Type: Blog
Topic: Do Not Call Solution

The Telephone Consumer Protection Act (TCPA) is a federal law that regulates how businesses contact consumers by phone, text, and fax. Enacted in 1991 and enforced by the Federal Communications Commission (FCC), the TCPA restricts the use of autodialers (ATDS), prerecorded and artificial voice messages, and unsolicited text messages. It works alongside the FTC’s Telemarketing Sales Rule (TSR) to create a comprehensive framework for outbound marketing compliance.
Violations carry significant financial exposure. TCPA statutory damages reach $500 per violation and $1,500 per willful violation, and consumers can bring individual lawsuits or class actions to enforce them. PossibleNOW’s DNCSolution® and MyPreferences® help organizations meet these requirements through automated DNC scrubbing, consent management, and real-time suppression across channels.
Key TCPA compliance topics covered in this blog include:
In the following sections, you’ll find information on:
Request a Demo Today
“Automation reduces risk only when it is backed by clean opt-out data and consistent enforcement. Centralize consent and opt-outs and suppress at the point of dial/send with audit logs.”
The Telephone Consumer Protection Act is a federal statute (47 U.S.C. § 227) that protects consumers from unwanted telemarketing communications. It restricts how businesses use automated dialing systems, prerecorded voice messages, and text messages to reach consumers, and it requires businesses to honor Do Not Call requests.
The FCC is the primary regulatory agency responsible for interpreting and enforcing the TCPA. The FTC plays a complementary role through the TSR, which governs the National Do Not Call Registry and adds its own telemarketing requirements.
The TCPA does not treat every communication in the same way. Requirements vary according to the message, technology, recipient, and purpose.
The TCPA can affect organizations that initiate or direct regulated calls, texts, prerecorded messages, or fax advertisements. This may include:
Courts have consistently found that brands are responsible for the actions of their third-party marketing partners, including lead generators, vendors, and remarketers, under applicable vicarious liability standards. Organizations should therefore monitor how partners collect consent, use customer data, and process opt-outs.

Consent requirements depend on the communication and technology involved. Prior express written consent is generally required for marketing calls or texts that use regulated automated technology or an artificial or prerecorded voice.
Consent records should document:
Consent must be clear, documented, and tied to a specific communication method or campaign.
Businesses must recognize reasonable requests to stop regulated calls or texts. Requests may arrive through common keywords, verbal statements, customer service channels, or other reasonable methods.
Marketing contact must stop as soon as possible and no later than 10 business days after the request is received. Businesses should document and timestamp each request when it arrives.
Every organization conducting outbound marketing must maintain its own internal Do Not Call list.
Federal law requires internal DNC records be retained for at least five years, though some states require 10 years. Many businesses choose to retain these records indefinitely as a best practice.
Federal rules generally restrict telephone solicitations to the period between 8 a.m. and 9 p.m. at the called party’s location. State laws may impose narrower windows, holiday restrictions, or emergency-related limits.
Campaign rules should be applied according to the recipient’s location rather than the caller’s time zone.
Telemarketers must provide accurate identifying information. Applicable rules may require the caller to identify the individual, the organization responsible for the call, and a telephone number that recipients can use to submit a Do Not Call request.
A request captured by one department should not remain isolated there. Suppression data must reach the dialer, CRM, campaign platform, customer service system, and relevant vendors before further outreach occurs.
Centralized records help reduce conflicting contact decisions and create an auditable history.
A phone number may be disconnected and reassigned after consent was collected. Calling or texting its new owner can create risk because the new subscriber did not provide the original permission.
Organizations should validate number status and compare disconnection dates with consent records before relying on older permission.
The TCPA sets federal rules for certain marketing calls and texts. The National Do Not Call Registry works alongside those rules by allowing consumers to limit telemarketing calls to their phone numbers. Together, they govern both the methods businesses use to contact consumers and whether a telemarketing call is permitted.
Some calls may qualify for an exemption, such as when the consumer has given valid permission or when an established business relationship applies. Exemptions are fact-specific, so businesses should review each situation before relying on one.
Even when an exemption applies, businesses must still honor any entity-specific Do Not Call request from the consumer.
TCPA violations carry significant financial exposure through private lawsuits, class actions, regulatory enforcement, and reputational harm.
