ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

What are the penalties for TCPA violations?

Back to InsightsWhat are the penalties for TCPA violations?

What are the penalties for TCPA violations?

Key Facts

  • A single TCPA violation costs $500, rising to $1,500 for willful conduct with no aggregate cap according to compliance research
  • 10,000 standard TCPA violations equal $5 million in damages, jumping to $15 million if deemed willful per legal analysis
  • A contact center making 50,000 monthly calls with 2% bad-consent rate faces class certification exposure "ending in eight zeros" per worst-case analysis
  • Dish Network paid $280 million for TCPA violations, Capital One $75.5 million, and Wakefield v. ViSalus resulted in a $925 million judgment for 1.85 million calls based on settlement records
  • 78% of all TCPA filings are class actions, with 2,788 cases filed in 2024—a 67% increase from 2023 per litigation trends
  • State mini-TCPA laws like Connecticut’s allow up to $20,000 per violation, stacking on federal claims per multi-jurisdictional risk analysis
  • The TRACED Act introduces civil penalties of up to $10,000 per call for certain robocall violations per regulatory developments

The Real Cost of a TCPA Violation: How Penalties Stack Up

A single non-compliant marketing call can cost $500. Multiply that across a campaign of thousands, and the math turns a lead-generation strategy into an existential liability.

The TCPA sets statutory damages at $500 per violation, which jumps to $1,500 when the conduct is deemed willful — such as failing to check the FCC Reassigned Numbers Database before dialing, according to compliance research. Critically, there is no aggregate cap, so damages stack mechanically call by call. As one legal analysis puts it, a plaintiff doesn't need to prove individual harm — only that the call happened to a US wireless number without prior express written consent.

The exposure scales fast. A contact center making 50,000 outbound dials a month with just a 2% bad-consent rate faces class certification exposure "ending in eight zeros," per the same worst-case analysis. Even 10,000 standard violations at $500 each equals $5 million — $15 million if willful.

Beyond the base statute, several multipliers and stacked liabilities dramatically raise the ceiling:

  • TRACED Act penalties — up to $10,000 per call for certain robocall violations, enforced by the FCC.
  • State mini-TCPA laws — Connecticut allows up to $20,000 per violation, and Florida, Oklahoma, Washington, and Maryland layer additional claims on top of federal ones.
  • Do-Not-Call violations under the FTC's Telemarketing Sales Rule — up to $50,120 per call.
  • Class actions — 78% of all TCPA filings, with 2,788 cases filed in 2024, a 67% jump from 2023.

The settlement record shows what this looks like in practice. Dish Network paid $280 million. Capital One paid $75.5 million largely over reassigned numbers. And in Wakefield v. ViSalus, a jury awarded a record $925 million for 1.85 million calls — roughly $500 per call, willful rate applied.

Here is the part most businesses miss: legal experts note that agencies and vendors do not indemnify the brands they dial for. If a third party runs your campaign and cuts corners, the liability lands on your business, not theirs. Even winning a TCPA class action typically means six-figure legal fees before any settlement.

This is why consent discipline matters more than dial volume. CallMyCustomers works only from lists of real customers, honors opt-outs immediately, and puts every script and message through owner approval before anything goes out — because permission isn't a legal checkbox, it's the difference between a reactivation campaign and a nine-figure headline.

Why TCPA Risk Is Rising—and Why Small Businesses Aren't Immune

TCPA risk is escalating rapidly, with 2,788 cases filed in 2024—a 67% increase from the prior year—and monthly class action filings surging to 172 by January 2025, a 268% jump over January 2024. Class actions now dominate enforcement, making up 78% of all TCPA filings, which means even a modest outreach list can trigger significant liability.

The mechanical nature of TCPA liability amplifies this risk: plaintiffs need only prove a call or text occurred without prior express written consent, not actual harm. As one expert noted, "The plaintiff doesn't have to prove individual harm. They just have to prove the call happened to a US wireless number without prior express written consent. The damages stack mechanically from there." This reality puts small businesses using customer lists for reactivation, reminders, or follow-ups directly in the crosshairs, especially when data hygiene lapses.

For service businesses relying on repeat work—like HVAC, dental clinics, or automotive shops—this creates a pressing compliance challenge. A single outdated number or missing consent record can transform a well-intentioned outreach campaign into a costly legal exposure. CallMyCustomers helps mitigate this risk by working only from verified customer lists, honoring opt-outs immediately, and ensuring every message is pre-approved by the business owner before delivery.

