
What happens if you violate TCPA?
Key Facts
- One non-compliant text message can cost $500, and willful violations treble to $1,500 per contact, per TCPA penalty research.
- A jury awarded $925 million against a multi-level marketing company for 1.8 million autodialed calls, a verdict affirmed on appeal.
- Just 10,000 TCPA violations can generate $5 million to $15 million in fines, according to industry analysis.
- The FCC imposed a $6 million penalty for AI deepfake robocalls in May 2024, with forfeitures reaching ~$23,727 per violation.
- Keller Williams faced a preliminarily approved $40 million settlement for unauthorized auto-dialing, per documented case outcomes.
- The most common source of TCPA exposure is data infrastructure failure, not flawed consent language, per technical analysis.
- Standard insurance policies typically exclude TCPA settlements as regulatory penalties, leaving businesses uncovered until a claim hits.
The Real Cost of a TCPA Violation: Strict Liability With No Cap
One text message. That's all it takes to owe someone $500. Now multiply that by every contact in your customer list, and you begin to see why TCPA exposure keeps business owners awake at night.
The TCPA imposes a strict liability standard. A plaintiff does not need to prove the company intended to break the law — good-faith errors and deliberate violations are legally indistinguishable, as compliance analysis makes clear. Your CRM glitched and re-imported opted-out contacts? Treated the same as a knowingly illegal robocall campaign.
The penalty structure is simple and brutal: $500 per violation, trebled to $1,500 for knowing or willful conduct. Courts interpret "willful" broadly — including reckless disregard or continuing to call after someone opts out, according to TCPA penalty research. Each individual call or text counts separately, so campaign volume drives total exposure.
Here's what that math looks like in practice:
- 10,000 violations = $5 million to $15 million in potential fines, per industry analysis
- 100,000 autodialed calls without consent = $50M base exposure, or $150M if willful
- 20,000 calls to numbers that should have been suppressed = $10M at the standard rate alone
Real cases prove the math. A jury awarded $925 million against a multi-level marketing company for 1.8 million calls violating autodialer regulations — a verdict later affirmed on appeal, as documented case outcomes show. A satellite TV provider faced a $61 million class action verdict, with damages trebled to $1,200 per call for knowing conduct. And a Florida court preliminarily approved a $40 million settlement against a real estate company — widely reported as the Keller Williams case — for unauthorized auto-dialing.
There is no aggregate cap. Worse, the most common source of enterprise exposure isn't flawed consent language — it's data infrastructure failure, like suppression list sync errors or re-imported opted-out contacts, per technical TCPA analysis. A small delay in fixing a sync error can quietly generate millions in liability. And don't count on insurance: standard GL and umbrella policies typically classify TCPA settlements as regulatory penalties rather than insurable losses — a gap most businesses discover only when a claim is filed.
This is why CallMyCustomers builds its entire outreach process around permission: working only from lists of real customers, honoring opt-outs immediately, and having the owner approve every message before anything is sent. When each message carries a $500–$1,500 price tag if it goes wrong, the cheapest compliance strategy is the one that starts before the first call.
Who Comes After You: The Four Enforcement Pathways That Stack
Violating the TCPA doesn't just risk one penalty—it can trigger multiple enforcement actions that stack and proceed independently. Private lawsuits and class actions remain the primary threat, with settlements ranging from under $1 million for small cases to over $75 million for large campaigns involving hundreds of thousands of violations. Individual plaintiffs can recover $500 to $1,500 per violation, with treble damages applying to knowing or willful conduct, meaning a campaign of just 10,000 unsolicited calls could generate $5 million to $15 million in liability.
Beyond private litigation, federal and state regulators can pursue parallel actions without coordination. The FCC can impose forfeitures up to approximately $23,727 per violation—as demonstrated by the $6 million penalty against Steve Kramer for AI deepfake robocalls in May 2024—while the FTC can levy penalties up to $51,744 per violation under the Telemarketing Sales Rule. State laws add another layer: Florida’s FTSA allows $500–$1,500 per violation for automated calls without prior express written consent, stackable with federal TCPA, and newer state privacy laws in Iowa and Delaware impose $7,500 per violation as of January 1, 2025.
