Industry-Specific Federal Requirements
A source-linked guide to industry-specific requirements and how this authority layer fits into U.S. A2P messaging programs.
What this authority layer covers
Federal privacy, health, financial, debt-collection, child-data, credit-reporting, and affiliate-marketing requirements that may apply to particular messaging programs.
Authorities and official sources
Each entry explains what the source says, where its limits are, and what it does not establish.
Federal regulation · Current
Regulation F, 12 C.F.R. Part 1006
How this authority relates to messaging
This source is part of the national legal baseline for U.S. messaging programs.
What the source establishes
- Regulation F expressly addresses debt-collection electronic communications, including text-message addresses, opt-out notices, inconvenient times, and third-party privacy risk.
Limits and important context
- Debt-collection texts require simple opt-out handling, time and place controls, and measures against impermissible third-party disclosure.
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Federal regulation
- Current status
- Current
Federal regulation · Current
HIPAA Privacy Rule marketing and safeguards layer
How this authority relates to messaging
This source is part of the national legal baseline for U.S. messaging programs.
What the source establishes
- HIPAA requires covered health-care messaging to protect PHI and distinguish treatment or reminder communications from marketing that requires authorization.
Limits and important context
- Applies to covered entities and business associates; operational controls include content classification, authorization logic, minimum-necessary messaging, and vendor safeguards.
Facts that may change the result
- Is the sender a HIPAA covered entity or business associate for this messaging activity?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Federal regulation
- Current status
- Current
Federal regulation · Current
GLBA Financial Privacy Rule and Safeguards Rule
How this authority relates to messaging
This source is part of the national legal baseline for U.S. messaging programs.
What the source establishes
- GLBA governs covered financial institutions’ use, sharing, and protection of customer information used in messaging programs.
Limits and important context
- Operational controls include privacy notices and sharing limits, service-provider oversight, information-security safeguards, and incident governance.
Facts that may change the result
- Is the sender or data use covered by GLBA?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Federal regulation
- Current status
- Current
Federal regulation · Current
COPPA Rule
How this authority relates to messaging
This source is part of the national legal baseline for U.S. messaging programs.
What the source establishes
- COPPA requires verifiable parental consent and child-data protections when an online messaging program is directed to children under 13 or knowingly collects their personal information.
Limits and important context
- Operational controls include age screening, parental-consent workflows, campaign exclusions, minimization, security, and retention limits.
Consent standard stated in the source
- verifiable parental consent
Facts that may change the result
- Is the service child-directed or does it knowingly collect personal information from children under 13?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Federal regulation
- Current status
- Current
Official agency guidance · Current
Fair Credit Reporting Act and Regulation V
How this authority relates to messaging
This source is relevant to the broader program, but the reviewed text does not expressly establish general SMS or MMS coverage.
What the source establishes
- Do not obtain or use report-based data without a permissible purpose; prescreened marketing is specifically regulated and consumers can opt out of prescreening.
Limits and important context
- Applies when a business uses consumer reports or other FCRA-governed data for eligibility, prescreening, account review, insurance, employment, or similar covered purposes. CFPB materials emphasize permissible-purpose limits and prescreening rules. Material if a messaging program uses consumer-report data, skip-trace data, or credit/insurance segmentation to build audiences, route offers, or trigger adverse or eligibility-related messages. High-risk wherever a text/SMS campaign is driven by credit, insurance, or employment-report logic rather than first-party customer data. Private-action analysis was not re-extracted in this pass. Current federal law; strongest surfaced official sources are CFPB FCRA materials and consumer guidance.
Facts that may change the result
- Does the program obtain or use consumer-report or other FCRA-governed data?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Official agency guidance
- Current status
- Current
Official agency guidance · Current
FACTA Affiliate Marketing Rule under Regulation V
How this authority relates to messaging
The reviewed source expressly applies to a particular type of text message or a specific messaging issue.
What the source establishes
- Requires a clear notice, a reasonable chance to opt out, and a simple opt-out method before affiliate eligibility information is used for marketing solicitations, unless an exception applies.
Limits and important context
- Applies to persons using eligibility information received from an affiliate to make marketing solicitations. Directly relevant where affiliated brands want to text or message consumers using account, transaction, or application data first collected by another affiliate. This is one of the clearest federal rules governing cross-affiliate reuse of personal data for marketing, which makes it unusually important for enterprise messaging programs with multiple brands or legal entities. Current; strongest surfaced official source is CFPB Regulation V, Subpart C.
Facts that may change the result
- Is affiliate eligibility information used to make a marketing solicitation?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Official agency guidance
- Current status
- Current
Official agency guidance · Current
FTC Health Breach Notification Rule
How this authority relates to messaging
This source is relevant to the broader program, but the reviewed text does not expressly establish general SMS or MMS coverage.
What the source establishes
- Requires notice to affected individuals, FTC notice, and sometimes media notice after covered breaches; the 2024 amendments clarified that unauthorized disclosure can itself be a “breach of security.” For breaches affecting 500+ people, FTC notice must be submitted at the same time individuals are notified.
Limits and important context
- Applies to vendors of personal health records, PHR-related entities, and certain service providers handling identifiable health information outside HIPAA. FTC guidance says it reaches many health apps and similar technologies not covered by HIPAA. Material for wellness, reproductive-health, symptom-tracking, condition-management, or appointment-related messaging programs operated outside HIPAA-covered structures. FTC guidance states noncompliance can trigger enforcement and significant civil penalties. This matters whenever health-related messaging data sits in consumer-app infrastructure rather than HIPAA pipelines. Updated rule effective July 29, 2024. Strongest surfaced official sources are FTC rule/guidance pages.
Facts that may change the result
- Is identifiable health information handled by a covered PHR vendor, PHR-related entity, or service provider outside HIPAA?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Official agency guidance
- Current status
- Current
Official agency guidance · Compliance timing stayed
CFPB Personal Financial Data Rights Rule
How this authority relates to messaging
This source is relevant to the broader program, but the reviewed text does not expressly establish general SMS or MMS coverage.
What the source establishes
- Third parties must meet authorization conditions and satisfy collection, use, and retention obligations for covered data.
Limits and important context
- Applies to the consumer-authorized sharing of covered financial data under section 1033. CFPB states the final rule requires covered data providers to make covered financial data available and imposes obligations on authorized third parties, including use, collection, and retention controls. Relevant for financial-services messaging programs that ingest or act on consumer-authorized account/transaction data, including account-alerting, financial coaching, debt-management, or fintech audience orchestration. The rule is enacted, but CFPB states the compliance dates were stayed by court order on October 29, 2025, and the rule is under reconsideration. That means it is architecturally important now, but timing is unstable. Final rule issued in October 2024; compliance dates currently stayed. Strongest surfaced official sources are CFPB rule pages.
Facts that may change the result
- Does the program ingest or act on consumer-authorized covered financial data?
Official and supporting sources
Source and review details
- Jurisdiction
- United States federal
- Source type
- Official agency guidance
- Current status
- Compliance timing stayed
Continue with the most useful next step
Move from a jurisdiction or authority layer to the sources and tools most likely to answer the next question.
Get a program-specific review
Use an advisory review when the result depends on facts that a public authority index cannot resolve.

