
Who must comply with TCPA?
Key Facts
- TCPA applies to any business calling or texting US consumers, including SMS treated as calls per FCC guidance
- Statutory TCPA damages are $500–$1,500 per violation with no cap on aggregate liability per compliance analysis
- A 100,000-message non-compliant campaign risks over $150 million in class-action exposure per industry analysis
- TCPA class actions filed through mid-2025 rose nearly 95% year-over-year per litigation tracking
- AI-generated voices now require prior express written consent as artificial/pre-recorded voices per FCC ruling
- Opt-outs must be honored in any reasonable manner within 10 business days effective April 11, 2025 per new FCC rules
- Carriers have blocked unregistered A2P 10DLC traffic since February 2025 per carrier enforcement
TCPA Applies to Your Business If You Call or Text US Customers
The Telephone Consumer Protection Act isn't a niche rule for telemarketers — it's the baseline for any business that calls or texts U.S. consumers. The FCC treats text messages as "calls" under the TCPA, so every SMS your business sends falls under the same consent and opt-out requirements as a phone call.
This scope captures service businesses running reactivation campaigns, appointment reminders, and review requests just as much as outbound sales teams. Industry analysis confirms TCPA compliance is "non-negotiable for any business making calls or sending texts," covering autodialed calls, pre-recorded messages, texts, and unsolicited faxes. The FTC's 2024 Telemarketing Sales Rule update even extended certain requirements to business-to-business calls, widening the net further.
Legal reviews highlight three developments that sharpen the obligation:
- AI-generated voices now count as "artificial or pre-recorded" voices, requiring prior express written consent (FCC ruling, February 2024)
- New opt-out rules effective April 11, 2025 require honoring revocation in any reasonable manner within 10 business days — down from 30
- All A2P 10DLC traffic must be registered; carriers have blocked unregistered traffic since February 2025
The cost of non-compliance is steep: statutory damages run $500–$1,500 per violation with no cap on aggregate liability, and a campaign of 100,000 non-compliant messages could expose a business to over $150 million in class-action risk. TCPA class actions filed through mid-2025 were up nearly 95% year-over-year.
For CallMyCustomers, this regulatory reality shapes every campaign we run. Our free list review scrubs against the National Do Not Call Registry and reassigned-number databases before a single message goes out — because consent attaches to the person, not the number. Opt-outs are honored immediately, not just within the legal window. Every script, offer, and message is approved by the business owner before outreach begins, and replies route straight into your booking flow so consent and conversation stay connected.
Key Compliance Triggers and Recent Regulatory Changes
Most TCPA violations don't come from rogue robocall operations — they come from ordinary businesses dialing the wrong number, ignoring an opt-out, or assuming an old consent still counts. Knowing the specific triggers is what separates a compliant outreach program from a six-figure lawsuit.
The prohibited list is short but unforgiving. Telemarketers may not call cell phones without prior consent, use autodialers against residential lines, contact numbers on the National Do Not Call Registry, or deliver pre-recorded messages without consent, per call center compliance guidance. Reassigned numbers are a particularly dangerous trap: legal analysis makes clear that consent attaches to the person, not the number — so when a customer changes numbers, your old permission dies with the old line.
The stakes are steep. Statutory damages run $500–$1,500 per violation with no cap on aggregate liability, and DNC Registry violations can reach $43,792 per call or text. A single 100,000-message campaign sent without valid consent could expose a business to more than $150 million in a class action.
Two recent developments reshaped the compliance landscape. First, the FCC's February 2024 declaratory ruling classified AI-generated voices as "artificial or pre-recorded voices," meaning AI-voice marketing calls now require prior express written consent. Second, the one-to-one consent rule was vacated in January 2025 after the Eleventh Circuit ruled the FCC lacked authority to redefine consent — but the FCC simultaneously tightened opt-out handling.
