Blog: Legal Requirements

Page 1

The 2025 TCPA 'Any Reasonable Means' Opt-Out Rule Explained

As of April 2025, the Federal Communications Commission (FCC) requires businesses to honor opt-out requests made through "any reasonable means" under the Telephone Consumer Protection Act (TCPA). The TCPA is a 1991 US federal law that regulates marketing calls and text messages sent using automated systems or prerecorded voices. The FCC...

GDPR Article 30: How to Create Your Record of Processing Activities

A Record of Processing Activities, or ROPA, is a written document that lists every way your business collects, uses, stores, shares, and protects personal data. Under Article 30 of the GDPR, almost every company operating in or targeting the EU needs one, whether you have 250 employees or just five. Article...

TCPA Compliance for SMS Marketing: How to Avoid Fines

Businesses can avoid Telephone Consumer Protection Act (TCPA) fines by taking steps such as providing disclosures, honoring opt-out requests, and getting express written consent before sending Short Message Service (SMS) marketing texts. This article explains what the TCPA is, whether it applies to SMS messages, the differences between how SMS messages...

How to Get Legal Consent for SMS Marketing (TCPA Express Written Consent Guide)

To send marketing (advertising/telemarketing) SMS in the U.S., you generally need "prior express written consent" when the texts are sent using automated technology covered by the TCPA and FCC rules. For purely informational/transactional texts (e.g., appointment reminders), the consent standard is typically "prior express consent" (not written), as long as the...

Vendor Management for GDPR: How to Audit Your Third-Party Tools

Organizations that rely on third-party tools to handle personal data should audit vendors to meet the European Union's (EU) General Data Protection Regulation (GDPR) requirements. This article explains what the GDPR is, why organizations are liable for vendor noncompliance, and how to conduct a GDPR vendor audit to reduce compliance risk. What...

The Hidden Contract Risk of Privacy Policies: When Disclosures Become Enforceable Promises

Courts are increasingly treating Privacy Policies as enforceable promises, not just regulatory notices. If your policy says you will not share data, will delete it after one year, or will encrypt it at rest, a judge may treat those statements like contract terms or warranties and hold you liable if...