# SMS Compliance Airship supports SMS and RCS compliance, including consent, disclosure, opt-in and opt-out, and number life cycle management. # SMS Compliance Requirements > Airship supports SMS compliance for consent, disclosure, opt-in and opt-out, and recordkeeping. > **Important:** Please note that this content is provided for information purposes only and is not intended to be nor should be relied on as legal or compliance advice. > > Different locations may have varying legal and privacy requirements for SMS/MMS/RCS notifications, so please verify with your legal or regulatory compliance team that your SMS/MMS/RCS usage, proposed use cases, and messaging configuration are compliant with applicable local laws and regulations.

The Airship Service provides customers with a platform for building successful SMS marketing programs by supporting compliance with laws and industry best practices as summarized in this document. These guidelines represent our current understanding of common compliance requirements generally applicable to Airship and our customers and do not constitute legal advice.

## Some Background on SMS Regulation Meeting regulatory requirements and maintaining best practices to support customer relationships are critical for brands that use SMS in their marketing strategy. Regulations such as the US Telephone Consumer Protection Act of 1991 (TCPA), the Canadian Anti-Spam Law (CASL), the General Data Protection Regulation (GDPR), the Directive on Privacy and Electronic Communications (the EU's ePrivacy Directive), and a variety of local US state laws and individual EU countries' regulations include strict requirements for sending SMS marketing messages. In addition to country- and state-specific laws and regulations that govern SMS messaging, wireless industry groups publish best practice guidelines for companies engaged in SMS marketing. These include key standards from the wireless industry association CTIA: * [CTIA Messaging Principles and Best Practices](https://api.ctia.org/wp-content/uploads/2019/07/190719-CTIA-Messaging-Principles-and-Best-Practices-FINAL.pdf) * [CTIA Short Code Monitoring Handbook](https://api.ctia.org/wp-content/uploads/2024/01/CTIA-Short-Code-Monitoring-Handbook-v1.9-FINAL.pdf) Certain telecommunications providers may also have their own Code of Conduct to govern traffic through their services, such as T-Mobile's Code of Conduct and Mobile Marketing Association's [Consumer Best Practices for Messaging](https://www.mmaglobal.com/files/bestpractices.pdf). ## General Requirements You must obtain consent and provide disclosure. ### Prior Express Written Consent TCPA in the US, and other applicable laws around the world, a business must provide clear and conspicuous information about its practices and get the recipient's express written consent to receive text messages before sending an automated message. Brands should never send messages to opt-in lists that have been shared or sold. Also, brands should check for the legal age of consent and the types of disclosures required based on their use case and where the recipient is located. In addition, brands should verify their use cases and numbers against local Do Not Call (DNC) registries to ensure no other restrictions may apply. Because considerations regarding DNC registries are highly specific to each use case, Airship cannot apply number filtering or automated channel uninstall for mobile numbers that appear on a DNC, in the US or any other known DNC. ### Clear and Conspicuous Disclosure Brands must be clear, concise and upfront in the call to action that prompts the consumer to opt in to receive SMS messages: * Identify the business to whom consent is being provided * Identify the consumer's phone number * Include a description of the recurring text messaging program and types of messages the consumer will receive (e.g., account alerts, news alerts, promotional alerts, coupons, reminders, etc.) * Disclose that texts will be sent using automated technology * Disclose that the consumer is not required to provide consent as a condition of a purchase * Disclose specific message frequency or that "message frequency varies" * Disclose that message and data rates may apply * Provide Customer Care and Opt-Out instructions * Provide links to applicable Terms of Use and Privacy Policy. * Terms of Use should include a section that details the SMS program, including program description and opt-in, opt-out, and help information * Privacy Policy must explicitly state that mobile opt-in data will not be shared or sold **Example of a call to action (e.g., on a website, store display, etc.)