Regulatory map by market

SMS Bridge, a product of Ino Tek Plus Holding

Template for review. This document was prepared for review by qualified counsel in each market where it is used. It is not legal advice.

This is a template prepared for review by qualified counsel. It is not legal advice and must not be relied on as a substitute for advice from a licensed lawyer in each market listed below.

Prepared for Ino Tek Plus Holding, Fort McMurray, Alberta, Canada. Product: SMS Bridge, a self hosted business texting system for field service companies. Contact info@inotekplus.com. Business line +1 (780) 215 1111 is never used for outbound testing or sending; do not use it for anything referenced in this document.

Last researched: August 31, 2026. Regulatory landscapes for SMS and AI change often. Anything market by market below should be re verified before a sales push into a new country.

How to read the verdict column

Canada (home market)

Law What it requires Sender ID Registration Penalty exposure Verdict
CASL (Canada's Anti-Spam Legislation) Applies to any "commercial electronic message" sent to an electronic address, and SMS is explicitly in scope (CRTC FAQ, crtc.gc.ca/eng/com500/faq500.htm, accessed Aug 31 2026). Requires (1) consent, express or implied, (2) sender identification in the message, (3) a working unsubscribe mechanism honoured promptly. Implied consent from an existing business relationship is time limited (see CASL s.10(10)). CASL does not apply to purely transactional or servicing messages ("your technician is 20 minutes away") because those are not commercial in nature, but marketing texts from a trades company clearly are. Must identify the sender in the message. No pre-registration under CASL itself. Up to CAD 10,000,000 per violation for organizations (Telerivet, "Canada SMS Compliance," telerivet.com/blog/canada-sms-compliance-casl-10dlc-registration, dated 2026-04-02). Yes, with our default "STOP honoured" and identification templates, for servicing texts. Marketing use needs the customer's own consent records; we should require them to warrant this (see terms_of_service.md).
PIPEDA (federal private sector privacy law) Requires meaningful consent to collect, use, and disclose personal information, and reasonable safeguards. Our AI classification of message content is a "use" of personal information and must be disclosed (see privacy_policy.md). Note: Bill C-36 (Protecting Privacy and Consumer Data Act) is a live legislative effort to replace Part 1 of PIPEDA; as of August 2026 PIPEDA is still the operative law (Fasken, "Canada's National AI Strategy," fasken.com, dated 2026-08-20). N/A N/A Administrative monetary penalties possible under recent PIPEDA amendments; exact cap not verified here, I don't know the current maximum figure, needs counsel. Yes, provided our privacy policy and consent flow are in place.
CRTC 10DLC / carrier registration rules 10DLC is the North American standard for application to person SMS over a long code number. Canadian numbers sending to US recipients must be A2P registered without exception (Telerivet, dated 2026-04-02). Canadian numbers sending only to Canadian recipients acquired before March 26, 2025 are not currently required to register for domestic traffic; numbers bought on or after that date need A2P registration or persona verification (same source). Carriers (Rogers, Bell, Telus) informally throttle unregistered long codes, with some guidance citing caps as low as 100 to 250 messages per day per number. Brand name shown to carriers during registration. Registration through a Campaign Service Provider such as Telnyx, required for numbers bought March 26, 2025 or later, and required regardless of purchase date for any cross border traffic to the US. Throttling or blocking, not a statutory fine. Needs work for any customer on Telnyx 10DLC gateway with a number bought after March 26, 2025, or any customer whose customers include US numbers. Not applicable to the Android handset relay gateway, which rides the carrier's normal consumer SIM plan rather than a registered business number; this is also why that gateway has no per message registration step but is subject to the carrier's own consumer "unlimited plan" fair use terms (see acceptable_use_and_sms_disclaimer.md).
Provincial: Quebec Law 25 In force since September 22, 2023 (McCarthy Tétrault, "Quebec's Law 25 and Cookies," mccarthy.ca, accessed Aug 31 2026). Requires privacy by design, breach notification, a privacy officer, and specific disclosure when technology is used to identify, locate, or profile a person, which plausibly covers our AI classification of inbound messages by intent or sentiment. Administrative monetary penalties can reach a high percentage of worldwide turnover; I do not have a verified current figure for the exact statutory maximum, needs counsel. N/A Requires a designated privacy officer, published privacy policy, and specific profiling notice. High; among the strictest of the provincial regimes. Needs work: our privacy policy must call out the AI classification feature explicitly for Quebec deployments, and the customer's own disclosure to end customers should mention it too.
Provincial: Alberta PIPA Governs private sector employers and businesses in Alberta, our home province. Generally permits collection, use, and disclosure of personal information without consent when reasonable for a business purpose and with notice, and separately allows employers to collect employee information for managing the employment relationship with reasonable notice (kedgeanchorlaw.ca, "Workplace Chat Privacy," dated 2026-05-28, discussing PIPA and R v Cole 2012 SCC 53). N/A N/A Fines exist under PIPA; I do not have a verified current maximum figure for AB PIPA, needs counsel. Yes for our home jurisdiction, subject to the employee monitoring analysis in employee_monitoring.md.
Provincial: BC PIPA Similar structure to Alberta's PIPA, private sector consent and notice based regime. N/A N/A I don't know the current BC PIPA maximum penalty figure, needs counsel. Yes, same posture as Alberta.

