← Back to blogdebt collection

NYC SHIELD Rule: New Text Message Limits for Debt Collectors

August 18, 2026 · Android Texter

NYC SHIELD Rule: New Text Message Limits for Debt Collectors

If you collect on New York City accounts and you're deciding how much to lean on text messaging, two separate problems just got harder to ignore at the same time. On August 4, 2026, the NYC Department of Consumer and Worker Protection (DCWP) published the first detailed FAQ on its new SHIELD debt collection rule, spelling out exactly how a strict contact cap and a new consent regime will apply to text messages once the rule takes effect. Separately, and unrelated to anything DCWP controls, the major carriers still treat debt collection as one of the industries they filter hardest at the network level, SHIELD-compliant or not. Here's what actually changes, what doesn't, and where the two problems meet.

What the SHIELD Rule Caps, and When

A desk calendar with a deadline marked in red among office paperwork The Stopping Harassment and Intimidation and Ensuring Lawful Debt Collection ("SHIELD") Rule was adopted by DCWP on February 26, 2026. It was originally set to take effect September 1, 2026; DCWP has since pushed that date to January 1, 2027 and used the extra runway to publish the FAQ, with a compliance webinar scheduled for October 5, 2026.

The headline number is the contact cap: no more than three communications or attempted communications per account within any rolling seven-day period, and the count isn't per channel, which is the part that trips people up. A phone call, a text, and an email to the same consumer about the same debt use up all three slots for that week combined. Regulation F's federal call-frequency rule works differently: it's a rebuttable presumption tied specifically to phone calls (no more than seven calls in seven days, or within seven days of a live conversation), and it doesn't set a hard numeric limit on texts or emails at all. SHIELD replaces that flexible, calls-only presumption with a bright-line cap that spans every channel. Mailed letters, communications the consumer initiates, and litigation-related contact fall outside the cap.

Who Has to Follow It

SHIELD isn't limited to third-party collection agencies. Original creditors are newly in scope once they stop sending periodic statements, accelerate a balance, or take or threaten legal action, the point where routine account servicing turns into collection activity. Debt buyers and collection attorneys working NYC consumer accounts are covered too. If your organization does first-party outreach on past-due balances and has treated itself as exempt because it isn't a "collection agency," that assumption is worth revisiting before January.

The New Rule for Texting a Debt

Close-up of a hand signing a written consent form on a clipboard Before SHIELD, whether you could text a New York consumer about a debt was mostly a TCPA and Reg F question. SHIELD adds a city-specific layer on top. A collector may only use a specific phone number, email address, or other electronic medium to communicate about a debt if one of three things is true: the collector has the consumer's direct, revocable, written consent to use that specific medium for that specific account; the collector is the original creditor and already had the consumer's direct consent to communicate about that account; or the consumer used that medium to contact the collector about the debt within the last 60 days and hasn't opted out since. Every electronic communication has to disclose the consumer's right to revoke that consent, and opt-outs are channel-specific: a consumer who stops texting hasn't necessarily stopped email.

There's a narrow carve-out worth knowing: a collector who doesn't yet have consent for a channel is allowed to send one electronic message whose sole purpose is asking for that consent, without that message itself counting as unauthorized collection contact.

Where SHIELD Sits on Top of the TCPA

None of this replaces the TCPA. SHIELD governs contact frequency and consent for a specific medium once you're already allowed to text the number. The TCPA still governs whether you had lawful consent to text a wireless number in the first place, and it still carries its own penalty structure independent of anything DCWP does. A New York City debt collector now has to clear three separate bars for the same text message: TCPA consent to contact the wireless number, SHIELD's medium-specific written consent for texting that account, and the 3-in-7 frequency cap. Getting the first two right and blowing through the third is still a violation.

Why "Written" Still Matters

A Magistrate Judge in the Southern District of Ohio recently recommended summary judgment for a collector in Sells v. Meade & Associates after finding that a consumer's verbal demand to stop calling didn't trigger the FDCPA's cease-communication protections, because the statute requires that request in writing and a spoken demand doesn't satisfy it. The collector had stopped calling anyway and coded the account "cease communication," which is what got the case dismissed, not the format of the request.