** ```text Text JOIN to 22255 to receive recurring autodialed offers and information from {BRAND NAME} Terms and Privacy Policy at [brand.example.com/sms-terms]. Message frequency varies with use. No purchase required. Reply HELP for help, STOP to end, Msg&data rates may apply. ``` ### Canada (CWTA) — Link Disclosure Requirement For SMS programs operating in Canada under Canadian Wireless Telecommunications Association (CWTA) guidance, if a message contains a clickable link, include the disclosure "Std msg & data rates may apply." in that message. This requirement helps satisfy carrier and CWTA expectations for clear consumer disclosures related to messages that drive to the web. Apply this disclosure alongside existing HELP/STOP language as appropriate. ### Written Consent (Opt-In) Brands may obtain digital consent via text message, email, website form, voice recording, etc. with the following requirements: * Cannot use a pre-checked box * Cannot require consent to receive SMS messages as a condition of sale * Should keep records of consent for at least four years (the statute of limitation for TCPA claims is four years) * Double opt-in, while not strictly required, is supported and recommended by Airship as a best practice * With single or double opt-in, the first text message should be a compliance message confirming opt-in and reiterating important information: * Identifying the brand * Message frequency, if not already provided * What types of messages * Message and data rates may apply * Customer Care and Opt-Out instructions * Provide links to terms and privacy policy, if not already provided Some jurisdictions may have additional consent requirements, including requirements around obtaining express written consent, which may need to include the consumer's phone number, express authorization to receive the message, and other notifications. Brands should check with their legal or regulatory compliance teams for the types of disclosures required based on their use case and where the recipient is located. **Example of confirmation message** ```text {BRAND NAME}: You've subscribed to receive recurring promotional msgs. Reply HELP for help, STOP to end. Msg&data rates may apply. ``` ### Time of Day Guidelines Brands should schedule their SMS notifications to account for carrier delivery delays, especially in locations with time of day requirements, including those required under TCPA and local state laws, which may be more restrictive. The TCPA prohibits telephone solicitation (including text messages) before 8 AM and after 9 PM in the recipient's time zone. A best practice is to send SMS notifications between 9 AM and 8 PM in the recipient's time zone. Local restrictions may be more stringent than the 8 AM to 9 PM TCPA standard. Brands should confirm time of day requirements for each location of operation. If brands have recipients in different time zones, then multiple time zones should be taken into consideration. In addition, if brands are targeting large audiences, scheduling further in advance of the prohibited period is advisable. Otherwise, the volume of messages may cause additional delivery delays. ### Customer Care and Opt-Out Instructions SMS programs should promote customer care contact and opt-out instructions in initial SMS program disclosures and then with every recurring message or at least once per month. ```text Reply HELP for help, STOP to end ``` ### Special Considerations for Transactional SMS SMS cannot be the only method for transactional messaging. Mobile carriers require an alternative method such as email or a phone call. An example of a common transactional SMS message is a one-time password. ## State-Specific Requirements Some US states have "mini-TCPA" or similar telemarketing laws that differ from federal requirements. Variations may include: - Consent standards for automated sales texts - Restricted contact hours based on recipients' local time - Frequency or attempt limits within a defined period - Pre-suit cure requirements, such as STOP and grace periods, and private rights of action - Content and identification expectations, such as disclosures and return-call capabilities - Registration, record keeping, and other program obligations - Presumptions tied to area codes or residency - Requirements to regularly include a callback-capable phone number in outbound messages Recommended approach: - Consult counsel to determine which state rules apply to your audience and use cases. - Configure opt-in flows and unsubscribe handling - Schedule sends to comply with the most restrictive applicable sending hours. - Maintain auditable consent and suppression records, and monitor state-level changes. Because state requirements evolve, verify current