TCPA compliance means following the US Telephone Consumer Protection Act when you send marketing calls or texts: get documented prior express written consent, identify your brand in every message, honor opt-outs immediately, respect quiet hours, and keep records that prove consent existed before the first message went out.

Key Takeaways

  • The TCPA governs marketing calls, texts, and prerecorded messages to US numbers, and it is enforced largely through private lawsuits, not just regulators.
  • Marketing texts require prior express written consent: a clear disclosure, an affirmative act by the subscriber, and a stored record of both.
  • Consent is per-purpose and per-brand. A checkout email opt-in does not authorize SMS promos, and one brand's consent does not travel to a sister brand.
  • Opt-out handling is operational, not legal theater: STOP, UNSUBSCRIBE, and free-text variants must suppress the number across every sending system you own.
  • TCPA compliance sits on top of, not instead of, carrier rules (A2P 10DLC) and state telemarketing statutes, several of which are stricter than federal law.
  • This article is marketing operations guidance, not legal advice. Have counsel review your consent language and retention policy before launch.

What Is the TCPA and Who Does It Apply To?

The Telephone Consumer Protection Act is a US federal statute that restricts how businesses can contact consumers by phone. It covers autodialed calls, prerecorded or artificial voice messages, marketing text messages, and unsolicited faxes. If you send SMS or MMS marketing to a US mobile number, or place automated outbound calls, you are in scope regardless of company size.

Two things make the TCPA unusually consequential for growth teams. First, it carries statutory damages per message rather than per campaign, so a single misconfigured send to a large list creates exposure that scales with list size. Second, it supports private actions, which means plaintiffs and class-action firms, not only agencies, drive enforcement. That combination is why disciplined SMS marketing programs treat consent capture as core infrastructure rather than a form field.

Scope also depends on who you are messaging. Existing-customer transactional notices, such as a shipping update or an appointment reminder, sit in a different bucket than promotional offers. The moment a message includes an offer, discount, or upsell, treat it as marketing and apply the stricter consent standard.

What Counts as Valid TCPA Consent for Text Messages?

For marketing texts, the standard is prior express written consent. In practice that has three parts you must be able to reproduce years later.

  1. Clear disclosure at the point of collection. State that the person agrees to receive marketing messages from your named brand, that messages may be automated, that consent is not a condition of purchase, and that message and data rates may apply.
  2. An affirmative act. An unchecked checkbox the user ticks, a typed keyword sent to your short code, or a signed form. Pre-checked boxes, consent bundled inside unrelated terms, and implied consent from a purchase do not meet the marketing standard.
  3. A durable record. Store the exact disclosure text shown, timestamp, IP or device context, the phone number, the source URL or keyword, and the consent scope. If you cannot show what the user actually saw, you effectively cannot prove consent.

Consent is also scoped. It applies to the brand named in the disclosure and the message categories described. Teams that run multiple brands, franchise locations, or acquired product lines frequently get this wrong by pooling numbers into one sending list. Keep consent attached to the collecting brand in your CRM and automation stack so scope survives platform migrations.

Purchased lists, scraped numbers, and third-party lead lists deserve special skepticism. A lead vendor's claim of consent is not your record of consent, and in a dispute the burden lands on the sender. If you buy leads, require pass-through of the actual disclosure text and timestamp, and store it yourself.

What Must Every Marketing Text Actually Contain?

Compliance shows up in message content, not only in the database. Use the table below as a per-message checklist for a US marketing SMS program.

ElementWhy it mattersPractical implementation
Brand identificationRecipients must know who is messaging themName the brand in the first message of every conversation and in all promos
Opt-out instructionsRevocation must be easy and obviousInclude "Reply STOP to opt out" at minimum on the welcome message and periodically after
Help instructionsCarrier and best-practice requirementSupport HELP and INFO keywords with an auto-reply naming the brand and support contact
Rate disclosureSets expectations set at opt-in"Msg and data rates may apply" on the confirmation message
Frequency expectationReduces complaints and carrier filteringState an approximate cadence at opt-in and stay inside it
Send-time controlQuiet-hour restrictions apply per recipientSchedule by recipient time zone, not by your office time zone

Send-time control is where automated programs fail most often. A batch send that looks fine in one time zone can land in the middle of the night several zones away. Store a time zone on every contact, default conservatively when it is unknown, and let your platform hold messages rather than releasing them early.

How Do You Handle Opt-Outs Without Leaking Between Systems?

