Skip to content
Compliance

What Is TCPA Compliance and Why It Matters in 2026

A clean list and approved copy are not compliance. TCPA asks different questions: who consented, what did they consent to, which channel are you using, and can you prove the answer for every contact?

GrowOutly Team15 min read
A timeline infographic tracing the Telephone Consumer Protection Act from its 1991 enactment through the 2026 rule changes.

TCPA compliance is the set of federal rules under the Telephone Consumer Protection Act that govern consent, autodialers, prerecorded calls, and SMS, enforced through private lawsuits. In 2025, one industry litigation report cited 2,628 TCPA cases, a 60.1% year-over-year surge, while another reported 1,807 TCPA class actions compared with 915 in 2024, a 97% increase. The litigation trends report shows why an outreach campaign can become a legal problem before the first agent speaks to a prospect.

The sales manager opening her campaign dashboard may think the work is finished. The list is clean, the copy is approved, and the dialer is ready. TCPA compliance asks different questions: Who consented, what did they consent to, which channel are you using, and can you prove the answer for every contact?

The Compliance Problem Hiding in Your Outbound Dialer

Maya is preparing a campaign with 50,000 records. Her team plans to call prospects, send follow-up SMS messages, and leave prerecorded voice messages for people who don't answer. The campaign looks like a routine growth initiative until she separates the list by recipient type, communication purpose, and technology.

Before a single dial, Maya needs to identify wireless numbers, residential landlines, VoIP landlines, and business landlines. The FCC's telemarketing guidance says TCPA protections cover consumer landlines, VoIP landlines, and mobile numbers, while business landlines fall outside several of those consumer protections. That classification changes the controls her team must apply.

The decision happens before transmission

Maya's pre-send workflow should answer five questions for each record:

  • Consent: Is there evidence of prior express consent, or prior express written consent where telemarketing automation requires it?
  • Purpose: Is the contact marketing, informational, emergency, or another permitted use?
  • Technology: Will an autodialer, prerecorded voice, artificial voice, or SMS automation transmit the message?
  • Suppression: Has the recipient joined a federal, state, internal, or seller-specific do-not-call list?
  • Revocation: Has the person opted out through a call, text, reply keyword, or another reasonable channel?

Regulated sellers usually run that as a gate in front of the dialer rather than a checklist beside it, which the cold calling playbook for insurance walks through end to end. A calling platform can help organize this workflow, but the compliance decision still needs a defensible record. A manager reviewing outgoing calls should be able to see why the system allowed one contact and blocked another.

Practical rule: Treat every outbound event as a decision record, not merely a dialer action.

When Maya launches the campaign, the exposure starts with call one. A missed opt-out, an outdated consent record, or a text sent after a revocation can affect later attempts across the campaign. TCPA liability can therefore compound through repeated outreach, especially because the statute permits private enforcement, as described in the FCC's TCPA rules.

The useful takeaway isn't a definition memorized for training. It's Maya's repeatable process: classify the contact, verify permission, check suppression records, select the right message controls, and preserve evidence before transmission.

How the TCPA Went From a 1991 Statute to a 2026 Minefield

A campaign can look compliant in its planning document and fail at send time. A consent record may cover one purpose, a system may use a different calling method, or a recipient may revoke permission through another channel. The TCPA therefore works less like a permanent checklist and more like a pre-send decision program.

Congress enacted the TCPA in 1991, and the FCC began implementing its rules in 1992 to restrict telemarketing calls, automatic telephone dialing systems, and prerecorded or artificial voice messages. Regulators and courts have continued to shape how consent, technology, and revocation operate. The timeline above shows how those changes accumulated.

The milestones that changed the operating model

The major operational shift came in 2012. The FCC required prior express written consent for covered telemarketing robocalls, removed the established business relationship workaround for home-phone telemarketing, and required an automated opt-out mechanism during each robocall. Consent became more specific, while opt-out handling became part of message design.

The technology analysis remains unsettled. The Supreme Court's Facebook v. Duguid decision narrowed the statutory autodialer question around systems using random or sequential number generation. That ruling did not remove separate duties involving consent, telemarketing, do-not-call lists, or revocation. A platform outside one autodialer interpretation can still create risk under another rule.

In 2025, the Supreme Court held that district courts are not bound by FCC interpretations under the Hobbs Act. The Eleventh Circuit vacated the FCC's one-to-one consent rule, and the FCC delayed cross-channel revocation compliance until April 2026 because systems needed reengineering, according to Goodwin's TCPA year-in-review analysis.