obligations and enforcement trends before launching campaigns. Airship does not enforce state-by-state rules automatically. Brands are responsible for the appropriate configuration and scheduling. ## Opt-In Methods Airship SMS supports two opt-in methods. Based on local regulatory requirements, additional consents may be needed as described above. Brands should check with their legal or regulatory compliance teams for the types of disclosures required based on their use case and where the recipient is located to complement the Airship Service configuration. ### Mobile-Originated Opt-In In response to a call to action from the brand, a consumer texts `JOIN` from their mobile device or responds through another form — i.e., a website, app, or any means other than sending a text with an opt-in keyword. This triggers the Airship SMS channel to send a double opt-in request (example message below, customizable for your brand): ```text {BRAND NAME}: Reply Y to agree to receive recurring autodialed {type of messages/alerts} and to our Terms of Service [insert TOS hyperlink] and Privacy Policy [insert PP hyperlink]. No purchase rqd. Message frequency varies. Reply HELP for help, STOP to end. Msg&data rates may apply. ``` In the Airship SMS channel, the consumer will not get added to the opt-in list until they reply with the keyword `Y`. Once added to the list, Airship SMS sends an automatic confirmation alert: ```text {BRAND NAME}: You've subscribed to receive recurring {type of messages/alerts}. Message frequency varies. Reply HELP for help, STOP to end. Msg&data rates may apply. ``` ### Brand-Managed Opt-In Opt-in owned by the brand and uploaded to Airship SMS via API or CSV file : The consumer uses the brand's website, app, paper form or other means to opt in to receiving SMS messages. The phone number and opt-in date/ time are then passed to Airship by the brand via the Airship API or uploaded via the Airship platform, and Airship SMS tracks the opt-in date/time in our database along with the phone number. If the number is not already in the Airship opt-in database for that brand, the number is automatically added to that opt-in database. If uploading via CSV, any number on the uploaded list that does not include an opt-in date/time is not added to the opt-in database and no message is sent to that number. Brands must make sure that the call to action for the opt-in clearly provides all necessary information under applicable law and that the consent meets applicable legal requirements. Transactional messages : Transactional messages are messages that are directly related to the service being provided, such as delivery updates for a package or appointment reminders. Once the consumer provides the brand with legally appropriate consent to receive transactional messages, the brand triggers the sending of the transactional message by providing the phone number and opt-in date to Airship SMS via our API as described above. It is important to note that consent to receive a transactional SMS notification cannot be used for sending any marketing SMS messages. Each opt-in database for a brand will have the same scope of messages, such as promotional alerts or account update alerts. A separate code will be required to add another type of campaign. Brands should make sure that written consents from legacy or existing customers include all legally required elements of a consent, and if in doubt, obtain new consents from existing consumers covering any missing requirements. ## Opt-Out Methods Under the TCPA in the US, and other applicable laws around the world, a consumer may revoke consent through any reasonable method, including verbal communication or, in the context of text messaging with keyword such as `STOP`. The brand should confirm that it is able to process requests received (1) via text, using words other than STOP (i.e., unsubscribe, cancel, etc.), and (2) via other channels, for example if a customer contacts customer support and asks to be opted-out of text messages. The business should unsubscribe that consumer out of all recurring text messaging programs and cease text messaging to that consumer, unless that consumer subsequently opts-in. ### Mobile-Originated Opt-Out When a consumer texts the brand with a keyword like STOP (or any of the other opt-out keywords specified by law or best practices), Airship SMS automatically responds with a confirmation and adds an opt-out date/time to our database (example message below, marketers can tailor the content of this opt-out confirmation message to fit their workflow and brand requirements): ```text {BRAND NAME}: You have opted-out and will no longer receive messages. Reply HELP