  • Federal statutory penalties start at $500 per violation, rising to $1,500 for willful conduct
  • State mini-TCPA laws like Connecticut’s allow up to $20,000 per violation
  • The TRACED Act introduces civil penalties of up to $10,000 per call for certain robocall violations

With litigation volume rising and liability stacking mechanically, proactive compliance isn’t just prudent—it’s essential for any business engaging customers by phone or text. Regular data scrubbing, express written consent, and utilization of the FCC Reassigned Numbers Database are no longer optional; they’re foundational to avoiding exposure in an increasingly litigious landscape.

Most TCPA violations stem from two fundamental compliance gaps that plaintiffs' attorneys consistently exploit: calling reassigned numbers using stale contact data and failing to document proper consent. Industry research shows that contact lists average six weeks old, creating significant risk when numbers get reassigned to new subscribers who never provided consent for your business. This data quality issue has been identified as the #1 compliance gap in TCPA litigation, with experts noting that every call to a reassigned number represents a potential $500 to $1,500 violation depending on whether it's deemed willful conduct.

The FCC requires express written consent that meets specific criteria: it must be in writing, clearly authorize the specific seller making the call, identify the exact phone number being contacted, and cannot be conditioned on a purchase. When businesses fail to maintain documentation proving these elements were met, they create what legal experts describe as the origin point for most TCPA violations. Without robust consent records, even well-intentioned outreach efforts can trigger statutory damages that escalate quickly in class action contexts where 78% of all TCPA filings occur.

Failure to check the FCC Reassigned Numbers Database before initiating calls can be treated as willful conduct by courts and regulators, potentially tripling liability from $500 to $1,500 per violation. This is particularly relevant for service businesses using customer lists for reactivation campaigns, where outdated information increases the likelihood of contacting reassigned numbers. Implementing weekly data hygiene protocols—rather than relying on the industry-standard six-week refresh cycle—directly addresses this vulnerability by ensuring numbers are verified against current reassignment records before outreach begins.

For businesses like CallMyCustomers that specialize in customer reactivation through approved calling campaigns, these compliance requirements shape every aspect of list processing and message delivery. The business model depends on maintaining current, permission-based contact information where explicit consent has been obtained and documented according to FCC standards. By integrating weekly list scrubbing with the Reassigned Numbers Database and preserving detailed consent records that meet all regulatory requirements, service businesses can significantly reduce their exposure to the mechanical nature of TCPA liability where damages accumulate based solely on call volume without proven harm. This proactive approach transforms compliance from a defensive necessity into a foundation for sustainable, permission-based customer engagement.

TCPA penalties stack mechanically: a plaintiff only has to prove a call or text reached a US wireless number without prior express written consent, and damages of $500 to $1,500 per violation accumulate from there — with no cap. The good news is that a disciplined outreach playbook removes nearly all of that exposure before a single message goes out.

Start with valid consent. Under FCC rules, written consent must clearly authorize a specific seller, identify the phone number, and not be conditioned on a purchase. Legal experts note that strong consent policies can do more than reduce damages — they can prevent class certification entirely, which matters when class actions make up 78% of all TCPA filings.

Scrub your data weekly. Stale data leading to calls to reassigned numbers is the #1 compliance gap plaintiffs' attorneys exploit — every call to a reassigned number is a $500–$1,500 violation. Most companies refresh contact data on a six-week cycle; weekly hygiene dramatically shrinks that window.

Query the FCC Reassigned Numbers Database before every campaign. Doing so earns safe harbor protection for the first call to a reassigned wireless number. Skipping the database lookup can be argued as willful conduct, tripling liability from $500 to $1,500 per violation.

Honor opt-outs immediately — in any reasonable form. Consent can be revoked "in any reasonable way at any time" unless a specific revocation procedure was agreed upon. A reply of "stop," a verbal request on a live call, or an email all count. Note that a pending FCC draft order may narrow revocations to specific message categories, so systems that distinguish marketing from informational messages (like appointment reminders) are worth building now.

Keep detailed records of every call and text. Comprehensive logs let you rebut plaintiffs whose telephone records lack content details, and they're often the difference between a dismissed claim and a certified class. As one analysis put it, the consent documentation gap is where most violations originate.

A compact checklist:

  • Obtain express written consent that names the seller and phone number, and isn't tied to a purchase.
  • Refresh contact data weekly and segment by recency before any reactivation campaign.
  • Query the FCC Reassigned Numbers Database before each campaign wave.
  • Process opt-outs immediately, regardless of channel or format.
  • Log every call and text with timestamps, consent references, and message content.

