What is the TCPA and what does tcpa compliance actually require?

The TCPA bans unconsented robocalls and texts. Violations cost $500, $1,500 per call. Learn exactly what compliance requires in plain English.

LeadCompliant Team
26 min read
In This Article

Last updated 2026-07-10

Person reviewing compliance documents at a desk with phones nearby
Person reviewing compliance documents at a desk with phones nearby

TL;DR

The Telephone Consumer Protection Act (47 U.S.C. § 227) restricts autodialed calls, prerecorded messages, and marketing texts to cell phones. Compliance means getting prior express written consent before texting or robocalling, honoring opt-outs immediately, and never calling numbers on the National DNC Registry. Violations carry statutory damages of $500 to $1,500 per individual message or call, with no cap on class actions.

What is the TCPA?

The Telephone Consumer Protection Act is a federal law Congress passed in 1991. It sits at 47 U.S.C. § 227 and is enforced mostly by the Federal Communications Commission, with private plaintiffs able to sue directly in federal or state court. That private right of action is what makes the TCPA so dangerous for outbound sales teams. You do not have to wait for the FCC to come after you. Any individual whose phone you called or texted without proper consent can file suit on their own.

Congress wrote the law after a flood of consumer complaints about unwanted autodialed calls. The original text covered telephone solicitations and automatic telephone dialing systems, known as ATDSs. Over the next three decades the FCC issued dozens of orders expanding and clarifying those definitions, and courts across the country split repeatedly on what counts as an ATDS. The Supreme Court settled part of that fight in 2021 in Facebook, Inc. v. Duguid, narrowing the ATDS definition to systems that use a random or sequential number generator to store or produce numbers to be called [1]. That ruling helped legitimate businesses that call from CRM lists. The rest of the TCPA's consent requirements stayed fully intact.

The law covers four channels: autodialed or prerecorded calls to cell phones, autodialed or prerecorded telemarketing calls to residential landlines, text messages to cell phones (the FCC treats SMS as a call under the statute), and unsolicited fax ads. This article focuses on calls and texts, which is where nearly all enforcement and litigation activity sits today.

What does TCPA compliance mean in practice?

TCPA compliance means your outbound program consistently meets the consent, disclosure, and opt-out rules the statute and the FCC's regulations impose. It is not a one-time certification. It is an ongoing operational posture, and it slips the moment you stop maintaining it.

Strip it down and compliance is three obligations. Get the right level of consent before you contact someone. Honor every opt-out request fast. Never contact a number on the National Do Not Call Registry unless you have an established business relationship or written permission.

The consent standard depends on what you are sending. For marketing texts and prerecorded telemarketing calls to cell phones, you need prior express written consent, a standard the FCC defined in its 2012 Report and Order (FCC 12-21) [2]. That means a signed written agreement, paper or electronic, in which the consumer clearly authorizes calls or texts from your company using an ATDS or prerecorded voice, and the agreement has to state that consent is not a condition of purchase. For purely informational calls (appointment reminders, fraud alerts, delivery notifications), prior express consent without the written formality is enough.

Honoring opt-outs is not optional. The FCC requires you to process opt-out requests within a reasonable time, and case law treats anything past 30 days as risky. For texts, replying STOP is the standard opt-out, and your system has to suppress that number before the next send cycle.

The National DNC Registry, maintained by the FTC under the Telemarketing Sales Rule as well as the TCPA, requires telemarketers to scrub their lists against it at least every 31 days [3]. Calling a registered number without a specific exemption is a separate violation stacked on top of any consent failure.

What are the TCPA penalties and how much can a lawsuit actually cost?

The numbers are what scare teams into taking this seriously. The TCPA sets statutory damages at $500 per violation, and no proof of actual harm is required [4]. If a court finds the violation was willful or knowing, that triples to $1,500. Each individual call or text is its own violation.

Send one unconsented marketing text blast to 10,000 people. That is potentially $5 million in statutory damages before any trebling analysis, and $15 million if the court finds willfulness. Class actions are the tool plaintiffs use to roll those per-message figures into verdicts and settlements that reach eight and nine figures.