United States

Law What it requires Sender ID Registration Penalty exposure Verdict
TCPA (Telephone Consumer Protection Act) Prior express written consent required before sending marketing texts using an automatic telephone dialing system to a cell phone. The FCC's "one to one consent" rule, which would have required a separate consent per seller, was scheduled for January 27, 2025 but was vacated by the Eleventh Circuit and never took effect (natlawreview.com and mcguirewoods.com, both dated January 2025; confirmed by Federal Register Vol. 90 No. 166, August 29, 2025, which formally reinstated the prior rule text). So the pre-2023 consent standard currently governs: it does not have to be one seller at a time, but prior express written consent for marketing texts is still required, and a right to revoke consent through any reasonable method took effect April 11, 2025 (mcguirewoods.com, dated 2025-01-28). Statutory damages of USD 500 to USD 1,500 per violation drive very large class action exposure; this is a private right of action law, heavily litigated. Not mandated by TCPA itself. Not a TCPA requirement; see A2P 10DLC below, which is a carrier rule, not a federal statute. USD 500 to USD 1,500 per text, treble for willful violations; class actions common. Needs work: our terms must make the customer, not us, the warrantor of TCPA consent, since we are a platform, not the sender of record for legal purposes (see terms_of_service.md). Servicing texts tied to an existing job are lower risk than marketing blasts, which our acceptable use policy should simply prohibit.
A2P 10DLC (carrier rule, not statute) Any business sending SMS over a 10 digit long code number through an application (which the carriers deem all Telnyx/Twilio-style traffic to be) must register a Brand and a Campaign with The Campaign Registry (campaignregistry.com, TCR Intro, dated 2026-08-19; Twilio docs, accessed Aug 31 2026). Unregistered traffic is throttled or blocked, not fined by government, but functionally unusable at volume. Brand name and campaign use case declared to TCR. Required for the Telnyx gateway. Not applicable to the Android handset relay gateway, which does not use an application to person registered number, it rides a normal consumer SIM. Commercial throttling/blocking, not a government fine. Needs work: every customer on the carrier API gateway needs Brand/Campaign registration before go live; budget one to five business days.
Florida Telephone Solicitation Act (FTSA) Amended by Chapter 2023-150, effective for suits filed on or after the amendment. Requires, among other things, that after a called party texts STOP, the sender has 15 days to cease, and provides a private right of action if texting continues after that window (sb.flleg.gov, Chapter 2023-150, approved May 25, 2023). This is a state law layered on top of TCPA, with its own statutory damages and its own litigation bar. N/A N/A Statutory damages per violation; I do not have a verified current per-violation dollar figure for FTSA as amended, needs counsel. Needs work: our STOP handling must process opt outs within the shorter of any federal or state deadline, and Florida's 15 day cure window should be built into the gate logic as a hard rule, not a best effort.
Oklahoma telephone solicitation law Oklahoma has its own consumer protection statute analogous to Florida's that has driven text message litigation. I don't know the current specific text of Oklahoma's SMS-specific provisions or its 2024/2025 amendment status, needs counsel. N/A N/A I don't know the current penalty structure, needs counsel. Needs work, flagged for local counsel review before any Oklahoma-heavy customer base.
CCPA/CPRA (California) Applies to for-profit businesses meeting revenue or data volume thresholds; grants California residents rights to know, delete, correct, and opt out of sale/sharing of personal information, and imposes purpose limitation and data minimization duties. A business texting product processing message content for AI classification should disclose this processing and confirm it does not constitute a "sale" or "sharing" of personal information as CPRA defines those terms. N/A N/A Civil penalties per violation, enforced by the California Privacy Protection Agency; I do not have a verified current per-violation cap, needs counsel. Yes for us as a processor/platform serving field service SaaS customers, provided our privacy policy and DPA meet the CCPA "service provider" contract requirements (see dpa_and_subprocessors.md).

