
What is a TCPA violation?
Key Facts
- A single TCPA violation costs $500 — trebled to $1,500 if willful — with no cap on damages, per TCPA penalty guidelines.
- One 10,000-text campaign without consent can create $5 million to $15 million in exposure, compliance researchers calculate.
- Sirius XM paid $28 million for calling Do Not Call numbers, tracked class action settlements show.
- Keller Williams faced a $40 million settlement over unauthorized auto-dialing, according to TCPA violation analysis.
- Since April 11, 2025, consumers can revoke consent 'in any reasonable manner' — even telling a cashier, legal analysis of the FCC Opt-Out Rule explains.
- Businesses have just 10 business days to honor an opt-out across every channel, under the FCC's new rule.
- Standard insurance policies typically won't cover TCPA settlements, leaving the loss on your balance sheet, the Alliance Risk team warns.
What Counts as a TCPA Violation — and Why It Catches Good Businesses Off Guard
A single text message sent without proper consent can trigger a lawsuit that costs more than a year of revenue. The Telephone Consumer Protection Act doesn't distinguish between bad actors and busy businesses that missed a compliance detail — it only asks whether the rules were followed.
The law breaks down into five violation categories that show up repeatedly in court filings. First, texts or calls sent without prior express written consent — the standard for marketing outreach to cell phones. Second, contacting numbers on the National or state Do Not Call registries, or ignoring a consumer's internal opt-out request. Third, autodialed calls to cell phones without that same written consent, including calls to reassigned numbers where the new owner never agreed to hear from you. Fourth, prerecorded or artificial voice messages — robocalls and ringless voicemail — delivered without proper authorization. Fifth, failing to honor revocation requests within 10 business days across every channel and system.
- Unsolicited texts without documented consent and clear opt-out language
- Calls to DNC-registered numbers or past opt-out requests
- Autodialed calls to cell phones — including reassigned numbers
- Prerecorded or artificial voice messages without authorization
- Failure to process revocations within 10 business days across all platforms
The burden of proving consent existed falls entirely on the business, not the plaintiff. That means every outreach campaign needs a verifiable consent trail — something that disappears fast when lists age, numbers change hands, or opt-outs get stuck in one system while messages go out from another. Class action data shows defendants span every industry: Sirius XM paid $28 million for DNC list violations, O'Reilly Automotive settled for $18.8 million over unsolicited texts, and a Florida real estate company faced a $40 million preliminary approval for unauthorized autodialing. Most settlements land between $1 million and $5 million, but with statutory damages of $500 to $1,500 per violation and no cap, the exposure scales with list size.
CallMyCustomers works only from lists of real, known customers — not purchased leads — and every script, offer, and message is approved by the business owner before a single call or text goes out. That permission-first model, combined with immediate opt-out honoring and centralized revocation processing, is how service businesses stay on the right side of rules that keep getting stricter. The FCC's 2024 text-message rule extended DNC protections to texts and closed the lead-generator loophole, while the Opt-Out Rule effective April 2025 lets consumers revoke consent "in any reasonable manner" — including telling a cashier — with the burden on the business to prove the method wasn't reasonable.
The Real Cost: $500 to $1,500 Per Call or Text, With No Cap
One text message can cost you $500. Send it knowingly — or in a way a court decides you should have known better — and that single message becomes $1,500.
The TCPA's penalty structure is brutally simple. Statutory damages run $500 per violation, trebled to $1,500 for willful violations, with no cap — and plaintiffs don't need to prove actual harm to collect, according to compliance guidance on TCPA penalties. A legal analysis of the TCPA's damages framework confirms the same math applies per class member, with a 4-year statute of limitations giving plaintiffs a long window to reach back through your outreach history.
Now run the numbers on a realistic campaign. A modest outreach push to a stale customer list — say, 10,000 text messages — creates $5 million to $15 million in potential exposure if consent was missing. There is no ceiling, because every message is a separate violation.
The settlements prove this isn't theoretical:
- Momentum Solar: up to $30 million
- Sirius XM: $28 million over calls to Do Not Call lists
- QuoteWizard: $19 million for spam texts to DNC Registry numbers
- Keller Williams: $40 million involving unauthorized auto-dialing
These figures come from tracked TCPA class action settlements, where most resolutions land between $1 million and $5 million — and roughly fifty suits were filed in a recent two-year span alone. The defendants aren't scammers; they include retailers, insurers, healthcare systems, and real estate brands.
Here's the part that catches most business owners off guard: you can't insure your way out of it. As the Alliance Risk team notes, standard general liability and umbrella policies typically classify TCPA settlements as regulatory penalties rather than insurable losses — a gap most businesses don't discover until a claim is already filed. The loss sits entirely on your balance sheet.
This is why consent discipline matters more than campaign ambition. It's the reason CallMyCustomers works only from lists of real customers, collects explicit consent in the booking flow, and has the owner approve every script and message before anything goes out — the burden of proving valid consent falls on the business, not the consumer. A free list review before any campaign dollar is spent tells you exactly what your list can safely produce. When a single unconsented message carries a four-figure price tag, the cheapest compliance decision is the one you make before you hit send.
The Rules Are Getting Stricter: The 2025 Opt-Out Rule and Text Message Protections
If your customer replies "STOP" to a text, that's no longer enough to keep you safe — they can now revoke consent almost any way they want, and the clock starts ticking the moment they do. The FCC's new Opt-Out Rule, effective April 11, 2025, fundamentally shifts how businesses must handle revocation requests, and many service businesses still don't know it exists.