A few real outcomes put scale to this. In 2019, Dish Network settled a combined TCPA and TSR case with the Department of Justice and four states for $280 million, the largest telemarketing settlement at the time [5]. Small companies face a different kind of danger, not headline settlements but existential ones. A startup with 50 employees sending non-compliant text blasts can face class exposure in the millions before a single deposition. Plaintiffs' attorneys work these cases on contingency and hunt for non-compliant SMS programs on purpose.

You can also be sued in small claims court for individual violations, which some serial plaintiffs do methodically. The defense cost alone often runs past the $500 or $1,500 at stake per call.

Violation typeStatutory damages per violationTrebled (willful)
Standard TCPA violation$500$1,500
DNC Registry violation (TCPA)$500$1,500
State law add-on (e.g., Florida FTSA)Varies, up to $500 extraVaries
FCC forfeiture (separate track)Up to $22,021 per day per violationN/A
TCPA by the numbers Key thresholds and liability figures every outbound team should know 500 Statutory damages per viola… (standard) 1,500 Statutory damages per viola… (willful) 31 DNC scrub frequency required (days) 4 Statute of limitations (yea… Source: 47 U.S.C. § 227; FCC FCC 23-107; FTC DNC Registry rules

Prior express written consent is the standard the TCPA requires for marketing texts and prerecorded telemarketing calls to cell phones. The FCC's 2012 rules defined it as "an agreement, in writing, bearing the signature of the person called that clearly authorizes the seller to deliver or cause to be delivered to the person called advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice" [2].

Electronic signatures count. A checkbox on a web form, a typed name in an enrollment flow, or a reply text confirming opt-in all qualify as long as the disclosure around them is clear. The disclosure has to say four things: the consumer is agreeing to receive autodialed or prerecorded marketing calls or texts, from which company by name, to the number they are providing, and that consent is not required to buy anything.

Three things go wrong with consent collection over and over. The disclosure gets buried in a terms-of-service link instead of sitting on the form itself, and courts have rejected that. The consent gets written broadly to cover unnamed "marketing partners," which the FCC's January 2025 one-to-one consent rule specifically prohibited by requiring consent to name each seller [6]. Or consent gets collected for one purpose (account notifications) and then used for another (promotional offers), which is not valid.

For SMS specifically, a double opt-in flow, where the subscriber replies YES after a confirmation text, creates a clean audit trail. The sms double opt-in approach is not legally required, but it gives you a second record of consent that is hard for a plaintiff to dispute.

Read up on sms opt-in requirements before you build your capture forms, because the disclosure language for texts carries specific CTIA industry-standard requirements on top of the TCPA's.

What communications does the TCPA actually cover?

The TCPA covers more than most teams realize, and coverage turns on three things: what technology you are using to send, what type of number you are calling, and whether the message is marketing or informational.

Autodialed or prerecorded calls and texts to cell phones are the highest-risk category. After Facebook v. Duguid [1], an ATDS is narrowly defined as a system with a random or sequential number generator. Many modern dialers and SMS platforms may not qualify under that definition. Here is the practical problem. You usually cannot predict how a plaintiff's attorney will characterize your software, and the litigation cost of finding out is enormous. Most compliance professionals still follow TCPA consent rules for any outbound SMS platform, ATDS question or not.

Prerecorded voice messages to residential landlines for telemarketing also require written consent under the 2012 FCC rules. Live-agent calls to landlines are governed by the DNC Registry rules and calling-time restrictions rather than the written consent standard.

Text messages carry the same weight as calls. The FCC has consistently treated SMS as calls under the TCPA. A marketing text sent without prior express written consent carries the same $500 per message liability as a robocall. This is where most small business exposure sits right now, because texting has a low perceived barrier and teams launch campaigns before anyone reviews them.

Unsolicited commercial faxes are still covered, though they are a shrinking slice of most outbound programs.

One misconception worth killing: B2B calls are not exempt. The TCPA applies whenever you are calling a cell phone number, business owner or not. Plenty of small business owners use a personal cell as their main line, which puts those numbers squarely under the statute.

