Restaurant SMS Compliance and Legal Requirements
Restaurants face millions in liability by conflating transactional and marketing consent in texts.

Text message marketing moves more revenue per dollar spent than almost any channel a restaurant has, but the rules governing it come from three separate systems that don't talk to each other and don't fail the same way. Miss where they overlap and a program built to fill seats starts generating legal exposure instead. This piece maps the overlap, and it takes a position most compliance guides dodge: the single biggest source of exposure isn't a missing opt-out button or a badly timed 3 a.m. text. It's the assumption that one signup covers every message that comes after it, and that assumption is where the rest of this piece keeps returning.
Start with enforcement, because it explains why operators tend to underestimate this until it's too late. A TCPA violation shows up as a lawsuit, sometimes a class action, months after the message went out. A CTIA violation shows up immediately but invisibly: the message just doesn't land, and nobody tells you why. An unregistered 10DLC campaign gets filtered the same way, silently, no matter how airtight the consent language is. Three failure modes, three timelines, and one operator responsible for tracking all three while also running a kitchen.
The money side isn't hypothetical, either. TCPA litigation filings surged 95% in 2025, and 2026 is tracking roughly 27% ahead of that pace. Kaiser Permanente settled for $10.5 million, SiriusXM paid $28 million, Zales Jewelers landed at $7.5 million. None of those are restaurants, and that's worth sitting with: this is what non-compliance costs organizations with legal departments and compliance officers on payroll, full-time. A restaurant with a modest list of 10,000 contacts, running one non-compliant campaign, carries theoretical exposure of $5 million to $15 million under TCPA's per-message damages structure. That's a number that can end a business.
Everything below, the registration process, the carrier rules, the state add-ons, sits on top of that one bad assumption about consent. Fix the foundation first.
How the TCPA applies to a restaurant's texting program, specifically
The TCPA, codified at 47 U.S.C. § 227, is the federal floor. It sets damages at $500 per unsolicited text, rising to $1,500 per message for violations found willful, and it's enforced mostly through class-action litigation rather than a government agency knocking on the door. Class actions are the mechanism because the math is simple: a plaintiff's attorney doesn't need one big injury, just a list of a few thousand people who got the same non-compliant text at the same time.
Four things every restaurant SMS program has to get right. Prior express written consent has to exist before a single marketing text goes out. Opt-out processing needs to work so STOP or UNSUBSCRIBE pulls the guest off every marketing list immediately and triggers exactly one confirmation message, not three. Quiet-hours compliance means sends only between 8 a.m. and 9 p.m. in the recipient's local time zone, not the restaurant's. And the program has to steer clear of SHAFT content, meaning sex, hate, alcohol, firearms, tobacco: categories both the law and the carriers restrict. A2P 10DLC registration sits on top of all four, and it gets its own section below because it deserves one.
Here's where restaurants specifically get into trouble: nearly every touchpoint that collects a phone number is also a consent event, whether anyone treats it that way or not. Reservation forms, waitlist iPads, loyalty kiosks, paper comment cards, the online ordering checkout page all qualify. Each one is a moment a court could later ask about: what, exactly, did this person agree to?
That question matters because transactional consent and marketing consent are legally distinct categories, even though restaurants collapse them into a single checkbox constantly. A guest who texts in to join the waitlist has agreed to get a text about their table. They have not agreed to get a promotional offer about discounted margaritas the following Tuesday. Treating those as interchangeable is the single most common way restaurant texting programs end up on shaky ground, and it happens because the checkbox is convenient, not because anyone thought it through. This is the most consequential assumption in the whole compliance picture, the idea that one signup equals blanket permission. Most of the actual legal exposure lives in that gap, between what operators assume and what the law requires.
So confirm consent properly, with a reply-Y SMS that logs a timestamp, an IP address, and the source channel it came from. Keep that proof for at least four to five years; five is the safer number if sources disagree. And name the actual business in the disclosure. "Our partners may contact you" is vague phrasing that's technically defensible under some readings and has still attracted a steady stream of litigation, because vague language is exactly what a plaintiff's attorney goes looking for.
Worth flagging: the one-to-one consent rule that briefly threatened to reshape all of this. The FCC proposed a rule requiring separate, individual consent for each sender on a shared list. The 11th Circuit vacated it in January 2025, and the FCC formally scrapped the rule later that year. Net effect: a single opt-in can now cover multiple senders, as long as the disclosure clearly names them. Restaurants sharing subscriber lists with delivery apps or loyalty aggregators should still audit that disclosure language, because "clearly named" is doing a lot of work in that sentence.
Two keywords carry specific legal weight. HELP has to return a message naming the business and giving a customer service contact; that's not optional garnish. START re-subscribes someone who previously opted out, but only through fresh affirmative consent, since prior consent doesn't carry forward. Once someone's out, they're out until they opt back in on their own terms.