for help ``` Airship does not send messages to any numbers that have opt-out dates associated with them. If the consumer decides to opt in again, the Double Opt-In or Brand Managed Opt-In methods described above will register a new opt-in date. ### Website- or App-Originated Opt-Out If a consumer changes their preferences in a Preference Center—or in some other way via the brand's website or app—the brand must pass the opt-out information to the Airship platform using the Airship API. Airship then adds the opt-out date/time to our database. ### Brand-Managed Opt-Out If you choose to manage SMS opt-outs outside of Airship, it is your responsibility to ensure that the opt-out status remains synchronized between your systems and Airship. Airship does not automatically track or enforce opt-out compliance unless explicitly configured to do so. To ensure users who have opted out in your environment are also suppressed within Airship, you must automate opt-out synchronization or maintain it manually. For automated management, you configure your external systems to notify Airship when a user opts out. For example, you would forward STOP messages or user opt-out actions to Airship's [Opt-out of SMS messages API endpoint](https://www.airship.com/docs/developer/rest-api/ua/operations/sms/#optoutsmschannel). For individual channels, you can change opt-in status manually in the dashboard. See [Viewing channel details](https://www.airship.com/docs/guides/audience/tools/contact-management/#viewing-channel-details) in *Contact Management*. Without either automated management or regular manual updates, Airship will continue to treat those SMS channels as opted-in, and may continue sending messages. In this case, Airship bears no responsibility for message delivery to users you have marked as opted out in your system. ### National Do Not Call Registry (DNC) Airship does not apply number filtering or automated channel uninstall for mobile numbers that appear on a DNC, in the US or any other known DNC registry. ## Reporting and Records Airship [SMS reports](https://www.airship.com/docs/guides/reports/engagement/#sms) give brands the ability to view opt-in and opt-out status for consumers who have provided consent to receive SMS messages from the brand. Brands should also maintain all consent records that provide relevant details. Various locations will have different requirements for how long a brand should maintain opt-in and opt-out records for SMS. Airship retains opt-in date/time records and opt-out date/time records for a mobile phone number in our database for four years. Airship customers can download their full channel listing via the [Channel Listing API](https://www.airship.com/docs/developer/rest-api/ua/operations/channels/#getchannels), which includes channel created-on date, the [MSISDN](https://www.airship.com/docs/reference/glossary/#msisdn), associated [sender ID](https://www.airship.com/docs/reference/glossary/#sender_id) (short code or long code), current opt-in or opt-out status, and opt-in or opt-out date for all SMS channels. You can also send opt-in and opt-out events into other business systems via [Real-Time Data Streaming](https://www.airship.com/docs/reference/glossary/#rtds). For details on how carrier deactivation affects SMS channels and message history, see [Default Carrier Deactivation Monitoring](https://www.airship.com/docs/developer/api-integrations/sms/compliance/number-lifecycle/#default-carrier-deactivation-monitoring) in *SMS Number Life Cycle Management*. # RCS Compliance Guidelines > Airship supports RCS compliance for consent, opt-in and opt-out, content restrictions, and recordkeeping. Rich Communication Services (RCS) is an advanced messaging protocol that enables interactive, media-rich communications. RCS messages automatically fall back to SMS/MMS when not supported. > **Important:** Please note that this content is provided for information purposes only and is not intended to be nor should be relied on as legal or compliance advice. > > Different locations may have varying legal and privacy requirements for SMS/MMS/RCS notifications, so please verify with your legal or regulatory compliance team that your SMS/MMS/RCS usage, proposed use cases, and messaging configuration are compliant with applicable local laws and regulations.

The Airship Service provides customers with a platform for building successful SMS marketing programs by supporting compliance with laws and industry best practices as summarized in this document. These guidelines represent our current understanding of common compliance requirements generally applicable to Airship and our customers and do not constitute legal advice.