What are the TCPA calling time restrictions and quiet hours?

The TCPA and its FCC regulations prohibit telephone solicitations before 8:00 a.m. or after 9:00 p.m. local time at the called party's location [7]. That is the federal floor. Several states set tighter windows.

The phrase that trips teams up is "local time at the called party's location." You need to know where the recipient's phone is, not where your call center sits. Dialing Florida from Phoenix means you run on Eastern time. If your scrubbing system does not handle time zones at the number level, you will generate violations on early-morning or late-night calls even when your team starts dialing at a reasonable hour locally.

States layer on top of the federal rule. California adds obligations through the California Consumer Privacy Act and its Rosenthal Act. The FCC has also issued rules on reassigned numbers and certain industries. If you work in debt collection, healthcare, or real estate, check state-specific rules before you assume the federal 8 a.m. to 9 p.m. window is your only constraint.

For SMS, the TCPA's time restrictions technically apply, and the CTIA's Messaging Principles and Best Practices recommend the same 8 a.m. to 9 p.m. window in the recipient's local time zone. A promotional text at 11 p.m. might not trigger a TCPA clock violation by itself if it is a non-autodialed message, but it drives up opt-out rates and can feed a pattern-of-conduct argument in litigation.

What is a TCPA compliance checklist for calls and SMS?

A usable compliance checklist covers consent, suppression, disclosures, timing, and recordkeeping. Here is what a real program looks like, organized by the stage where each check happens.

Before you build a list or start a campaign:

  • Confirm the legal basis for contacting each number. For marketing texts and robocalls to cell phones, that means prior express written consent with a compliant disclosure.
  • Scrub your list against the National DNC Registry. You have to register with the FTC's DNC program and scrub at least every 31 days [3].
  • Scrub against your internal do-not-contact list, which must include every prior opt-out from your program.
  • If you bought leads, verify that the captured consent names your company specifically. Under the FCC's one-to-one consent rule effective January 2025 [6], a third-party vendor's generic form that names multiple buyers is no longer enough.
  • For SMS, confirm your sms opt-in form contains the required disclosures: program name, message frequency, HELP and STOP instructions, and a statement that message and data rates may apply.

During a campaign:

  • Respect the 8 a.m. to 9 p.m. local time window at the recipient's location.
  • Include your company name and a callback number in every autodialed or prerecorded call.
  • For texts, include your company name and opt-out instructions in the first message of any new conversation thread.

After each campaign and on an ongoing basis:

  • Process STOP replies and any other opt-out requests before the next send. For SMS, suppression should be near real-time.
  • Retain consent records, including the form language, timestamp, IP address, and phone number, for at least four years, which matches the TCPA's statute of limitations.
  • Audit your consent capture forms and disclosures at least quarterly, because the FCC issues new orders and courts issue new rulings that move the line on what passes.

LeadCompliant's free tcpa sms compliance checker can validate your disclosure language and flag gaps before you launch a campaign.

For a downloadable version of this list with field-by-field guidance, the LeadCompliant compliance kit has templates built around the current FCC rules.

The FCC adopted a rule in December 2023, effective January 27, 2025, that ended the practice of using a single consent form to authorize marketing contacts from multiple unidentified sellers [6]. Under the old system, a lead generation page could collect one consent covering a broad category like "insurance providers," then sell that lead to dozens of buyers who each treated the consent as their own.

The new rule demands a one-to-one relationship. The consumer's consent has to name the specific seller who will contact them, and the call or text has to be logically and topically related to the website where consent was collected. That is a big shift for anyone who buys leads from aggregators or comparison-shopping sites.

What it means in practice: audit every lead source. If a vendor gives you leads and their consent form does not name your company, that consent does not cover you. You either get the vendor to fix the form, collect your own consent directly, or stop using that source.

The rule also tightened requirements for consent forms on your own site. The consumer must be able to see which seller they are consenting to hear from, and the consent must connect logically to the service they requested. A mortgage comparison tool cannot collect consent for auto insurance companies.

Stay current on how courts and the FCC are reading this rule at tcpa news today, because enforcement guidance is still developing.

