Compliance Guide

TCPA Compliance: Rules, Consent & Penalties

What is TCPA compliance?

Short answer

TCPA compliance means following the Telephone Consumer Protection Act (47 U.S.C. § 227) when you call or text consumers. In practice it requires documented prior express written consent before marketing to a mobile number with an autodialer or prerecorded voice, honouring opt-outs within 10 business days, and scrubbing your list against the National Do Not Call Registry at least every 31 days. Damages run $500 to $1,500 per call or text.

On this page

The Telephone Consumer Protection Act is the single largest legal risk in outbound calling, and the reason is structural: it grants consumers a private right of action with fixed statutory damages. A plaintiff does not have to prove they lost money. They have to prove you called, and that you lacked consent.

That design has produced an industry of serial filers, and it means the cost of a sloppy lead list is not theoretical. This page covers what the rules actually require in 2026, including two recent changes that most vendor content still reports incorrectly.

What changed recently

The one-to-one consent rule was vacated in January 2025 and never took effect. New revocation rules did take effect on 11 April 2025, cutting the opt-out window to 10 business days. The separate "revoke-all" provision remains suspended, and the FCC has proposed deleting it. Details in the sections below.

What the TCPA actually restricts

The statute targets a specific combination: the technology used, the type of number called, and the purpose of the call. Miss any of the three and you can misjudge your exposure.

TCPA requirements by call type and destination
You are doing thisTo this kind of numberYou need
Marketing, using an autodialer or prerecorded voiceMobilePrior express written consent
Marketing, manually dialledMobileNo autodialer consent needed, but DNC rules still apply
Informational or transactional, autodialledMobilePrior express consent (a lower bar -- providing the number can suffice)
Marketing, prerecorded voiceResidential landlinePrior express written consent, subject to exemptions
Any marketing call or textNumber on the National DNC RegistryConsent, or an established business relationship

Text messages count as calls. The FCC has consistently treated SMS and MMS as within scope, so every consent rule above applies to your SMS campaigns as written.

Almost every TCPA dispute turns on consent -- whether it existed, whether it covered this seller and this number, and whether you can prove it. The burden of proof is yours, not the plaintiff's. A consent record you cannot produce is functionally the same as no consent at all.

Prior express written consent

For marketing robocalls and robotexts to mobile numbers, you need a signed written agreement that:

  • identifies the specific seller authorised to make the calls;
  • identifies the specific number being consented to;
  • states that the consumer agrees to receive autodialed or prerecorded marketing;
  • discloses that consent is not a condition of any purchase.

Electronic signatures are valid under the E-SIGN Act. What matters operationally is retention: keep the form, the timestamp, the IP address, and the exact page or script the consumer saw.

The one-to-one consent rule that never happened

In December 2023 the FCC adopted a rule requiring consent to be given to one seller at a time, and limiting calls to subjects "logically and topically associated" with the interaction that produced the consent. It was aimed at the lead-generation practice of one form authorising dozens of buyers.

On 24 January 2025, the Eleventh Circuit vacated it in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277, holding that the FCC had exceeded its statutory authority because the rule conflicted with the ordinary meaning of "prior express consent." The court remanded to the agency, which has no deadline to act.

Why this matters when you read other guides

A great deal of published TCPA content -- including pages from established vendors -- still describes one-to-one consent as a live or upcoming requirement. It is not. It was vacated before its effective date. If a compliance article you are relying on has not been updated since January 2025, treat its consent section as unreliable.

Revocation, as of April 2025

The FCC's revocation order did take effect on 11 April 2025, and it tightened things meaningfully:

  • 10 business days to process an opt-out, down from 30.
  • Consumers may revoke by any reasonable means. The keywords stop, quit, revoke, opt out, cancel, unsubscribe and end are automatically effective; other phrasings create a rebuttable presumption of revocation that you must disprove.
  • Revocation crosses channels: an opt-out sent by text also ends calls, and vice versa.
  • If your platform cannot receive reply texts, you must disclose that and offer another reasonable route.
  • You may send one confirmation text, within 5 minutes, containing no marketing content.

One provision is not in force. Section 64.1200(a)(10) would require a revocation given in response to one kind of informational message to end all future messages on unrelated topics. The FCC waived it in April 2025, extended the waiver again in January 2026, and in an October 2025 rulemaking proposed removing it altogether. Sensible planning treats it as unsettled rather than imminent.

Do Not Call obligations

DNC rules run alongside the consent rules -- satisfying one does not satisfy the other.

  • Scrub against the National DNC Registry at least every 31 days. The FTC tightened this from quarterly effective 1 January 2005; it has been the standard for two decades.
  • Every seller needs its own Subscription Account Number (SAN). If a telemarketer or service provider scrubs on your behalf, you share your SAN with them -- you do not rely on theirs.
  • Maintain an internal do-not-call list. This obligation is independent of the federal registry and has no exemptions.
  • Consumer registrations do not expire. A number stays on the registry until it is disconnected and reassigned, or the consumer removes it.
  • State registries exist too, and several impose stricter rules than the federal baseline.

