TCPA compliance checklist: Best practices for your marketing

TL;DR
- TCPA is the US law that says you need someone’s OK before you call, text, or fax them for marketing.
- Get clear, written consent first, tell people what they’re signing up for, and keep proof of it.
- Always give an easy way to opt out, and only reach out between 8 am and 9 pm.
- Rules keep changing. The “one-to-one consent” rule got scrapped, but revocation rules (letting people cancel any way they want) are mostly active now.
- States are piling on their own stricter laws too, so what’s compliant can depend on where your customer lives.
- Bottom line: document everything, because breaking the rules can mean real lawsuits and real money.
Overview
You have a product or service you can’t wait to share with potential customers, and you’re ready to market it. Before you start sending out emails or text messages (SMS) or making phone calls, sit down with your legal team and make sure you have considered every marketing law and regulation. One important best practice is checking off the items on your TCPA compliance checklist.
The Telephone Consumer Protection Act (TCPA) was established in the United States in 1991 and aims to protect consumers from receiving telephone solicitations from businesses without consumers’ consent. Because of concerns with data privacy and data protection, the rules and regulations change constantly; if you aren’t careful, you could face expensive lawsuits or fines if a consumer claims they did not give consent to be contacted. The last thing you want is for a lead to sue your company.
What is TCPA compliance?
TCPA compliance refers to adhering to the Telephone Consumer Protection Act, a crucial regulation designed to protect consumers from unsolicited calls, texts, and faxes. Businesses must obtain explicit consumer consent before initiating telemarketing communications, maintain do-not-call lists, and honor time restrictions on calls to avoid hefty penalties.
Compliance is not only a legal requirement but also a best practice to foster trust and maintain a positive reputation among consumers. Adhering to TCPA guidelines helps mitigate legal risks and enhances customer relations, making it a fundamental aspect of responsible business operations.
TCPA compliance guide: What’s on the TCPA consent compliance checklist?
A TCPA consent compliance checklist, paired with a TCPA compliance guide, helps you choose marketing technologies that stay aligned with TCPA and TCPA SMS compliance requirements from the start. That makes it easier to run efficient, cost-effective campaigns without having to retrofit compliance later.
TCPA checklist
- Obtain and store prior express written consent
- Use clear disclosure language
- Opt-in follow-up requirements
- Include an opt-out option
- Only contact during approved hours
- Scrub against the national DNC (Do-Not-Call) and RND (Reassigned Numbers Database) lists.
- SMS protections
Maintain that you are properly capturing and storing proof of consent
- Provide proof that the consumer gave consent by checking the box or completing the form.
- Provide a visual record of the TCPA disclosure language the consumer viewed with a session replay solution that makes it easy to identify consent language and the consumer’s action of providing their consent (i.e., entering requested information, checking the consent box, and pressing the “Submit” button).
- Documentation should be collected and stored by a reliable, independent third party so that it can’t be manipulated.
- Documentation should be easily accessible and shareable.
- Perform periodic audits (spot checks) of your consent documentation to confirm that your protection is reliable.
- If buying leads from partners, make sure your document of consent matches the lead you purchased.
- If buying leads from partners, verify consent in real time before you call or text the lead.
Learn more about the importance of TCPA consent.
Use clear, concise, and informative disclosure language
- The disclosure language (i.e., the terms and conditions the customer is agreeing to by submitting the form) is clear and easy to understand (avoid “legalese”).
- The disclosure statement is clearly visible in the immediate vicinity of the opt-in button.
- The disclosure statement states the identity of the company that will contact the consumer.
- The disclosure statement states that communication may be in the form of an SMS (text) or automatic telephone dialing system (ATDS).
- If you’re using a pre-recorded voice in the call, this is clearly stated in the disclosure.
- The disclosure states that opting in to receiving messages is not a requirement to take advantage of the offer.
- The disclosure states the approximate number of calls and text messages the consumer may receive.
- Work with your privacy, legal, and design teams to determine the most reasonable, balanced way to meet webpage notice and consent language compliance requirements.
- Review any TCPA disclosure statements with your legal department to make sure that the statement follows your company’s legal and compliance requirements.
TCPA opt-in requirements
Once a customer opts in to your messages (either sales/marketing or transactional messages), send a detailed disclosure message. The opt-in confirmation should include:
- Your business name.
- The purpose of the messages.
- How often texts will be sent (daily, weekly, monthly).
- Notification of possible text and data rates.
- A link to the full terms and conditions.
- Directions for getting help if needed.
- Steps to opt out of future messages.
TCPA opt-out requirements
- Under the TCPA, make sure that your business offers a straightforward opt-out method for messages.
- Implement a ‘STOP’ response feature that allows customers to text ‘STOP’ to halt SMS communications.
- Regularly remind subscribers of the opt-out process by including ‘STOP’ instructions routinely in messages.
