Navigation
X Close

Resource Center

TCPA Law Explained: Compliance Rules for Marketing Calls and Texts 

Type: Blog
Topic: Do Not Call Solution

Businessman using laptop with document online for approve quality assurance and ERP management, Quality management with assurance, Quality control and improvement.

The Telephone Consumer Protection Act (TCPA) is a federal law that regulates how businesses contact consumers by phone, text, and fax. Enacted in 1991 and enforced by the Federal Communications Commission (FCC), the TCPA restricts the use of autodialers (ATDS), prerecorded and artificial voice messages, and unsolicited text messages. It works alongside the FTC’s Telemarketing Sales Rule (TSR) to create a comprehensive framework for outbound marketing compliance. 

Violations carry significant financial exposure. TCPA statutory damages reach $500 per violation and $1,500 per willful violation, and consumers can bring individual lawsuits or class actions to enforce them. PossibleNOW’s DNCSolution® and MyPreferences® help organizations meet these requirements through automated DNC scrubbing, consent management, and real-time suppression across channels. 

Key TCPA compliance topics covered in this blog include: 

  • Communications regulated by the TCPA  
  • Consent and opt-out requirements  
  • National and internal Do Not Call rules  
  • Penalties and enforcement  
  • State Mini-TCPA laws  
  • Common compliance risks  
  • Practical controls for marketing teams 

In the following sections, you’ll find information on:

Request a Demo Today

Ron Patrick Headshot
“Automation reduces risk only when it is backed by clean opt-out data and consistent enforcement. Centralize consent and opt-outs and suppress at the point of dial/send with audit logs.”
– Ron Patrick, SVP, Product, PossibleNOW

What Is the TCPA? 

The Telephone Consumer Protection Act is a federal statute (47 U.S.C. § 227) that protects consumers from unwanted telemarketing communications. It restricts how businesses use automated dialing systems, prerecorded voice messages, and text messages to reach consumers, and it requires businesses to honor Do Not Call requests. 

The FCC is the primary regulatory agency responsible for interpreting and enforcing the TCPA. The FTC plays a complementary role through the TSR, which governs the National Do Not Call Registry and adds its own telemarketing requirements. 

What Communications Does the TCPA Regulate? 

The TCPA does not treat every communication in the same way. Requirements vary according to the message, technology, recipient, and purpose. 

  • Marketing calls: Telephone solicitations may be subject to consent, calling-hour, identification, and Do Not Call requirements.  
  • Text messages: The FCC treats text messages as calls for purposes of the TCPA. Automated marketing texts may require prior express written consent.  
  • Artificial or prerecorded voice messages: Telemarketing calls using artificial or prerecorded voices generally require prior express written consent unless an exception applies.  
  • Autodialed communications: Calls made with technology that meets the TCPA’s definition of an automatic telephone dialing system may trigger additional restrictions.  
  • Fax advertisements: Unsolicited fax advertisements are regulated, including requirements related to permission and opt-out notices. 

Who Does the TCPA Apply To? 

The TCPA can affect organizations that initiate or direct regulated calls, texts, prerecorded messages, or fax advertisements. This may include: 

  • Brands and campaign owners  
  • Internal marketing and sales teams  
  • Call centers  
  • Lead generators  
  • Vendors and remarketers  
  • Third-party agents acting on behalf of another organization  

Courts have consistently found that brands are responsible for the actions of their third-party marketing partners, including lead generators, vendors, and remarketers, under applicable vicarious liability standards. Organizations should therefore monitor how partners collect consent, use customer data, and process opt-outs. 

Infographic by PossibleNOW titled 'Who Does the TCPA Apply to?' Four blue cubes with orange icons represent covered groups: 1) Telemarketers and call centers, 2) Companies that outsource calls, 3) Organizations collecting customer data, and 4) Anyone handling personal or contact information. The PossibleNOW logo and tagline 'Marketing Compliance Made Simple' are at the top.

Key TCPA Compliance Rules 

Consent requirements depend on the communication and technology involved. Prior express written consent is generally required for marketing calls or texts that use regulated automated technology or an artificial or prerecorded voice. 

