TCPA compliance: the plain-English guide

What TCPA stands for, what the law actually requires, what a violation costs, and a checklist you can work through before your next campaign goes out.

Last reviewed August 2026  ·  Written by the Bigly Sales team  ·  General information, not legal advice

Short answer

TCPA stands for the Telephone Consumer Protection Act, a US federal law passed in 1991 and codified at 47 U.S.C. § 227. It governs how businesses may call and text consumers, and the FCC writes the implementing rules at 47 CFR § 64.1200.

In practice TCPA compliance comes down to four things: get the right kind of consent before you dial, scrub against the Do Not Call registries, call only within permitted hours in the recipient's own time zone, and honour opt-outs immediately and keep the records to prove all of it. Statutory damages run $500 per violation, or up to $1,500 per violation where the conduct was wilful or knowing, and there is a private right of action, which is why TCPA cases are so often filed as class actions.

Legal compliance starts with the TCPA

The Telephone Consumer Protection Act is the federal statute that restricts unsolicited telemarketing calls, autodialed calls, prerecorded and artificial voice calls, text messages and junk faxes. Congress passed it in 1991 in response to the growth of automated dialing, and it has been amended and reinterpreted many times since, most consequentially by the Telephone Consumer Protection Act amendments and by a long series of FCC orders and court decisions.

Two features make the TCPA unusually significant for anyone running outbound calls. First, it carries statutory damages, so a plaintiff does not have to prove they suffered any financial loss. Second, it grants a private right of action, meaning consumers can sue directly rather than waiting for a regulator. Combine per-call statutory damages with a private right of action across a calling list of any size, and you have the conditions for the class actions the plaintiffs' bar files every week.

How the TCPA works, and who enforces it

It helps to separate the three layers that people lump together as "TCPA law", because they are written and enforced by different bodies and they do not say the same things.

LayerWhere it livesWho enforcesWhat it governs
The TCPA47 U.S.C. § 227, FCC rules at 47 CFR § 64.1200FCC, plus private lawsuitsThe channel: consent, autodialers, artificial and prerecorded voice, calling hours, DNC
Telemarketing Sales Rule16 CFR § 310FTC, plus state AGsThe sales conduct: deception, disclosures, abusive practices, record keeping
State mini-TCPAsState statutesState AGs, plus private lawsuitsOften stricter consent, narrower calling windows, registration, extra damages

The practical consequence is that federal compliance is a floor, not a finish line. Florida, Oklahoma and Washington are the most frequently cited mini-TCPA states, and several others impose their own registration requirements, Sunday and holiday restrictions or daily attempt caps. A campaign that dials nationally has to apply the stricter of the federal rule and the rule in the recipient's state, per recipient.

TCPA requirements

Stripped of the case law, these are the obligations that actually shape how you build a calling operation.

  • Consent appropriate to the call. Marketing calls placed with an autodialer or an artificial or prerecorded voice require prior express written consent. Purely informational or transactional calls sit under a lower standard. The type of call determines the standard, not your intent.
  • Do Not Call screening. Screen against the National Do Not Call Registry, applicable state registries, and your own internal do-not-call list. All three, not just the national one.
  • Calling hours. No telemarketing calls before 8:00 a.m. or after 9:00 p.m. in the called party's local time, with several states imposing tighter windows.
  • Identification. Callers must identify the individual or business responsible for the call and provide a telephone number or address at which they can be reached.
  • An automated opt-out on prerecorded calls. Prerecorded telemarketing calls must offer an interactive opt-out mechanism during the message.
  • Immediate honouring of revocation. A consumer may revoke consent by any reasonable means, and revocation must be processed promptly across every channel and campaign, not just the one they were called on.
  • An internal do-not-call policy and trained staff. A written policy, available on demand, plus training for anyone involved in placing calls.
  • Records that survive. Consent evidence, scrub results and call records retained long enough to defend a claim filed months or years later.

Consent is where most TCPA exposure is created, and the distinction that matters is between two standards.

Prior express consent

The lower standard, sufficient for non-marketing calls such as appointment reminders, delivery notifications or account alerts. Giving a business your number in connection with a transaction can constitute this kind of consent for calls closely related to that transaction.

Prior express written consent

The higher standard, required for marketing and advertising calls made with an autodialer or an artificial or prerecorded voice. To qualify, the agreement generally has to be in writing, signed, and clearly disclose that the consumer will receive such calls, that they may be made using automated technology, and that consent is not a condition of purchase. It must also identify the seller who will be calling.

Where operators get caught

A single consent form does not cover every brand that later buys the lead. If the consent language names one seller and a different company places the call, that consent may not protect the caller. This is the single most common defect we see in purchased lead data, and it is also the area where the rules have been most actively litigated in recent years, so treat the current position as something to confirm with counsel rather than assume.

Revocation

Consumers can withdraw consent by any reasonable means, including saying so on the call in words nobody scripted. A system that only recognises a fixed keyword list will miss revocations and keep dialing, which is exactly the fact pattern that turns one complaint into a class action.