European Union and United Kingdom

Law What it requires Sender ID Registration Penalty exposure Verdict
GDPR / UK GDPR Requires a lawful basis (consent or legitimate interest, contract performance for servicing texts) for processing personal data, data subject rights (access, erasure, portability, objection), a Data Processing Agreement between controller and processor, and international transfer safeguards (Standard Contractual Clauses or UK IDTA) if data leaves the EEA/UK. Our AI classification of message content is "automated processing" and must be disclosed; if it produces decisions with legal or similarly significant effect on the person (unlikely here, since it routes messages rather than denies service), Article 22 profiling rules would also apply. N/A N/A Up to EUR 20,000,000 or 4% of global annual turnover, whichever is higher, under GDPR Art. 83(5). Yes, provided we execute a proper DPA, disclose the AI classification, and offer EU hosting or SCCs for any data that leaves the region. Self hosted deployments where the customer's own server never leaves the EU sidestep most of the transfer question.
ePrivacy Directive / UK PECR Governs unsolicited electronic marketing including SMS. UK ICO guidance confirms electronic mail marketing rules (specific consent, or "soft opt-in" for existing customers with a clear opt out at collection and in every message) apply the same way to texts as to email (ico.org.uk, "Electronic mail marketing," accessed Aug 31 2026; the ICO notes this guidance is under review following the UK's Data (Use and Access) Act, so it may change). Must not disguise or conceal sender identity; valid contact address required. No central registration; DNC-style opt out list does not exist for UK/EU text, individual consent/soft opt-in governs instead. UK ICO fines under PECR are historically lower than GDPR fines but can still reach significant sums; I do not have a verified current UK PECR maximum figure post Data (Use and Access) Act, needs counsel. Yes for servicing texts. Marketing texts need either specific consent or the "soft opt-in" and a clear opt out in every message, which our template disclaimers should enforce by default.
EU AI Act Article 50 transparency obligations became generally applicable and enforceable on August 2, 2026 (Mondaq, "Not Delayed, Not Deferred," dated 2026-08-05; JDSupra, dated 2026-08-19). These require that any AI system designed to interact directly with a natural person, such as an auto responder, make clear to the person that they are dealing with an AI system, unless obvious from context. High risk system obligations were pushed to December 2, 2027 by the "AI Omnibus" (Regulation (EU) 2026/1744, in force July 27, 2026). Our AI message classifier that decides what gets escalated and our AI auto responder both plausibly fall under Article 50 if the auto responder talks directly to the end customer. N/A No registration for Article 50 duties as such; high risk systems (not our current use case, since we do not believe our classifier meets the high risk criteria as drafted, but this needs counsel to confirm given the AI Omnibus text) would require conformity assessment from December 2027. Administrative fines under the AI Act can reach EUR 35,000,000 or 7% of global turnover for the most serious prohibited-practice violations; transparency violations sit at a lower tier, and I do not have a verified current figure for the Article 50 specific tier, needs counsel. Needs work: any AI auto responder feature sold into the EU needs a visible "you are talking to an automated assistant" disclosure from launch. See cookies_and_web.md for detail.

Australia

Law What it requires Sender ID Registration Penalty exposure Verdict
Spam Act 2003 Requires consent (express or reasonably inferred), a clear unsubscribe mechanism, and identification of the sender before sending "commercial electronic messages" including SMS (business.gov.au, "Promoting your business by email or text messages," accessed Aug 31 2026). Businesses sending branded SMS/MMS must register their sender ID on the SMS Sender ID Register or messages are labelled "Unverified" (same source). SMS Sender ID Register for branded messages. Civil penalties enforceable by ACMA; I do not have a verified current per-contravention dollar figure, needs counsel. Needs work: register a sender ID before launch to avoid "Unverified" labelling that will hurt deliverability and trust for trades customers.
Privacy Act 1988 Governs collection, use, and disclosure of personal information by APP entities, similar in structure to PIPEDA. N/A N/A I don't know the current per contravention penalty structure following 2022 amendments, needs counsel. Yes, with a standard privacy policy update for Australian Privacy Principles language.

New Zealand

Privacy Act 2020 and the Unsolicited Electronic Messages Act 2007 govern consent based texting, broadly similar in structure to Australia's regime (consent, sender identification, functioning unsubscribe). I do not have current, source-dated confirmation of any 2024 to 2026 amendments to either statute, needs counsel before relying on the above summary for a live customer. Verdict: needs work, pending that confirmation.

Mexico

I don't know the current state of Mexican SMS-specific marketing regulation with confidence. Mexico's general data protection law (LFPDPPP) governs personal data processing and requires a privacy notice and consent for certain processing, but I have not verified SMS-specific consent or sender registration rules for this report. Needs counsel before selling in Mexico. Verdict: needs work.