What are the TCPA's established business relationship exemptions?

The TCPA has an established business relationship (EBR) exemption for certain calls to residential landlines listed on the DNC Registry. Under it, a company can call a residential number on the DNC list if the consumer made a purchase or financial transaction with the company within the past 18 months, or made an inquiry or application within the past three months [7].

The EBR exemption does not apply to cell phones for autodialed or prerecorded marketing calls and texts. That is the single most important thing to understand about it. If you are texting mobile numbers, the EBR is not your consent defense. You need prior express written consent whether or not you have an existing customer relationship.

For live-agent telemarketing calls to cell phones, the EBR can reduce your DNC Registry exposure because the relationship temporarily exempts the number from DNC restrictions. It does not override the consent requirement for ATDS use.

Watch out for the manager who tells a rep "we can call them, they're a past customer." That may be true for live-agent calls to DNC-listed landlines under the 18-month EBR. It is flat wrong for a text blast to that same customer's cell phone.

How do TCPA rules apply to SMS and text message marketing specifically?

Text message marketing sits where TCPA consent rules, FCC regulations, the CTIA's Messaging Principles, and carrier-level compliance all meet. Get any one of them wrong and your messages get blocked, your short code gets suspended, or you get sued.

The TCPA side requires prior express written consent for marketing texts sent via ATDS to cell phones. After Facebook v. Duguid, the debate over whether standard SMS platforms qualify as ATDSs continues, but that debate is expensive to have in court. The cleaner move is to treat all outbound marketing SMS as requiring TCPA-compliant consent.

The CTIA, the wireless industry trade group, publishes Messaging Principles and Best Practices that carriers use to evaluate SMS traffic. Under those guidelines, every marketing SMS program needs documented opt-in consent, a clear STOP opt-out, the program name in messages, and opt-out honoring within a defined window [8]. Carriers can and do suspend short codes and 10DLC-registered numbers for breaking these standards, with no FCC action needed.

For businesses just building an SMS program, the sms opt-in process and the structure of your sms opt-in form are where compliance starts. The form has to show the disclosure before the consumer submits, not in a follow-up email.

Restaurants, real estate teams, and other local businesses trip up here because they grab a general-purpose marketing text message service without reading its terms or understanding the consent requirements. A platform being TCPA-friendly does not make your list clean.

For sector-specific guidance, see real estate text message marketing for property industry nuances, and sample text message marketing for restaurants for hospitality use cases.

Can you be sued personally for TCPA violations as a business owner?

Yes. Courts have held individual officers, managers, and employees personally liable for TCPA violations when they directly participated in or authorized the non-compliant conduct. Incorporating does not automatically shield you just because a corporation made the calls.

The standard varies by circuit, but in general, personal liability attaches when an individual directly participated in the violation, or authorized or ratified it with knowledge. A CEO who greenlights a mass text campaign with no compliance review is far more exposed than one who had a documented program that a rogue employee went around.

This matters most for founders and sales managers at small companies. If the company has thin assets and a class-action plaintiff wins, reaching for individual defendants is a real litigation strategy. Building a documented compliance program, even an imperfect one, is meaningful evidence that you took your obligations seriously.

The "we relied on our vendor" defense does not fully protect you either. Under FCC guidance, companies are responsible for the compliance of their agents and third-party lead generators acting on their behalf.

What records do you need to keep to defend a TCPA claim?

The TCPA carries a four-year statute of limitations under 28 U.S.C. § 1658, so a plaintiff can sue up to four years after a violation [9]. Your records have to survive that window and be organized enough to actually use in litigation.

The minimum record set for any outbound SMS or call program:

1. Consent records: the exact form language the consumer saw, the timestamp, the IP address, the phone number, and the channel (web form, inbound text, paper). Screenshots beat database exports because they show what the consumer actually saw.

2. DNC scrub logs: the dates you ran scrubs, against which lists, and which numbers got suppressed.

3. Opt-out records: every STOP reply or verbal opt-out, the timestamp, and confirmation that the number was suppressed before the next campaign.

