TCPA Compliance for SMS Review Requests: A 2026 Guide
Last updated: Jul 20, 2026
One wrong text can cost you $500 per recipient. Here is how to stay compliant while running effective SMS review request campaigns.
The Telephone Consumer Protection Act (TCPA) is unforgiving. A single non-compliant SMS can trigger a $500 fine per recipient — and $1,500 per recipient for willful violations. For a campaign of 1,000 recipients, that is $500,000 to $1.5M in potential liability.
Here is what you need to do to stay compliant:
1. Get explicit written consent. Pre-checked boxes do not count. The customer must actively check a box acknowledging they agree to receive SMS. Capture the timestamp, IP, and consent text.
2. Register a 10DLC campaign. Since 2022, US carriers require A2P 10DLC (Application-to-Person 10-Digit Long Code) registration for business SMS. Use Twilio to register your campaign and brand.
3. Respect quiet hours. Do not send SMS outside 9am–8pm in the recipient's local timezone. Build timezone detection into your send logic.
4. Handle opt-out keywords. STOP, UNSUBSCRIBE, CANCEL, END, and QUIT must be honored within 24 hours. Set up a webhook to process these automatically.
5. Include identifying information. Every SMS must identify your business name. "Hi from Bamboo Garden" is compliant; "Hi" is not.
6. Do not use shortened links without disclosure. If you use a branded short link, disclose it (e.g., "Leave a review: bamboogarden.com/r/abc123").
7. Keep consent records for 4 years. If you get audited, you need to prove consent for every number you texted.
ReviewReply handles all of this automatically — opt-in capture, 10DLC registration, quiet hours, opt-out processing, and consent record retention. But understanding the rules helps you design better campaigns and avoid costly mistakes.