This is exactly how permission-based outreach should work: campaigns built from lists of real customers, with every message approved before it's sent. Done right — the way CallMyCustomers runs its reactivation campaigns, with opt-outs honored immediately and every touch documented — TCPA compliance stops being a legal minefield and becomes simply good customer communication.

How CallMyCustomers Keeps Reactivation Campaigns Compliant

Protecting your business from costly TCPA violations starts with a compliance-first approach to reactivation campaigns. With statutory damages of $500 per violation—rising to $1,500 for willful conduct—and no cap on aggregate liability, the financial exposure can escalate quickly, as demonstrated by the $925 million judgment in Wakefield v. ViSalus for 1.85 million non-compliant calls. CallMyCustomers eliminates this risk by operating only from lists of real, verified customers, ensuring every outreach targets individuals with an established relationship to your business.

Every script, offer, and message is reviewed and approved by you before deployment, maintaining full control over how your brand communicates. We honor opt-outs immediately and scrub data weekly—far exceeding the industry-standard 6-week average—to prevent calls to reassigned numbers, which experts identify as the #1 compliance gap exploited by plaintiffs. For clinic clients, we layer in BAA/HIPAA compliance and follow A2P 10DLC standards, ensuring patient outreach meets clinical and regulatory expectations without compromising permission-based engagement.

Before any work begins, we conduct a free list review to assess both revenue potential and compliance health. This zero-risk step reveals what your list can produce, confirms data quality, and outlines setup costs—so you know exactly what to expect before spending a dollar. It’s how we turn past customers into booked work, approved by you, run by us.

Frequently Asked Questions

How much can a single TCPA violation actually cost my business?
Federal statutory damages are $500 per violation, but that jumps to $1,500 when conduct is deemed willful — such as failing to check the FCC Reassigned Numbers Database before dialing. There's no cap on aggregate liability, so a plaintiff only has to prove the call happened without prior express written consent, and damages stack mechanically call by call.
What's the biggest TCPA settlement or judgment on record?
The largest is a $925 million jury award in Wakefield v. ViSalus for 1.85 million non-compliant calls — roughly $500 per call at the willful rate. Other major settlements include Dish Network at $280 million and Capital One at $75.5 million, the latter largely over reassigned numbers.
Are TCPA lawsuits really increasing, or is this just hype?
Litigation is genuinely surging: 2,788 TCPA cases were filed in 2024, a 67% jump from 2023, and monthly class action filings hit 172 by January 2025 — a 268% increase year over year. Class actions now make up 78% of all TCPA filings, meaning even a modest outreach list can trigger significant liability.
Can state laws make TCPA penalties even worse than the federal $500?
Yes. State mini-TCPA laws stack on top of federal claims — Connecticut allows up to $20,000 per violation, and Florida, Oklahoma, Washington, and Maryland layer additional claims on top of federal ones. The TRACED Act also adds FCC-enforced penalties of up to $10,000 per call for certain robocall violations, and FTC Do-Not-Call violations can reach $50,120 per call.
If I hire an agency to run my campaigns, aren't they liable for TCPA violations — not me?
No — legal experts note that agencies and vendors do not indemnify the brands they dial for, so if a third party cuts corners, the liability lands on your business. Even winning a TCPA class action typically means six-figure legal fees before any settlement, which is why CallMyCustomers works only from verified customer lists with every message owner-approved and opt-outs honored immediately.
What's the most common compliance mistake that leads to TCPA violations?
Stale data leading to calls or texts to reassigned numbers is the #1 compliance gap plaintiffs' attorneys exploit — every call to a reassigned number is a $500–$1,500 violation. Most companies refresh contact data on a six-week cycle, but querying the FCC Reassigned Numbers Database before each campaign earns safe harbor protection for the first call, and skipping it can be treated as willful conduct.

Compliance Is Cheaper Than the Verdict

TCPA penalties stack mechanically: $500 per violation, $1,500 if willful, with no aggregate cap — and class actions made up 78% of the 2,788 TCPA cases filed in 2024, a 67% jump from the prior year. The record $925 million Wakefield v. ViSalus judgment shows how quickly a single campaign can turn into a nine-figure headline. The good news is that nearly all of this exposure is preventable with express written consent, weekly data scrubbing, Reassigned Numbers Database checks, immediate opt-out honoring, and detailed call records. That discipline is exactly how CallMyCustomers runs its reactivation campaigns — from verified customer lists only, with every script approved by the business owner before anything goes out. Your next step is simple: audit your consent records and data refresh practices before your next outreach campaign. Or let us do it for you — start with a free list review to see what your past customers are worth, with zero risk and no dollar spent until you know exactly what to expect.

Stay in the Loop