- Private lawsuits: $500–$1,500 per violation (treble for willful)
- FCC forfeitures: up to ~$23,727 per violation
- FTC penalties: up to $51,744 per violation
- State laws: Florida’s FTSA ($500–$1,500), Iowa/Delaware ($7,500 each)
For businesses like CallMyCustomers managing reactivation campaigns for US service providers, this multi-pathway exposure means a single data infrastructure failure—such as a suppression list sync error—could simultaneously invite private class actions, FCC forfeitures, FTC penalties, and state-level fines. Each pathway operates independently, with no requirement for coordination between agencies or plaintiffs, creating compounding financial risk that scales directly with call volume. Understanding this layered enforcement landscape is essential for building compliant outreach that protects both customer relationships and business viability.
How Businesses Actually Get Into TCPA Trouble
Many businesses stumble into TCPA trouble not through deceptive language, but through preventable data failures. The most common trigger for enterprise exposure is suppression list sync errors or re-imported opted-out contacts—issues that can turn a routine campaign into millions in liability overnight. Even when consent was properly obtained initially, a breakdown in data hygiene can reactivate contacts who have already revoked permission, exposing the business to strict liability regardless of intent.
Continuing outreach after an opt-out request remains a leading cause of avoidable violations. Under the FCC’s 2026 revocation-of-consent rule, businesses must honor opt-out requests within 10 business days, and any contact after that point is treated as a willful violation eligible for treble damages—raising penalties from $500 to $1,500 per call or text. Contacting reassigned numbers presents another hidden risk, as the new subscriber never provided consent, yet the caller is still liable under TCPA’s strict liability framework. These violations often go unnoticed until a pattern emerges in consumer complaints or legal filings.
The financial exposure scales directly with volume, making even small errors costly at scale. For example, 20,000 calls to numbers that should have been suppressed create $10 million in exposure at the standard rate, while 50,000 texts sent without valid consent at the willful rate generate $75 million in statutory exposure before class certification. What many businesses discover too late is that standard general liability and umbrella policies typically exclude TCPA claims, classifying settlements as regulatory penalties rather than insurable losses—leaving them financially exposed when a claim is filed. For companies like CallMyCustomers, which manage high-volume reactivation campaigns on behalf of service businesses, these risks underscore why compliance isn’t just legal due diligence—it’s revenue protection.
- Implement real-time suppression list controls to prevent sync errors
- Process opt-out requests immediately and stop all contact within 10 business days
- Integrate Reassigned Number Database checks before every outreach attempt
How to Run Customer Outreach Without TCPA Risk
Reactivating past customers is one of the most cost-effective ways to grow revenue, but it carries real legal risk if not done with strict TCPA compliance. The law treats every unsolicited call or text as a separate violation, with penalties starting at $500 per incident and jumping to $1,500 for willful or knowing violations, such as continuing outreach after a customer has opted out. These fines are not capped, meaning even a modest campaign can generate millions in liability if consent records are poorly managed or suppression lists fail to sync. For example, contacting 20,000 numbers that should have been suppressed creates $10 million in exposure at the standard rate, and FCC penalties can exceed $23,727 per violation for regulatory enforcement. The most common source of TCPA risk isn’t flawed consent language—it’s data infrastructure failures, like re-imported opted-out contacts or sync errors in suppression lists, which can go unnoticed until damages accumulate.
To run customer outreach without TCPA risk, businesses must build compliance into every step of the reactivation process. This starts with working exclusively from lists of real customers who have documented, verifiable consent for the specific type of outreach being conducted—whether it’s a service reminder, renewal notice, or win-back offer. Consent records should be maintained separately by campaign type to ensure alignment with what the customer originally authorized, especially since state laws like Florida’s FTSA can stack additional penalties on top of federal TCPA. Opt-out requests must be processed immediately and honored without delay, as FCC rules effective 2026 require cessation within 10 business days, and calling after revocation is treated as a willful violation eligible for treble damages. Before any message is sent, the business owner should approve the script, offer, and timing to ensure alignment with brand voice and compliance standards. Finally, integrating reassigned number checking prevents liability from contacting new subscribers who never consented to communications from your business.