4. Campaign records: the message content, the send time, the recipient list (post-suppression), and the platform used.

5. Lead source documentation: if you bought leads, the vendor contract and any representations they made about consent.

In a class action, the first thing plaintiffs' counsel demands in discovery is your consent records. If you cannot produce them, you cannot show the class was properly consented, and you are staring at a default judgment or a settlement under duress. Storage for this data costs almost nothing next to the cost of not having it.

For teams building their recordkeeping from scratch, lead generation compliance news tracks FCC and FTC enforcement actions that often reveal exactly what records were missing in losing cases.

Frequently asked questions

What is the TCPA in simple terms?

The TCPA (Telephone Consumer Protection Act, 47 U.S.C. § 227) is a federal law that restricts how businesses call and text consumers. It bans autodialed or prerecorded marketing calls and texts to cell phones without written consent, requires honoring Do Not Call requests, and limits calling hours to 8 a.m. to 9 p.m. local time. Violations cost $500 to $1,500 per individual contact.

What is required for TCPA compliance?

TCPA compliance requires obtaining prior express written consent before sending marketing texts or robocalls to cell phones, scrubbing call lists against the National DNC Registry at least every 31 days, honoring opt-out requests before the next contact, calling only between 8 a.m. and 9 p.m. local time, and keeping consent and suppression records for at least four years. Each requirement is independently enforceable.

What does TCPA compliance mean for a small business?

For a small business, TCPA compliance means building a documented process before you start any outbound calling or texting program. That includes collecting consent with proper disclosure language, maintaining a suppression list, scrubbing against the DNC Registry, and storing records. Small businesses carry the same liability exposure as large ones, and a class action can be existential for a company with limited assets.

Does the TCPA apply to text messages?

Yes. The FCC has consistently ruled that SMS text messages are calls under the TCPA. Marketing texts sent via an automatic telephone dialing system to cell phones without prior express written consent violate the statute. Each individual text is a separate violation carrying $500 to $1,500 in statutory damages, which makes a non-compliant mass text campaign potentially millions of dollars in liability.

Prior express written consent is a signed (paper or electronic) agreement in which the consumer clearly authorizes a specific company to send autodialed or prerecorded marketing calls or texts to their number. The agreement must state that consent is not required to make a purchase. The FCC defined this standard in its 2012 Report and Order (FCC 12-21). A checkbox on a web form qualifies if the disclosure language meets FCC standards.

How often do I need to scrub my call list against the DNC Registry?

At least every 31 days, under FTC regulations implementing both the Telemarketing Sales Rule and the TCPA. You must register with the FTC's National DNC Registry to access scrubbing. Some compliance teams scrub more often (weekly or before every campaign) to cut the risk of calling a number added to the registry after their last scrub. Legitimate users get a set number of free area codes each year.

Effective January 27, 2025, the FCC's one-to-one consent rule prohibits using a single consent form to cover multiple unnamed sellers. Consent must now identify your specific company by name and connect logically to the service the consumer requested on the originating website. Businesses that buy leads from aggregators must verify that each lead's consent form names them specifically, or that consent is legally invalid for their use.

Are B2B calls exempt from the TCPA?

No. The TCPA applies whenever you call or text a cell phone number, regardless of whether the recipient uses it for business. Many small business owners use a personal cell phone as their primary business contact, and those numbers are fully protected by the TCPA. The statute's B2B exception is narrow and does not cover autodialed or prerecorded calls or texts to cell phone numbers without consent.

How long does a plaintiff have to sue under the TCPA?

Four years, under the general federal statute of limitations at 28 U.S.C. § 1658. That is why compliance teams keep consent and suppression records for at least four years. Some parties have argued for a shorter one-year period, but most federal courts apply the four-year window, so it is the safe assumption for recordkeeping.

What is the TCPA compliance checklist for SMS specifically?

For SMS: collect prior express written consent with a visible disclosure (program name, message frequency, HELP/STOP instructions, message and data rates may apply); name your company in the disclosure; honor STOP replies before the next send; scrub against the DNC Registry; send only between 8 a.m. and 9 p.m. local time; retain consent records for four years; and under the 2025 FCC rule, ensure consent identifies your company by name.