Effective April 11, 2025, businesses must honor consent revocation in any reasonable manner within 10 business days — down from up to 30 days. The burden falls on the business, with a rebuttable presumption that any revocation method is reasonable. Per legal analysis of the new rules, the following now count as valid opt-outs:
- Reply texts using words like "stop," "quit," "unsubscribe," or "cancel" — deemed per se reasonable
- Informal requests such as "please take me off the list"
- Revocations by voicemail or email, not just official opt-out channels
One clarification message may be sent within five minutes of a revocation request, and opt-out records should be retained at least four years to match the statute of limitations. Businesses running reactivation outreach — like the win-back and reminder campaigns CallMyCustomers manages for service businesses — should treat real-time opt-out processing as the operating standard rather than the 10-day ceiling. Experts also note the FCC delayed until April 11, 2026 only the cross-type revocation requirement, and advise building compliant systems during the interim rather than waiting.
Practical Steps to Achieve and Maintain TCPA Compliance
Knowing the TCPA applies to your business is only half the battle — the other half is building workflows that keep you compliant campaign after campaign. The good news: the core safeguards are practical, repeatable, and easier to maintain than most owners expect.
Start with list hygiene. Scrub every outreach list against the National Do Not Call Registry and reassigned-number databases before each campaign. Contacting reassigned numbers is one of the most common TCPA lawsuit triggers, because consent attaches to the person, not the number — if a customer's old cell number now belongs to a stranger, your prior consent is worthless. Many providers, including CallMyCustomers, build this scrubbing into the free list review stage, so compliance is verified before a single message goes out.
Register for A2P 10DLC before you text anyone. All businesses sending application-to-peer SMS over 10-digit long codes must register with The Campaign Registry, and carriers have blocked unregistered traffic since February 2025. Plan ahead: brand registration takes 1–3 business days, and campaign registration takes another 2–7. Certain industries — including cannabis, firearms, payday loans, and debt relief — are ineligible for 10DLC registration entirely.
Process opt-outs in real time. The FCC's opt-out rules took effect April 11, 2025, and they changed the math. Consumers can now revoke consent "in any reasonable manner" — a reply text, a voicemail, even an email — and businesses must honor requests within 10 business days, down from up to 30. Words like "stop," "cancel," or "unsubscribe" are per se reasonable, but even informal requests like "please take me off the list" must be honored. Real-time opt-out processing is the safest standard — waiting the full 10 days invites risk you don't need.
Document everything. Consent records, opt-out logs, and call records are your only defense when a dispute arises. Key retention benchmarks:
- Keep opt-out records at least four years, matching the TCPA statute of limitations
- Retain call records for two years under TCPA and Telemarketing Sales Rule requirements
- Store consent documentation with timestamps, channel, and campaign context
- Track state-specific rules — Virginia will require 10-year opt-out retention starting January 2026
The stakes justify the effort. Statutory damages run $500–$1,500 per violation with no aggregate cap, and TCPA class actions through mid-2025 were up nearly 95% year-over-year. A compliant reactivation campaign starts with a clean, permissioned list — and a workflow where every script and opt-out is handled before, not after, the first call goes out.
Frequently Asked Questions
Does TCPA apply to my business if I only text my existing customers?
What happens if I send a text to a number that’s been reassigned to someone else?
Do I need written consent to use AI-generated voices in my outbound calls?
How quickly must I honor a customer’s opt-out request under the new TCPA rules?
Do I need to register for A2P 10DLC if I’m sending texts through a 10-digit long code?
How long should I keep opt-out and consent records to stay protected from TCPA lawsuits?
Compliance Isn't the Barrier to Reactivation — It's the Foundation
The short answer to "who must comply with TCPA?" is simple: if your business calls or texts U.S. customers — even ones you've served before — the law applies to you. The rules have only tightened, with AI voices now requiring written consent, opt-outs that must be honored within 10 business days through nearly any channel, and carriers blocking unregistered text traffic outright. The financial stakes are equally clear: statutory damages of $500–$1,500 per violation with no aggregate cap, and TCPA class actions up nearly 95% year-over-year through mid-2025. The good news is that the safeguards — list scrubbing against the DNC Registry and reassigned numbers, real-time opt-out handling, and documented consent — are practical and repeatable. That's exactly how CallMyCustomers runs every reactivation campaign: your list reviewed before a single message goes out, every script approved by you, and opt-outs honored immediately. If you have a list of past customers worth winning back, start with a free list review — you'll see what it can produce, compliantly, before spending a dollar.