ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Do Not Call Rules

Who must comply with TCPA?

Back to InsightsWho must comply with TCPA?

Who must comply with TCPA?

Key Facts

  • TCPA applies to any business calling or texting US consumers, including SMS treated as calls per FCC guidance
  • Statutory TCPA damages are $500–$1,500 per violation with no cap on aggregate liability per compliance analysis
  • A 100,000-message non-compliant campaign risks over $150 million in class-action exposure per industry analysis
  • TCPA class actions filed through mid-2025 rose nearly 95% year-over-year per litigation tracking
  • AI-generated voices now require prior express written consent as artificial/pre-recorded voices per FCC ruling
  • Opt-outs must be honored in any reasonable manner within 10 business days effective April 11, 2025 per new FCC rules
  • Carriers have blocked unregistered A2P 10DLC traffic since February 2025 per carrier enforcement

TCPA Applies to Your Business If You Call or Text US Customers

The Telephone Consumer Protection Act isn't a niche rule for telemarketers — it's the baseline for any business that calls or texts U.S. consumers. The FCC treats text messages as "calls" under the TCPA, so every SMS your business sends falls under the same consent and opt-out requirements as a phone call.

This scope captures service businesses running reactivation campaigns, appointment reminders, and review requests just as much as outbound sales teams. Industry analysis confirms TCPA compliance is "non-negotiable for any business making calls or sending texts," covering autodialed calls, pre-recorded messages, texts, and unsolicited faxes. The FTC's 2024 Telemarketing Sales Rule update even extended certain requirements to business-to-business calls, widening the net further.

Legal reviews highlight three developments that sharpen the obligation:

  • AI-generated voices now count as "artificial or pre-recorded" voices, requiring prior express written consent (FCC ruling, February 2024)
  • New opt-out rules effective April 11, 2025 require honoring revocation in any reasonable manner within 10 business days — down from 30
  • All A2P 10DLC traffic must be registered; carriers have blocked unregistered traffic since February 2025

The cost of non-compliance is steep: statutory damages run $500–$1,500 per violation with no cap on aggregate liability, and a campaign of 100,000 non-compliant messages could expose a business to over $150 million in class-action risk. TCPA class actions filed through mid-2025 were up nearly 95% year-over-year.

For CallMyCustomers, this regulatory reality shapes every campaign we run. Our free list review scrubs against the National Do Not Call Registry and reassigned-number databases before a single message goes out — because consent attaches to the person, not the number. Opt-outs are honored immediately, not just within the legal window. Every script, offer, and message is approved by the business owner before outreach begins, and replies route straight into your booking flow so consent and conversation stay connected.

Key Compliance Triggers and Recent Regulatory Changes

Most TCPA violations don't come from rogue robocall operations — they come from ordinary businesses dialing the wrong number, ignoring an opt-out, or assuming an old consent still counts. Knowing the specific triggers is what separates a compliant outreach program from a six-figure lawsuit.

The prohibited list is short but unforgiving. Telemarketers may not call cell phones without prior consent, use autodialers against residential lines, contact numbers on the National Do Not Call Registry, or deliver pre-recorded messages without consent, per call center compliance guidance. Reassigned numbers are a particularly dangerous trap: legal analysis makes clear that consent attaches to the person, not the number — so when a customer changes numbers, your old permission dies with the old line.

The stakes are steep. Statutory damages run $500–$1,500 per violation with no cap on aggregate liability, and DNC Registry violations can reach $43,792 per call or text. A single 100,000-message campaign sent without valid consent could expose a business to more than $150 million in a class action.

Two recent developments reshaped the compliance landscape. First, the FCC's February 2024 declaratory ruling classified AI-generated voices as "artificial or pre-recorded voices," meaning AI-voice marketing calls now require prior express written consent. Second, the one-to-one consent rule was vacated in January 2025 after the Eleventh Circuit ruled the FCC lacked authority to redefine consent — but the FCC simultaneously tightened opt-out handling.

Effective April 11, 2025, businesses must honor consent revocation in any reasonable manner within 10 business days — down from up to 30 days. The burden falls on the business, with a rebuttable presumption that any revocation method is reasonable. Per legal analysis of the new rules, the following now count as valid opt-outs:

  • Reply texts using words like "stop," "quit," "unsubscribe," or "cancel" — deemed per se reasonable
  • Informal requests such as "please take me off the list"
  • Revocations by voicemail or email, not just official opt-out channels

One clarification message may be sent within five minutes of a revocation request, and opt-out records should be retained at least four years to match the statute of limitations. Businesses running reactivation outreach — like the win-back and reminder campaigns CallMyCustomers manages for service businesses — should treat real-time opt-out processing as the operating standard rather than the 10-day ceiling. Experts also note the FCC delayed until April 11, 2026 only the cross-type revocation requirement, and advise building compliant systems during the interim rather than waiting.

Practical Steps to Achieve and Maintain TCPA Compliance

Knowing the TCPA applies to your business is only half the battle — the other half is building workflows that keep you compliant campaign after campaign. The good news: the core safeguards are practical, repeatable, and easier to maintain than most owners expect.

Start with list hygiene. Scrub every outreach list against the National Do Not Call Registry and reassigned-number databases before each campaign. Contacting reassigned numbers is one of the most common TCPA lawsuit triggers, because consent attaches to the person, not the number — if a customer's old cell number now belongs to a stranger, your prior consent is worthless. Many providers, including CallMyCustomers, build this scrubbing into the free list review stage, so compliance is verified before a single message goes out.

