Summarize with AI
TCPA compliance mistakes are the operational gaps in an outbound calling program that expose a company to statutory damages under the Telephone Consumer Protection Act. They are almost never single agent errors. They are settings, sync failures, and missing records that repeat on every call a campaign places.
That is why the damages get large so fast. Statutory damages run at 500 dollars per violation and up to 1,500 dollars for a willful or knowing violation, with no aggregate cap. A defective consent setup applied across a 10,000 call campaign is an eight figure exposure, argued by plaintiffs’ firms that file these cases for a living.
Most call centers believe compliance is handled because agents are trained and a scrub list exists. The ten TCPA compliance mistakes below are the ones that actually appear in filed complaints, and every one of them lives at the system level.
TL;DR
TCPA damages are 500 dollars per call, rising to 1,500 dollars for willful violations, with no cap on the total. The ten TCPA compliance mistakes that generate lawsuits are unverifiable consent, stale do-not-call scrubbing, uncontrolled retry logic, calls outside permitted hours, opt-outs that never reach the dialer, automated dialing without consent, missing caller identification, reassigned numbers, ignored state rules, and no audit trail.
The federal floor for do-not-call list updates is every 31 days under the FTC’s Telemarketing Sales Rule. Treat that as a floor and check suppression at dial time instead.
No platform removes legal risk, and any vendor promising that is selling you something. Consent quality, lead source, and script language still decide the outcome, so confirm your program with counsel.
Key takeaways
- Damages are statutory at 500 dollars per call, or 1,500 dollars for willful violations, with no aggregate cap.
- The TCPA compliance mistakes that produce lawsuits are infrastructure gaps, not training gaps. Manual processes fail under volume.
- Consent you cannot document is consent you do not have. Purchased and aggregated lead lists are the biggest single source of exposure.
- The FTC requires covered telemarketers to remove National Do Not Call Registry numbers from calling lists at least every 31 days.
- The FCC’s one-to-one consent rule was vacated in January 2025 and never took effect. Prior express written consent remains the operative standard.
- State rules are stricter than federal in several states, and Florida limits both calling hours and call frequency.
- If you cannot produce consent records, scrub logs, and opt-out timestamps in discovery, you have no defense however careful the campaign was.
Table of contents
- What TCPA compliance mistakes are
- What a TCPA violation actually costs
- The ten mistakes at a glance
- Mistakes 1 to 5: Consent and contact rules
- Mistakes 6 to 10: Systems, states, and records
- Why manual compliance fails under volume
- How Bigly Sales prevents TCPA compliance mistakes
- A pre-launch compliance checklist
- TCPA compliance mistakes FAQ
- The bottom line
What TCPA compliance mistakes are
TCPA compliance mistakes are failures to meet the consent, contact, disclosure, and recordkeeping duties that the Telephone Consumer Protection Act and its implementing rules place on anyone making telemarketing or automated calls. The statute is codified at 47 U.S.C. 227 and carries a private right of action, which is why plaintiffs’ firms rather than regulators drive most of the litigation.
Two things make these failures unusual. Intent does not help you, and the fact that a lead vendor called the record clean does not transfer the liability. They also repeat. A misconfigured retry rule does not fail once. It fails identically on every call until somebody notices, which is the pattern that supports class certification.
What a TCPA violation actually costs
The headline number is 500 dollars per violation, rising to 1,500 dollars where the violation is willful or knowing. There is no aggregate cap, so exposure scales with call volume rather than stopping at a statutory ceiling.
The settlement is only part of the bill. Defense costs on a case that reaches discovery commonly run into six figures, and discovery is disruptive because it demands consent records, call detail records, scrub logs, scripts, and vendor contracts on a court timetable. Most cases open with a demand letter rather than a filing. Paying a small demand resolves that claim but also confirms your program answers demands, which tends to attract more of them.
The ten mistakes at a glance
The table below maps each of the ten TCPA compliance mistakes to the operational condition that causes it and the control that stops it before a call is placed.
