← All postsCompliance & Law

Recordkeeping for Text Compliance, What to Keep and How Long

If a TCPA complaint or a carrier audit arrives, the question is always the same: can you prove it? Your compliance records are the entire answer, and a campaign that can produce them is defensible while one that can't is exposed, regardless of how careful it actually was. Here's what to keep and for how long.

What records does a campaign have to keep?

Three things, each tied to a specific phone number with a timestamp:

  • The opt-in. When and how each contact consented, the event, the method, and what they agreed to receive.
  • The sends. What messages went to which numbers and when.
  • The opt-outs. Every STOP or human-worded opt-out, and proof you honored it.

The through-line is attribution: every record should point to a specific number at a specific moment. A vague "we had consent" is worth nothing; "this number opted in via this form on this date" is a defense.

How long do you keep it?

At least four years. The TCPA's window makes four years the practical floor, so retention should be automatic and durable, not a folder someone maintains by hand. Build it so the platform captures and keeps the record as a matter of course, because the one time you need it, reconstructing it after the fact isn't an option.

Why does the record matter more than being careful?

Because in a dispute, careful is invisible and the record is everything. A campaign can run a genuinely clean program and still lose if it can't show the receipts, and a plaintiff's lawyer isn't interested in how good your intentions were. The record turns your compliance from a claim into evidence. This is the same principle behind consent and opt-out handling: do it right, and log that you did.

Frequently asked questions

How long do you have to keep text consent records?

At least four years, tied to the TCPA's window. Keep the opt-in, the sends, and the opt-out for each number, with timestamps.

What counts as a good consent record?

One attributable to a specific number and moment: the opt-in event, the method, and what the person agreed to. A general "we had consent" isn't enough.

Who's responsible for keeping the records?

You, the sender. Even if a platform stores them, the compliance responsibility sits with the campaign, so make sure retention is automatic and you can produce it.

Keep reading: the complete TCPA guide and handling opt-outs the right way. For the rules, see the FCC.

This is general information, not legal advice, current as of the date above.

TaggedrecordkeepingTCPAconsentopt-out

Every message runs the compliance checks before it leaves.

Get started