Compliance center
TCPA, 10DLC and what your consent record has to carry
Prior express written consent, A2P 10DLC registration with a political authorization token, and a consent record that carries the language, the timestamp, the source URL and the version.
Last updated 2026-08-28
The short version
If you are sending automated text messages to a mobile number, you need prior express written consent from that person for that kind of message. Not implied consent. Not “they gave us their number.” Not “they donated.” A phone number sitting on a supporter record is a phone number, not a permission.
Ballot Signal captures consent as a record with fields, not as a checkbox somewhere in a database. What that record contains is below.
Prior express written consent, concretely
The consent has to be an affirmative act by the person, disclosing that they agree to receive automated messages, from you, at the number they provided — and it cannot be a condition of purchase. In practice, the things that make a consent record defensible are:
- The exact language shown to the person at the moment they consented.
- A timestamp for when they consented.
- The source — the specific page URL where the consent was captured.
- The version of the consent language and policy in force at the time.
- Evidence of the affirmative act — what they clicked or checked, not merely that the page contained a disclosure.
Ballot Signal stores all five on the supporter record, and includes all five in every export and every push to a downstream platform. See what you get for the field names.
The one-to-one consent rule was vacated
In January 2025 the Eleventh Circuit vacated the FCC’s one-to-one consent rule in Insurance Marketing Coalition v. FCC. That rule would have required consent to name a single identified seller and to be logically and topically associated with the interaction that produced it.
Two things follow, and campaigns routinely get both wrong:
- The rule is gone, so the stricter one-to-one requirement it would have imposed is not in force.
- The pre-existing prior express written consent requirements still apply in full. Vacating the newer rule did not deregulate consent. If you were relying on the vacatur as a reason to be looser, you have misread it.
A2P 10DLC and the political authorization token
Application-to-person messaging over standard 10-digit long codes requires brand and campaign registration with the carrier registry. Political messaging carries an extra requirement: a political authorization token, issued through Campaign Verify, which vets that the entity registering is the committee it claims to be.
Verify the current requirements and enforcement dates against Campaign Verify and your carrier’s own documentation before you plan around them. A lot of the dates circulating in vendor blog posts are wrong or stale, and we would rather send you to the primary source than repeat a number we cannot stand behind.
What Ballot Signal does and does not do here
Does: capture the consent language, timestamp, source URL, version and consent categories; carry them into every destination; store consent withdrawals as events; make the whole record exportable on demand.
Does not: make an unconsented number textable, register your brand or campaign with the carrier registry, obtain your political authorization token, or decide for you whether a given piece of consent language is adequate. Those are yours, and any vendor who tells you otherwise is selling you a problem.
Related
- Consent-first — how the gate actually works
- Email & SMS integrations — every SMS destination and what it requires
- Tatango — a platform that enforces opt-in at the API level
Elsewhere in the compliance center
State privacy laws
Only Texas and Virginia expressly exempt political organizations. Colorado and New Jersey exempt no nonprofits. Oregon, Maryland, Delaware and Minnesota have only narrow exemptions.
FEC & in-kind contributions
Under 11 CFR 100.52(d), services must be billed at the usual and normal charge — a commercially reasonable rate prevailing at the time. Discounts outside the ordinary course of business can become in-kind contributions.
CIPA & website tracking
Trackers that fire before consent are the core exposure. The Ninth Circuit held in Javier v. Assurance IQ that prior consent is required and retroactive consent is not enough.
Voter file rules
Resolution is limited to your own consented first-party data plus a commercial identity graph. Deep voter-file matching requires a data partnership we have not signed.
See what your own website already knows.
Book a 20-minute walkthrough. We will look at your site's current consent posture first — that part is useful whether or not you buy anything.