| Mistake | What triggers it | Control that prevents it |
|---|---|---|
| 1. Unverifiable consent | Aggregated leads with vague or prechecked opt-in language | Consent token checked before the dial |
| 2. Stale do-not-call scrubbing | Weekly or monthly batch scrubs against the registry | Suppression check at dial time |
| 3. Uncontrolled retry logic | Campaign set to maximize contact attempts | Frequency caps enforced by state and campaign |
| 4. Calls outside permitted hours | Dialing on the call center’s clock, not the recipient’s | Calling windows applied by recipient location |
| 5. Opt-outs that never reach the dialer | Agent logs the request in the wrong system | Detection during the call plus instant suppression |
| 6. Automated dialing without consent | Assuming a dialer is exempt because an agent clicks | Consent gate on every automated campaign |
| 7. Missing caller identification | Script buries who is calling and why | Mandatory disclosure at the top of the script |
| 8. Reassigned numbers | Old consent on a number now held by someone else | Reassignment and disconnect checks before dialing |
| 9. Ignored state rules | Federal rules applied uniformly across all states | State rule set selected per recipient |
| 10. No audit trail | Records scattered across spreadsheets and inboxes | Consent, transcript, and scrub logs in one system |
Mistakes 1 to 5: Consent and contact rules
The first five TCPA compliance mistakes all concern permission and contact limits, which is to say whether you were allowed to place the call at all, and when.
1. Calling without provable prior express written consent
Prior express written consent is the foundation. If you cannot produce a record showing that a specific consumer agreed in writing to receive marketing calls from your company at that number, you are exposed on every call you placed.
This fails most often with purchased or aggregated lists. A lender buys leads described as consented. The form language was vague, the checkbox was prechecked, and the consent named a different company. The lender cannot reconstruct the trail.
One clarification matters because it is widely misreported. The FCC’s one-to-one consent rule, which would have required separate consent for each identified seller, was vacated by the Eleventh Circuit in January 2025 and never took effect. Prior express written consent under the existing standard remains the operative test. Adopting one-to-one consent as internal policy anyway is still sound, because it produces exactly the documentation a defense needs.
2. Letting do-not-call scrubbing fall behind
Calling a number on the National Do Not Call Registry without an established business relationship or written consent is a violation. The FTC’s Telemarketing Sales Rule requires covered sellers and telemarketers to update calling lists by removing registry numbers at least every 31 days. The FTC compliance guide sets out that duty alongside calling-hour limits and required disclosures.
Treat 31 days as the legal floor. A weekly batch job still leaves a window in which you can call someone who registered days earlier, and that window is where complaints come from.
3. Uncontrolled retry logic and call frequency
There is no single federal cap on how many times you may dial one number in a day, which is why this mistake survives so long. Exposure comes from two directions. Repeated calls to a number that never answers build a harassment narrative, and several states set explicit limits. Florida’s Telephone Solicitation Act limits commercial telephonic sales calls to three within a 24 hour period on the same subject matter.
The pattern is familiar. A lead does not answer, the system queues a callback two hours later, then another the next morning, then another that afternoon. By Friday the same consumer has six call records and never picked up once. Set frequency caps per campaign and per state and enforce them in the platform, not in a training document. Our guidance on AI calling cadence covers attempt limits that stay inside those boundaries.
4. Calling outside permitted hours
Federal telemarketing rules prohibit calls before 8 a.m. or after 9 p.m. in the recipient’s local time. Several states are narrower. Florida ends telephonic sales calls at 8 p.m. local time, so a nationwide campaign cannot run on one window.
The mistake happens whenever dialing is scheduled on the call center’s clock. A West Coast operation starting at 6 a.m. Pacific is legal for East Coast leads and illegal for Mountain Time leads in the same batch. Area code is a weak proxy for location on mobile numbers, so use the best location data you have and default to the conservative window when sources conflict.
5. Opt-outs that never reach the dialer
An opt-out is only honored when the number stops being dialed. Verbal acknowledgement by an agent is not compliance.
This one breaks in the sync layer. The consumer asks to be removed, the agent agrees, and the request lands in the CRM but not the dialer, or in one campaign but not the other three. Under the FCC’s revocation rules a consumer may revoke consent by any reasonable means, and callers must honor do-not-call and revocation requests within a reasonable time not exceeding 10 business days. The requirement that revocation carries across channels rather than only the channel where it was given is the item with a 2026 compliance date, and cross-channel suppression is what you should build toward now.
Compliance review
Find the gap before a plaintiff does
We will walk your outbound stack and show where consent, suppression, and records break under volume. The review takes about 30 minutes.
Mistakes 6 to 10: Systems, states, and records
The remaining TCPA compliance mistakes are about the machinery around the call, covering how it is dialed, what is disclosed, whose rules apply, and what you can prove afterward.
6. Automated dialing or prerecorded voice without consent
Using an automatic telephone dialing system or an artificial or prerecorded voice for marketing calls to wireless numbers without prior express written consent is a violation. In February 2024 the FCC confirmed that AI-generated voices count as artificial voices, so an AI voice agent sits squarely inside the rule.
