📡 The Big Story
CalPrivacy Just Fired Its First Shot, and It's Aimed at Data-Heavy Platforms
California's Privacy Protection Agency just launched its first-ever formal sectoral audit, and while the initial target is gig economy platforms (Uber, DoorDash, and friends), anyone in messaging should be reading this like it's their own performance review. The audit is zeroing in on whether these platforms are actually honoring CCPA data access rights for both consumers AND workers. Translation: CalPrivacy is done writing strongly-worded letters. They're doing actual, formal audits now.
Here's why this matters for messaging specifically: A2P platforms, CPaaS providers, and every SMS marketing tool out there sits on absolute mountains of PII. Phone numbers, opt-in logs, message content, engagement data, cross-platform identifiers. If you think CalPrivacy is going to audit rideshare and then just... stop... I've got a grey route to sell you. Gig platforms are the warm-up act. Data-heavy industries with worker-facing data (hi, contact centers) are next.
The uncomfortable truth is most messaging companies have never had their access-request workflows tested by a real regulator. Your privacy policy says "we respond in 45 days." Cool. But when CalPrivacy shows up wanting proof you actually did it for 10,000 requests last quarter, that's a very different conversation. Build the muscle now. 🔥
🔥 What's Moving
TSR Record Retention Doubles-Plus, from 2 Years to 5 💀
The FTC quietly amended the Telemarketing Sales Rule and nobody updated their checklist. Retention just went from 2 years to 5, and you have to keep per-call records including the script used and the disposition. On top of TCPA. On top of state mini-TCPAs. On top of sector rules like Medicare and ACA that have their own clocks.
Look, if you're running outbound programs and your data retention policy still says "we purge after 24 months," you're already out of compliance. This is the kind of thing that doesn't matter at all until a class action lawyer asks for four-year-old call records and you don't have them. Then it matters a whole lot.
TCPA in 2026: The Circuit Split Nobody Wanted 👀
Vida put together a nice recap of where TCPA actually landed after the 11th Circuit vaporized one-to-one consent in January 2025 (formally killed in September 2025). Multi-seller consent is back on the menu at the federal level. But revocation rules got teeth: consumers can opt out through any reasonable method, and you've got 10 business days to honor it across every channel.
The "any reasonable method" language is the sleeper. Someone replies "please stop" to your email and expects your SMS to stop too? Yeah, that's on you to figure out. Consent architecture is officially a full-time engineering problem.
Comfone + VOX Team Up to Squeeze Grey Routes 👀
Comfone (the roaming/signaling folks) and VOX Solutions are partnering to help MNOs monetize A2P traffic. The polite framing is "control, protect, and monetise." The real framing is: carriers globally are tired of watching enterprise SMS revenue leak through SIM farms and grey routes, and they're arming up.
Good for legitimate senders, honestly. Grey routes are a race to the bottom that eventually ends with your OTP getting flagged as spam in Bangladesh. But brace for pricing pressure in emerging markets over the next 12 months.
UK Considers Sunsetting MMS 😴
The UK is assessing when to pull the plug on MMS as RCS Business Messaging scales. Honestly? Good. MMS in 2026 is like keeping a fax machine on your desk "just in case." The RCS transition has been glacial, but the UK actually has the CPaaS maturity to pull this off. US carriers will watch, take notes, and then do nothing for another three years.
Google Messages Feature Drop: Vibes-Based Rollouts Continue 🤡
9to5Google's running tracker of what's actually shipping in Google Messages is basically a monument to the gap between the Universal Profile 4.1 spec and reality. Customizable attachments grid! Long-press menu updates! Read receipts redesign, part TWO! Meanwhile iOS 27 finally added replies and photo reactions to Android-iPhone RCS, which is the only thing anyone actually wanted.
🏆 Winner of the Week: Compliance lawyers, who just got a lifetime employment guarantee courtesy of CalPrivacy, the FTC, and the 11th Circuit all at once.
📉 Loser of the Week: Anyone whose data retention policy hasn't been touched since 2023, because your five-year TSR clock started running while you were reading LinkedIn.
📊 By the Numbers
- 5 years: New TSR record retention requirement, up from 2. That's a 150% increase in storage, indexing, and retrieval burden for every outbound program in the country.
- $500 to $1,500: TCPA damages per violating call or text. Multiply by a class of 50,000 recipients and you understand why plaintiff firms have such nice offices.
- 10 business days: The new federal window to honor a revocation of consent across ALL channels. Not the channel it came in on. All of them.
🔮 What We're Watching
CalPrivacy's audit scope creep. The gig economy audit is round one. We're watching for the second sectoral announcement, and betting it lands on either adtech or communications platforms before Q1 2027. If you handle worker data OR consumer messaging data at scale, start red-teaming your DSAR workflow now.
RCS iOS-Android parity. With iOS 27 finally shipping replies and photo reactions cross-platform, the wall between the green and blue bubbles is officially rubble. The question is whether brands will actually invest in RCS Business Messaging campaigns now that the addressable audience is real. My money says the first big consumer brand goes all-in by Black Friday.
💡 The Hot Take
Here's my hot take, and I'm ready to defend it: the messaging industry's biggest risk in 2027 isn't AI-generated spam, isn't carrier fees, and isn't the RCS transition. It's compliance debt.
Everyone spent the last five years optimizing for deliverability, throughput, and conversion rates. Meanwhile the legal ground shifted underneath everyone. TSR retention doubled. One-to-one consent died and got replaced by a mess of circuit-level interpretations. Revocation now spans channels. CalPrivacy started actually auditing people. State mini-TCPAs are proliferating like Marvel spinoffs.
The platforms that win the next 24 months won't be the ones with the flashiest AI agents or the cheapest per-message pricing. They'll be the ones whose compliance infrastructure isn't held together with Zapier and hope. Boring? Absolutely. But "we can prove consent, retention, and revocation across every channel in under 60 seconds" is about to be the most important sales slide in the deck.
Sexy tech gets you customers. Sturdy compliance keeps them. Plan accordingly.