## General Requirements You must obtain consent and provide disclosure. - All rules applicable to SMS/MMS also apply to RCS. Review the [SMS Compliance Requirements document](https://www.airship.com/docs/developer/api-integrations/sms/compliance/requirements/) and the [Airship Acceptable Use Policy](https://www.airship.com/legal/acceptable-use/). - Obtain explicit, documented consent from each recipient before sending RCS messages. Consent must clearly indicate the types of messages the recipient will receive and must not be bundled with other consents. - Consent must be specific to the brand and campaign and cannot be transferred, bought, sold, or obtained from third‑party lists. - Maintain records of consent — including timestamps, consent method, and scope — for at least four years or as required by local law. - If you do not send the first message within a reasonable period after consent is obtained, reconfirm consent in the initial message. ## Consent and Opt‑In Consent must be obtained via a clear call to action, for example a website form, app, SMS, or other digital means. Do not use pre‑checked boxes or require consent as a condition of purchase. The call to action must: - Identify the brand - Specify the recipient’s phone number - Describe the types and frequency of RCS messages - Disclose that messages may be sent using automated technology - State that consent is not required for purchase - Provide links to Terms of Use and Privacy Policy - Include [opt‑out instructions](#optout-and-revocation-of-consent) ## Sender Identification Every RCS message must clearly identify the sender, which is the party that obtained consent, except for follow‑up messages in an ongoing conversation thread. ## Opt‑Out and Revocation of Consent Regarding consent: - Recipients must be able to revoke consent at any time by replying with standard opt‑out keywords such as STOP, UNSUBSCRIBE, CANCEL, END, QUIT. - The initial RCS message must include opt‑out instructions, such as "Reply STOP to unsubscribe." - When a recipient opts out, you may send one final confirmation message. No further messages may be sent unless new consent is obtained. - Opt‑out requests must be processed promptly and applied across all recurring RCS messaging programs. ## Content Restrictions Do not send RCS messages containing: * Counterfeit goods * Dangerous products or services * Products, services, or content that enable dishonest behaviors * Dangerous or derogatory content * Shocking content * Capitalizing on sensitive events * Animal cruelty * Adult or sexual content * Tobacco * Political content * Unauthorized content * Gambling or gambling-related activities * Firearms/weapons * Cannabis * Prescription drugs/medications * Alcohol For additional information, see Google's [Acceptable Use Policy](https://developers.google.com/business-communications/rcs-business-messaging/terms-and-policies/aup) in their *RCS for Business* documentation. ## Country‑Specific Requirements Always review and comply with country‑specific RCS messaging requirements, which may include additional consent, content, or technical restrictions. ## Recordkeeping and Reporting Maintain records of opt‑in and opt‑out status, including timestamps and consent method, for at least four years or as required by local law. Be prepared to provide proof of consent and compliance upon request from Airship or regulators. ## Enforcement and Violation Handling Violations of these RCS requirements may result in suspension or removal of messaging capabilities by Airship or its providers. Report suspected violations to Airship immediately by contacting your account manager or [Airship Support](https://support.airship.com). # SMS Number Life Cycle Management > Airship uses carrier data and, optionally, the FCC's Reassigned Numbers Database (RND) to remove or suppress US phone numbers that are no longer valid recipients. > **Important:** Please note that this content is provided for information purposes only and is not intended to be nor should be relied on as legal or compliance advice. > > Different locations may have varying legal and privacy requirements for SMS/MMS/RCS notifications, so please verify with your legal or regulatory compliance team that your SMS/MMS/RCS usage, proposed use cases, and messaging configuration are compliant with applicable local laws and regulations.

The Airship Service provides customers with a platform for building successful SMS marketing programs by supporting compliance with laws and industry best practices as summarized in this document. These guidelines represent our current understanding of common compliance requirements generally applicable to Airship and our customers and do not constitute legal advice.

