Home/Playbook/SMS consent, TCPA and CAN-SPAM for restaurants

Compliance & ops

Consent: the part of marketing that has a legal department attached

What prior express written consent actually requires, what a defensible consent record contains, and the email and SMS rules that carry real penalties.

Compliance & ops5 sections4 questions answered
Compliance & ops illustration

This chapter is general information about how consent works in marketing operations, not legal advice: for your own programme, take advice from a lawyer in your jurisdiction. What follows is the operational shape that compliant restaurant messaging takes, and the record-keeping that makes it defensible.

What prior express written consent means in practice

In the United States, marketing text messages generally require prior express written consent under the TCPA. The requirements are specific and the penalties are assessed per message, which is why a modest list can produce a very large claim.

  • Affirmative action by the consumer. A ticked box they ticked themselves, a keyword they texted, a form they submitted. Never pre-selected.
  • Clear disclosure at the point of consent: that they will receive marketing messages, from whom, roughly how often, that message and data rates may apply, and how to stop.
  • Not a condition of purchase. Stated explicitly. You may not require SMS consent to place an order or join a loyalty programme.
  • Separate from other agreements. Bundling SMS consent into terms acceptance or a loyalty signup is the single most common defect.
  • Retained records. Timestamp, source, the exact language displayed, and the identifier of the person consenting.

A consent record that would survive a challenge

The question in any dispute is what the customer actually saw and did. A record that cannot answer that is not much of a record.

FieldWhy
Timestamp (with timezone)Establishes when consent was given
Channel and sourceWeb form, till, keyword, printed form, which one
Exact disclosure text shownThe single most important field, and the one most often missing
Version identifier of that textSo you can prove which wording was live on that date
IP address or terminal IDTies the action to a device
Consenting identifierPhone number or email as provided
Subsequent opt-out eventsComplete history, not just current state

Store the wording, versioned. "They ticked a box" is not a defence if nobody can say what the box said.

Opt-out has to work everywhere, instantly

STOP and its common variants must be honoured immediately and across every campaign, every journey and every store. The failure mode that causes real trouble is a customer who opted out of one campaign still receiving another because the suppression was applied at list level rather than at contact level.

Enforce suppression at send time against a single authoritative record, not at list-build time. Email unsubscribes have a ten-business-day window under CAN-SPAM but there is no operational reason not to honour them immediately, and every reason to.

Email rules are lighter but not absent

CAN-SPAM requires accurate header and sender information, a non-deceptive subject line, identification of the message as an advertisement, a valid physical postal address, a working opt-out mechanism, and opt-outs honoured promptly.

Other jurisdictions are stricter. GDPR and UK PECR generally require consent for marketing email to individuals and grant additional rights over data. If you have customers in those jurisdictions, the operational answer is to run the stricter standard everywhere rather than to maintain two systems.

Who is responsible in a multi-location business

Consent is generally given to a specific brand or entity, and consent collected by one franchisee does not automatically extend to another or to the franchisor. Multi-unit and franchise operators need this settled in writing before any list is combined, because merging lists across entities is one of the more common ways a compliant programme becomes non-compliant overnight.

Questions

Can I text a customer who gave me their number to receive a delivery?

Not for marketing. A number provided for order fulfilment is transactional, and using it promotionally is precisely the fact pattern most TCPA claims are built on. Collect marketing consent separately and explicitly.

How long does consent last?

There is no fixed expiry in the statute, but consent to messages from a business a customer has not engaged with for years is practically and reputationally weak. Many operators re-confirm after 12–24 months of inactivity, which also improves list quality.

Do I need consent for direct mail?

No. Postal mail does not carry the prior-consent requirement that electronic messaging does, which is part of why it remains useful for reaching households with no digital relationship. Data protection rules on how you store and use the underlying data still apply.

What about a franchisee using the brand list?

Get it settled in the franchise agreement and in writing. Consent given to one legal entity does not automatically transfer to another, and combined lists across franchisees are a recognised risk area. This is a case for actual legal advice rather than a rule of thumb.

Keep reading

Related chapters

All 46 chapters

This is one chapter of the job.

marketing.pizza runs all of it, every night, across every store you have.