Register for A2P 10DLC before you text anyone. All businesses sending application-to-peer SMS over 10-digit long codes must register with The Campaign Registry, and carriers have blocked unregistered traffic since February 2025. Plan ahead: brand registration takes 1–3 business days, and campaign registration takes another 2–7. Certain industries — including cannabis, firearms, payday loans, and debt relief — are ineligible for 10DLC registration entirely.

Process opt-outs in real time. The FCC's opt-out rules took effect April 11, 2025, and they changed the math. Consumers can now revoke consent "in any reasonable manner" — a reply text, a voicemail, even an email — and businesses must honor requests within 10 business days, down from up to 30. Words like "stop," "cancel," or "unsubscribe" are per se reasonable, but even informal requests like "please take me off the list" must be honored. Real-time opt-out processing is the safest standard — waiting the full 10 days invites risk you don't need.

Document everything. Consent records, opt-out logs, and call records are your only defense when a dispute arises. Key retention benchmarks:

  • Keep opt-out records at least four years, matching the TCPA statute of limitations
  • Retain call records for two years under TCPA and Telemarketing Sales Rule requirements
  • Store consent documentation with timestamps, channel, and campaign context
  • Track state-specific rules — Virginia will require 10-year opt-out retention starting January 2026

The stakes justify the effort. Statutory damages run $500–$1,500 per violation with no aggregate cap, and TCPA class actions through mid-2025 were up nearly 95% year-over-year. A compliant reactivation campaign starts with a clean, permissioned list — and a workflow where every script and opt-out is handled before, not after, the first call goes out.

Frequently Asked Questions

Does TCPA apply to my business if I only text my existing customers?
Yes, TCPA applies to any business making calls or sending texts to U.S. consumers, including existing customers, because the FCC treats text messages as 'calls' under the law. This means consent and opt-out requirements still apply even for reactivation or reminder messages to people who have previously done business with you. Industry analysis confirms TCPA compliance is 'non-negotiable for any business making calls or sending texts.'
What happens if I send a text to a number that’s been reassigned to someone else?
Sending a text to a reassigned number can trigger a TCPA violation because consent attaches to the person, not the phone number — so your old consent is invalid when the number changes hands. This is a common lawsuit trigger, and contacting reassigned numbers without re-verifying consent exposes businesses to statutory damages of $500–$1,500 per violation. Legal analysis clarifies that consent dies with the old line when a customer changes numbers.
Do I need written consent to use AI-generated voices in my outbound calls?
Yes, as of the FCC’s February 2024 ruling, AI-generated voices are classified as 'artificial or pre-recorded' voices under the TCPA, which requires prior express written consent before use in marketing calls. This means businesses using AI voice technology for outreach must obtain explicit written permission from consumers beforehand. Legal reviews highlight this development as a key change sharpening TCPA obligations.
How quickly must I honor a customer’s opt-out request under the new TCPA rules?
Effective April 11, 2025, businesses must honor opt-out requests in any reasonable manner within 10 business days — down from the previous 30-day window. This includes informal requests like 'please take me off the list' and revocations via voicemail or email, not just formal opt-out channels. Legal analysis confirms the burden is on the business to process these requests promptly, with real-time handling recommended as the safest standard.
Do I need to register for A2P 10DLC if I’m sending texts through a 10-digit long code?
Yes, all businesses sending application-to-peer (A2P) SMS over 10-digit long codes (10DLC) must register with The Campaign Registry, as carriers have blocked unregistered traffic since February 2025. Registration involves brand verification (1–3 business days) and campaign setup (2–7 business days), and certain industries like cannabis, firearms, payday loans, and debt relief are ineligible. Industry guidance notes that 10DLC registration is required to avoid message blocking and stay compliant.
How long should I keep opt-out and consent records to stay protected from TCPA lawsuits?
Opt-out records should be retained for at least four years to match the TCPA statute of limitations, while call records must be kept for two years under TCPA and Telemarketing Sales Rule requirements. Consent documentation should include timestamps, channel, and campaign context, and businesses in Virginia must prepare for a 10-year opt-out retention rule effective January 2026. Compliance experts advise thorough recordkeeping as a critical defense in disputes.

Compliance Isn't the Barrier to Reactivation — It's the Foundation

The short answer to "who must comply with TCPA?" is simple: if your business calls or texts U.S. customers — even ones you've served before — the law applies to you. The rules have only tightened, with AI voices now requiring written consent, opt-outs that must be honored within 10 business days through nearly any channel, and carriers blocking unregistered text traffic outright. The financial stakes are equally clear: statutory damages of $500–$1,500 per violation with no aggregate cap, and TCPA class actions up nearly 95% year-over-year through mid-2025. The good news is that the safeguards — list scrubbing against the DNC Registry and reassigned numbers, real-time opt-out handling, and documented consent — are practical and repeatable. That's exactly how CallMyCustomers runs every reactivation campaign: your list reviewed before a single message goes out, every script approved by you, and opt-outs honored immediately. If you have a list of past customers worth winning back, start with a free list review — you'll see what it can produce, compliantly, before spending a dollar.

Stay in the Loop