Legally, revocation of consent can be made through any reasonable means. Operationally that means you cannot only honor the exact word STOP in the exact channel. Plan for three paths.

  1. Keyword opt-outs. STOP, END, QUIT, CANCEL, UNSUBSCRIBE, and common misspellings, handled automatically by your SMS platform with an immediate confirmation message.
  2. Free-text and human opt-outs. "Please stop texting me" in a reply, a request to a support agent, or a note on a call. These require a routing rule so a human action writes back to the suppression list.
  3. Cross-channel and cross-system propagation. If the number exists in your CRM, your ecommerce platform, and a separate transactional sender, suppression must reach all of them.

Build one authoritative suppression list and make every sender read from it. The most common failure pattern is a marketing platform that honors STOP while a lifecycle tool or an agency-owned account keeps a stale copy of the list. Treat that the same way you would treat broken conversion tracking: a data-integrity defect with a clear owner, not an acceptable quirk.

Keep opt-out records forever. Deleting a suppressed contact to "clean" the database can cause the same number to be re-added by a later import, which reopens the exposure you already closed.

How Does TCPA Compliance Relate to A2P 10DLC and State Laws?

Three separate rule layers apply to the same text message, and passing one does not clear the others.

Federal statute (TCPA). Sets the consent, identification, and revocation baseline, and creates the litigation risk.

Carrier rules (A2P 10DLC and short-code programs). Carriers require brand and campaign registration, accurate use-case declarations, and opt-in evidence before they will deliver application-to-person traffic at volume. Registration approval is not a legal safe harbor, but registration failure will quietly throttle or block your deliverability equivalent for SMS.

State telemarketing statutes. Several states impose stricter conditions than federal law, including narrower calling windows, separate registration or bonding, and their own private rights of action. If you send nationally, your compliance floor is effectively the strictest state you message into.

The practical takeaway for a growth team: design one conservative program rather than per-state variants. Conservative defaults mean explicit standalone consent, a documented cadence, tight quiet hours, and one suppression source of truth. That configuration satisfies the strict cases and costs you very little in performance, because consented, well-paced lists outperform aggressive ones anyway.

What Does a Compliance-Ready SMS Program Look Like Operationally?

Turn the rules into an owned checklist that survives staff turnover.

  1. Inventory every sender. Marketing platform, CRM workflows, support desk, agency accounts, and any custom API sender. Unknown senders are the top source of violations.
  2. Standardize opt-in surfaces. One approved disclosure block, versioned, used on every form, popup, checkout, and keyword campaign. Store the version ID with each consent record.
  3. Wire consent into your data model. Channel-level consent flags with source, timestamp, and scope, mirrored into the warehouse alongside your lead scoring and lifecycle fields.
  4. Automate suppression. Central list, real-time propagation, and an alert when any sender attempts a message to a suppressed number.
  5. Set retention rules. Keep consent and revocation evidence for at least the applicable statute-of-limitations window, and longer if counsel advises.
  6. Audit quarterly. Sample records, replay the opt-in path, and confirm what a real subscriber sees today still matches the stored disclosure.

Teams that already run disciplined consent signaling for web analytics have an advantage here, because the habits transfer: capture consent at the source, propagate it as data, and never let a downstream tool invent permission it was not given.

Frequently Asked Questions

Does the TCPA Apply to B2B Text Messages?

Yes, in practice. The TCPA protects the number, not the job title, so a business contact using a mobile number is still covered. Many B2B teams assume a work cell is exempt and that assumption is a common source of exposure.

Is an Email Opt-In Enough to Send Marketing Texts?

No. Consent is channel-specific and purpose-specific. An email subscription does not authorize SMS marketing, even if the subscriber also gave you a phone number for shipping or account verification.

How Fast Do I Have to Honor an Opt-Out?

Treat it as immediate. Automated keyword opt-outs should suppress the number before the next scheduled send, and human-received requests should be logged the same day. Do not rely on a batch process that runs weekly.

Can I Text an Existing Customer About a Promotion Without Written Consent?

Transactional messages about an order or appointment sit in a different category, but promotional content requires the marketing consent standard. If the message sells something, get prior express written consent first.

Is A2P 10DLC Registration the Same Thing as TCPA Compliance?

No. 10DLC is a carrier delivery requirement about who you are and what you send. TCPA compliance is a legal requirement about whether the recipient agreed to hear from you. You need both, and passing registration does not defend a consent claim.