What A2P 10DLC registration requires and how to complete it
Application-to-Person, or A2P, messaging is any text sent from a platform or piece of software to a person, which covers essentially every marketing text, reservation reminder, and loyalty alert a restaurant sends through an SMS tool. Standard 10-digit long codes used for A2P messaging now require 10DLC registration regardless of volume. A restaurant sending 200 texts a month and one sending hundreds of thousands face the identical requirement, which surprises smaller operators who assume the rule scales with size. The smallest operators, the ones with the thinnest compliance staff, are the ones most likely to skip registration on the assumption it's a big-chain problem. That assumption is backward: the big chains have legal teams checking this. The independents don't, and they're the ones most exposed.
Why care beyond the legal box-check? Because carriers treat unregistered traffic as probable spam by default, and filter or block it accordingly. A restaurant can have flawless, complete TCPA consent on file for every subscriber and still watch its messages vanish into the carrier network if registration is missing. Registration is, functionally, how carriers verify the sender isn't a spoofed number running a scam. Skipping it doesn't speed anything up; it just makes the program invisible, a quieter failure than a lawsuit but one that leaves the operator with far less information about what actually went wrong.
The process runs in two steps. Brand registration comes first: the restaurant registers its legal business identity through The Campaign Registry, the centralized U.S. database that carriers and platforms both check against. Campaign registration comes second, specific to the use case: promotional offers, loyalty program, reservation reminders, each described separately, including message content and how consent was collected. Both steps run through the restaurant's Campaign Service Provider, the SMS platform doing the actual sending. Twilio, Bandwidth, and Infobip all function as CSPs in this system, among others.
This is not a one-time errand. Registrations expire after 12 months and need annual renewal, meaning re-submitting brand and campaign details for re-approval. This is the compliance gap that catches restaurants constantly: someone sets up registration once, the messages start flowing, and eleven months later nobody remembers it needs to happen again. Deliverability quietly drops and the first instinct is to blame the SMS platform, when the actual problem is a lapsed registration sitting unnoticed.
One more wrinkle worth checking before assuming coverage: a restaurant running multiple distinct programs, say a loyalty text list and a separate reservation reminder flow, may need separate campaign registrations for each one. Don't assume one registration blankets every use case. Ask the CSP directly, in writing, and get the answer before launch rather than after deliverability tanks.
CTIA guidelines and why carrier compliance determines whether your messages arrive
CTIA sets the messaging principles carriers actually enforce at the network level, and that's a fundamentally different mechanism from a statute enforced through litigation. This is the distinction that trips people up: TCPA violations produce fines and lawsuits after the fact, while CTIA violations produce filtering and blocking before the fact, with the harm showing up as bad deliverability numbers rather than a legal notice. A restaurant can be perfectly TCPA-compliant on paper and still have its messages suppressed at the carrier level for a CTIA violation nobody flagged. It's a quiet failure mode, one that can end a texting program without anyone ever getting sued.
What does CTIA actually require, in practice? Clear opt-in disclosure at the point of consent, spelling out what program the subscriber is joining, roughly how often they'll hear from you, the standard message-and-data-rates line, and how to opt out. Consistent keyword behavior for STOP, HELP, UNSUBSCRIBE, and START, matching everything laid out under TCPA, except now a carrier enforces it instead of a court. Message content that actually matches the registered campaign use case: a restaurant registered for "loyalty program messages" sending an unrelated flash-sale blast is exactly the kind of mismatch that gets flagged. And no deceptive content, no misleading sender ID.
The practical upshot: that little auto-reply confirmation text sent the moment someone joins a list is doing double duty. It's a TCPA best practice and a CTIA requirement at the same time, and it should name the program, confirm enrollment, state how often messages go out, and include opt-out instructions, all in one short text.
CTIA also backs up the SHAFT restriction, and restaurants run into this more than most industries, because a routine happy-hour promotion happens to reference alcohol. Carriers can filter alcohol-adjacent content without an age gate, no warning issued first. Some operators route those promotions through a separate opt-in flow that collects date-of-birth confirmation, creating an age-verified segment that can receive the margarita specials without tripping the filter. Treat that as the standard, not the exception. Hoping the carrier doesn't notice is the approach most likely to backfire, and it's the approach a surprising number of restaurants still take, mostly because nobody's told them otherwise.
State-level rules that add obligations on top of the federal floor
TCPA and CTIA set the national baseline. States keep stacking their own layer on top, often called "mini-TCPA" statutes, and the trend points toward more of these arriving rather than fewer. That makes state law the least stable part of this whole framework, the piece most worth re-checking next year even if nothing else moves.
California carries the most direct bite for restaurants right now. If a subscriber list includes California residents, and for most restaurants it will, the CCPA layers on disclosure requirements around the sale or sharing of personal information, phone numbers included. A restaurant handing subscriber data to a third-party loyalty aggregator or marketing platform can trigger CCPA's definition of a "sale," which requires an opt-out mechanism beyond a standard STOP reply. Worth asking directly: does the platform vendor's contract actually address this, or is the restaurant assuming coverage that was never written down anywhere?
EU and UK exposure is rarer for a single-location independent, but not zero, particularly for restaurants marketing internationally or collecting numbers through a web-based reservation system that doesn't check where the guest is booking from. GDPR requires a lawful basis for processing a phone number, gives the subscriber rights to access, delete, and port their data, and demands consent language that doesn't map cleanly onto U.S. standards. That framework sits alongside 10DLC compliance rather than replacing it. A restaurant with even a handful of EU or UK subscribers should treat GDPR as additive, not optional.