Consent records should document: 

  • Who provided consent  
  • The number covered  
  • The disclosure presented  
  • The date and time  
  • The collection source  
  • The scope of the permission  

Consent must be clear, documented, and tied to a specific communication method or campaign.  

Honor Opt-Out and Revocation Requests 

Businesses must recognize reasonable requests to stop regulated calls or texts. Requests may arrive through common keywords, verbal statements, customer service channels, or other reasonable methods. 

Marketing contact must stop as soon as possible and no later than 10 business days after the request is received. Businesses should document and timestamp each request when it arrives.  

Maintain an Internal Do Not Call List 

Every organization conducting outbound marketing must maintain its own internal Do Not Call list. 

Federal law requires internal DNC records be retained for at least five years, though some states require 10 years. Many businesses choose to retain these records indefinitely as a best practice.  

Follow Calling-Time Restrictions 

Federal rules generally restrict telephone solicitations to the period between 8 a.m. and 9 p.m. at the called party’s location. State laws may impose narrower windows, holiday restrictions, or emergency-related limits. 

Campaign rules should be applied according to the recipient’s location rather than the caller’s time zone.  

Provide Required Identification 

Telemarketers must provide accurate identifying information. Applicable rules may require the caller to identify the individual, the organization responsible for the call, and a telephone number that recipients can use to submit a Do Not Call request.  

Apply Opt-Outs Across Relevant Systems 

A request captured by one department should not remain isolated there. Suppression data must reach the dialer, CRM, campaign platform, customer service system, and relevant vendors before further outreach occurs. 

Centralized records help reduce conflicting contact decisions and create an auditable history. 

Account for Reassigned Numbers 

A phone number may be disconnected and reassigned after consent was collected. Calling or texting its new owner can create risk because the new subscriber did not provide the original permission. 

Organizations should validate number status and compare disconnection dates with consent records before relying on older permission. 

How Do the TCPA and National Do Not Call Rules Work Together? 

The TCPA sets federal rules for certain marketing calls and texts. The National Do Not Call Registry works alongside those rules by allowing consumers to limit telemarketing calls to their phone numbers. Together, they govern both the methods businesses use to contact consumers and whether a telemarketing call is permitted. 

Some calls may qualify for an exemption, such as when the consumer has given valid permission or when an established business relationship applies. Exemptions are fact-specific, so businesses should review each situation before relying on one. 

Even when an exemption applies, businesses must still honor any entity-specific Do Not Call request from the consumer. 

TCPA Penalties and Enforcement 

TCPA violations carry significant financial exposure through private lawsuits, class actions, regulatory enforcement, and reputational harm. 

Statutory damages under the TCPA: 

  • $500 per violation for calls that violate consent, Do Not Call, or other TCPA provisions 
  • $1,500 per willful violation when the caller knowingly disregarded the law 

The TCPA includes a private right of action, allowing individual consumers to file lawsuits or join class actions against violators. Settlements in TCPA-related class actions routinely reach into the millions of dollars. 

The FCC and state attorneys general may also pursue enforcement under applicable authority. Separate violations of the FTC’s Telemarketing Sales Rule can carry civil penalties of up to more than $53,000 per non-compliant contact. 

Accurate consent records, scrub receipts, suppression histories, and campaign logs can help demonstrate the controls used before outreach occurred. 

State Mini-TCPA Laws: How They Affect Marketing Campaigns 

Several states, including Florida, Oklahoma, and Maryland, have enacted laws commonly described as Mini-TCPAs. These state telemarketing regulations often go beyond federal TCPA requirements, and some impose higher statutory damages than federal law. 

Some mini-TCPAs use broader definitions of automated systems than the federal TCPA, which can bring additional calling or texting practices within their scope. A few states operate their own Do Not Call lists, while others rely on the National Registry and enforce separate state requirements. 

For businesses operating across multiple jurisdictions, a fragmented approach to compliance can result in overlapping violations and compounding penalties. Organizations operating across jurisdictions should apply rules according to where the recipient is located rather than relying on one nationwide campaign standard.

Speak With an Expert Today

Common TCPA Compliance Risks: What Businesses Should Avoid 

Consent stored across disconnected platforms may be incomplete, outdated, or unavailable when a campaign launches. 

Delayed Opt-Out Processing 

Manual handoffs can allow additional calls or texts after a consumer has revoked consent. 

