outright by US carriers, so 10DLC brand and campaign registration is no longer optional infrastructure; it's the difference between messages arriving and messages disappearing silently.

The CTIA framework layers additional requirements on top of TCPA:

  • SHAFT content restrictions. Sex, Hate, Alcohol, Firearms, and Tobacco content is restricted or prohibited in A2P campaigns regardless of whether the recipient consented, and adjacent categories like payday loans, credit repair, and get-rich-quick offers face similar scrutiny during registration.
  • Explicit opt-in language at registration. Campaign submissions have to state which brand is messaging, what type of content will be sent, and how frequently, and that disclosure has to match what the consumer actually saw when they opted in.
  • Quiet hours. Marketing texts are expected to stay within roughly 8 am to 9 pm in the recipient's local time zone.
  • No public link shorteners. Bitly, TinyURL, and similar generic shorteners are strongly associated with spam traffic and routinely trigger carrier filtering; branded or dedicated short domains are the accepted alternative.
  • Ongoing audits, not one-time approval. Carriers now review registered campaigns after approval, so a 10DLC brand that drifts from its declared use case can lose throughput or get blocked even after initially passing registration.

This is also where the CTIA/TCPA distinction trips people up. A campaign can be fully TCPA-compliant on the consent side and still get filtered by carriers for failing CTIA standards, and the reverse is just as true: passing carrier vetting doesn't mean the underlying consent record would survive a TCPA lawsuit. Compliant programs have to clear both bars independently.

State laws add a layer the federal rules don't cover

Roughly a dozen US states have their own SMS-specific statutes, and several are stricter than the federal TCPA, including Florida's Telephone Solicitation Act, along with newer laws in Oklahoma and Washington. Where a state law imposes a tighter standard than the TCPA, the state law controls for residents of that state. The practical approach most compliance teams land on is applying the strictest applicable standard to every contact based on their state of residence, rather than maintaining separate rulesets per state, which becomes unmanageable at scale.

Most compliance guides stop at consent and opt-out language. For fintech and enterprise senders, though, a meaningful share of real-world violations trace back to the delivery layer rather than the consent record: grey-route traffic that bypasses registered, carrier-vetted paths, SMS pumping fraud that inflates message volume through unverified numbers, and OTP delivery that routes through intermediaries with no visibility into consent or suppression status at the point of send. We've written before about why fintech apps are moving OTP traffic away from API-only aggregators and toward telecom-native delivery for exactly this reason: direct MNO relationships and consent state tracked at the point of send close a gap that pure aggregation layers often leave open. That's a separate conversation from the legal frameworks above, but it's the operational half of the same problem. The best consent record in the world doesn't help if the message that gets delivered doesn't match what was actually registered and approved.

FAQ

Is the FCC's one-to-one consent rule still in effect in 2026? No. The Eleventh Circuit vacated it in January 2025, and the FCC has reinstated the pre-2023 prior express written consent standard, which does not require seller-by-seller consent.

What's the current deadline for TCPA opt-out compliance? The core opt-out rules, including the any-reasonable-method standard and the ten-business-day compliance window, have been enforceable since April 11, 2025. Only the "revoke-all" cross-program provision remains delayed, currently until January 31, 2027.

Does GDPR require double opt-in for SMS marketing? GDPR itself doesn't mandate double opt-in specifically, but most national ePrivacy implementations require clear, specific opt-in consent for electronic marketing, and double opt-in is widely used as the more defensible standard given how skeptically regulators treat legitimate interest as a basis for SMS.

What happened to the EU's ePrivacy Regulation? The European Commission withdrew the proposal on February 11, 2026, ending the effort to replace the ePrivacy Directive with a single EU-wide regulation. Electronic marketing compliance in the EU now permanently depends on GDPR plus each member state's own national rules.

Can a keyword-only opt-out system still be compliant? Not reliably. The FCC's any-reasonable-method standard means a system that only recognizes STOP, QUIT, END, and similar keywords can miss valid revocations phrased in plain language, which creates real TCPA exposure even if the standard keywords are handled correctly.

Does 10DLC registration replace the need for TCPA-compliant consent? No. 10DLC and CTIA compliance govern whether carriers deliver a message at all. TCPA and GDPR govern whether the underlying consent to send it was lawful. A campaign needs to satisfy both independently.

The bottom line

SMS compliance in 2026 didn't get simpler; it got more specific. The federal consent bar came down slightly, the opt-out bar went up meaningfully, and the EU traded the promise of one law for the reality of many. Teams that treat these as three separate tracks- consent architecture, opt-out infrastructure, and carrier-level delivery compliance- are the ones that stay out of both litigation and the spam filter at the same time.

What to do next

  • Audit your current opt-out handling against the any-reasonable-method standard, not just keyword matching
  • Confirm your 10-business-day revocation processing is enforced across every channel a consumer might use to opt out
  • Review EU consent language country by country rather than assuming one EU-wide standard covers every market
  • Check your 10DLC campaign registrations still match your actual message content and declared use case
  • Replace any public link shorteners in SMS content with a branded short domain
  • Map which of your message flows (OTP, transactional, marketing) route through intermediaries versus direct carrier connections, and where consent status is actually being checked at send time

Running OTP or transactional SMS through infrastructure that can't tell you a number's real consent and opt-out status at the moment of send is a compliance gap hiding as a delivery problem. Yootelco's telecom-native routing, including our dedicated OTP authentication infrastructure, keeps that check close to the network layer instead of several hops away from it. If you want a walkthrough of how your current SMS or OTP traffic would hold up under an FCC or carrier audit, talk to our team.

Read more