For outreach managers, the practical question is not whether consent exists. Before each call or text, confirm the permission's scope, the technology involved, the authority that applies, and whether an opt-out made by call, SMS keyword, or another reasonable method will block future outreach across channels.

Four terms create most early confusion for outreach teams. Explain them correctly in a standup meeting, and your team can make better decisions before a campaign reaches production.

Prior express consent means the recipient gave permission before the automated or prerecorded communication. Prior express written consent is the more explicit form required for telemarketing messages in circumstances covered by FCC rules. Think of it as an open front door that the consumer voluntarily left open for a defined purpose. A phone number appearing in a lead file isn't, by itself, proof of the required permission.

An autodialer, or automatic telephone dialing system, is technology that stores or produces numbers and dials them automatically. The legal definition has generated competing interpretations, particularly after the Supreme Court's Duguid decision. Your team shouldn't reduce the question to whether a vendor calls its product a “power dialer.” Document what the system does. What a power dialer is and how it works describes the sequential, human-initiated call loop, and power dialer vs predictive dialer covers why dialing ahead of an available rep carries the abandonment exposure that a one-to-one loop avoids.

A prerecorded call delivers a recorded or artificial voice instead of a live agent speaking from scratch. It can trigger consent requirements even when the dialing process differs from a classic autodialer. The FCC's telemarketing rules explain that autodialed or prerecorded calls and texts to wireless numbers generally require prior express consent, while telemarketing messages require prior express written consent.

The Do Not Call list is a separate control. Consent doesn't eliminate the need to screen against applicable DNC records, internal suppression lists, and prior seller-specific requests.

TCPA Key Terms at a Glance

TermPlain-English DefinitionWhy It Matters
Prior express consentPermission obtained before an automated or prerecorded contactThe caller bears the burden of proving consent
Prior express written consentExplicit written permission for covered telemarketing communicationsThe message purpose and authorization must match
AutodialerTechnology that stores or produces numbers and dials automaticallyThe equipment's function can affect the applicable rules
Prerecorded callA call using a recorded or artificial voiceIt can require consent independently of the dialing method
DNC listA suppression record for people who don't want telemarketingIt operates alongside consent, not instead of it

These tests work independently. A contact can have consent but still require suppression because the permission doesn't cover the current seller or purpose. Another can be absent from a DNC list but still be unsuitable for an automated marketing text because the required consent record is missing.

Why the Channel, the Recipient, and the Purpose All Change the Rules

A consent record has meaning only in context. The same phone number might support a service reminder but not a promotional text, or a live agent call but not a prerecorded message. The FCC's wireless-number guidance says autodialed or prerecorded calls and texts to wireless numbers generally require prior express consent, while telemarketing messages require prior express written consent. The FCC's consumer guidance on consent and revocation also places the burden of proving consent on the caller.

Three variables determine the control

Channel describes how the message reaches the person. Voice, SMS, and prerecorded or artificial voice communications can have different requirements. A platform shouldn't treat “contacted” as one universal permission state.

Recipient matters because wireless numbers and consumer landlines receive different protections from business landlines. Reassigned numbers create another hazard. A previously valid consent record may belong to the former user, not the person who now controls the number. Recycling is routine in pooled overlay markets, as our guide to area code 832 sets out, which is why the live subscriber status matters more than the history attached to the line.

Purpose separates telemarketing from informational, emergency, collection, or service communications. Marketing usually demands the clearest authorization. A product renewal reminder might be informational, but adding a promotional offer can change the analysis.

ChannelRecipientPurposeMinimum ConsentKey Caveat
Automated voiceWireless numberTelemarketingPrior express written consentConfirm purpose and seller scope
SMSWireless numberMarketingPrior express written consent under the FCC frameworkCourts are split on how TCPA private actions apply to texts
Automated voiceWireless numberInformationalPrior express consent generally appliesKeep the message consistent with the stated purpose
Live callConsumer landlineTelemarketingApply consent and DNC controlsLocal calling-time and seller-specific rules may also matter
Voice or SMSBusiness landlineBusiness outreachAnalyze the applicable rule and purposeCRS guidance excludes business landlines from certain consumer protections

Consider a SaaS company sending a renewal reminder to a customer whose phone number has changed hands. The CRM may show a prior relationship, but that relationship doesn't prove the current recipient authorized automated contact. The company should verify the number and consent state, suppress the record if ownership is uncertain, and avoid treating an old customer field as perpetual permission.