When reactivation is permission-based and owner-approved, it becomes a competitive advantage rather than a liability. CallMyCustomers designs every campaign around these safeguards—using only client-provided customer lists, processing opt-outs in real time, verifying numbers against the Reassigned Number Database, and requiring explicit owner sign-off before any outreach begins. This approach turns dormant relationships into booked work while keeping TCPA risk firmly under control. By treating compliance as the foundation of engagement—not an afterthought—service businesses can safely reactivate their customer base, drive repeat revenue, and avoid the financial and reputational damage that comes from even a single compliance breakdown. For home services, clinics, salons, and other repeat-driven industries, this disciplined method ensures that re-engagement feels helpful, not intrusive, and stays fully within the bounds of the law.
Your Next Step: Reactivate Customers the Compliant Way
The math is unforgiving: a single campaign of 10,000 non-compliant contacts can generate $5 million to $15 million in potential fines under TCPA's per-violation structure with no aggregate cap. That exposure compounds when state laws like Florida's FTSA stack parallel penalties on top of federal liability, and it multiplies again if a court finds willful conduct — pushing per-violation damages from $500 to $1,500. The FCC's top consumer protection priority remains stopping illegal robocalls, with enforcement actions reaching hundreds of millions of dollars against violators.
Most businesses don't discover their vulnerability until a claim is filed. Standard liability policies typically classify TCPA settlements as regulatory penalties rather than insurable losses, leaving companies fully exposed. The most common source of enterprise liability isn't flawed consent language — it's data infrastructure failures like suppression list sync errors or re-imported opted-out contacts that trigger massive liability at scale.
A compliant reactivation program eliminates these risks by design. CallMyCustomers starts with a free list review that segments your customer data by recency, old quotes, expiring memberships, and referral potential — so you know exactly what your list can legally and profitably produce before spending a dollar. Every script, offer, and message receives owner sign-off before outreach begins. Real humans handle the judgment; automation handles only the scale.
- List review and segmentation at no cost — quoted setup, clear expectations
- Owner approves every message before it sends; replies route straight to your booking process
- Opt-outs honored immediately across all channels; consent collected explicitly at booking
- Works from your CRM, spreadsheet, or POS list exactly as it is — no software to buy or learn
The result is a second revenue engine built on permission, not risk. Your next booked customer already knows your business — we just help them remember why they chose you.
Frequently Asked Questions
How much is a TCPA violation fine per call or text?
Can I get in trouble for a TCPA violation even if it was an honest mistake?
What's the biggest fine ever awarded for TCPA violations?
Besides lawsuits, who else can come after me for TCPA violations?
Does my business insurance cover TCPA fines?
What's the most common way businesses accidentally violate the TCPA?
One Text Away From $500: Why Compliance Comes First
TCPA violations carry consequences that scale faster than most business owners expect: $500 per call or text, $1,500 for willful conduct, no aggregate cap, and enforcement that stacks across private lawsuits, the FCC, the FTC, and state laws like Florida's FTSA. Because the law imposes strict liability, a good-faith data error — a suppression list sync failure or a re-imported opted-out contact — is treated exactly the same as a deliberate violation. And since standard insurance policies typically exclude TCPA claims, most companies discover their exposure only when the claim arrives. The good news is that the highest-risk failures are also the most preventable: honor opt-outs immediately, verify numbers against the Reassigned Number Database, and keep consent records tied to what customers actually agreed to. If reactivation outreach is part of your growth plan, the safest path is a permission-based process where every message is owner-approved before it sends. Start with a free list review from CallMyCustomers — you'll see exactly what your customer list can legally and profitably produce before spending a dollar.