Executive Summary
Consumers need to understand how often a brand will text them. A message frequency disclosure—whether “up to 4 messages per month” or “message frequency varies”—is a core element of clear opt-in calls-to-action, confirmation texts, and privacy/SMS terms pages. Carriers and CSPs look for frequency language in Campaign materials and public policies; CTIA best practices expect recurring programs to describe frequency in confirmation messages. This guide explains how to choose wording, where to place it, how it interacts with “Msg & data rates may apply,” common mistakes, and an implementation checklist—without inventing a single mandatory federal phrase that covers every program.
Short answer: Include a clear message frequency disclosure at opt-in and in recurring-program confirmations. Use a numeric range when your cadence is stable; use “message frequency varies” when volume depends on account activity—and explain the pattern in your TCR message_flow. Pair frequency language with Brand identity, message types, rates, STOP, and HELP.
Who This Is For / Who It Is Not For
Who this is for
- Marketing and compliance drafting SMS CTAs
- Product teams building preference centers
- Anyone fixing privacy-policy rejections tied to missing frequency language
- CSPs’ customers preparing Campaign packets
Who this is not for
- Teams seeking one magic sentence that immunizes against all TCPA claims
- Non-SMS push/email frequency policies (different channels)
Definitions
| Term | Meaning |
|---|---|
| Message frequency disclosure | Statement of how often SMS will be sent |
| Frequency varies | Flexible cadence disclosure when volume is event-driven |
| Numeric frequency | Fixed upper bound (e.g., up to X msgs/month) |
| Confirmation message | Post-opt-in SMS restating program terms |
| Call-to-action (CTA) | Invitation to opt in with disclosures |
| Recurring program | Ongoing SMS relationship vs one-time text |
Why Frequency Disclosure Matters
CTIA Messaging Principles state that after opt-in to recurring messaging, confirmation messages should include a clear description of how to opt out and disclose that messages are recurring and the frequency of messaging, among other elements. Twilio’s guidance for web opt-in privacy policies includes message frequency alongside rates and mobile-number non-sharing themes (collect business info).
Missing or misleading frequency language creates:
- Campaign vetting friction
- Consumer distrust and higher STOP rates
- Harder defense when someone claims surprise at volume
Related: Msg & data rates disclosure.
Choosing Numeric vs “Frequency Varies”
| Pattern | Best when | Example |
|---|---|---|
| Numeric cap | Stable newsletter or weekly tips | “Up to 4 msgs/month” |
| Per-event | Appointments, deliveries, fraud alerts | “Frequency varies based on your appointments” |
| Hybrid | Account alerts + optional promo | Separate disclosures per program |
Do not say “up to 4/month” if you routinely send 20. Truthfulness beats clever brevity.
Placement Map
| Surface | Include frequency? | Notes |
|---|---|---|
| Web opt-in CTA | Yes | Near unchecked box / phone field |
| Keyword opt-in reply | Yes in confirm | Program enroll confirm |
| Privacy Policy SMS section | Yes | Especially if web opt-in |
| SMS Terms page | Yes | Helpful for reviewers |
| Periodic reminders | Optional refresh | Especially after cadence changes |
| TCR message_flow | Yes | Explain real pattern |
Example Disclosures (Illustrative)
Stable marketing
Msg frequency: up to 4 msgs/month. Msg & data rates may apply. Reply STOP to opt out, HELP for help.
Appointment-driven
Message frequency varies based on your appointments (typically 1–3 texts per visit). Msg & data rates may apply. STOP to opt out, HELP for help.
Account alerts
Frequency varies with account activity (e.g., login alerts, deliveries). Msg & data rates may apply. Manage alerts at [URL]. STOP to opt out.
Confirmation SMS bundle
You’re subscribed to [Brand] [Program]. Frequency: [disclosure]. Msg & data rates may apply. Reply HELP for help, STOP to cancel.
Decision Framework
- Measure actual historical cadence per program.
- Pick numeric vs varies (honestly).
- Write CTA + confirmation + privacy snippets consistently.
- Put the same story in TCR message_flow.
- If marketing and alerts differ, disclose separately—do not blend.
- Re-review when product launches increase volume.
- QA that production automations cannot exceed disclosed numeric caps without UX change.