Can I text someone who gave me their number on a contact form?

Only if the contact form carried a compliant TCPA consent disclosure that the person saw and agreed to before submitting. A phone number on a contact form by itself, with no TCPA disclosure, is not consent to receive marketing texts. You can respond to the inquiry by text if the reply relates directly to what they asked, but you cannot add them to a recurring marketing SMS list without proper written consent.

Does the established business relationship exemption cover texts to past customers?

No. The EBR exemption applies to live-agent telemarketing calls to DNC-listed residential landlines only. It does not apply to autodialed or prerecorded calls or texts to cell phones. To text a past customer for marketing, you need prior express written consent regardless of how long the relationship has existed. This is one of the most common misconceptions that leads to TCPA exposure.

What is the difference between a TCPA violation and a DNC violation?

A TCPA violation broadly covers unauthorized use of an ATDS or prerecorded voice to contact a cell phone. A DNC violation specifically means calling or texting a number registered on the National Do Not Call Registry without an applicable exemption. Both carry $500 to $1,500 per violation in statutory damages. A single call can be both a TCPA consent violation and a DNC violation, each counted separately in some cases.

How does a double opt-in protect me under the TCPA?

A double opt-in, where the subscriber confirms by reply text after initial sign-up, creates a second timestamped record of consent that is hard for a plaintiff to dispute. It is not legally required under the TCPA, but it strengthens your evidence that the consumer affirmatively wanted your messages. It also cuts the risk of someone entering a wrong number on a form and that number getting unwanted texts.

Sources

  1. U.S. Supreme Court, Facebook, Inc. v. Duguid, 592 U.S. 395 (2021): The Supreme Court narrowed the ATDS definition to systems that use a random or sequential number generator to store or produce numbers to be called.
  2. FCC, Report and Order FCC 12-21 (2012 TCPA Rules): The FCC's 2012 Report and Order defined prior express written consent and required it for autodialed or prerecorded telemarketing calls and texts to cell phones, stating consent is not a condition of purchase.
  3. FTC, National Do Not Call Registry: Telemarketers must scrub their call lists against the National DNC Registry at least every 31 days.
  4. 47 U.S.C. § 227(b)(3), Telephone Consumer Protection Act: The TCPA sets statutory damages at $500 per violation, trebled to $1,500 for willful or knowing violations, with no proof of actual harm required.
  5. U.S. Department of Justice, Dish Network TCPA Settlement Press Release (2019): In 2019, Dish Network settled a combined TCPA and TSR case with the Department of Justice and four states for $280 million, at the time the largest telemarketing settlement in U.S. history.
  6. FCC, Report and Order FCC 23-107, One-to-One Consent Rule (2023, effective January 27, 2025): The FCC's one-to-one consent rule, effective January 27, 2025, requires that TCPA consent identify the specific seller by name and be logically and topically related to the website where consent was collected, eliminating group consent covering multiple unnamed sellers.
  7. 47 C.F.R. § 64.1200, FCC Regulations implementing the TCPA: FCC regulations prohibit telephone solicitations before 8:00 a.m. or after 9:00 p.m. local time at the called party's location, and codify the established business relationship exemption for residential landline DNC calls.
  8. 28 U.S.C. § 1658, Federal Statute of Limitations: The general four-year federal statute of limitations at 28 U.S.C. § 1658 applies to TCPA claims in most federal circuits.
  9. FTC, Telemarketing Sales Rule, 16 C.F.R. Part 310: The FTC's Telemarketing Sales Rule, alongside the TCPA, requires DNC Registry scrubbing at least every 31 days and imposes separate penalties for telemarketing violations.

Disclaimer: LeadCompliant is a compliance review tool, not a law firm. We do not provide legal advice. Consult with a TCPA attorney for legal guidance on specific compliance questions. Compliance scores, audits, and risk assessments are informational only.

LeadCompliant Team

LeadCompliant provides expert guidance and tools to help you succeed. Our content is reviewed for accuracy and kept up to date.

Related Articles

Related Glossary Terms

LeadCompliant
Build My Kit