The National Do Not Call Registry

The National Do Not Call Registry is the federal list of consumer phone numbers that have asked not to receive telemarketing calls. It was established in 2003 and is administered by the Federal Trade Commission, with sellers and telemarketers accessing it through the registry's subscription service. Registrations do not expire, so a number stays on the list until the consumer removes it.

  • Scrub on a schedule. Telemarketers are required to check the registry at least every 31 days and remove listed numbers from their calling lists. Practically, more frequent scrubbing is safer.
  • The registry is not the whole obligation. Several states maintain their own registries, and your internal do-not-call list has to be screened as well.
  • Limited exemptions exist. Calls made with prior express written consent, calls to consumers with whom you have an established business relationship within the applicable window, and non-commercial or purely informational calls are treated differently. Exemptions are narrower than most sales teams assume, and an exemption from the DNC rules is not an exemption from the rest of the TCPA.
  • Internal lists never expire. If somebody asks you not to call, that request applies indefinitely regardless of registry status.

TCPA violations and what they cost

Damages are statutory and per violation, which is what makes volume dangerous.

ConductStatutory damagesExposure across a campaign
Negligent violation$500 per call or text10,000 calls = $5,000,000
Wilful or knowing violationUp to $1,500 per call or text10,000 calls = up to $15,000,000

Those numbers are not a worst-case rhetorical device. They are the arithmetic a plaintiffs' firm performs before deciding whether to file, and they explain why TCPA claims are usually brought as class actions rather than individual suits. Add the cost of defence, discovery into your consent records and the operational disruption of a litigation hold, and the real figure is higher than the damages line alone.

The violations that generate the most claims are mundane: calling a number on the DNC registry, calling outside permitted hours because the dialer used the call center's clock rather than the recipient's, continuing to call after a revocation the system did not recognise, and relying on consent language that named a different seller.

For a fuller treatment of how these cases actually arise, see our analysis of record TCPA class action filings and the ten compliance mistakes that get call centers sued.

TCPA compliance checklist

Work through this before a campaign goes live, and again whenever your lead sources or dialing states change.

  1. Classify every call type. Marketing or transactional? Autodialed, artificial or prerecorded voice, or manual? The answer sets which consent standard applies.
  2. Verify consent at the record level. For each number, can you produce the language shown, the timestamp, the source, and the seller named? If the consent came with purchased data, can the vendor produce it?
  3. Confirm the seller named in the consent is the entity placing the call. If not, treat the consent as unreliable.
  4. Scrub the national registry, applicable state registries, and your internal list. Document the scrub date and result per record, at least every 31 days.
  5. Apply calling windows by recipient, not by office. Determine the recipient's jurisdiction and apply the stricter of the federal 8 a.m. to 9 p.m. local rule or the state rule.
  6. Load state-specific restrictions. Sunday and holiday rules, daily attempt caps, registration requirements and any industry-specific conditions for the states you dial.
  7. Make opt-out recognition semantic. The system must catch a revocation phrased in any reasonable way, suppress the number immediately, and propagate that suppression across every campaign and channel.
  8. Decide your AI disclosure position and set it at system level. Not in a prompt a model can drift away from.
  9. Publish an internal do-not-call policy and train the team. Keep evidence of the training.
  10. Set retention long enough to defend a late claim. Consent records, scrub logs, recordings, transcripts and dispositions.
  11. Run a monthly exception report. Calls outside windows, calls to suppressed numbers, missing consent. Investigate every exception rather than noting the count.
  12. Have counsel review the programme annually and after any rule change. This list is a starting point for that conversation, not a substitute for it.

How the TCPA applies to AI voice calls

The important development for anyone using AI voice agents is that the FCC has confirmed AI-generated voices count as "artificial" within the meaning of the TCPA. The practical effect is that an AI-voiced outbound marketing call is treated like a prerecorded robocall: it needs prior express written consent, and the artificial-voice restrictions apply.

This is often misunderstood as a rule about the technology. It is not. The obligations were always there; AI simply moves you into the stricter category while also making it trivially easy to place far more calls than a human team could, which multiplies whatever your consent and suppression process gets wrong.

The controls that matter are therefore the same ones described above, just executed automatically because the volume makes manual oversight meaningless. That is the argument for enforcing them before the dial rather than reviewing them afterwards, and it is the basis on which we compare the vendors in this market in our guide to TCPA-compliant AI calling platforms. For the AI-specific detail, see TCPA consent requirements for AI voice calls and the FTC and FCC AI calling rules.

How Bigly Sales handles compliance

Bigly Sales operates as a managed calling platform, which means the controls described on this page are built into execution rather than handed to your team as a configuration exercise. Every attempt is screened before it is placed.

  • TCPA. Federal and state-by-state dialing rules, calling windows applied in the recipient's local time zone, state emergency and holiday restrictions, state caps on daily attempts, consent validation (TrustedForm compatible), and automatic opt-out and DNC suppression.
  • FCC and FTC. Number registration and whitelisting, caller identification, and opt-out handling aligned to the Telemarketing Sales Rule.
  • HIPAA-aware workflows. For healthcare clients, scripting and data handling designed around protected health information. See our healthcare page for detail.
  • Evidence retention. Call recordings, transcripts, dispositions, consent records and scrub results retained so a claim can be answered months later.