Requirements Matrix
| Element | Weak | Strong |
|---|---|---|
| CTA frequency | Missing | Present + accurate |
| Privacy policy | Generic privacy only | Dedicated SMS section with frequency |
| Confirmation SMS | “Thanks” only | Full program terms incl. frequency |
| Message_flow | “Users opt in online” | Describes typical monthly/event volume |
| Multi-program | One vague line | Per-program disclosures |
Risk and Failure Modes
| Risk | Failure | Mitigation |
|---|---|---|
| Under-disclosure | Consumers shocked by volume | Align ops with copy |
| Over-promising low frequency | Breach of numeric cap | Cap engines or change copy first |
| Copy inconsistency | CTA vs privacy disagree | Single source of truth snippet |
| Buried disclosure | Tiny gray footer only | Clear and conspicuous CTA |
| One disclosure for two programs | Promo + fraud alerts mixed | Separate opt-ins |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Cadence measurement | Analytics | Report |
| Snippet library | Compliance | Approved strings |
| CTA update | Web | Screenshots |
| Privacy SMS section | Legal/web | URL |
| Confirmation template | Messaging | Template ID |
| message_flow update | Ops | Campaign text |
| Automation guardrails | Engineering | Rate limits |
| Quarterly review | Compliance | Diff log |
Use MyTCRPlus tools and privacy templates when packaging public pages—process support, not legal clearance.
How Often to Disclose Frequency
Disclose at enrollment, in the confirmation for recurring programs, and in public policy pages supporting web opt-in. Re-disclose when the consumer joins a new program or when you materially change cadence. You do not need to append a full legal paragraph to every single reminder if enrollment terms were clear—but refreshing STOP and identity remains good practice, and some brands periodically restate frequency on care messages.
Coordination With Rates and Non-Sharing Language
Frequency rarely stands alone. A durable disclosure cluster includes:
- Brand / program name
- Message types
- Frequency
- Msg & data rates may apply
- STOP / HELP
- Privacy link
- “Not a condition of purchase” for marketing PEWC contexts
Keep a shared component in your CMS so web, email-to-SMS, and keyword flows cannot drift.
Testing Plan
- Screenshot CTA before/after
- Enroll test handset; capture confirmation body
- Confirm privacy URL loads without login
- Submit Campaign with matching language
- After approval, spot-check 10 random production sends for surprise promos that change effective frequency
FAQ
Is “message frequency varies” enough?
Often acceptable for event-driven programs if you explain the pattern in message_flow and keep volume reasonable. Prefer numeric caps for steady marketing calendars.
Do one-time texts need frequency disclosure?
One-time programs still need clear program description; recurring frequency language is most critical for ongoing campaigns. Follow your CSP examples.
Where do CSPs look for frequency language?
Opt-in screenshots, privacy/SMS terms, confirmation samples, and message_flow narratives.
Can frequency differ by channel?
SMS consent is channel-specific; disclose SMS frequency separately from email.
What if we increase from 4 to 12 messages monthly?
Update disclosures and consider re-consent for marketing programs—consult counsel on material changes.
Does frequency disclosure replace PEWC?
No. It is one disclosure element inside a broader consent framework.
Should HELP mention frequency?
HELP should provide care contact; frequency is usually in enroll/confirm. Consistency helps.
How does this relate to quiet hours?
Quiet hours are send-time policy; frequency is volume expectation. Implement both.
Snippet Governance Model
Store frequency disclosures as versioned components (e.g., freq_marketing_v3, freq_appointments_v2). Web, app, keyword, and confirmation templates must reference component IDs—not pasted prose. When analytics shows average sends exceeding a numeric cap, engineering pages product before compliance rewrites. This prevents the classic failure where marketing increases digests from weekly to near-daily while the CTA still says “up to 4/month.”
Message_flow Language Examples
Weak: “Customers opt in on our website.”
Stronger: “Customers opt in by entering a mobile number on https://example.com/book and checking the appointment-reminder box that discloses message frequency varies (typically 1–3 messages per appointment), msg & data rates may apply, STOP, HELP, and links to Privacy and Terms. Staff may also enroll callers using script v4, then send a confirmation SMS.”
Reviewers and future you will thank the specificity.
Extended Operating Narrative
Treat compliance as a product surface, not a one-time ticket. Assign a named owner, define what “done” means for each journey (registered Campaign, consent flag, STOP tested, samples matched), and refuse to launch automations that fail the gate. When vendors promise they are “fully compliant,” demand written answers: who is the Brand, who stores opt-in evidence, how STOP propagates, and what happens when a Campaign is rejected. Put those answers in the contract folder beside your TCR IDs.
Build a living evidence pack: Brand/Campaign identifiers, dated screenshots of every CTA, the exact disclosure snippet versions, sample message packs, consent field dictionary, quiet-hours policy, and a RACI across compliance, marketing, engineering, and the CSP. If a carrier, partner, or counsel asks for proof, you should be able to produce the pack without archaeology in personal inboxes.
Operational cadence matters. Review template diffs monthly. Mystery-shop your own opt-in quarterly. Reconcile suppression lists across CRM and the messaging platform weekly if you run high volume. After any privacy-policy edit, re-check that SMS-specific language still appears in the public HTML (not only in a CMS preview). After any new lead form goes live, confirm it writes the same consent objects your send-time checks expect.