Incomplete Suppression Lists 

Checking only the National Registry overlooks internal requests, state requirements, and other applicable restrictions. 

Contacting Reassigned Numbers 

Permission tied to a former subscriber may not authorize contact with the current owner of the number. 

Unmonitored Marketing Partners 

Courts have consistently found that brands are responsible for the actions of their third-party marketing partners. Poor partner oversight can expose the organization behind the campaign. 

Weak Audit Records 

A business may struggle to defend its process when it cannot produce the consent disclosure, timestamp, source, scrub result, or opt-out history. 

Changing State Requirements 

State calling restrictions can change independently of federal law. Static policies and infrequent legal reviews may leave campaigns operating under outdated rules.

FAQs

What does the TCPA prohibit? 

The TCPA prohibits unsolicited marketing calls and texts made using automatic telephone dialing systems or prerecorded and artificial voice messages without prior express written consent. It also prohibits calling numbers listed on the National Do Not Call Registry or an organization’s internal DNC list without a valid exemption. 

What are the consequences of TCPA violations? 

Recipients may seek actual losses or statutory damages of up to $500 per violation. A court may increase the award to as much as $1,500 when a violation is willful or knowing. Businesses may also face class actions, regulatory investigations, legal costs, and brand damage. 

Does the TCPA apply to text messages? 

Yes. The FCC treats text messages as “calls” under the TCPA. Marketing texts sent using an ATDS or to numbers on the National Do Not Call Registry are subject to the same consent and suppression requirements as voice calls. 

Does the TCPA apply to email? 

No. The TCPA and TSR regulate telephone calls, text messages, and faxes. Email marketing is governed by the CAN-SPAM Act and applicable state consumer protection statutes. 

Does the TCPA apply to B2B calls? 

Yes. The TCPA applies to any telephone communication made for marketing or solicitation purposes, regardless of whether the recipient is a consumer or a business. B2B organizations that use autodialers, prerecorded messages, or SMS for marketing outreach are typically subject to TCPA requirements. 

How quickly must businesses honor an opt-out? 

Businesses must cease regulated calls and texts as soon as possible after receiving an opt-out request, and no later than 10 business days. The request should be documented and timestamped when received.  

Who is responsible when a third-party vendor places the call? 

When outside partners such as lead generators, vendors, and remarketers handle marketing outreach, courts have consistently treated the brand behind the campaign as potentially liable for their conduct.  

Are small companies exempt from the TCPA? 

No, small companies are not exempt from TCPA requirements. The TCPA does not provide a general exemption based on company size. Small businesses must follow the same applicable consent, calling, texting, and Do Not Call requirements as larger organizations. 

What is the difference between the TCPA and the TSR? 

The TCPA is a federal statute enforced by the FCC that governs consent, autodialer use, prerecorded messages, and Do Not Call obligations. The TSR is a federal trade regulation enforced by the FTC that governs telemarketing practices, administers the National Do Not Call Registry, and carries its own penalties for violations. Businesses engaged in outbound marketing must comply with both. 

Request a Demo Today

How PossibleNOW Helps Organizations Stay TCPA Compliant 

TCPA compliance becomes harder when consent, suppression, and campaign data are spread across separate systems. PossibleNOW provides enterprise-class technology for applying consistent contact rules across teams and vendors. 

  • DNCSolution®: Scrubs records against federal, state, wireless, and company-specific lists. It supports real-time or batch processing, automated suppression, reporting, and audit histories.  
  • MyPreferences®: Centralizes customer consent, preferences, opt-outs, and revocations. Updates can be distributed across departments and connected technology platforms.  
  • RegInfoHub®: Provides current federal and state regulatory information, legal references, interpretive summaries, alerts, and jurisdiction-specific research tools. 

Together, these TCPA compliance platforms help organizations suppress restricted contacts before a call or text is initiated, maintain defensible records, and apply customer choices across complex operations. 

Disconnected consent and suppression processes increase the chance of unwanted contact. PossibleNOW gives marketing, call center, legal, and risk teams a centralized framework for managing those decisions at enterprise scale. 

Reduce TCPA risk before the next campaign begins. Contact PossibleNOW to discuss a more defensible approach to consent and Do Not Contact management.