We also retain outside counsel recognised in FCC and FTC matters, and we use consent-capture platforms such as Jornaya Lead ID and TrustedForm to evidence permission at the point of collection. None of that removes your own obligations as the seller, which is the point of the checklist above.

Frequently asked questions

What does TCPA stand for?

TCPA stands for the Telephone Consumer Protection Act, a US federal law enacted in 1991 and codified at 47 U.S.C. § 227. It regulates telemarketing calls, autodialed calls, artificial and prerecorded voice calls, text messages and junk faxes.

What is TCPA compliance?

TCPA compliance means operating a calling programme so that every call meets the Act's requirements: the correct standard of consent for that call type, screening against federal, state and internal Do Not Call lists, dialing only within permitted hours in the recipient's local time, honouring opt-outs immediately, identifying the caller, and retaining records that prove all of it.

What are the penalties for a TCPA violation?

Statutory damages are $500 per violating call or text, rising to as much as $1,500 per violation where the violation was wilful or knowing. Because damages are per call and consumers have a private right of action, claims are frequently filed as class actions.

What is prior express written consent?

It is the higher consent standard required for marketing calls made with an autodialer or an artificial or prerecorded voice. The agreement generally must be written and signed, must clearly disclose that automated marketing calls will be made, must name the seller placing them, and must state that consent is not a condition of purchase.

What is the National Do Not Call Registry?

It is the federal registry of consumer phone numbers that have opted out of telemarketing calls, established in 2003 and administered by the Federal Trade Commission. Telemarketers must scrub their calling lists against it at least every 31 days, and registrations do not expire.

What are the permitted TCPA calling hours?

Telemarketing calls may not be placed before 8:00 a.m. or after 9:00 p.m. in the called party's local time. Several states set narrower windows, and some add Sunday or holiday restrictions, so the applicable limit is whichever rule is stricter for that recipient.

Does the TCPA apply to text messages?

Yes. Text messages are treated as calls for TCPA purposes, so the consent, opt-out and suppression obligations apply to SMS and MMS campaigns in the same way they apply to voice calls.

Does the TCPA apply to B2B calls?

Business-to-business calls receive different treatment in some respects, but the exemption is narrower than commonly assumed, particularly where the number reached is a mobile phone or a sole proprietor's line. Do not treat a list as exempt simply because it is labelled B2B.

Are AI voice calls covered by the TCPA?

Yes. The FCC has confirmed that AI-generated voices are "artificial" for TCPA purposes, which places AI-voiced marketing calls in the same category as prerecorded robocalls and means prior express written consent is required.

What is a mini-TCPA?

A state statute that imposes obligations beyond the federal TCPA. Florida, Oklahoma and Washington are the most frequently cited, adding stricter consent standards, narrower calling windows and in some cases additional damages and their own private right of action.

Who is liable, the platform or the business making the calls?

In practice the seller on whose behalf the calls are made carries the exposure, which is why a vendor's assurance that its platform is compliant is not by itself a defence. Ask any vendor to state in writing which controls it operates and which remain your responsibility.

Is AI outbound calling legal?

Yes, when it is done with the right consent and inside the applicable rules. The technology is not the issue; the consent standard, the calling window, DNC screening and disclosure are. AI-voiced marketing calls sit in the stricter artificial-voice category, so they require prior express written consent.

How does Bigly Sales help with TCPA compliance?

Bigly enforces the controls before each dial rather than reviewing them afterwards: consent validation, DNC scrubbing across federal, state and internal lists, calling windows applied in the recipient's local time zone, state holiday and frequency rules, and immediate opt-out suppression. You remain the seller, so the obligations stay yours, but the execution is automated.

Does Bigly AI identify itself on calls?

AI disclosure is a system-level setting you control per campaign rather than an instruction inside a prompt, so the behaviour is consistent across every call instead of depending on how a model responds.

What happens when someone asks to stop calls?

The request is recognised by meaning rather than by matching a keyword list, the number is suppressed immediately, and that suppression propagates across every campaign and channel, not just the one they were called on.

Are calls recorded and disclosed?

Calls are recorded and transcribed so the consent record, the conversation and the disposition can be produced later. Recording disclosure requirements vary by state, which is part of the jurisdiction logic applied before the dial.

See compliance enforced before the dial

We will run a live campaign against your criteria and show you the pre-dial checks as they happen: consent, scrub result, jurisdiction and calling window, per call. Most clients are live in three business days.

Book A Free Demo Or call (855) 525-4843

This page is general information, not legal advice. The TCPA is actively litigated and both federal and state rules change; several points above have been the subject of recent court decisions and FCC orders. Nothing here creates an attorney-client relationship, and it should not be relied on as a substitute for advice about your specific programme. Confirm your obligations with qualified counsel before launching or changing a calling campaign. Related reading: TCPA compliance for AI outbound calling, the AI calling glossary, and our guide to TCPA-compliant AI calling platforms.