
What are the rules of the TCPA?
Key Facts
- TCPA violations cost $500–$1,500 per call or text with no proof of injury required, per BCLP's legal analysis.
- Since April 11, 2025, businesses must honor opt-outs made in any reasonable manner within 10 business days, down from 30, per the FCC's rule announcement.
- A Colorado satellite TV provider faced a $61 million class action verdict for vendor-placed calls to 18,000 DNC-listed consumers, according to DNC.com's litigation analysis.
- Just 44 law firms or lawyers filed 60% of TCPA lawsuits over a 17-month period, per U.S. Chamber Institute data.
- Average TCPA class action settlements reached $6.6 million in early 2018, according to Womble Bond Dickinson research.
- Florida's mini-TCPA restricts calls to 8am–8pm and caps outreach at three calls per topic per 24 hours, per Foster LLP attorneys.
- Outsourcing outreach doesn't outsource liability — FCC vicarious liability makes a vendor's TCPA violations legally yours, as Foster LLP explains.
Why the TCPA Is a Real Risk for Legitimate Businesses
Many businesses assume TCPA enforcement targets only overseas spammers or shady telemarketers, but the reality is different. The TCPA is a strict-liability statute carrying $500–$1,500 per violation in statutory damages, a four-year statute of limitations, and an uncapped private right of action — and compliant-minded U.S. businesses are increasingly the primary litigation targets. Even well-intentioned outreach campaigns for appointment reminders, service follow-ups, or seasonal promotions now carry significant compliance weight, especially after the FCC’s 2025 opt-out rule change took effect on April 11, 2025.
This rule fundamentally changed how businesses must handle consent revocation. Consumers can now opt out “in any reasonable manner” — including telling a cashier, sending an email, leaving a voicemail, or using keywords like STOP or UNSUBSCRIBE — and businesses must honor these requests within 10 business days across both calls and texts. A single clarification text is permitted within five minutes of a revocation request, but if no response is received, the business must assume the opt-out applies to all future automated communications. Failure to comply risks costly class action exposure, with average settlements reaching $6.6 million in early 2018 and individual verdicts exceeding $500,000 in some cases.
For service businesses relying on repeat customers, these rules mean every text reminder or callback attempt must be backed by verifiable consent and immediate opt-out processing. CallMyCustomers works exclusively from verified customer lists and honors opt-outs immediately, routing replies back into the client’s booking system so outreach feels useful, not pushy. Staying compliant isn’t just about avoiding fines — it’s about preserving trust with the customers who already know your business.
- Statutory damages range from $500 to $1,500 per violation with no proof of injury required
- The opt-out compliance window was reduced from 30 to 10 business days effective April 11, 2025
- 60% of TCPA lawsuits over a 17-month period were filed by just 44 law firms or lawyers
The Core TCPA Rules: Consent, DNC Lists, and the New 2025 Opt-Out Requirements
Every text you send to a customer carries legal weight, and the TCPA's rules now extend to how — and how fast — you stop. The stakes are real: violations carry statutory damages of $500–$1,500 per violation, with no proof of injury required and a four-year statute of limitations, according to BCLP's analysis of the new rules.
Consent: the marketing vs. informational distinction
Marketing texts, marketing robocalls, and fax advertisements all require prior express written consent — conspicuously disclosed, separately signed, and authorizing autodialed or prerecorded telemarketing. Informational and transactional messages are different: regular express consent suffices and can be presumed from context, as ActiveProspect's TCPA guide explains. Handing your bank your phone number, for instance, presumes consent for account-related texts.
Do Not Call lists: now covering texts
The FCC's 2024 rulemaking codified that National DNC Registry protections extend to text messages, so businesses must scrub outbound lists against the Registry — not just for calls. An internal DNC list is equally mandatory. DNC.com's compliance guidance recommends honoring internal opt-outs immediately and suppressing known litigators, since legitimate U.S. businesses are the primary litigation targets.
The April 11, 2025 opt-out rules
The biggest recent change: consumers may now revoke consent in any reasonable manner, and businesses must honor it within 10 business days — down from the prior 30-day window. Reasonable methods include:
- Text keywords like STOP, END, REVOKE, CANCEL, or UNSUBSCRIBE
- Automated key presses, websites, email, or voicemail
- Telling a cashier or calling headquarters — any method carries a rebuttable presumption of reasonableness
Revocation made through any medium applies to both robocalls and robotexts, per the FCC's rule announcement. The scope is asymmetric: opting out of marketing stops only marketing, but opting out of an informational message halts all future non-emergency calls and texts.
One narrow window remains. Businesses may send a single clarification text within 5 minutes of a revocation request — containing no marketing content — to determine its scope. If the consumer doesn't respond, the business must assume revocation applies to everything.
For service businesses running reactivation outreach, this is why vendors matter: the FCC applies vicarious liability, so an outsourced campaign's violations are yours. CallMyCustomers works only from real-customer lists with opt-outs honored immediately, and every script is owner-approved before anything is sent — the practical structure these rules demand.
State Mini-TCPA Laws and Vendor Liability: The Rules That Sneak Up on You
Most businesses that worry about TCPA compliance study the federal rules carefully — and then get blindsided by two layers of exposure that never appear in the federal statute. State "mini-TCPA" laws and vicarious liability for vendors are where the expensive surprises live.
