🎉 10% OFF — Claim your exclusive discount before it ends
Blog

Webinar Compliance in 2026: The 5 Laws That Can Bite You

The five laws that quietly govern every webinar: recording consent, TCPA texts, CAN-SPAM email, GDPR, and FTC earnings claims. Plain-English rules, real penalties, and copy you can steal.

September 18, 2026 · 16 min read · by Derek Haywood

#Tier 4#Compliance#webinar-compliance#recording-consent#tcpa#can-spam#gdpr#ftc-earnings-claims
Webinar Compliance in 2026: The 5 Laws That Can Bite You

It is 20 minutes before your webinar and you are staring at a checkbox. The form asks people to opt in to text reminders, and someone wants to know if the pre-checked box counts as consent. You do not know. You hit go anyway, because 400 people are waiting. That gap between “I think we’re fine” and “I know we’re compliant” is where the fines live.

Five laws quietly govern almost every webinar you run: state recording-consent laws when you capture attendee audio or video, the TCPA and A2P 10DLC for SMS reminders, CAN-SPAM for email, GDPR for anyone in the EU, and the FTC’s earnings-claim rules if you sell from the stage. None care whether you are a solo coach or a Fortune 500. This guide walks all five in plain English, shows how each breaks, and hands you consent copy to paste into your funnel today.

Table of contents

  1. What breaking these rules actually costs
  2. Law 1: Recording consent, the one nobody talks about
  3. Law 2: TCPA and A2P 10DLC for your SMS reminders
  4. Law 3: CAN-SPAM for every reminder and follow-up email
  5. Law 4: GDPR the moment one EU registrant signs up
  6. Law 5: FTC earnings claims if you sell from the stage
  7. The same five laws at three sizes
  8. Objections, answered
  9. FAQ

What breaking these rules actually costs

Every rule below exists because someone abused a channel until regulators wrote a fine schedule, and the fines are per-violation. One bad text to a 5,000-person list is potentially 5,000 problems.

What one webinar compliance mistake can cost: up to $53,088 per CAN-SPAM email, $500 to $1,500 per TCPA text, and up to €20M under GDPR, per violation

Those are ceilings, not typical outcomes. But class actions are the real SMS threat, and one registrant who screenshots a non-compliant text can turn a $2,000 launch into a legal headache. The real cost is usually the time and the deliverability damage, not the fine. And webinars are worth protecting: in the 2026 B2B content marketing report from CMI and MarketingProfs, marketers ranked webinars their second most effective distribution channel, behind in-person events.

01326395252In-person events51Webinars42Email (non-newsletter)42Organic social41Blog37Email newsletter

Share of B2B marketers rating each channel among their most effective for distribution. Source: CMI / MarketingProfs, B2B Content Marketing 2026.

Almost nobody thinks about the recording, which is backwards: it is the law most operators quietly break.

The rule: most states follow “one-party consent,” so you can record a conversation if one person in it (you) agrees. But roughly a dozen require all-party consent. California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington are usually listed as strict, and a handful more are hybrid. The Reporters Committee recording guide keeps a state-by-state breakdown.

It bites the moment an attendee speaks on a mic, appears on camera, or joins a breakout: now you are recording a conversation, not a one-way talk. If one attendee sits in an all-party state without consent, your recording is legally shaky, and you rarely know where attendees are.

How it breaks: A coach records a live Q&A, an attendee in Florida asks a question on camera, then later objects to being in the replay that now sells a $3,000 program. Now you are deleting the segment, or worse.

The fix is simple: get consent in the registration flow and again verbally at the top of the event:

That verbal line does double duty: it covers you legally and tells nervous attendees how to take part without being on tape.

Law 2: TCPA and A2P 10DLC for your SMS reminders

SMS is your best reminder channel and the most friction-heavy. It runs on two rules people blur together.

The TCPA is the federal law. For marketing texts it wants prior express written consent, the opt-in has to be clear about what the person is signing up for, and it cannot be buried in your terms as a pre-checked box. Every message needs an easy STOP opt-out. Damages run $500 per text, up to $1,500 for a willful violation, counted per message. The landscape is in motion (an FCC rule tightening consent was struck down in early 2025), but the safe posture has not changed: clear written consent, keep the record, honor STOP instantly.

A2P 10DLC is the carrier rule, and it is not optional. To text US phones from a standard 10-digit number, you register your brand and campaign through your provider (Twilio, GoHighLevel, or another platform). Skip it and carriers filter or block your traffic. Twilio’s A2P 10DLC docs spell out the process, which takes a few days.