Channel, recipient, and purpose should therefore be fields in the campaign decision engine. They shouldn't remain assumptions inside a spreadsheet note.

SMS Outreach Keywords Every Compliance Program Must Honor

SMS programs need a real reply path, not just a footer that says “opt out.” The FCC-recognized stop-style keywords are STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE. When recipients use these terms in reply text messages, FCC guidance treats them as per se revocations. Carlton Fields' opt-out guidance also recommends handling HELP replies by returning the sender's identity and contact information.

Normalize capitalization, spacing, and punctuation before the platform evaluates a reply. Store the original message as evidence, then place the number on the relevant suppression list. The opt-out should propagate to calling, SMS, and other covered outreach workflows instead of remaining trapped in one campaign.

A consent disclosure should explain the program identity, recurring message purpose, expected frequency, message and data rates, and links to privacy and terms policies before consent is collected. Twilio's consent guidance recommends preserving the timestamp, method, and exact opt-in language.

A usable SMS control pattern

Use an opt-in statement that clearly identifies the seller and the type of messages. For example:

By selecting this checkbox, I agree to receive recurring marketing text messages from the identified business at the number provided. Message frequency varies. Message and data rates may apply. Consent isn't a condition of purchase. See the Privacy Policy and Terms.

Only include those policy links if they exist and accurately describe the program. The important operational principle is to save the exact text shown to the subscriber, not a later version of the form.

A first-message confirmation can identify the sender, state the program purpose, and give the recipient a clear way to stop:

Business Name: You're subscribed to recurring marketing messages. Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to unsubscribe.

Your SMS workflow should also define what happens with ambiguous replies. A message such as “remove me from promotions” should receive human review or a conservative suppression action, rather than being ignored. For teams managing SMS outreach, the system should record the keyword, timestamp, source number, response, and resulting suppression state.

An infographic showing how TCPA violation penalties can accumulate to create significant financial exposure for businesses.

How TCPA Penalties Stack Up Into Real Financial Risk

A single automated text sent after an opt-out may look like a small operational error. The same decision, repeated across a calling or SMS campaign, can create separate allegations tied to separate contacts. TCPA exposure therefore depends on both the conduct and the number of transmissions.

Private enforcement allows recipients to bring claims, and plaintiffs may seek to combine similar claims in a class action. The financial risk behaves less like one invoice and more like a meter that advances with each disputed call or message. A campaign can become expensive even when every individual contact seemed minor.

The statutory baseline is $500 per violation, with $1,500 for a willful violation, as reflected in the FCC's TCPA rules. A 2024 FCC inflation adjustment raised that willful-violation maximum above $1,500, though the exact adjusted figure isn't established here. Confirm the current number with counsel rather than turning an unverified figure into a planning assumption.

Why campaign volume changes the analysis

A post-revocation message may indicate a failed suppression control, an outdated consent record, or a vendor that did not receive the update. If the same recipient receives more messages, each transmission may receive separate scrutiny. Cross-channel decisions matter too. A phone opt-out, text keyword, or other reasonable revocation signal should not disappear just because the next communication is sent through a different system.

The reported litigation trends illustrate an active enforcement environment, not a guaranteed result for any particular campaign. Court interpretations and agency positions remain unsettled in 2026, so teams should document the rule applied to each channel, purpose, and recipient type. Automation deserves added review because it can repeat one faulty decision at scale.

A suppression failure can become a consent, evidence, vendor-management, and campaign-governance failure at the same time.

Use penalty arithmetic to test controls, not to predict a judgment. Per-contact liability makes every pre-send decision economically important, especially when calls or texts can continue without a fresh human review.

A Pre-Send Compliance Checklist for Outbound Calling and SMS

A defensible workflow should stop a message before transmission when the record fails a required test. It should also leave an evidence trail that explains the decision later.

The operational version of this lives in our TCPA compliance checklist for outbound teams, which covers the single pre-dial and pre-SMS decision gate, cross-channel revocation handling, and the audit record a reviewer actually needs.

A checklist graphic outlining essential compliance steps for outbound business phone calls and SMS marketing campaigns.

Check the permission record

Start with the source, timestamp, exact disclosure, seller identity, phone number, and consent method. Confirm that the permission covers the campaign's purpose and channel. If the record authorizes service messages only, don't use it for a promotional sequence.