Under the rule, consumers can revoke consent "in any reasonable manner" — and the FCC presumes nearly any method is reasonable. That includes keywords like STOP, QUIT, END, CANCEL, or UNSUBSCRIBE, but also a voicemail, an email, or simply telling your front desk clerk. Per legal analysis of the rule, businesses can no longer designate an exclusive opt-out channel, and the burden falls on the business to prove why a revocation request wasn't reasonable.
Once a revocation arrives, you have 10 business days to honor it across every system — calls, texts, robocalls, and robotexts alike. A revocation in one channel extends to all channels. Businesses may send a single clarification text within 5 minutes (with no marketing content), but without an affirmative consumer response, all communications must cease.
The practical danger is fragmentation. Compliance researchers warn that opt-out requests "trapped in one CRM, dialer, messaging platform, business unit, or vendor system" create serious exposure (ActiveProspect). If your texting vendor honors the opt-out but your calling team never hears about it, you're still liable — and at $500 per violation, trebled to $1,500 for willful conduct, the exposure compounds fast. This is why CallMyCustomers routes every revocation through a single pipeline across calls, texts, and emails, and honors opt-outs immediately rather than waiting out the legal minimum.
The tightening doesn't stop at opt-outs. The FCC's 2024 rulemaking also extended National Do Not Call Registry protections to text messages and closed the "lead generator loophole" (Federal Register). The cost of ignoring these rules shows up in recent settlements: O'Reilly Automotive paid $18.8 million over unsolicited texts, and QuoteWizard settled for $19 million for texting numbers on the DNC Registry (ClassAction.org).
One wrinkle adds confusion: courts are split on whether DNC rules for "residential subscribers" even apply to cell phones. In Loudermilk v. Maelys Cosmetics, one court called a landline-only reading "untenable," while others have concluded the DNC rules don't reach cell phones at all (Greenspoon Marder LLP).
Until appellate courts resolve the split, the conservative play is clear:
- Assume DNC rules apply to personal cell phones and texts, not just landlines.
- Train every customer-facing staff member to log revocations — a word at the counter counts.
- Centralize opt-out processing so no request dies in one vendor's system.
- Scrub lists against DNC registries before every campaign, not once a year.
For businesses running reactivation campaigns on known customers, these rules aren't a reason to stop reaching out — they're a reason to make sure every message is permissioned, approved, and revocable on the customer's terms.
How to Stay Compliant: Five Practices That Prevent Violations
The good news is that TCPA compliance isn't complicated — it just has to be consistent. With penalties of $500 per violation (trebled to $1,500 for willful violations) and no statutory cap, a single sloppy campaign can snowball into millions in liability, as penalty guidelines make clear. Five practices keep you on the right side of the line.
Collect and document consent at every touchpoint. The burden of proving valid consent falls on the business, not the consumer, and prior express written consent is required for marketing texts and robocalls. Build consent collection into your booking flow and keep records — if you can't show it, it doesn't count.
Honor opt-outs immediately, everywhere. At least eight of roughly 50 recent class actions involved messaging that continued after a customer opted out, according to class action filings. Under the FCC's Opt-Out Rule, effective April 11, 2025, consumers can revoke consent "in any reasonable manner" — a STOP text, a voicemail, even a comment to a cashier — and you have 10 business days to comply across all channels. Opt-outs trapped in one CRM or dialer are a leading source of exposure, so keep revocation processing centralized.
Scrub your lists before you dial. Calling numbers on the National or State DNC registries is one of the most common violation categories, and the settlements show the stakes: Sirius XM paid $28 million, QuoteWizard $19 million for texts to DNC-listed numbers. Scrub against the registries and check the Reassigned Number Database — when a customer changes numbers, the new owner never consented, and you're still liable for the call.
Treat every cell phone as protected. Courts are split on whether DNC rules for "residential subscribers" apply to personal cell phones and texts. Until appellate clarity emerges, attorneys at Greenspoon Marder recommend assuming DNC rules apply and calibrating your program accordingly — a conservative posture that costs little now and saves everything later.
- Collect explicit, documented consent at every customer touchpoint
- Honor opt-outs immediately, centrally, and across every channel
- Scrub lists against DNC registries before any campaign
- Check reassigned numbers before dialing
- Assume DNC rules apply to personal cell phones and texts
This is also how we operate at CallMyCustomers. Campaigns run only from lists of real customers, consent is collected in the booking flow, opt-outs are honored immediately, and every script, offer, and message is approved by the business owner before anything is sent. For a done-for-you reactivation service, compliance isn't a feature — it's the foundation.
Compliance Is Cheaper Than the Alternative
TCPA violations don't come from bad intentions — they come from missing consent records, unscrubbed lists, opt-outs trapped in disconnected systems, and reassigned numbers nobody checked. With statutory damages of $500 to $1,500 per violation and no cap, and insurance typically refusing to cover the loss, a single careless campaign can wipe out years of profit. The rules are only getting stricter: the FCC's 2025 Opt-Out Rule lets customers revoke consent in almost any way they choose, and you have 10 business days to honor it across every channel. The good news is that staying compliant is straightforward — document consent at every touchpoint, scrub lists before every campaign, treat all cell phones as protected, and centralize opt-out processing so nothing slips through. That's exactly how CallMyCustomers runs reactivation outreach: only to real customers, with owner-approved scripts and immediate opt-out honoring built in. Your next step is simple — review how your business collects, stores, and acts on consent today. Want certainty before you spend a dollar? Get a free list review and see exactly what your customer list can safely produce.