
Who must comply with TCPA?
Key Facts
- A single non-compliant text can cost $500 to $1,500, with no requirement that anyone prove actual injury, according to BCLP's legal analysis.
- The largest TCPA judgment ever awarded totaled $925 million, per Drips' overview of consent rule changes.
- The FCC can seek up to $16,000 per violation — $26,000 for intentional ones, according to MS Law Group's TCPA FAQ.
- Since April 11, 2025, businesses must honor opt-out requests in any reasonable manner within ten business days, under the FCC's new Opt-Out Rule.
- TCPA wireless restrictions cover all wireless numbers — even ones given to you for business purposes — per Gryphon's compliance guide.
- A violating call today can trigger a lawsuit up to four years later, matching the TCPA's four-year statute of limitations.
- Businesses must scrub against the National Do Not Call Registry at least every 31 days unless exempt, per MS Law Group's TCPA FAQ.
Identifying Your TCPA Compliance Obligations
If your business picks up the phone, sends a text, or follows up on a lead using any kind of automated system, the TCPA likely applies to you — whether you think of yourself as a "telemarketer" or not. That surprises a lot of owners of HVAC companies, dental practices, and law firms who assume the rules only target robocall scammers.
The reality is broader. Under the TCPA, compliance obligations trigger when a business uses an automatic telephone dialing system (ATDS), sends marketing texts or robocalls, contacts wireless numbers, or engages in telemarketing. Legal experts note that TCPA wireless restrictions apply to all wireless numbers — residential, business, or hybrid use — meaning even a number provided for business purposes carries violation risk (Gryphon's compliance guide).
Even more importantly, businesses using any system with the capacity to function as an autodialer face high risk even if the automated features aren't actively used. You don't get a pass because you only "sometimes" use the dialing function.
Here are the core triggers that put your business under TCPA obligations:
- Using an ATDS or any system with autodialing capacity for outbound calls or texts
- Sending marketing text messages or making marketing robocalls, which require prior express written consent
- Contacting wireless numbers, regardless of whether the number serves business or personal use
- Engaging in telemarketing, including scrubbing against the National Do Not Call Registry at least every 31 days unless exempt
The stakes are real. TCPA statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury (BCLP's legal analysis), and the FCC can seek up to $16,000 per violation — $26,000 for intentional ones (MS Law Group's TCPA FAQ). Judgments in TCPA class actions have exceeded $925 million in recent years.
The compliance landscape also shifted in April 2025. The FCC's Opt-Out Rule, effective April 11, 2025, requires businesses to honor revocation of consent in "any reasonable manner" within ten business days. The burden of proof sits with the business to show an opt-out request wasn't reasonable — and non-standard language like "no more texts!" counts. This affects all consumer outreach, not just traditional sales calls.
For service businesses that respond to leads by text and phone — the kind of fast follow-up CallMyLeads automates for its clients — this is exactly why consent capture, immediate opt-out honoring, and quiet-hours rules must be built into the response system rather than bolted on afterward. Regulators are also increasingly pursuing personal liability against owners and executives, so "the vendor handled it" is not a defense.
Understanding Consent Requirements and Risk Exposure
A single text message sent without the right kind of consent can cost your business up to $1,500 — and plaintiffs don't need to prove anyone was actually harmed. That's the reality of the TCPA's consent framework, and it's why understanding the difference between two similar-sounding terms matters more than most business owners realize.
Prior express written consent (PEWC) is the gold standard required for marketing texts, marketing robocalls, and fax advertisements. According to legal analysis from BCLP, businesses must obtain this written agreement before any promotional message goes out — and responding to a call-to-action like "Text SAVE to 54321" may not be enough, as numerous TCPA lawsuits have argued.
Prior express consent (PEC) is a lower bar, sufficient for informational messages. Think appointment reminders, delivery notifications, or booking confirmations. This distinction is exactly why lead response and appointment-setting workflows need careful design — a new lead asking about your service is one thing, but following up with promotional offers requires the higher consent standard.