State laws can be stricter than the federal TCPA — and they apply even when federal rules don't. Florida restricts calls to 8 am–8 pm local time and caps you at three calls on the same topic per 24 hours, with a broad definition of what counts as an autodialer, according to Foster LLP attorneys. Oklahoma's Telephone Solicitation Act is modeled on Florida's framework.
New York goes further: practitioner analysis notes the state requires an opt-out opportunity within three seconds of a call starting — regardless of consent. Washington and California restrict unsolicited texts regardless of the technology used, and Michigan, Maryland, Virginia, and Texas have enacted or are considering additional protections.
The practical takeaway for any business calling into multiple states:
- Map every state you dial or text into, not just where you're headquartered
- Comply with the most restrictive applicable standard — a conservative approach covers you everywhere
- Track state laws separately, since they change independently of federal rules
The second blind spot is vendor liability. The FCC has made clear that outsourcing your outreach doesn't outsource your liability — vicarious liability means a vendor's TCPA violations are legally yours, and contractual indemnification clauses don't erase statutory responsibility, as Foster LLP explains.
The cautionary tale is real. A Colorado satellite TV provider received a $61 million class action verdict for calls placed by a vendor — more than 50,000 calls to over 18,000 consumers on the DNC list, according to DNC.com's litigation analysis. The same company separately paid a $280 million FTC penalty. And with 30–40% of TCPA complaints in a given year becoming class actions, one vendor's sloppy dialing can scale into a nine-figure problem.
This is why vendor accountability matters contractually, not just verbally. Legal practitioners recommend requiring vendors to maintain TCPA compliance programs, support opt-out processing, sync suppression data, and grant audit rights.
It's also why CallMyCustomers runs outreach only from lists of real customers with every message approved by the business owner before it goes out — permission and oversight are the cheapest compliance tools available. When a vendor calls on your behalf, their practices are your legal exposure. Choose accordingly.
How to Run Compliant Customer Outreach Without Killing Your Campaigns
Knowing the rules is one thing; running campaigns that respect them without grinding to a halt is another. The good news is that TCPA compliance and productive outreach aren't opposites — permission-based campaigns built on real customer relationships tend to perform better anyway.
Start with consent documentation. For telemarketing, retain a signed, standalone prior express written consent record specifying the sender, the number, authorization for autodialed or prerecorded messages, and that consent isn't a condition of purchase, as Foster LLP attorneys recommend. Because the statute of limitations runs four years, BCLP Law advises keeping those records at least that long.
Next, build opt-out processing that works across every channel. Since April 11, 2025, consumers can revoke consent "in any reasonable manner" — a STOP text, a voicemail, an email, even telling a cashier — and you must honor it within 10 business days, with revocation applying to both calls and texts. The burden of proving a method unreasonable falls on the business, so your systems need to capture revocations from any touchpoint and sync them across campaigns and vendors.
Then scrub your lists. Suppress numbers on the National DNC Registry, maintain an internal do-not-call list, and compliance best practices also suggest suppressing known litigators and serial plaintiffs. This is where working from lists of real, known customers — people who actually did business with you — dramatically reduces risk compared with cold outreach.
Finally, hold vendors accountable. The FCC applies vicarious liability, meaning a vendor's violation is your violation — one company faced a $61 million verdict for calls placed by a third party. When CallMyCustomers runs reactivation campaigns, the model reflects this reality directly:
- Campaigns work only from lists of real customers, never scraped or purchased leads
- The owner approves every script, offer, and message before anything goes out
- Opt-outs are honored immediately, well inside the 10-business-day window
- Explicit consent is collected at booking, creating a documented permission trail
That structure matters because reactivation of known customers is inherently permission-based — you're reconnecting with people who chose your business, not interrupting strangers. Check state rules too: Florida's mini-TCPA caps calls at three per 24 hours and restricts calling to 8 am–8 pm, and multistate operators must follow the strictest applicable standard.
Compliance done right isn't a brake on campaigns — it's the foundation that lets you keep reaching the customers who already know you, season after season, without legal exposure.
Frequently Asked Questions
What are the basic rules of the TCPA that businesses have to follow?
How much can a TCPA violation actually cost my business?
What changed with the TCPA opt-out rules in April 2025?
If a customer texts STOP, do I have to stop calling them too?
Am I liable if my vendor or call center breaks TCPA rules on my behalf?
Do state TCPA laws matter, or do I just follow the federal rules?
Compliance Is the Foundation, Not the Brake
The TCPA's rules come down to a few clear obligations: get the right consent before marketing outreach, scrub against the National DNC Registry, honor opt-outs made in any reasonable manner within 10 business days, and remember that state mini-TCPA laws and vendor vicarious liability extend your exposure well beyond the federal statute. With statutory damages of $500–$1,500 per violation and average class action settlements reaching $6.6 million, the businesses getting hit hardest are legitimate ones — not overseas spammers. Your next steps: audit how consent is captured at booking, verify opt-outs sync across every channel within the new window, and put any vendor's compliance practices in writing before a single call goes out. The good news is that reactivating customers you already have — people who chose your business — is inherently lower-risk than cold outreach. CallMyCustomers runs campaigns only from verified customer lists, honors opt-outs immediately, and puts every script in your hands for approval before anything is sent. If you'd like to see what your existing customer list could produce, start with a free list review — you'll know your rate, setup, and potential before spending a dollar.