Brazil

Law What it requires Sender ID Registration Penalty exposure Verdict
LGPD (Lei Geral de Proteção de Dados) In full force since August 2021, modeled closely on GDPR, applies extraterritorially to any organization processing the personal data of people located in Brazil (Telerivet, "Brazil SMS Compliance," telerivet.com/blog/brazil-sms-compliance-anatel-lgpd, dated 2026-04-13). Requires a lawful basis, data subject rights, and ANPD (Autoridade Nacional de Proteção de Dados) as enforcement authority. Alphanumeric sender IDs require pre-registration that can take up to roughly ten weeks depending on carrier (same source). ANATEL governs telecom-side registration; short codes are the primary application-to-person mechanism, not long codes. LGPD fines can reach 2% of Brazilian revenue per violation, capped per infraction; I do not have a verified current cap figure in reais, needs counsel. Needs work: alphanumeric sender ID lead time and ANATEL rules (including sending-hour restrictions, no promotional SMS on Sundays per the same source) make Brazil a slower market to enter, not a day-one market.

UAE and Saudi Arabia

Law What it requires Sender ID Registration Penalty exposure Verdict
UAE, TDRA Unsolicited Electronic Communications Regulatory Policy Requires clear opt-in/opt-out mechanisms for marketing SMS with a UAE link, monitored by TDRA, with licensee reporting obligations (tdra.gov.ae, policy version 1.1, dated 13 June 2022, accessed Aug 31 2026). N/A specified in the excerpt reviewed. Applies through the licensed telecom operators (Etisalat, du), not directly to end businesses in the way TCR registration works. Regulatory action against telecom licensees; I do not have a verified direct penalty schedule for end businesses, needs counsel. Needs work, given reliance on the local telecom operator's own compliance chain rather than a US-style open carrier API market.
Saudi Arabia I don't know the current Saudi SMS marketing and data protection regulatory detail (PDPL implementation specifics) with confidence, needs counsel. Needs work, verdict withheld pending counsel review.

India

Law What it requires Sender ID Registration Penalty exposure Verdict
TRAI DLT (Distributed Ledger Technology) registration All Principal Entities (businesses) and Telemarketers sending commercial SMS in India must register on the DLT platform; TRAI has issued repeated deadlines and directions through 2024 tightening traceability requirements (trai.gov.in, PR No. 90 of 2024, and Direction dated 04 May 2024, both accessed Aug 31 2026, though the OCR text retrieved was partially garbled and specific dates should be re-verified against the original PDF before quoting to a customer). Registered sender header/template required; unregistered templates are blocked at the carrier level. Mandatory DLT registration of entity, header, and message template before any traffic flows. Message blocking rather than a direct statutory fine for unregistered senders; underlying telecom law penalties exist but I do not have a verified current figure, needs counsel. No / high risk on day one: DLT registration, government entity paperwork, and template pre-approval make India a project, not a signup. Do not represent to a customer that they can start texting in India without this lead time.

Singapore

Law What it requires Sender ID Registration Penalty exposure Verdict
PDPA + Do Not Call (DNC) Registry Before sending telemarketing SMS, an organization must check the recipient's number against Singapore's No Text Message Register, one of three DNC registers (dnc.gov.sg, "Do Not Call Registry Business Rules," accessed Aug 31 2026). Checks can be done via a paid bulk lookup. Non-marketing, transactional service texts are generally exempt from the DNC check requirement, but PDPA consent and notification obligations for personal data still apply. N/A specified. DNC number checking is mandatory before marketing sends; there is a per-number check fee. PDPA fines can be significant per contravention; I do not have a verified current cap figure, needs counsel. Yes for servicing texts. Needs work for marketing texts, which require the DNC check step to be built into our send pipeline before we can honestly tell a Singapore customer they are compliant.

South Africa

Law What it requires Sender ID Registration Penalty exposure Verdict
POPIA The Information Regulator published a formal Guidance Note on Direct Marketing on December 3, 2024, distinguishing marketing by unsolicited electronic communication (including SMS) from other marketing and generally requiring prior consent, unless the recipient is an existing customer being marketed similar products with an opt out offered (polity.org.za, dated 2024-12-10). N/A specified. N/A Administrative fines and potential criminal liability for serious contraventions under POPIA; I do not have a verified current maximum fine figure, needs counsel. Yes for servicing texts with a standard privacy notice; needs work for marketing use to align with the December 2024 Guidance Note specifics.

Summary: where the per-message-cost or registration burden makes our model hard

Overall day-one sellable list (Yes or Yes-with-standard-setup)

Canada, United States (with TCPA/FTSA consent warranties from the customer and 10DLC registration for the carrier gateway), United Kingdom, European Union (with DPA and Article 50 AI disclosure), Australia (after Sender ID registration), Singapore (servicing texts).

Needs work before selling

Brazil, UAE, Saudi Arabia (pending counsel), New Zealand (pending counsel confirmation of current statute state), Oklahoma-heavy US customer bases (pending counsel), Mexico (pending counsel), South Africa marketing use.

No / high risk without a structural project

India, unless the customer is prepared for a multi-week DLT registration project before their first message ever sends.