Reassigned numbers: the trap that catches careful callers

Consent attaches to the person, not the digits. When a consumer gives you consent and later gives up the number, that number is aged for 45 days and reassigned to someone new -- and your consent is worthless the moment it changes hands. The FCC estimates roughly 35 million mobile numbers are disconnected and made available for reassignment each year.

The FCC's Reassigned Numbers Database (live since November 2021, at reassigned.us) exists for this. You query a number plus the date you obtained consent, and get one of three answers:

Reassigned Numbers Database query responses
ResponseMeaningWhat to do
YesPermanently disconnected since your consent dateDo not call without fresh consent
NoNot disconnected since that dateSafe to call, and the safe harbour applies
No DataInsufficient records to answerYour judgement -- no safe harbour either way

The safe harbour protects you from liability if you call a reassigned number in reliance on an erroneous "no". It has four elements: you held consent before reassignment; you called after it; you checked the most recent database data and received "no"; and that "no" was wrong. Note the first element -- the safe harbour cannot rescue a call you never had consent to make.

Two limits worth internalising. Carriers report disconnections on the 15th of each month, so "most recent data" effectively means re-scrubbing monthly. And the database says nothing about wrong numbers -- digits that never belonged to your consumer at all. For those you need commercial phone-intelligence data, not the RND.

What violations cost

TCPA and TSR penalty amounts
RouteAmountWho brings it
TCPA statutory damages$500 per call or textPrivate plaintiff or class
TCPA willful or knowingUp to $1,500 per call or textPrivate plaintiff or class
TSR civil penaltiesUp to $53,088 per violationFTC (inflation-adjusted annually)
State telemarketing lawsVaries; some exceed federalState attorneys general, private suits

The absence of a damages cap is what makes this a business risk rather than a compliance line item. Per-violation damages multiplied by a campaign-sized list is how a routine SMS blast becomes an existential number.

Serial litigators

A small, organised population files TCPA claims as a business. Their methods are deliberate: seeding numbers into lead-generation forms, maintaining many lines, documenting every contact, and -- as compliance practitioners have reported -- coordinating so that a number changes hands after consent is given, defeating the consent on file.

You cannot identify these numbers by looking at them. They are valid, active mobile numbers that pass every technical check. The only practical defence is to compare your list against a court-sourced database of known filers before the campaign runs, which is what a batch litigator scrub does.

TCPA compliance checklist

A working list. It is not a substitute for counsel, and it will not fit every business.

Before you collect a lead

  • Consent language names your company specifically, not a category of "partners".
  • The form discloses that consent is not a condition of purchase.
  • You capture and retain the timestamp, IP address, and the exact wording shown.
  • If you buy leads, your contract obliges the vendor to produce consent records on demand -- and you have tested that they can.

Before every campaign

  • Scrub against the National DNC Registry, within the last 31 days.
  • Scrub against your internal do-not-call list.
  • Scrub against applicable state registries.
  • Check line type, so marketing texts are not sent to landlines and disconnected numbers are dropped.
  • Run a known-litigator check.
  • For aged leads, query the Reassigned Numbers Database.

Operationally, all the time

  • Opt-outs processed within 10 business days, across every channel.
  • All seven FCC revocation keywords recognised by your platform.
  • Calling hours respected -- 8am to 9pm in the consumer's time zone, not yours.
  • Caller ID transmits an accurate name and a callable number.
  • Consent records retained at least four years, matching the TCPA statute of limitations.
  • Written policies exist, staff are trained, and both are documented.

Where NumberBroom fits

NumberBroom covers the list-hygiene rows above: carrier-level validation to establish line type, and a court-sourced litigator check, in one pass over your CSV at $0.20 per number, $5 minimum, with no subscription. It does not manage consent, and no scrubbing tool can -- consent is a process you own. See how the different categories of TCPA tooling fit together, or check a single number free to see the output format.

TCPA questions people actually ask

What does TCPA stand for?

TCPA stands for the Telephone Consumer Protection Act, a federal law passed in 1991 and codified at 47 U.S.C. § 227. It restricts telemarketing calls, texts, and faxes, and it is enforced both by the FCC and by private plaintiffs who can sue directly.

How much is a TCPA violation?

The TCPA sets statutory damages of $500 per call or text, which a court may increase to up to $1,500 per violation where the conduct was willful or knowing. There is no cap on the total, which is why class actions reach eight figures -- 20,000 improper texts is a $10 million exposure at the trebled rate.

Separately, the FTC can pursue civil penalties of up to $53,088 per violation of the Telemarketing Sales Rule. That figure is adjusted for inflation annually.

Is the one-to-one consent rule in effect?

No. The FCC's one-to-one consent rule was vacated by the Eleventh Circuit in Insurance Marketing Coalition Ltd. v. FCC on 24 January 2025. The court held the FCC exceeded its statutory authority because the rule conflicted with the ordinary meaning of "prior express consent." It never took effect.

A single consent form naming multiple sellers can still be valid. The pre-existing prior-express-written-consent requirements continue to apply unchanged. Be careful with older articles -- a lot of vendor content still describes this rule as upcoming.

What is prior express written consent?