Statutory damages under the TCPA:
The TCPA includes a private right of action, allowing individual consumers to file lawsuits or join class actions against violators. Settlements in TCPA-related class actions routinely reach into the millions of dollars.
The FCC and state attorneys general may also pursue enforcement under applicable authority. Separate violations of the FTC’s Telemarketing Sales Rule can carry civil penalties of up to more than $53,000 per non-compliant contact.
Accurate consent records, scrub receipts, suppression histories, and campaign logs can help demonstrate the controls used before outreach occurred.
Several states, including Florida, Oklahoma, and Maryland, have enacted laws commonly described as Mini-TCPAs. These state telemarketing regulations often go beyond federal TCPA requirements, and some impose higher statutory damages than federal law.
Some mini-TCPAs use broader definitions of automated systems than the federal TCPA, which can bring additional calling or texting practices within their scope. A few states operate their own Do Not Call lists, while others rely on the National Registry and enforce separate state requirements.
For businesses operating across multiple jurisdictions, a fragmented approach to compliance can result in overlapping violations and compounding penalties. Organizations operating across jurisdictions should apply rules according to where the recipient is located rather than relying on one nationwide campaign standard.
Speak With an Expert Today
Consent stored across disconnected platforms may be incomplete, outdated, or unavailable when a campaign launches.
Manual handoffs can allow additional calls or texts after a consumer has revoked consent.
Checking only the National Registry overlooks internal requests, state requirements, and other applicable restrictions.
Permission tied to a former subscriber may not authorize contact with the current owner of the number.
Courts have consistently found that brands are responsible for the actions of their third-party marketing partners. Poor partner oversight can expose the organization behind the campaign.
A business may struggle to defend its process when it cannot produce the consent disclosure, timestamp, source, scrub result, or opt-out history.
State calling restrictions can change independently of federal law. Static policies and infrequent legal reviews may leave campaigns operating under outdated rules.
The TCPA prohibits unsolicited marketing calls and texts made using automatic telephone dialing systems or prerecorded and artificial voice messages without prior express written consent. It also prohibits calling numbers listed on the National Do Not Call Registry or an organization’s internal DNC list without a valid exemption.
Recipients may seek actual losses or statutory damages of up to $500 per violation. A court may increase the award to as much as $1,500 when a violation is willful or knowing. Businesses may also face class actions, regulatory investigations, legal costs, and brand damage.
Yes. The FCC treats text messages as “calls” under the TCPA. Marketing texts sent using an ATDS or to numbers on the National Do Not Call Registry are subject to the same consent and suppression requirements as voice calls.
No. The TCPA and TSR regulate telephone calls, text messages, and faxes. Email marketing is governed by the CAN-SPAM Act and applicable state consumer protection statutes.
Yes. The TCPA applies to any telephone communication made for marketing or solicitation purposes, regardless of whether the recipient is a consumer or a business. B2B organizations that use autodialers, prerecorded messages, or SMS for marketing outreach are typically subject to TCPA requirements.
Businesses must cease regulated calls and texts as soon as possible after receiving an opt-out request, and no later than 10 business days. The request should be documented and timestamped when received.
When outside partners such as lead generators, vendors, and remarketers handle marketing outreach, courts have consistently treated the brand behind the campaign as potentially liable for their conduct.
No, small companies are not exempt from TCPA requirements. The TCPA does not provide a general exemption based on company size. Small businesses must follow the same applicable consent, calling, texting, and Do Not Call requirements as larger organizations.
The TCPA is a federal statute enforced by the FCC that governs consent, autodialer use, prerecorded messages, and Do Not Call obligations. The TSR is a federal trade regulation enforced by the FTC that governs telemarketing practices, administers the National Do Not Call Registry, and carries its own penalties for violations. Businesses engaged in outbound marketing must comply with both.
Request a Demo Today
TCPA compliance becomes harder when consent, suppression, and campaign data are spread across separate systems. PossibleNOW provides enterprise-class technology for applying consistent contact rules across teams and vendors.
Together, these TCPA compliance platforms help organizations suppress restricted contacts before a call or text is initiated, maintain defensible records, and apply customer choices across complex operations.
Disconnected consent and suppression processes increase the chance of unwanted contact. PossibleNOW gives marketing, call center, legal, and risk teams a centralized framework for managing those decisions at enterprise scale.
Reduce TCPA risk before the next campaign begins. Contact PossibleNOW to discuss a more defensible approach to consent and Do Not Contact management.