// Compliance

A2P SMS compliance: 10DLC, GDPR consent, and sender registration

Application-to-person messaging is regulated, and non-compliance shows up as throttled or blocked traffic, not just legal risk. This guide covers the essentials: US 10DLC registration, consent and GDPR obligations, and how sender registration differs by region β€” enough to get verification traffic flowing legitimately.

What A2P messaging is

A2P (application-to-person) messaging is any SMS sent by a system rather than typed by a human β€” OTPs, alerts, notifications, and marketing. Carriers treat A2P differently from personal texting: it must be registered and consented, and unregistered A2P traffic is increasingly filtered or blocked outright.

Verification codes are A2P even though users request them, so the rules below apply to your OTP traffic.

  • A2P covers OTPs, alerts, reminders, and marketing.
  • Carriers require registration and, for many message types, proof of consent.
  • Unregistered A2P is throttled or blocked in strict markets.

US 10DLC registration

In the United States, application messaging over standard 10-digit long codes must go through 10DLC (10-digit long code) registration: you register your brand (your business identity) and each campaign (the use case, such as "account verification"). Registration sets your throughput and trust score; skipping it means heavy filtering.

  1. 1

    Register your brand

    Submit your business identity (legal name, EIN, contact) to establish your sender identity with The Campaign Registry via your provider.

  2. 2

    Register each campaign

    Describe each use case β€” for OTP this is typically an account-verification / 2FA campaign β€” with sample messages and opt-in details.

  3. 3

    Get throughput assigned

    Your brand + campaign vetting determines your messages-per-second and daily limits.

  4. 4

    Keep it current

    Update registrations when your use case, volume, or message content changes materially.

!

Toll-free A2P also requires verification in the US, and short codes are separately provisioned β€” 10DLC is specifically the long-code path.

Sender registration by region

Beyond the US, many countries operate their own registration and sender-ID regimes. The specifics change often, so confirm current rules with your provider per destination β€” but the shape is consistent: register who you are and what you send.

RegionTypical requirement
United States10DLC brand + campaign registration (long code); toll-free verification; short-code provisioning
United Kingdom / EUAlphanumeric sender IDs common; GDPR consent and data-handling obligations
IndiaDLT registration of sender ID and message templates
Southeast AsiaPer-country sender-ID registration; some markets require pre-approved templates
Middle EastSender-ID registration often mandatory; unregistered senders frequently blocked
Illustrative, not exhaustive β€” confirm current requirements per country with your provider.

Build compliance into the flow

Compliance is easier as design than as cleanup. Capture the purpose and consent at the point you collect the number, template your messages so they match what you registered, and log enough to prove what was sent and why. When rules shift in a market, a well-structured flow is a configuration change, not a rebuild.

  • Record purpose and consent at number capture.
  • Match live message templates to what you registered.
  • Log sends with enough context to demonstrate compliance.
  • Review registrations when you enter a new country or change use case.

Frequently asked questions

Do OTP messages need 10DLC registration in the US?+

Yes. OTP and 2FA messages sent over standard long codes are A2P traffic and require 10DLC brand and campaign registration. Without it your messages face heavy carrier filtering and low throughput. Toll-free and short-code paths have their own separate requirements.

Is a phone number personal data under GDPR?+

Yes. A phone number identifies a person and is personal data under GDPR and similar laws. Collect it for a stated purpose, secure it, keep it only as long as necessary, and honor access and deletion requests.

Can I send marketing to a number a user gave me for verification?+

Not without separate, explicit consent. A number collected to verify an account is consented for that transactional purpose only. Reusing it for marketing without a fresh opt-in violates consent rules in most jurisdictions.

Do compliance rules really affect delivery?+

Very much so. Unregistered or non-compliant A2P traffic is throttled or blocked by carriers, so registration is a deliverability lever as much as a legal one. Getting 10DLC or local sender-ID registration right directly improves the rate at which your codes arrive.

EdgeGigs

Need 10DLC or sender registration handled properly?

Hire a vetted developer to set up A2P registration, consent capture, and compliant messaging templates for your regions.

Find a developer on EdgeGigs β†’