## Default Carrier Deactivation Monitoring Each day, US mobile carriers send Airship a list of phone numbers that are deactivated, disconnected, suspended, reassigned, or otherwise no longer eligible to receive messaging for the original subscriber. Because the list aggregates data only from participating carriers, it does not cover every US number. The Airship Service applies carrier deactivation updates on a recurring schedule, uninstalling SMS channels for numbers found in carrier deactivation records and purging their message history. Default carrier deactivation monitoring is enabled automatically for all US SMS customers. ## Reassigned Numbers and the FCC RND Phone numbers may be permanently disconnected and later reassigned to a new subscriber. Under the TCPA and similar regulations, consent generally applies to the current subscriber or customary user of a phone number. Messaging a reassigned number creates compliance risk when valid consent for the current subscriber no longer exists. In the US, the FCC's Reassigned Numbers Database (RND) contains permanently disconnected or reassigned numbers and is comprehensive across all carriers. ## FCC RND Scanning Two FCC RND scanning services are available: - [Carrier deactivation RND scanning](#carrier-deactivation-rnd-scanning) extends [default carrier deactivation monitoring](#default-carrier-deactivation-monitoring) with FCC RND verification before permanent removal. - [Full audience RND scanning](#full-audience-rnd-scanning) is an ad hoc scan of a customer-defined SMS audience against the FCC RND. Contact your Airship account manager to add FCC RND scanning services to your account. They may be subject to additional commercial terms. ### Carrier Deactivation RND Scanning Carrier deactivation RND scanning adds FCC RND verification to default carrier deactivation monitoring. When enabled, Airship verifies carrier-deactivated US SMS numbers against the FCC RND before finalizing removal or suppression, and places deactivated numbers into a suppressed state during the RND check. Suppressed numbers are excluded from messaging until they are removed or restored. Airship performs RND queries on a recurring basis for suppressed numbers, according to the FCC RND's monthly update, to assess whether they were permanently disconnected after the date of consent. Numbers indicated as permanently disconnected or reassigned are removed or handled according to your configuration. Numbers not indicated as reassigned are restored from suppression. ### Full Audience RND Scanning A full audience RND scan is an ad hoc scan of US numbers in a customer-defined SMS list against the FCC RND. For each eligible number, Airship queries the FCC RND using the [MSISDN](https://www.airship.com/docs/reference/glossary/#msisdn) and the registered opt-in date to assess whether the number was reported as permanently disconnected or reassigned after the consent date. Scans are performed on the customer's behalf, according to the terms in the applicable order form. Results can help identify numbers that may no longer be associated with the original consenting subscriber, and are most relevant to the [FCC safe harbor considerations](#fcc-safe-harbor-considerations) below. ## Comparison of Default and Optional Management Services The following table compares SMS life cycle management services for US SMS customers: | | Default carrier deactivation monitoring | Carrier deactivation RND scanning | Full audience RND scanning | | --- | --- | --- | --- | | **Availability** | Enabled by default | Optional, may be subject to additional commercial terms | Optional, subject to the terms of the applicable order form | | **Uses FCC RND** | No | Yes | Yes | | **Data source** | Carrier deactivation files from participating US carriers — not all carriers participate | Carrier deactivation files verified against the FCC RND | FCC RND — comprehensive across US carriers as defined by the FCC program | | **Cadence** | Recurring | Recurring, triggered by carrier deactivation | Ad hoc, one-time or periodic | | **Channel handling** | Channels for deactivated numbers are uninstalled | Channels are suppressed during RND check, then removed or restored based on result | Customer decides based on results | {class="table-col-1-20"} ## Real-Time Data Streaming When Airship suppresses a channel during carrier deactivation processing, it reports an [SMS carrier deactivation event](https://www.airship.com/docs/developer/rest-api/connect/schemas/sms-compliance-events/#carrier-deactivation) in [Real-Time Data Streaming](https://www.airship.com/docs/reference/glossary/#rtds). Uninstall and suppression-removal actions from RND scanning are reported as [SMS RND scan events](https://www.airship.com/docs/developer/rest-api/connect/schemas/sms-compliance-events/#rnd-scan). The `source` property on RND scan events indicates which service triggered the event: `monthly_scan` for recurring deactivation processing and `app_scan` for a full audience scan. ## Customer Responsibilities The FCC RND and Airship's optional RND scanning services address US regulatory frameworks. They do not replace country-specific obligations elsewhere. Customers remain responsible for consent management, messaging decisions, and regulatory compliance. For full audience RND scans, customers are also responsible for scan scope, eligibility, and interpretation. Feature availability and pricing are subject to your agreement and may change. Confirm current capabilities with your Airship account team. Manage suppression through the API or using [Contact Management](https://www.airship.com/docs/guides/audience/tools/contact-management/) in the dashboard. ## FCC Safe Harbor Considerations The FCC's RND framework may support TCPA safe harbor protection in some circumstances, such as when a number is queried within 30 days prior to messaging and the RND erroneously indicates the number has not been reassigned. Additional requirements must be met for the safe harbor to apply. Safe harbor treatment depends on the facts, applicable law, and regulatory guidance. Airship does not guarantee safe harbor protection or any particular regulatory outcome. Use of RND-related features does not guarantee compliance with applicable laws or regulations and does not replace legal analysis.