ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
TCPA and Do Not Call Rules

What are some of the prohibited acts covered under TCPA?

Back to InsightsWhat are some of the prohibited acts covered under TCPA?

What are some of the prohibited acts covered under TCPA?

Key Facts

Why TCPA Violations Are a Budget-Killer for Lead-Driven Businesses

A single automated text to the wrong number can cost more than the lead was ever worth. Under the TCPA, statutory damages run $500 to $1,500 per call or text — and the person suing doesn't have to prove they suffered any actual injury, according to BCLP's analysis of the FCC's opt-out rules.

Regulators add their own layer of pain. The FCC can fine businesses up to $16,000 per violation and $26,000 per intentional violation, per a TCPA requirements breakdown from McGlinchey Stafford. Multiply that across a lead list of thousands, and the math turns ugly fast.

The ceiling isn't theoretical, either. TCPA judgments have topped $925 million in recent years, fueled by what one law firm describes as "a cottage industry of professional plaintiffs and class action attorneys" chasing statutory damages (source).

Here's the uncomfortable part: the businesses most exposed are the ones doing everything right from a sales perspective. Speed-to-lead is the whole game in home services, dental, legal, and insurance — the first business to respond usually wins the job. But fast response means automated response, and automated calls and texts sit squarely in the TCPA's crosshairs.

Every one of these common growth tactics carries statutory risk:

  • Auto-texting a new lead within seconds of a form fill — marketing texts require prior express written consent
  • Running AI or prerecorded voice follow-up calls — treated the same as robocalls under the law
  • Calling a number that was reassigned since consent was given — mistaken belief of consent is not a defense
  • Continuing to message someone who replied "STOP" — under the April 11, 2025 Opt-Out Rule, that one word ends both texts and automated calls, and must be honored within ten business days
  • Skipping the 31-day scrub against the National Do Not Call Registry

And "I didn't know" doesn't work. The FDIC's compliance manual makes clear the rules apply without exception, and willful or knowing violations are exactly what trigger the tripled $1,500 damages. Courts don't grade on intent to harm — they grade on process.

That's why the smartest operators treat compliance as infrastructure, not an afterthought. Consent captured at the moment of booking, opt-outs honored instantly and automatically, quiet hours respected, and every message logged. Services like CallMyLeads build exactly this into automated lead response — explicit consent collection in the booking flow, immediate opt-out handling, and A2P 10DLC-registered texting — so speed-to-lead doesn't become speed-to-lawsuit.

The takeaway is simple: automation without a compliance layer is a liability machine. The same system that books a $10,000 roofing job in 30 seconds can generate a six-figure class action if consent and opt-outs aren't handled by design.

Most TCPA violations don't happen because a business set out to break the law — they happen when a well-meaning follow-up system crosses a line the business never knew existed. Knowing exactly what the law forbids is the first step to calling and texting leads without fear.

Consent is the foundation. The TCPA prohibits using autodialers or artificial and prerecorded voices — including AI voices — to contact cell phones without the recipient's consent, and telemarketing texts and robocalls require prior express written consent, according to legal analysis from McGlinchey Stafford. That written agreement must disclose that signing is not a condition of purchase, per the FDIC Consumer Compliance Examination Manual. Prerecorded telemarketing to residential lines is likewise off-limits without consent.

The old "established business relationship" escape hatch is closed. Under 2012 FCC revisions, that exemption can no longer be used to avoid consent requirements for autodialed or prerecorded telemarketing calls, even if the person bought from you yesterday. Dual-purpose calls — part informational, part sales — count as telemarketing, too.

Do Not Call rules add a second layer. Telemarketers are generally prohibited from calling numbers on the National DNC Registry and must scrub their lists every 31 days, per the same legal analysis. Businesses must also maintain an internal DNC list with a written policy and trained staff. Calling someone who made a company-specific DNC request is prohibited even if you have an established business relationship or written consent — and those requests must be honored for at least five years.

The law also shields sensitive lines from automated outreach. Per the FDIC manual, autodialed or prerecorded calls are prohibited to:

  • Emergency lines, including 911, hospital and medical lines, poison control, fire protection, and law enforcement
  • Guest room or patient room lines in hospitals, healthcare facilities, and elderly homes
  • Paging services, cellular services, or any number where the called party pays for the call

The stakes are real: statutory damages run $500 to $1,500 per violation with no need to prove actual injury, and BCLP's analysis of the FCC's new Opt-Out Rule notes the burden of proving an opt-out unreasonable falls on the business. That's why compliant systems like CallMyLeads collect explicit consent at booking and honor opt-outs immediately and automatically — speed and compliance have to work together, not at odds.

Ignoring Opt-Outs: The New Rule That Trips Businesses Up (April 2025)

Getting consent right is only half the battle. Since April 11, 2025, how you handle a consumer's opt-out can land you in just as much trouble as calling without permission in the first place.

The FCC's new Opt-Out Rule, effective April 11, 2025, fundamentally changed what "revoking consent" means. Consumers may now revoke consent "in any reasonable manner," which means businesses can no longer specify an exclusive means for doing so. A customer who texts "I do not want to hear from you" — or tells a cashier, leaves a voicemail, or emails headquarters — has likely revoked consent, and the business bears the burden of proving the request was unreasonable.

The rule also makes opt-outs cross-channel. Replying "STOP" to a text now ends both texts and automated voice calls, and a marketing opt-out can't be applied only to marketing messages while informational calls continue. Businesses must honor revocation within 10 business days, and only one post-revocation clarification message is allowed — sent within five minutes, with no marketing content, and it must stop if the customer doesn't respond.

