Text-Message Marketing: Complying with the law
Text-message marketing has become part of the everyday retail playbook.
Loyalty reminders, abandoned-cart prompts, back-in-stock alerts, store event notices, curbside pickup updates, limited-time offers and personalized outreach all depend on a channel that is immediate, visible and comparatively inexpensive.
While texting is now pervasive, the legal rules governing that infrastructure are still catching up. The Telephone Consumer Protection Act (TCPA) is a federal statute that restricts certain calls, texts, and other communications made without the required consent.
Although enacted in 1991, long before today’s mobile-first retail environment, the law has become a significant source of potential liability for companies using automated outreach, prerecorded or artificial voices, and marketing text messages.
For retailers, the TCPA can cover several common forms of customer outreach, including:
•limits on certain automated or prerecorded calls to cell phones;
•limits on artificial or prerecorded voice calls to residential lines; and
•compliance with Federal Communications Commission rules protecting residential subscribers from unwanted telephone solicitations, including do-not-call protections.
Although these restrictions can overlap within a single marketing campaign, they regulate different conduct and can create distinct compliance risks.
Two Decisions, Two Different Results
Two federal appeals court decisions issued in 2026 underscore how differently courts may treat text messages under the TCPA. Although both decisions produced favorable outcomes for the defendants, neither gives retailers a blanket exemption from the law. Instead, they illustrate how the content, technology, and legal theory behind a claim can determine the result.
In January, the Ninth Circuit considered a text message containing written text and an automatically downloaded video file. The video allegedly included an artificial or prerecorded voice, but it did not play automatically. The recipient had to tap the thumbnail or play button before hearing the audio.
The court affirmed dismissal of the case, concluding that the message was not initiated “using” the recorded voice because the recipient had to take an additional step (click “play”) to play the video and hear the audio.
For retailers, the takeaway is that the way multimedia content is delivered is important. A video that remains silent unless a customer chooses to play it may be treated differently from audio that begins automatically when the customer opens the text message. Retailers using videos or other rich-media content should therefore consider not only what a message contains, but also how a consumer experiences it.
A July decision from the Seventh Circuit addressed a different TCPA situation. There, consumers alleged that they received unwanted marketing texts and calls and that the outreach continued even after they asked not to be contacted. Their claims relied on a TCPA provision allowing a private lawsuit when someone receives more than one unwanted “telephone call” within a 12-month period.
The court concluded that unwanted text messages were not “telephone calls” under that particular provision because, when the TCPA was enacted in 1991, a telephone call was commonly understood as communication by sound. The ruling narrowed one possible path for private lawsuits involving texts, but it did not eliminate the broader compliance risks surrounding text-message marketing.
The court acknowledged that federal do-not-call protections have been extended to text messages under another part of the law and noted that unwanted texts may still be addressed through agency enforcement or other TCPA provisions.
For retailers, the two decisions highlight an important distinction: A court’s ruling that a particular text does not violate one TCPA provision does not necessarily mean the message is permissible under every provision.
Retailers Need to Build Compliance Into the Campaign
For retailers operating nationwide, the result is an uneven legal landscape. The same text campaign could face different challenges depending on the federal circuit where the action is filed, the technology used. and the specific TCPA provision at issue. All of this makes advance compliance planning especially imperative before a campaign launches.
Useful guardrails for text messaging programs may include:
•Using clear language when requesting a customer’s consent;
•Maintaining reliable records showing when and how the customer opted-in;
•Providing simple and conspicuous opt-out instructions;
•Processing STOP and other opt-out requests promptly; and
•Using suppression systems to prevent further messages after consent has been withdrawn.
Know What Your Vendors Are Doing
Vendor management is equally important because many retailers rely on outside platforms, agencies, lead generators, loyalty-program administrators, and data partners to run messaging programs at scale. Risk can increase when consent is collected by one party, stored by another, and acted on by yet another.
Retailers should monitor:
•How and when a customer’s number entered the system;
•What the customer was told when providing the number;
•Where and for what purposes that number is being used; and
•Whether an opt-out request is honored across every relevant platform and vendor.
Vendor contracts can reinforce that oversight by addressing consent records, timely opt-out processing, list maintenance, audit rights, indemnification, and approval requirements for campaigns that may present greater risk.
A Changing Law for a Changing Channel
The TCPA was written for communications in a different era, and retail customer engagement has changed dramatically since then. Today, brands connect with customers on mobile devices, often in real time and across multiple platforms.
Text messaging remains one of the most effective ways to reach consumers, but it currently sits at the intersection of outdated statutory language, evolving technology, and active litigation.
The recent TCPA decisions provide retailers useful guidance and, in specific circumstances, potential defenses. They also demonstrate why businesses should not assume that all text messages, technologies, or TCPA claims will be treated alike.
By pairing effective customer outreach with documented consent, dependable opt-out procedures, and careful vendor oversight, retailers can place themselves in a stronger position as the legal landscape continues to develop.
Roma Patel is an associate at Robinson+Cole — an AM Law 200 law firm — on the data privacy + cybersecurity team.


