ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
TCPA and Do Not Call Rules

Who must comply with TCPA?

Back to InsightsWho must comply with TCPA?

Who must comply with TCPA?

Key Facts

Identifying Your TCPA Compliance Obligations

If your business picks up the phone, sends a text, or follows up on a lead using any kind of automated system, the TCPA likely applies to you — whether you think of yourself as a "telemarketer" or not. That surprises a lot of owners of HVAC companies, dental practices, and law firms who assume the rules only target robocall scammers.

The reality is broader. Under the TCPA, compliance obligations trigger when a business uses an automatic telephone dialing system (ATDS), sends marketing texts or robocalls, contacts wireless numbers, or engages in telemarketing. Legal experts note that TCPA wireless restrictions apply to all wireless numbers — residential, business, or hybrid use — meaning even a number provided for business purposes carries violation risk (Gryphon's compliance guide).

Even more importantly, businesses using any system with the capacity to function as an autodialer face high risk even if the automated features aren't actively used. You don't get a pass because you only "sometimes" use the dialing function.

Here are the core triggers that put your business under TCPA obligations:

  • Using an ATDS or any system with autodialing capacity for outbound calls or texts
  • Sending marketing text messages or making marketing robocalls, which require prior express written consent
  • Contacting wireless numbers, regardless of whether the number serves business or personal use
  • Engaging in telemarketing, including scrubbing against the National Do Not Call Registry at least every 31 days unless exempt

The stakes are real. TCPA statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury (BCLP's legal analysis), and the FCC can seek up to $16,000 per violation — $26,000 for intentional ones (MS Law Group's TCPA FAQ). Judgments in TCPA class actions have exceeded $925 million in recent years.

The compliance landscape also shifted in April 2025. The FCC's Opt-Out Rule, effective April 11, 2025, requires businesses to honor revocation of consent in "any reasonable manner" within ten business days. The burden of proof sits with the business to show an opt-out request wasn't reasonable — and non-standard language like "no more texts!" counts. This affects all consumer outreach, not just traditional sales calls.

For service businesses that respond to leads by text and phone — the kind of fast follow-up CallMyLeads automates for its clients — this is exactly why consent capture, immediate opt-out honoring, and quiet-hours rules must be built into the response system rather than bolted on afterward. Regulators are also increasingly pursuing personal liability against owners and executives, so "the vendor handled it" is not a defense.

A single text message sent without the right kind of consent can cost your business up to $1,500 — and plaintiffs don't need to prove anyone was actually harmed. That's the reality of the TCPA's consent framework, and it's why understanding the difference between two similar-sounding terms matters more than most business owners realize.

Prior express written consent (PEWC) is the gold standard required for marketing texts, marketing robocalls, and fax advertisements. According to legal analysis from BCLP, businesses must obtain this written agreement before any promotional message goes out — and responding to a call-to-action like "Text SAVE to 54321" may not be enough, as numerous TCPA lawsuits have argued.

Prior express consent (PEC) is a lower bar, sufficient for informational messages. Think appointment reminders, delivery notifications, or booking confirmations. This distinction is exactly why lead response and appointment-setting workflows need careful design — a new lead asking about your service is one thing, but following up with promotional offers requires the higher consent standard.

The financial exposure is not theoretical. Private plaintiffs can recover $500 per violation, or $1,500 for willful violations, with no cap on total damages. The largest TCPA judgment ever awarded totaled $925 million. And the statute of limitations runs four years — a violating call today can trigger a lawsuit in 2029.

Key risk factors that catch businesses off guard:

  • Consent doesn't transfer to reassigned numbers — a common violation trigger when a consumer gives up their phone number.
  • Regulators are increasingly pursuing personal liability against owners and executives, not just the business entity.
  • Since April 11, 2025, opt-out requests must be honored in any reasonable manner within ten business days.
  • Wireless restrictions apply to all wireless numbers — even ones used for business purposes.

For businesses that live on speed-to-lead, this is why compliance can't be an afterthought. Services like CallMyLeads build consent collection and immediate opt-out handling into every booking flow, so fast response doesn't come at the cost of a four-figure penalty per message. Slow response costs jobs, but non-compliant response can cost the business itself.

Building a TCPA-Compliant Lead Response System

Speed means nothing in lead response if every fast follow-up creates legal exposure. The good news: you can respond in seconds and stay inside TCPA rules — but only if compliance is built into the system, not bolted on afterward.

Start with opt-out management. Under the FCC's Opt-Out Rule effective April 11, 2025, businesses must honor revocation of consent in any reasonable manner within ten business days. That means a reply like "no more texts!" must stop outreach — and the opt-out must propagate across every channel, so a text opt-out also halts calls. If a lead opts out mid-nurture sequence, the system should catch it before the next touch fires. CallMyLeads handles this automatically, honoring opt-outs the moment they arrive rather than waiting out the window.