The lesson generalizes: documentation of exactly what a consumer asked for, and when, in writing, keeps showing up as the deciding factor in these cases. SHIELD's own consent requirement runs the same direction: a collector has to be able to show, per account and per medium, that a specific written consent exists. A dashboard that keeps a permanent, timestamped record of every inbound and outbound text on an account is doing double duty here: it's the operational log and the compliance record.

The Separate Problem: Getting the Text Delivered at All

A smartphone on a desk displaying an incoming text message alert Even a SHIELD-compliant, TCPA-compliant, fully-consented text to a New York debt account still has to survive the carrier layer, and that's where most collection agencies hit a wall that has nothing to do with New York law. The major carriers route standard business texting through A2P 10DLC, the registration system that requires brand and campaign approval through The Campaign Registry before a message ever reaches a phone. Debt collection is one of the categories aggregators like Twilio commonly reject outright or throttle hard at the campaign-review stage, regardless of how clean the underlying consent and content are. The industry classification itself is the problem, not any individual message.

Android Texter sits on the other side of that line because it routes messages through a user-owned Android phone's own carrier connection, the same way a text from a personal phone works. That traffic is person-to-person SMS, not application-to-person business messaging, so it isn't subject to A2P 10DLC's campaign registration or industry gating. It doesn't change anything about SHIELD, the TCPA, or Reg F. The consent you need, the 3-in-7 cap, and the written-consent record are exactly as required as they'd be on any other channel. What it changes is whether a compliant message actually has a path to the phone in the first place.

A Compliance Checklist Before January 1, 2027

  • Map every NYC account by contact channel, and total calls, texts, and emails together against the 3-per-7-days cap, not per channel.
  • For any number or address you plan to text or email, confirm you have written, medium-specific consent, or that the consumer texted/emailed you first within the last 60 days without opting out.
  • Add a revocation disclosure to every electronic communication template.
  • If you're an original creditor doing first-party outreach, confirm at what point your accounts cross into "collection activity" under the rule's trigger definitions.
  • Keep the validation notice process on paper. SHIELD doesn't change the requirement to mail it regardless of what channel first contact used.
  • Separately, confirm your texting platform can actually reach NYC numbers without being filtered by carrier-side industry gating.

Frequently Asked Questions

Does the SHIELD Rule apply to text messages, or just phone calls?

Both, plus email. The 3-in-7 contact cap and the medium-specific consent requirement cover calls, texts, and emails together as a combined limit per account, not as separate limits per channel.

When does the SHIELD Rule actually take effect?

January 1, 2027. DCWP originally set September 1, 2026 as the effective date, then pushed it back and used the extra time to publish its FAQ and schedule an industry webinar for October 5, 2026.

Does SHIELD replace TCPA consent requirements for texting?

No. SHIELD adds a city-specific contact-frequency cap and a medium-specific written-consent requirement on top of the TCPA, which still separately governs whether you had lawful consent to text a wireless number at all.

Are original creditors covered, or just collection agencies?

Original creditors are covered once an account moves from routine servicing into collection activity: stopping periodic statements, accelerating the balance, or threatening legal action. It isn't limited to third-party agencies or debt buyers.

If I'm fully SHIELD- and TCPA-compliant, will my texts actually reach NYC consumers?

Not automatically. Carrier-side A2P 10DLC filtering is a separate hurdle from any consumer-protection law. Debt collection campaigns get rejected or throttled at that layer regardless of consent quality, which is a deliverability problem, not a legal one.

Getting the consent and frequency rules right is table stakes under SHIELD; it doesn't help if the message never lands. If carrier filtering is the piece you're still fighting, Android Texter routes outbound SMS through an actual Android handset instead of an A2P-registered short code, so debt collection traffic isn't sorted into the categories Twilio and its peers throttle by default, while consent, frequency, and every other obligation under SHIELD, Reg F, and the TCPA remain entirely on you.