Teams talk themselves out of this one by arguing their dialer requires agent interaction. Courts have gone different ways on what counts as an autodialer and the analysis is fact specific. The safer assumption is that if the system can queue, dial, and connect without a person entering each number, treat it as covered and gate it on consent.
7. Failing to identify the caller and the purpose
Telemarketing rules require prompt disclosure of who is calling and that the call is a sales call. Under the FTC’s rule the disclosure comes at the outset, before the pitch, and prerecorded telemarketing messages must identify the caller at the beginning of the message. There is no comfortable 30 second grace period.
The failure shows up in automated scripts that open with the offer. The consumer hears a pitch from an unnamed caller, feels misled, and complains. Even where the rest of the call was clean, a missing identification is its own violation.
8. Calling reassigned numbers
A reassigned number is one the original subscriber gave up and a carrier later issued to somebody new. Consent belonged to the previous holder, so the call is unconsented no matter how clean your original record is.
Three year old consent on a number disconnected six months ago and reissued last month is the classic fact pattern. Check numbers against reassignment and disconnect data before dialing, keep the date each consent was captured, and age out stale records rather than dialing them forever.
9. Applying federal rules uniformly and ignoring the states
Several states regulate telemarketing more tightly than federal law, and their rules apply based on where the consumer is. Florida’s Telephone Solicitation Act adds consent, frequency, and hour restrictions of its own. Oklahoma and Washington have enacted telemarketing statutes with private rights of action. California’s all-party consent recording law changes what you must disclose before recording.
The mistake is treating federal compliance as sufficient and finding the state overlay after a complaint reaches an attorney general. Maintain a state rule set, apply it per recipient, and have counsel review the states you dial most.
10. No call recording, consent record, or audit trail
If you are sued, you win or lose on documents. That means consent records tied to a specific number and date, call detail records, scrub logs, opt-out timestamps, and the script version in use at the time. If those cannot be produced in discovery, the practical outcome is a settlement whether or not the campaign was compliant.
The failure is usually storage, not intent. Records sit across a lead vendor portal, a dialer export, a CRM, and someone’s inbox, and nobody can assemble them on a discovery timeline. Store them together, keep them searchable by phone number, and check retention against state recording consent rules before you turn recording on everywhere.
Why manual compliance fails under volume
Every one of these TCPA compliance mistakes is easy to avoid on a single call. Read the consent record, check the clock, note the opt-out. Outbound programs do not make one call. They make thousands a day, and a control that depends on somebody remembering will be skipped at a predictable rate.
Automation cuts both ways. A human agent makes a mistake slowly and one at a time. A misconfigured campaign repeats the identical mistake across every record in the list before anyone reads a report. The useful question about an outbound platform is not what it can do, but what it refuses to do when a rule is not satisfied. Our controls are set out on the legal and compliance page.
How Bigly Sales prevents TCPA compliance mistakes
Bigly Sales runs managed outbound programs rather than handing over a self-serve tool, and the controls sit inside the calling workflow. A managed deployment can include consent validation before the dial, suppression against the National Do Not Call Registry and your internal list, state-aware calling windows applied by recipient location, frequency caps agents cannot override, opt-out detection during the call with immediate suppression across every campaign, and consent tokens, transcripts, recordings where permitted, and scrub logs stored together for audit. The wider picture is covered in our guide to TCPA compliance for managed AI sales.
Here is the honest caveat. None of this removes legal risk. Your exposure still depends on where leads came from, how consent was worded, what the script says, and which states you dial. A platform enforces the rules you configure. It cannot make a bad lead list good. If lead sourcing is your weak point, fix that first, because no amount of dial-time enforcement repairs consent that was never validly obtained.
A pre-launch compliance checklist
Run this before a campaign goes live, not after the first complaint. Eight questions cover most TCPA compliance mistakes.
- Can you produce, for any number in the list, the consent record including form language, timestamp, and source.
- Does suppression run at dial time against both the federal registry and your internal do-not-call list.
- Are calling windows driven by the recipient’s location, with the narrower state window winning any conflict.
- Is there a per-number frequency cap that campaign settings cannot override.
- Does an opt-out captured on one campaign suppress the number on all of them, including other channels.
- Does the script identify the company and the purpose of the call before anything else.
- Are numbers checked for disconnection and reassignment, and is stale consent aged out.
- Has counsel reviewed your top states and signed off on the script and consent language.
Watch
Would your dialer pass an audit today?