The financial exposure is not theoretical. Private plaintiffs can recover $500 per violation, or $1,500 for willful violations, with no cap on total damages. The largest TCPA judgment ever awarded totaled $925 million. And the statute of limitations runs four years — a violating call today can trigger a lawsuit in 2029.
Key risk factors that catch businesses off guard:
- Consent doesn't transfer to reassigned numbers — a common violation trigger when a consumer gives up their phone number.
- Regulators are increasingly pursuing personal liability against owners and executives, not just the business entity.
- Since April 11, 2025, opt-out requests must be honored in any reasonable manner within ten business days.
- Wireless restrictions apply to all wireless numbers — even ones used for business purposes.
For businesses that live on speed-to-lead, this is why compliance can't be an afterthought. Services like CallMyLeads build consent collection and immediate opt-out handling into every booking flow, so fast response doesn't come at the cost of a four-figure penalty per message. Slow response costs jobs, but non-compliant response can cost the business itself.
Building a TCPA-Compliant Lead Response System
Speed means nothing in lead response if every fast follow-up creates legal exposure. The good news: you can respond in seconds and stay inside TCPA rules — but only if compliance is built into the system, not bolted on afterward.
Start with opt-out management. Under the FCC's Opt-Out Rule effective April 11, 2025, businesses must honor revocation of consent in any reasonable manner within ten business days. That means a reply like "no more texts!" must stop outreach — and the opt-out must propagate across every channel, so a text opt-out also halts calls. If a lead opts out mid-nurture sequence, the system should catch it before the next touch fires. CallMyLeads handles this automatically, honoring opt-outs the moment they arrive rather than waiting out the window.
Next, scrub your lists before you dial or text. Federal rules require checking against the National Do Not Call Registry at least every 31 days, and contacting a reassigned number — where the original lead's consent doesn't transfer to the new owner — is one of the most common violation triggers. Screening against the Reassigned Number Database before outreach protects you from calling someone who never consented to anything.
Respect the clock. The federal calling window runs 8 am to 9 pm in the recipient's time zone, and more than 20 states impose stricter hours than the federal standard. An after-hours answering system helps here: instead of letting a 10 pm call go to voicemail, capture the lead with a text-back and queue the compliant callback for the morning — the lead stays warm without a curfew violation.
Finally, document everything and keep it:
- Consent records — date, time, method, and exact language, retained for at least four years to match the TCPA's statute of limitations
- Opt-out requests and processing timestamps, kept four years or longer
- DNC scrubbing logs showing when each check ran
- Call and text records demonstrating adherence to time-of-day restrictions
The four-year retention window isn't arbitrary — a violating call can trigger legal action up to four years after placement, and with penalties of $500 to $1,500 per violation and class actions exceeding $925 million, your records are your defense.
None of this requires slowing down. A CRM-integrated response system can log consent at capture, enforce quiet hours, and sync opt-outs across channels in real time — so speed and compliance run on the same rails.
Frequently Asked Questions
Does the TCPA apply to my business if I'm not a telemarketer?
What's the difference between prior express consent and prior express written consent?
How much can a TCPA violation actually cost my business?
What changed with the FCC's Opt-Out Rule in April 2025?
Am I safe if I only text a number the customer gave me for business purposes?
Can I blame my vendor or software if a TCPA violation happens?
Turn Compliance Into Your Competitive Edge
TCPA compliance isn't just about avoiding fines—it's about building trust and protecting your business from risks that can emerge years later. As we've seen, obligations apply broadly to any business using automated systems for outreach, especially when contacting wireless numbers or sending marketing messages. The stakes are high, with penalties up to $1,500 per violation and a four-year statute of limitations, but the solution is straightforward: build compliance into your lead response from the start. That means capturing proper consent, honoring opt-outs in any reasonable manner within ten business days, scrubbing against the Do Not Call and Reassigned Number databases, respecting calling hours, and documenting everything. For service businesses that rely on speed-to-lead, this isn't a slowdown—it's a safeguard that lets you move fast without looking over your shoulder. Systems like CallMyLeads are designed to handle these requirements automatically, so your team can focus on converting leads, not managing legal exposure. Take the next step: review your current lead response workflow for TCPA gaps and see how automation can keep you compliant and competitive.