Under the new rule, the following practices are now prohibited:

  • Requiring a specific or exclusive opt-out method
  • Applying an opt-out from one message type to only some future calls or texts
  • Failing to honor revocation within ten business days
  • Sending more than one post-revocation clarification message

The stakes are real. TCPA statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury, and TCPA judgments have exceeded $925 million in recent years. That's why automated systems that honor opt-outs immediately — the way CallMyLeads handles opt-outs across its lead response flows — remove a risk that manual processes routinely miss.

Three related violations trip up businesses too. Caller ID manipulation has been prohibited since a 2010 TCPA amendment. Prerecorded messages must include identity and purpose disclosures plus an automated, interactive opt-out mechanism — omitting any of these is itself a violation. And reassigned numbers carry no good-faith exception: mistaken belief of consent is not a defense, though a 2019 safe harbor exists where the caller obtained and can prove prior consent, and the FCC's Reassigned Numbers Database helps mitigate the risk.

Keep consent and opt-out records for at least four years — the TCPA statute of limitations. When the burden of proof sits with you, documentation is your best defense.

How to Stay Compliant While Still Responding to Leads in Seconds

Speed matters — but a lawsuit costs more than a missed lead. The TCPA imposes statutory damages of $500–$1,500 per violation with no requirement to prove actual injury, and FCC fines reach $16,000 per violation (or $26,000 for intentional ones) according to legal analysis. TCPA judgments have exceeded $925 million in recent years per court records. The only way to keep response times in seconds without exposing the business is to build compliance into every step of the flow.

Prior express written consent must be a signed agreement that discloses signing is not a condition of purchase, and the signature may be electronic per federal examination guidance. That consent belongs in every lead-capture and booking form — not buried in a privacy policy. The new FCC Opt-Out Rule, effective April 11, 2025, requires businesses to honor revocation within 10 business days across all channels; a "STOP" text ends both texts and automated voice calls under the rule. Companies cannot require an exclusive opt-out method, and even non-standard requests (a voicemail, an email, telling a cashier) carry a rebuttable presumption of reasonableness per the same analysis.

  • Collect explicit written consent in every lead-capture and booking flow, disclosing it's not a condition of purchase
  • Honor opt-outs immediately and automatically across all channels
  • Scrub the National DNC Registry every 31 days and maintain a written internal DNC policy with trained staff
  • Disclose AI identity in every call and include required opt-out mechanisms in prerecorded messages
  • Retain consent and opt-out records for at least four years

A done-for-you AI response system like CallMyLeads builds these safeguards in — consent collection at booking, automatic cross-channel opt-out handling, DNC scrubs, AI disclosure on every call, and record retention — so speed never comes at the cost of a lawsuit.

Frequently Asked Questions

What are the main things the TCPA actually prohibits businesses from doing?
The TCPA prohibits using autodialers or artificial and prerecorded voices — including AI voices — to contact cell phones without consent, with telemarketing texts and robocalls requiring prior express written consent. It also bans calling numbers on the National Do Not Call Registry, failing to honor opt-outs, prerecorded telemarketing to residential lines without consent, and calling protected lines like 911, hospital rooms, and paging services.
How much can a single TCPA violation actually cost my business?
Statutory damages run $500 to $1,500 per call or text, and the person suing doesn't have to prove any actual injury — willful or knowing violations trigger the $1,500 tier per legal analysis of the FCC's rules. The FCC can also fine businesses up to $16,000 per violation ($26,000 for intentional ones), and TCPA judgments have topped $925 million in recent years.
If someone filled out my form, isn't that consent to text them back?
Not necessarily — marketing texts require prior express written consent, meaning a signed agreement that discloses signing is not a condition of purchase, per the FDIC's compliance guidance. The old "established business relationship" loophole closed under 2012 FCC revisions, so even past customers can't be autodialed or robocalled for telemarketing without proper written consent.
What changed with the FCC's new opt-out rule in April 2025?
Since April 11, 2025, consumers can revoke consent "in any reasonable manner," so businesses can no longer require an exclusive opt-out method like texting STOP — a voicemail, email, or even telling a cashier counts, and the business bears the burden of proving a request was unreasonable. Opt-outs are also cross-channel: a "STOP" text ends both texts and automated calls, and revocation must be honored within 10 business days.
I called a number that got reassigned to someone new — am I still liable even though I had consent from the original owner?
Yes — mistaken belief of consent is not a defense for reassigned numbers, though a 2019 safe harbor exists if you obtained prior consent and can prove it, per the FDIC compliance manual. Checking the FCC's Reassigned Numbers Database before outreach campaigns helps mitigate this risk.
How often do I need to scrub my lead list against the Do Not Call Registry?
Telemarketers must scrub against the National DNC Registry at least every 31 days, and businesses must also maintain an internal DNC list with a written policy and trained staff, per legal analysis from McGlinchey Stafford. Company-specific DNC requests must be honored for at least five years — even if the customer has an established business relationship or gave written consent.

Fast Follow-Up Shouldn't Come With a Lawsuit Attached

The TCPA's prohibited acts all trace back to the same theme: contact people without consent, ignore their opt-outs, or call numbers you shouldn't — and the law will make you pay for it, at $500 to $1,500 per violation with no proof of injury required. The good news? None of these rules block fast lead response. They just demand that speed be built on a compliant foundation: written consent captured at the moment of booking, opt-outs honored instantly across every channel, DNC scrubs every 31 days, and records kept for at least four years. If you're building your own follow-up system, start by auditing those four areas today. And if you'd rather not stitch it together yourself, a done-for-you service like CallMyLeads builds consent collection, automatic opt-out handling, and compliance into every lead response — so you can answer every lead in seconds, 24/7, without wondering whether the next text is the one that triggers a class action. Stop paying for leads you never get to talk to — and stop risking the ones you do.

Build My Lead Response Plan

Get lead response tips that actually work