How it breaks: An operator imports a purchased list, blasts a “we’re going live” text, and half never delivers because the campaign was never registered. The delivered half goes to people who never opted in. That is the TCPA violation and the deliverability problem in one move.

The phrase “consent is not a condition of registering” keeps the opt-in standing on its own. For the deeper build, see our SMS reminder compliance guide.

Law 3: CAN-SPAM for every reminder and follow-up email

Email feels safe because everyone does it, but CAN-SPAM is a real federal law with a checklist and a per-email penalty. Good news: you satisfy all of it once, in your template.

Per the FTC’s compliance guide, every commercial email has to:

  1. Use accurate “From,” “To,” and routing information, so the recipient can tell who sent it.
  2. Use a subject line that reflects the actual content. No bait.
  3. Identify the message as an ad where that applies.
  4. Include your valid physical postal address. A registered mailbox counts.
  5. Give a clear opt-out, honored within 10 business days, that keeps working for at least 30 days.

The penalty is the wake-up: up to $53,088 per email under the FTC’s 2025 inflation-adjusted schedule. Confirm the current-year figure at send time, because it ticks up most years.

How it breaks: A launch email uses a curiosity-gap subject line (“you left this behind…”) unrelated to the webinar, has no physical address in the footer, and routes the unsubscribe link to a 404. That is three violations in one email, times your whole list.

Set the template once. That is far easier when the cadence is one system, which is how we structure the webinar email sequence.

Consent, opt-out, and A2P registration, wired in from day one

The Webinar Snapshot ships the registration consent boxes, the STOP-handling SMS cadence, the CAN-SPAM-ready email templates, and the A2P 10DLC setup already built into your GoHighLevel account. You run the webinar; the compliant plumbing runs itself. Installed in about 24 hours.

Law 4: GDPR the moment one EU registrant signs up

GDPR applies not to European companies but to European people on your list. If your ads reach the EU or a German registrant signs up, their data is under GDPR.

The core requirement is a lawful basis to process personal data. For marketing that basis is almost always consent, and GDPR consent is a high bar: freely given, specific, informed, and unambiguous, which means no pre-checked boxes and no bundling (Article 6 sets out the bases). People can also demand to see, correct, or delete their data. Fines reach up to €20 million or 4% of worldwide annual turnover, whichever is higher. Small operators are not the priority, but “unlikely to be fined” is a bad thing to bet a business on.

How it breaks: A US course creator runs Meta ads that spill into the EU, collects registrants with no consent basis, then cannot honor a deletion request because the contact is scattered across three tools. The scramble is the punishment even if the fine never comes.

The practical move for small teams: keep one CRM as the single home for contacts so a deletion request is one action, not a treasure hunt, the same reason your webinar data should live in one system.

Law 5: FTC earnings claims if you sell from the stage

This one catches coaches and course sellers. The second you say “our students make X” or “I built this to six figures,” you are making an earnings claim, and the FTC has rules about those.

Under the Business Opportunity Rule (16 CFR Part 437), a seller who makes an earnings claim must have a reasonable basis and written substantiation in hand, and be able to hand over an earnings claim statement. In plain terms: prove it, with records, first. A bigger rule is coming: the FTC advanced a broader deceptive-earnings-claims effort from a 2022 advance notice to a formal proposed rule in early 2025. It is not final yet, so re-check before relying on any provision, but the direction is more scrutiny, not less.

How it breaks: A coach shows screenshots (“students hitting $30k months”) with no records and no disclaimer. A refund fight turns into a complaint, and now the coach must substantiate a claim they cannot back up.

The disclaimer is not a magic shield: it has to be true and backed by records. But honest numbers plus a plain caveat beat a screenshot with a dollar sign and a prayer.

The same five laws at three sizes

The rules do not change with your size, but which ones bite hardest does.

The solo coach doing $2k to $50k a month. Your exposure is concentrated in SMS and earnings claims: you are the face making the promise and probably texting reminders. Prioritize a written SMS opt-in with STOP, A2P registration, and a truthful disclaimer under every result. Add the verbal recording line the second the Q&A camera is on. GDPR is low priority unless you market to the EU.

The mid-size B2B team, 20 to 500 people. Exposure widens to email volume and GDPR, because you send more and reach further. Prioritize a locked-down CAN-SPAM email template, a documented consent basis, and a single CRM of record so deletion and access requests are one action. Reminder SMS still needs the TCPA treatment, and recorded demos need attendee consent.