Next, scrub your lists before you dial or text. Federal rules require checking against the National Do Not Call Registry at least every 31 days, and contacting a reassigned number — where the original lead's consent doesn't transfer to the new owner — is one of the most common violation triggers. Screening against the Reassigned Number Database before outreach protects you from calling someone who never consented to anything.

Respect the clock. The federal calling window runs 8 am to 9 pm in the recipient's time zone, and more than 20 states impose stricter hours than the federal standard. An after-hours answering system helps here: instead of letting a 10 pm call go to voicemail, capture the lead with a text-back and queue the compliant callback for the morning — the lead stays warm without a curfew violation.

Finally, document everything and keep it:

  • Consent records — date, time, method, and exact language, retained for at least four years to match the TCPA's statute of limitations
  • Opt-out requests and processing timestamps, kept four years or longer
  • DNC scrubbing logs showing when each check ran
  • Call and text records demonstrating adherence to time-of-day restrictions

The four-year retention window isn't arbitrary — a violating call can trigger legal action up to four years after placement, and with penalties of $500 to $1,500 per violation and class actions exceeding $925 million, your records are your defense.

None of this requires slowing down. A CRM-integrated response system can log consent at capture, enforce quiet hours, and sync opt-outs across channels in real time — so speed and compliance run on the same rails.

Frequently Asked Questions

Does the TCPA apply to my business if I'm not a telemarketer?
Yes — the TCPA applies to any business that calls, texts, or follows up on leads using an automated system, whether or not you think of yourself as a telemarketer. HVAC companies, dental practices, and law firms are all covered if they use an autodialer or send marketing texts. Even a system with the capacity to function as an autodialer creates risk even if you rarely use that feature.
What's the difference between prior express consent and prior express written consent?
Prior express consent (PEC) is enough for informational messages like appointment reminders or booking confirmations. Prior express written consent (PEWC) is the higher standard required for marketing texts, marketing robocalls, and fax ads — and legal analysis from BCLP notes that responding to a call-to-action like 'Text SAVE to 54321' may not be enough to count as written consent.
How much can a TCPA violation actually cost my business?
Statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury, and the FCC can seek up to $16,000 per violation — $26,000 for intentional ones. There's no cap on total damages, and the largest TCPA judgment ever awarded totaled $925 million. A violating call today can trigger a lawsuit up to four years later.
What changed with the FCC's Opt-Out Rule in April 2025?
Effective April 11, 2025, businesses must honor revocation of consent in 'any reasonable manner' within ten business days — and the burden of proof sits with you to show an opt-out request wasn't reasonable. Non-standard language like 'no more texts!' counts, and per BCLP's legal analysis, this applies to all consumer outreach, not just sales calls. The opt-out must also propagate across every channel, so a text opt-out should halt calls too.
Am I safe if I only text a number the customer gave me for business purposes?
Not necessarily. TCPA wireless restrictions apply to all wireless numbers — residential, business, or hybrid use — so even a number provided for business purposes carries violation risk. Consent also doesn't transfer if the number gets reassigned to a new owner, which is one of the most common violation triggers.
Can I blame my vendor or software if a TCPA violation happens?
No — regulators are increasingly pursuing personal liability against owners and executives, not just the business entity, so 'the vendor handled it' is not a defense. That's why services like CallMyLeads build consent capture, immediate opt-out honoring, and quiet-hours enforcement directly into the response system, and why you should keep consent records, opt-out logs, and DNC scrubbing logs for at least four years to match the statute of limitations.

Turn Compliance Into Your Competitive Edge

TCPA compliance isn't just about avoiding fines—it's about building trust and protecting your business from risks that can emerge years later. As we've seen, obligations apply broadly to any business using automated systems for outreach, especially when contacting wireless numbers or sending marketing messages. The stakes are high, with penalties up to $1,500 per violation and a four-year statute of limitations, but the solution is straightforward: build compliance into your lead response from the start. That means capturing proper consent, honoring opt-outs in any reasonable manner within ten business days, scrubbing against the Do Not Call and Reassigned Number databases, respecting calling hours, and documenting everything. For service businesses that rely on speed-to-lead, this isn't a slowdown—it's a safeguard that lets you move fast without looking over your shoulder. Systems like CallMyLeads are designed to handle these requirements automatically, so your team can focus on converting leads, not managing legal exposure. Take the next step: review your current lead response workflow for TCPA gaps and see how automation can keep you compliant and competitive.

Build My Lead Response Plan

Get lead response tips that actually work