When something fails—rejection code, spike in STOPs, filtering—run a blameless incident review. Capture timeline, customer impact, root cause (copy drift, wrong Campaign, bad list, website outage), and corrective actions with owners and due dates. Close the loop by updating the sample pack or message_flow if production reality changed.
Finally, educate executives with precise language: registration is necessary for 10DLC deliverability; it is not a TCPA shield; throughput depends on account and carrier rules; fees are provider-specific; and no reputable partner should sell guaranteed approval rates. That clarity prevents panic-driven snowshoeing and budget fiction.
Extended Operating Narrative
Treat compliance as a product surface, not a one-time ticket. Assign a named owner, define what “done” means for each journey (registered Campaign, consent flag, STOP tested, samples matched), and refuse to launch automations that fail the gate. When vendors promise they are “fully compliant,” demand written answers: who is the Brand, who stores opt-in evidence, how STOP propagates, and what happens when a Campaign is rejected. Put those answers in the contract folder beside your TCR IDs.
Build a living evidence pack: Brand/Campaign identifiers, dated screenshots of every CTA, the exact disclosure snippet versions, sample message packs, consent field dictionary, quiet-hours policy, and a RACI across compliance, marketing, engineering, and the CSP. If a carrier, partner, or counsel asks for proof, you should be able to produce the pack without archaeology in personal inboxes.
Operational cadence matters. Review template diffs monthly. Mystery-shop your own opt-in quarterly. Reconcile suppression lists across CRM and the messaging platform weekly if you run high volume. After any privacy-policy edit, re-check that SMS-specific language still appears in the public HTML (not only in a CMS preview). After any new lead form goes live, confirm it writes the same consent objects your send-time checks expect.
When something fails—rejection code, spike in STOPs, filtering—run a blameless incident review. Capture timeline, customer impact, root cause (copy drift, wrong Campaign, bad list, website outage), and corrective actions with owners and due dates. Close the loop by updating the sample pack or message_flow if production reality changed.
Finally, educate executives with precise language: registration is necessary for 10DLC deliverability; it is not a TCPA shield; throughput depends on account and carrier rules; fees are provider-specific; and no reputable partner should sell guaranteed approval rates. That clarity prevents panic-driven snowshoeing and budget fiction.
Extended Operating Narrative
Treat compliance as a product surface, not a one-time ticket. Assign a named owner, define what “done” means for each journey (registered Campaign, consent flag, STOP tested, samples matched), and refuse to launch automations that fail the gate. When vendors promise they are “fully compliant,” demand written answers: who is the Brand, who stores opt-in evidence, how STOP propagates, and what happens when a Campaign is rejected. Put those answers in the contract folder beside your TCR IDs.
Build a living evidence pack: Brand/Campaign identifiers, dated screenshots of every CTA, the exact disclosure snippet versions, sample message packs, consent field dictionary, quiet-hours policy, and a RACI across compliance, marketing, engineering, and the CSP. If a carrier, partner, or counsel asks for proof, you should be able to produce the pack without archaeology in personal inboxes.
Operational cadence matters. Review template diffs monthly. Mystery-shop your own opt-in quarterly. Reconcile suppression lists across CRM and the messaging platform weekly if you run high volume. After any privacy-policy edit, re-check that SMS-specific language still appears in the public HTML (not only in a CMS preview). After any new lead form goes live, confirm it writes the same consent objects your send-time checks expect.
When something fails—rejection code, spike in STOPs, filtering—run a blameless incident review. Capture timeline, customer impact, root cause (copy drift, wrong Campaign, bad list, website outage), and corrective actions with owners and due dates. Close the loop by updating the sample pack or message_flow if production reality changed.
Finally, educate executives with precise language: registration is necessary for 10DLC deliverability; it is not a TCPA shield; throughput depends on account and carrier rules; fees are provider-specific; and no reputable partner should sell guaranteed approval rates. That clarity prevents panic-driven snowshoeing and budget fiction.
Key Takeaways
- Message frequency disclosure belongs in CTAs, confirmations, and supporting policies.
- Be truthful: numeric caps or honest “varies” with explanation.
- Align TCR message_flow with live copy.
- Separate programs with different cadences.
- Pair with rates, STOP/HELP, and Brand identity.
- Guardrail automations so send volume cannot silently exceed disclosures.
- Re-review when product behavior changes.
Disclaimer
This article is for informational purposes only and is not legal advice. Carrier policies, CSP requirements, fees, TCR processes, professional ethics rules, and TCPA/state laws change and are fact-specific. Confirm requirements with your provider and qualified counsel before registering or sending commercial messages.