For anyone running multiple locations, skip the temptation to calibrate consent flows market by market. Build to the strictest jurisdiction that applies anywhere in the footprint instead, full stop, even though it's less elegant. Nobody has to remember which state's rules apply to which store, which matters more than elegance once the list crosses a few thousand names. And across all of it, the retention number to hold onto is five years: keep consent records that long and the restaurant can defend against a challenge under essentially any applicable standard, state or federal.
Building the opt-in flow: what compliant consent collection looks like at each restaurant touchpoint
Every phone number collected is a potential consent event, and every collection method carries a different risk profile. The legal standard doesn't change by channel, but the practical risk changes a lot. Worth walking through touchpoint by touchpoint instead of treating consent as one uniform box to check.
Web-based sign-up forms, whether it's loyalty enrollment, a newsletter, or the online ordering checkout, need an unchecked-by-default SMS consent box. A pre-checked box is easy for a guest to miss, and a court will treat that oversight as the restaurant's problem, not the guest's. The disclosure language needs to sit right next to the phone number field, not three clicks deep in a privacy policy nobody reads. Required elements: program name, roughly how often messages will come, the "message and data rates may apply" line, and opt-out instructions.
In-restaurant collection, iPads at the host stand, loyalty kiosks, paper comment cards, faces the same disclosure bar. The medium doesn't lower the standard. Paper cards deserve a hard look here: skip them if there's any other option. There's no automatic timestamp, no IP capture, and someone has to manually digitize the record later, by hand, at risk of transposing a digit. That's the highest-risk collection method on this entire list, full stop. Kiosk and iPad flows should be built so the screen physically cannot advance without a deliberate opt-in tap, not a default state the guest has to notice and undo.
Keyword opt-in, texting JOIN to a short code or long code, carries the lowest friction of the group. Consent gets captured the instant the keyword lands, and the auto-reply confirming enrollment needs every disclosure element right there in that first response. Timestamp and source channel log themselves automatically, a built-in advantage paper cards can't match.
Reservation platforms deserve their own callout, because this is where restaurants assume coverage they don't actually have. A guest who books through OpenTable or Resy or a similar platform has consented to that platform's terms. They have not consented to the restaurant's marketing list, even though the restaurant now has their number sitting right there in the reservation system, one export away from a campaign. That number needs its own separate opt-in step before it lands on any marketing list. Skipping that step, treating the reservation number as marketing-ready, is one of the most common ways restaurants end up texting people who never agreed to hear from them. It's the same mistake from the TCPA section in a new setting: one signup, assumed to cover everything downstream of it.
Across every channel, the confirmation text is the connective tissue: an auto-reply that restates the program name, confirms enrollment, states frequency, and includes STOP instructions. That single message does triple duty: a double-opt-in step, a timestamped proof record, and CTIA's confirmation requirement, all in one text. And whatever channel the number came through, the same four data points need logging and storage for at least five years: timestamp, source channel, the exact disclosure language the person saw, and the specific affirmative action they took.
Running a compliant ongoing SMS program: message cadence, content rules, and list hygiene
Compliance doesn't stop once someone opts in. Every message sent afterward has to independently clear the same TCPA, CTIA, and carrier bars laid out above, message by message, indefinitely, with no grace period for a program that used to be compliant.
Sending windows come first. Messages go out between 8 a.m. and 9 p.m. in the recipient's local time zone, not wherever the restaurant sits. That distinction matters for any restaurant near a metro area or interstate corridor, since the subscriber list probably spans more than one time zone even for a single-location operation. Most SMS platforms support time-zone-aware scheduling; the failure mode isn't that the feature doesn't exist, it's that nobody turned it on.
Content rules apply to every send, no exception carved out for a genuinely good campaign idea. SHAFT still applies, meaning that happy-hour text is still alcohol content and still needs the age-gating or verified-segment treatment described earlier. Message content has to match whatever campaign type got registered under 10DLC; a flash-sale promo sent from a number registered for "loyalty program updates" is a mismatch carriers can and do act on. And every marketing message needs a visible opt-out line, "Reply STOP to unsubscribe," either in the body or as a consistent footer. Consistent is the operative word: if the footer's format drifts from campaign to campaign, that's an inconsistency a carrier's automated review can catch and flag.
Opt-out handling is the one part of this framework with zero room for creative interpretation, and it's worth being blunt about that: there is no acceptable version of getting this wrong. STOP, UNSUBSCRIBE, QUIT, CANCEL, and END all trigger immediate removal from every marketing list, plus exactly one confirmation reply. No follow-up texts asking if the guest is sure, no delay while someone manually processes the request. Immediate, automatic, done. It's the simplest rule in the whole system, and also the one that costs the most when ignored, because a failed opt-out isn't a filtering problem or a lapsed registration. It's a fresh unsolicited text sent to someone who already asked to leave, and that's the exact fact pattern a class action gets built from.


