Summary:
In order to submit your institution's texting campaigns through Twilio, we need a few compliance pieces in place on your end first. Twilio, like all messaging platforms, must register every business texting campaign under a carrier framework called A2P 10DLC, which exists to confirm that your texts are sent to people who've actually agreed to receive them.
As part of that registration, Twilio now requires us to submit a direct link to your institution's privacy policy and terms and conditions—as of June 30, 2026, these need to be active, publicly accessible URLs rather than general descriptions. Your privacy policy also needs to explicitly state that students' mobile information won't be shared or sold to third parties for marketing purposes; this is one of the most common reasons campaigns get rejected when it's missing.
Twilio also has specific rules around how consent itself must be collected: opt-in must be explicit, with checkboxes that aren't pre-checked, and must include a clear "message and data rates may apply" disclaimer. Implicit consent, such as an existing relationship with a student, isn't sufficient on its own for promotional or marketing-style texts—explicit opt-in is required. Below, we'll walk through exactly what needs to be included in your consent message, privacy policy, and terms and conditions so we can get your campaign approved without delays
In this article:
Requirements and Examples
Consent / Opt-in
Required CTA disclosures for web-form opt-in include: program description, brand identity, fees ("Message and data rates may apply"), message frequency, HELP/STOP details, and links to both the Privacy Policy and Terms & Conditions.
Your consent language must include:
- Opt-in Keywords: START, YES, JOIN, OPTIN
- Program description (what they're signing up for)
- Message frequency (how often they'll get texts - you may say message frequency varies)
- "Message and data rates may apply"
- Clear opt-out instructions ("Reply STOP to opt out")
-
Link to compliant privacy policy
-
Privacy policy must state:
- "No mobile information will be shared with third parties/affiliates for marketing/promotional purposes"
- Information sharing only permitted for customer service subcontractors
- Text messaging opt-in data will not be shared with third parties
-
Privacy policy must state:
Here is an example of an accepted Opt-in:
Consent needs to be voluntary. If customers have to opt-in to messaging to complete a purchase or create an account, your registration will be rejected. Here's what that means in practice:
- Users can't be required to opt-in as a condition for completing unrelated actions (creating an account, making a purchase, or accessing services).
- Messaging consent must be separate from terms of service, privacy policies, or other agreements.
- Consent controls (checkboxes, toggles) must be blank or off by default.
| This works | This doesn't |
| ☐ "Yes, I'd like to receive text alerts about my order" (Unchecked by default, voluntary) | ☑ "I agree to receive text messages" (Pre-checked box) |
| Separate checkbox for SMS consent, distinct from Terms of Service agreement | "By agreeing to our Terms of Service, you consent to receive promotional messages" (Consent bundled with ToS) |
| "Add my mobile number for delivery updates (optional)" | "Phone number required to complete purchase" with mandatory SMS opt-in |
| Separate opt-in for order updates vs. marketing messages | Single opt-in that enrolls customer in both transactional AND marketing campaigns |
Privacy Policy
This is one of the most critical and commonly overlooked requirements. Twilio has introduced new fields during U.S. A2P 10DLC Campaign registration: a Privacy Policy URL and a Terms & Conditions URL — both must be valid, publicly accessible links.
What the privacy policy must specifically say:
Even if the current policy does not contain any language around data sharing, the privacy policy must confirm that the mobile information of the end user opting in to the message program will never be shared or sold to third parties or lead generators — absence of such language is a major source of 10DLC rejection. The privacy policy must be easily accessible through a clearly labeled link in the initial call-to-action, or a declaration in the initial call-to-action that mobile opt-in data will not be shared. An example declaration: "No mobile data will be shared with third parties/affiliates for marketing/promotional purposes at any time."
So the university's existing privacy policy is likely not enough on its own — it must be checked to confirm it explicitly covers SMS/mobile data sharing.
Terms & Conditions
The Terms & Conditions page must be publicly accessible at a stable URL and should at a minimum include:
- what the texting program is
- who is sending
- message frequency
- how to opt out (STOP)
- how to get help (HELP)
- and the "Message and data rates may apply" disclaimer
HINT: Your privacy policy and terms and conditions can live at the same URL, as long as both are clearly included on the page.
Additional Resources
- Texting Policies and FAQs
- Have questions? Contact us via support@pharosresources.com
Comments
0 comments
Please sign in to leave a comment.