The short answer: keep SMS opt-in records for at least four years after your last message to that subscriber, and keep opt-out records permanently. The four-year floor comes from the statute of limitations that federal courts apply to TCPA claims, the catch-all limitations period in 28 U.S.C. 1658. Because the burden of proving consent falls on the sender, not the recipient, your consent records are your defense file: if a claim arrives in year three and you purged the record in year two, you are defending a lawsuit with nothing in your hands. This article answers the retention questions organizations actually ask, in FAQ form.

Why Four Years Is the Baseline

The TCPA (47 U.S.C. 227) does not contain its own statute of limitations, so courts apply the general federal catch-all period of four years under 28 U.S.C. 1658. That means a recipient can file suit up to four years after a message was sent, seeking statutory damages of $500 per violation and up to $1,500 per willful violation. When that happens, the legal question is almost always "did the sender have valid consent?", and courts and the FCC's rules (47 CFR 64.1200) place the burden of demonstrating consent on the sender. The practical consequence: any message you sent in the last four years may need a consent record behind it, so the record must outlive the message by the full limitations window. For the deeper legal background, see our guide to the TCPA statute of limitations.

Four years is a floor, not a ceiling. Timing arguments (when the clock starts, whether later messages restart it, how class actions affect the window) can extend practical exposure, which is why many compliance teams standardize on five years or simply retain consent records for the life of the subscriber relationship plus four years.

Retention Rules at a Glance

Record TypeMinimum RetentionWhy
Opt-in records (form submissions, signed forms, keyword logs, confirmation replies)4 years after the last message to that subscriberTCPA claims can be filed within the 4-year catch-all limitations period of 28 U.S.C. 1658, and the sender bears the burden of proving consent
Opt-out (STOP) recordsPermanentYou must be able to prove you honored a revocation, and the number must stay suppressed even if the person reappears on a future list
Disclosure language versions (what the form or ad actually said)As long as any opt-in captured under that version is retainedConsent is only as good as the disclosure it was based on; you must show what the subscriber saw
Message content and delivery logs4 years recommendedShows what was actually sent, whether it stayed within the consented scope, and when the last message went out
Do-not-call and internal suppression list entriesPermanentSuppression only works if the list never forgets
Records subject to other regimes (HIPAA programs, public agencies)Per the applicable regime if longerHIPAA (45 CFR Parts 160 and 164) documentation rules and state public records laws can impose their own schedules on top of the TCPA baseline

What Exactly Should an Opt-In Record Contain?

Retention length matters only if the record itself can carry your burden of proof. A complete opt-in record includes:

  • The phone number and, where collected, the subscriber's name.
  • The date and time of the opt-in, to the second.
  • The capture source: which web form and URL, which keyword and campaign, which paper form or event.
  • The exact disclosure language displayed at capture, version-controlled, since forms change over time and you must show what this subscriber agreed to.
  • The affirmative act: checkbox state and submission log, signature image, or the inbound keyword message itself.
  • Supporting metadata: IP address for web opt-ins, the confirmation (double opt-in) reply if used, and the welcome message you sent back.

The full list of what to store, and the parallel rules for message logs, is covered in our companion piece on SMS records retention requirements.

Organizing Records So You Can Actually Use Them

Retention is only half the job; retrieval is the other half. A consent archive you cannot search under deadline pressure is functionally the same as no archive. Structure the records around the phone number as the primary key, so that a single lookup returns the complete story for any subscriber: every opt-in event with its disclosure version, every message sent, every STOP or HELP interaction, and the current suppression status. Store the disclosure language library separately, version-numbered and dated, and reference versions from subscriber records instead of pasting the text into each one; this keeps the archive small and makes it trivial to prove exactly what a form said on a given date.

Run a quarterly retrieval drill: pick a handful of random subscribers and time how long it takes to assemble each one's full consent file. If the answer is hours of cross-referencing between a form tool, a spreadsheet, and a messaging platform export, consolidate before a dispute forces you to. Litigation holds are the other operational wrinkle: if you receive a demand letter, a complaint, or a credible threat of a claim, suspend all scheduled deletion for the affected records immediately, even if your normal schedule would have purged them.

Vendor Changes and Data Portability

Consent records frequently live inside a texting platform, and platforms get replaced. Before closing any vendor account, export the complete consent and suppression dataset (opt-ins with timestamps and sources, message logs, opt-outs) and verify the export actually contains the disclosure and consent fields, not just the contact list. Migrating only the phone numbers is a classic failure: the new platform has a list, but the proof that anyone consented stayed behind in a deactivated account. Treat the consent archive as your organization's property and make export capability a requirement in any platform evaluation.

Two Timing Questions That Decide Your Schedule

Does the four-year clock start at opt-in or at the last message?

Count from the message, not the opt-in, because that is what a claim would actually be about. The limitations period runs from each allegedly unlawful message, and every text you send within the scope of a consent may need that consent produced as evidence. So the safe rule is: retain the opt-in record until four years after the final message sent in reliance on it. A subscriber who opted in six years ago but received a message last month still needs their consent record on file for four more years.

What about subscribers who opt out?

Keep both halves forever, or at minimum keep the opt-out permanently and the opt-in for four years after the final message. The opt-out entry proves you honored the STOP request from the moment it arrived; the opt-in record proves the messages before the STOP were lawful. Deleting a number from your database entirely is the worst option, because the suppression disappears with it and a future list import could re-message someone who revoked.

This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.

Frequently Asked Questions

How long should you keep SMS opt-in records?

At least four years after the last message sent to that subscriber, matching the four-year federal catch-all statute of limitations (28 U.S.C. 1658) that courts apply to TCPA claims. Many organizations retain them for five years or for the life of the relationship plus four years as a margin of safety.

Who has to prove consent in a TCPA dispute?

The sender. Consent is treated as the sender's defense to raise and support, so the organization that sent the message must produce evidence that valid consent existed when the message went out. If the record was purged or never captured, the practical result is usually the same as having no consent at all.

Should opt-out records be deleted after a retention period?

No. Opt-out and suppression records should be kept permanently. They are your proof that a STOP was honored, and they prevent re-messaging a revoked number if it later appears in an imported list or a new campaign. Opt-out entries are small; there is no storage argument for purging them.

Do platform message logs count as consent records?

Only partially. Delivery logs show what you sent, but consent proof requires the capture side: the disclosure language, the timestamp, and the subscriber's affirmative act. If your texting platform holds the logs and a separate form tool holds the opt-ins, export and consolidate regularly; if you ever switch vendors, migrate the consent archive before the old account closes.

Do HIPAA or public records laws change the retention answer?

They can lengthen it, never shorten it. HIPAA's documentation rules (45 CFR Parts 160 and 164) impose their own multi-year retention on compliance documentation for covered entities, and messages sent by government agencies may be retainable under state public records laws on separate schedules. Apply the longest applicable requirement to each record.

Consent Records That Keep Themselves

FRANSiS logs every opt-in, confirmation reply, and STOP automatically, with timestamps, source, and the disclosure version attached to each subscriber, so your four-year evidence file builds itself while the AI Powered Helper handles the conversations. Contact us to put your consent records on autopilot.