A written agreement, signed by the consumer, that clearly authorises the specific seller to deliver marketing calls or texts to a specific number using an autodialer or prerecorded voice. It must disclose that consent is not a condition of purchase. An electronic signature counts.

It is required for marketing to mobile numbers. Purely informational or transactional calls sit under a lower standard.

How quickly must I honour an opt-out?

Within 10 business days. The FCC's revocation rules, effective 11 April 2025, shortened this from the previous 30 business days.

Consumers may revoke using any reasonable method. The words stop, quit, revoke, opt out, cancel, unsubscribe, and end are treated as automatically effective; anything else creates a rebuttable presumption that consent was revoked.

Who is exempt from TCPA rules?

No one is fully exempt, but several categories face lighter requirements. Calls made with the consumer's prior express written consent are permitted. Purely informational and transactional calls, calls from tax-exempt non-profits, political calls, and calls to a consumer with whom you have an established business relationship are treated differently from marketing robocalls.

Two cautions. Exemptions from the Do Not Call Registry rules are not exemptions from the TCPA's autodialer and consent rules -- they are separate requirements. And an internal do-not-call request must always be honoured, whatever category you fall into.

Do TCPA rules apply to text messages?

Yes. The FCC treats SMS and MMS as "calls" under the TCPA, so the same consent requirements apply to texts as to voice calls. Marketing texts to a mobile number require prior express written consent.

Practical consequence: sending a marketing text to a landline fails silently and wastes spend, while sending one to a mobile without documented consent creates $500–$1,500 of exposure per message. Line type matters for both reasons. See the full SMS compliance breakdown, including why A2P 10DLC registration is a separate requirement from TCPA consent.

Does scrubbing my list make me TCPA compliant?

No. Scrubbing removes known risk from a list -- invalid numbers, wrong line types, registry matches, known serial litigators -- but it cannot manufacture consent you never obtained. Consent is the foundation; scrubbing is risk reduction on top of it.

Treat them as two separate obligations: get and document consent, then scrub before every campaign.

What is the TCPA safe harbor?

The clearest safe harbor in the TCPA rules applies to reassigned numbers. If you held valid consent, the number was later reassigned to someone else without your knowledge, and you checked the FCC's Reassigned Numbers Database before calling and received a "no" answer, you are protected from liability for that one call -- even though the "no" turned out to be wrong. The four elements all have to be met; there is no general TCPA safe harbor that excuses a call made without consent in the first place.

Some state mini-TCPA statutes define their own, separate safe harbors -- for example, a cure period for isolated technical violations. Those are state-specific and do not apply to the federal TCPA.

What are TCPA disclosure requirements?

Three disclosure obligations run in parallel, and they attach at different points in the relationship:

  • At the point of consent. A written consent agreement must state that consent is not a condition of purchase.
  • During the call, promptly. Under the Telemarketing Sales Rule (16 C.F.R. § 310.4(d)), a telemarketer must promptly disclose the identity of the seller, that the call's purpose is to sell something, and the nature of the goods or services.
  • On every marketing text. A clear way to opt out -- reply STOP or equivalent -- has to be available, and an opt-out request must be honored within 10 business days.

None of these substitute for the underlying consent requirement; they are obligations on top of it.

Does the TCPA have a healthcare exemption?

A narrow one. The FCC's rules (47 C.F.R. § 64.1200(a)(2)) exempt certain healthcare messages -- appointment reminders, wellness checkups, pre-registration and pre-operative instructions, lab results, post-discharge follow-up, prescription notifications, and home healthcare instructions -- from the written consent requirement when made by or on behalf of a HIPAA-covered entity or its business associate. Ordinary prior express consent is still required; only the "written" form is waived.

The exemption has real limits: no telemarketing, solicitation, advertising, billing, or debt-collection content; no charge to the patient; a cap of one message per day and three per week per provider; and every message must offer an opt-out that is honored immediately. It does not cover marketing calls from a healthcare business, only these specific operational categories.

Does TCPA apply to email marketing?

No. The TCPA governs calls and text messages -- the FCC treats SMS and MMS as calls for this purpose, but not email. Commercial email is regulated separately, primarily by the CAN-SPAM Act, which has its own requirements (accurate header information, a functioning opt-out, a postal address) and its own penalty structure.

If a campaign mixes channels -- email plus SMS follow-up, for example -- the SMS leg still needs TCPA-compliant consent even though the email leg does not.

Not legal advice. NumberBroom is a phone data and list hygiene tool, not a law firm. This page summarises publicly available federal rules as of Jul 29, 2026 and is provided for general information only. TCPA and state telemarketing law change frequently and apply differently depending on your business, your consent records, and the states you call. Consult qualified counsel before relying on any of it.
Scrub litigators out before you dial
Carrier-level validation and a TCPA litigator check in one job. $0.20 per number, $5 minimum, no subscription.
Upload a list
Cameron Hoffman

Founder, NumberBroom · 10 years in telecommunications and marketing

Cameron Hoffman is the founder of NumberBroom and has spent 10 years working in telecommunications and marketing. He built NumberBroom after repeatedly watching outbound teams dial purchased lists that were full of dead numbers, landlines and TCPA litigators.