Then check current status:

  • Verify number type: Identify whether the number is wireless, a consumer landline, VoIP landline, or business landline.
  • Search suppression records: Match against federal, state, internal, and seller-specific DNC records.
  • Process revocations: Apply opt-outs from calls, texts, keywords, web forms, and other reasonable channels.
  • Review number changes: Use appropriate reassigned-number controls before relying on historical consent.
  • Confirm timing: Apply the campaign's conservative calling and sending window based on the recipient's local time.

The FCC telemarketing guidance supports the central operational rule: automated or prerecorded wireless communications need the applicable consent before transmission, and each robocall needs an opt-out mechanism.

Lock the message and the dialer

Before launch, check sender identification, purpose, frequency disclosure, and opt-out instructions. For SMS, test STOP-style keywords and HELP responses from a real reply path. For prerecorded voice, confirm that the message and opt-out mechanism function as approved.

Keep the controls conservative where the facts are uncertain. Don't invent attempt caps or safe-harbor assumptions as if they were universal TCPA requirements. Instead, set internal limits, document them, and have counsel validate any rule tied to abandoned calls, quiet hours, reassigned numbers, or specialized dialing technology.

A system such as DNC compliance software can support list screening, but no platform replaces a documented consent policy and accountable review. If you are still choosing the systems that enforce these gates, our comparison of 10 TCPA compliance software options covers the suppression, consent-evidence, reassigned-number, and litigator tools directly, while 10 outbound call center software platforms scores the calling layer they have to sit in front of. Save the opt-in language, source page, timestamp, keyword, agent or workflow identity, suppression reason, and delivery result.

Keeping Your Program Defensible as the Rules Keep Moving

A prospect replies STOP to a text after consenting to calls, then an outbound dialer schedules another touch. A defensible program has already decided what that reply means, which channels it suppresses, and what evidence it will retain. TCPA compliance works best as a live, pre-send decision program, not a consent checklist completed at launch.

The policy layer states what qualifies as consent, which seller and purpose that permission covers, how a recipient can revoke it, and when outreach must stop. Write each rule so an agent, engineer, and compliance reviewer can apply it consistently.

The control layer converts policy into system behavior. It covers DNC screening, number classification, consent-state checks, keyword normalization, cross-channel suppression, message review, and local-time controls. A rule stored only in a handbook cannot reliably stop a noncompliant call or message before transmission.

The evidence layer preserves the decision trail. Store the exact opt-in disclosure, timestamp, source, phone number, consent scope, reply history, call record, suppression event, and system decision. That trail only holds together when the dialer writes to the same contact record the rest of the team works from, which is the queue-to-record loop power dialer CRM describes. If a demand arrives, the team should reconstruct the event from records rather than memory or a screenshot from an outdated campaign.

Monitor the areas that remain unsettled

Recent court and FCC developments show why this program needs regular review. The 2025 Supreme Court decision concerning FCC interpretations, the Eleventh Circuit's action on one-to-one consent, the delayed cross-channel revocation compliance date in April 2026, and developments in the Seventh and Fifth Circuits can change how a campaign should be configured. ZwillGen's analysis of the court split reports that the Seventh Circuit held the TCPA private cause of action for “telephone calls” does not include text messages, while the Fifth Circuit held that prerecorded telemarketing calls require prior express consent and rejected the FCC's written-consent requirement.

While authority remains divided, configure campaigns conservatively. Treat marketing texts as a high-risk channel, preserve proof of authorization, process revocations immediately, and ask counsel to assess the circuit and state rules governing each campaign.

Set a recurring operating cadence:

  • Audit consent records quarterly: Check disclosures, purposes, and disputed or outdated permission.
  • Test keywords monthly: Confirm STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE trigger the intended suppression result.
  • Process revocations immediately: Update the master record before another campaign import can use it.
  • Assign one owner: Give a named compliance lead responsibility for court decisions, FCC actions, vendor changes, and control testing.

TCPA compliance continues after approval. Every outbound event should pass a current decision process, with policy, controls, and evidence kept aligned as interpretations change.

GrowOutly brings outbound calling, two-way SMS, CRM records, DNC screening, and pre-send compliance checks into one workspace, helping teams review contacts before a call or message is placed. Visit GrowOutly to see how its outreach and compliance workflows can fit into a TCPA operating process.

Run this playbook on your own list

On the demo call we pull a real list in your market, scrub it against the DNC and litigator files, and dial it with you.

  • No setup fee
  • Cancel anytime
  • Live number on the demo call