The larger operation running evergreen at scale. Everything is a volume problem now, and volume turns a per-violation penalty into a real number. Prioritize audited consent capture with timestamps, a real deletion process, legal review of evergreen earnings language, and recording consent baked into the platform. At this size, “we meant to” is not a defense.

Across all three the throughline is the same: compliance is not a person remembering the right thing at 20 minutes to showtime. It is a system that captures consent, honors opt-outs, and keeps records automatically.

Webinar compliance do and don’t panel: use an unchecked consent box, register A2P 10DLC and honor STOP, and back income claims with records, versus pre-checking opt-ins, texting an unregistered list, or hiding the unsubscribe

Objections, answered

“I’m tiny. Does any of this really apply to me?” Yes. The TCPA, CAN-SPAM, and recording laws apply per message and per recording, not per company size. A 200-person list can generate 200 violations from one bad send. The upside: at your size the fixes are cheap.

“My platform records automatically. Isn’t that their problem?” No. The platform provides the tool, but you decide to record and market the footage, so the consent obligation is yours. A passive “this call is being recorded” banner is weaker than an explicit opt-in plus a verbal notice.

“Won’t a consent checkbox tank my opt-in rate?” A well-worded, single-purpose checkbox costs little and earns a list that actually wants to hear from you, which beats a bigger list you cannot legally text. The version that tanks trust is the pre-checked, buried, gotcha kind.

“Do I need to hire a lawyer for all this?” Not for the basics. Consent boxes, a compliant footer, STOP handling, and an honest disclaimer are operational, not legal. Bring in an attorney when the stakes climb: heavy EU marketing, aggressive earnings claims, high-volume SMS.

FAQ

Do I legally need consent to record my own webinar?

To record your own presentation, no. But once attendees speak, appear on camera, or join a Q&A, you are recording a conversation, and roughly a dozen all-party-consent states require every participant to agree. Since you cannot know where attendees are, get consent at registration and again verbally at the start.

What is the difference between the TCPA and A2P 10DLC?

The TCPA is the federal law governing consent for marketing texts, at $500 to $1,500 per message. A2P 10DLC is the US carrier registration that lets your texts get delivered from a standard number. You need both: TCPA for the legal right to send, A2P for delivery.

Does CAN-SPAM apply to reminder emails or only newsletters?

It applies to any commercial email, including reminders and follow-ups that promote your webinar or offer. Every one needs accurate headers, an honest subject line, your physical postal address, and a working opt-out honored within 10 business days.

I'm a US business. Do I really have to worry about GDPR?

If people in the EU register or land on your list, yes. GDPR follows the person's location, not your company's. You need a lawful basis to process their data, a privacy notice, and the ability to delete it on request. If you never accept EU registrants, exposure is low.

Can I show income screenshots on my webinar?

Only if you can back them up. The Business Opportunity Rule requires a reasonable basis and written substantiation before you claim earnings. Pair any documented result with a clear 'not typical or guaranteed' disclaimer, and keep the records.

What is the single most-ignored webinar compliance risk?

Recording attendees without consent. Operators obsess over email and SMS and forget a live Q&A is a recorded conversation under state all-party-consent laws. It is also the easiest to fix: one checkbox and one spoken sentence.

Compliance is not the exciting part of running webinars, but it is what lets you keep the revenue you earn.

Run your webinars on a platform that handles A2P and consent natively

GoHighLevel gives you the A2P 10DLC registration, the consent tracking, the STOP handling, and the single CRM of record that makes compliance a setting instead of a scramble. Start GoHighLevel through our partner link and unlock up to 30% off the Webinar Snapshot install.

Disclosure: the link above is an affiliate link. If you start GoHighLevel through it, we may earn a commission at no extra cost to you. We only recommend the platform our own system is built on.

About the author

Derek Haywood is a GoHighLevel Automation Engineer based in Denver, CO. A former B2B SaaS sales engineer, he builds the plumbing behind webinar funnels: the triggers, tags, consent capture, and reminder cadences that keep a launch compliant and running without anyone babysitting it. He has a low tolerance for broken automations and an even lower one for vague compliance hand-waving.

Sources

Ready to put this into practice?

Install the Webinar Snapshot in 24 Hours

Every workflow above — already built, refined across 80+ U.S. webinar hosts, installed for you for $997 one-time.