The questions an auditor asks first, and the records most outbound teams cannot produce on the day they are asked for them.
TCPA compliance mistakes FAQ
What are the most common TCPA compliance mistakes in call centers?
Unverifiable consent is the most common by a wide margin. It happens when a call center buys leads from an aggregator and cannot later show the specific form language, timestamp, and seller the consumer agreed to. The next most common TCPA compliance mistakes are stale do-not-call scrubbing, opt-out requests that never sync to the dialer, and calls placed on the call center’s clock rather than the recipient’s local time.
How much does a TCPA violation cost?
Statutory damages are 500 dollars per violation and up to 1,500 dollars where the violation is willful or knowing. There is no aggregate cap, so a class covering a full campaign can reach seven or eight figures. Defense costs on a case that reaches discovery commonly run into six figures on their own, separate from any settlement, and discovery pulls operations staff away from running the business.
Can I use an auto-dialer for cold calling?
Not for marketing calls to wireless numbers without prior express written consent from the person you are dialing. Whether a particular system counts as an automatic telephone dialing system is fact specific and courts have reached different conclusions. The safer operating rule is that if your platform can queue, dial, and connect without a person entering each number individually, treat it as covered and require documented consent.
Is the FCC one-to-one consent rule in effect?
No. The rule would have required consent to each identified seller separately, but the Eleventh Circuit vacated it in January 2025 and it never took effect. Prior express written consent under the existing TCPA standard remains the operative requirement. Many outbound teams adopted one-to-one consent as internal policy anyway, because it produces cleaner documentation and removes any dispute over which company a consumer agreed to hear from.
How often do I need to scrub against the National Do Not Call Registry?
The FTC’s Telemarketing Sales Rule requires covered sellers and telemarketers to update calling lists by removing registry numbers at least every 31 days. That is a legal floor rather than a best practice. High-volume programs check suppression much closer to the moment of dialing, because a 31 day window leaves room to call somebody who registered three weeks earlier and now has a complaint worth filing.
What is a reassigned number violation?
It happens when you call a number your records show as consented, but the carrier has since reissued it to a different person. The new subscriber never gave consent, so the call is unconsented even though your original record was genuine. Reassignment is a common lawsuit trigger because consent records age silently. Check against reassignment and disconnect data before dialing and age out old consent.
Do state telemarketing laws matter if I follow federal rules?
Yes, and they apply based on where the consumer is rather than where your operation sits. Florida’s Telephone Solicitation Act adds its own consent requirement, a three call per 24 hour limit on the same subject matter, and an 8 p.m. cutoff. Oklahoma and Washington have their own statutes. California’s all-party recording consent law affects disclosures. Federal compliance is the starting point, not the finish line.
What records do I need if I am sued?
You need the consent record tied to the specific number and date, including form language and source, plus call detail records, do-not-call scrub logs, opt-out timestamps, and the script version in use when the call was placed. If you cannot assemble those on a discovery timeline the case usually settles regardless of compliance. Keep records together and searchable by phone number rather than scattered across vendor portals.
Does using an AI voice agent change my TCPA obligations?
It does not reduce them. In February 2024 the FCC confirmed that AI-generated voices are artificial voices under the TCPA, so an AI voice agent placing marketing calls to wireless numbers needs the same prior express written consent as any prerecorded call. Identification, do-not-call, calling window, and opt-out rules apply the same way. The advantage of automation is enforcement consistency, not a lighter legal standard.
Can a platform guarantee TCPA compliance?
No, and treat any vendor claiming otherwise as a warning sign. A platform can enforce the rules you configure, block calls that fail a consent or suppression check, and produce the records you need in discovery. It cannot validate consent that was never properly obtained, choose your lead sources, or approve your script language. Compliance stays shared between your operation, your lead vendors, and your counsel.
The bottom line
The TCPA compliance mistakes that generate lawsuits are boring, repeatable, and fixable. Consent you cannot document. Suppression that runs on a schedule instead of at dial time. Opt-outs that stop at the CRM. Records nobody can assemble. None of that requires a bad actor. It only requires a system that lets a call go out when a check has not passed.
Fix the enforcement point rather than the training deck. Move every control to the moment before the dial, keep records in one searchable place, and have counsel review your consent language and your top states before the next campaign launches. This article is general information about common TCPA compliance mistakes and is not legal advice.
Managed outbound
Compliance enforced on every dial
We run number registration, consent checks, suppression, and audit trails as part of the deployment. Most programs are live within weeks.