Discover the latest requirements of consent revocation now.
TCPA calling hours
- Businesses should not text or call subscribers before 8:00 AM or after 9:00 PM. Be aware that some states have slightly different time allowances and restrictions. Also, be mindful of time zone differences in and across states.
- Avoid contacting customers outside these hours to prevent complaints and potential issues.
TCPA compliance checklist (SMS)
Under the TCPA case law and FCC interpretations, text messages are considered similar to phone calls. Current compliance best practice is to treat text messages in the same way or under the same scope of requirements as phone call outreach. To stay compliant and avoid costly legal penalties, businesses must follow all TCPA guidelines. A TCPA compliance checklist for texting will help you meet all requirements before sending SMS communications.
Here are the key steps to keep your marketing texting efforts TCPA-compliant:
- Obtain prior express written consent – Before sending any marketing or promotional campaign texts, you must have clear, written consent from the recipient.
- Provide clear disclosures – Consumers should know what they are opting into, including messaging frequency, possible costs, and opt-out instructions at the point of consent.
- Offer easy opt-out options – Consumers can revoke consent through any reasonable method, not just by replying “STOP.” That includes phrases like “unsubscribe,” “cancel,” “quit,” or “end,” and even a verbal request during a call. According to revocation rules, businesses must honor these requests within 10 business days, and may send one clarification text to confirm the scope of the opt-out before stopping.
- Respect timing and frequency limits – when using text recruiting software, avoid excessive messaging and only send texts during TCPA-approved hours to respect consumer privacy.
- Keep accurate records – Document consent, message logs, and opt-out requests to bolster compliance.
TCPA trends for 2026
TCPA compliance in 2026 is more fragmented than ever. State-level laws keep adding new requirements on top of the federal rules, and businesses need to track both to stay compliant.
One-to-one consent rule is dead
The FCC’s one-to-one consent rule, which would have required lead generators to get separate consent for each company they contact on behalf of, is no longer part of the picture. A federal court struck it down in January 2025, and the FCC formally dropped it later that year. If you’ve been planning around this rule, you can stop. The core prior express written consent requirement it was meant to tighten is still in place, though, and it’s reverted to the pre-2023 standard. A single, clear disclosure can still authorize multiple sellers to contact a consumer, as long as the consent is unambiguous. That matters if you rely on shared or co-registration lead forms.
Revocation rules are only partly in effect
Most of the FCC’s newer revocation rules are already in force. Since April 11, 2025, consumers can revoke consent in any reasonable way (not just by texting “STOP”), businesses must honor the request within 10 business days, and only one clarification text is allowed in response. The one piece still delayed is the “revoke-all” rule: the requirement that a single “STOP” wipe out consent across every channel and business unit, even for unrelated messages. That’s been pushed back twice and now isn’t required until January 31, 2027. Don’t assume you’re off the hook on revocation generally. Only that narrow cross-channel piece is on hold.
State laws keep expanding
States like Florida, Oklahoma, Texas, and Maryland have their own mini-TCPA laws with tighter consent rules and broader autodialer definitions, and more states are joining them.
Virginia now requires businesses to honor do-not-call requests, including “STOP” or “UNSUBSCRIBE” replies to texts, for 10 years, under amendments to the Virginia Telephone Privacy Protection Act that took effect January 1, 2026. The law also creates a private right of action with escalating statutory damages ($500 for a first violation, $1,000 for a second) plus attorneys’ fees, making it one of the more litigation-friendly state statutes to watch.
AI is now under closer watch
Regulators are also paying closer attention to AI. As more companies use automated systems for lead generation, dialing, and personalized messaging, expect more scrutiny of how these tools handle consent and disclosure. Building compliant systems now will save you headaches as the rules keep evolving.
FAQs
Your company could face up to a $1,500 fine per call or text message.
Not all lawsuits are large class-action ones; individuals file smaller lawsuits as well. The ones who file the most lawsuits are known as “serial litigators.” They claim TCPA violations and usually settle out of court for amounts ranging from $10,000 to $250,000.
Many marketers think obtaining consent is too complicated, so they follow ineffective strategies, such as mixing transactional-alert message campaigns with marketing campaigns, or avoiding the use of SMS technologies or pre-recorded messages; however, these methods waste a lot of time and money, plus, they open companies up to the risk of legal issues.
The best way to comply is to only reach out to opt-in leads who have given their consent to be contacted–and make sure you have documented that consent.
The best proof of consent a business can have is prior express written consent. “Written” means language can be hardcopy or electronic. “Consent” is the acknowledgment of the language by an opt-in action from the consumer (i.e., checking a checkbox) near their contact info and/or the submit button on a web page form. Be careful with the use of pre-checked checkboxes on web forms as, depending on design, they may not always meet the opt-in or “express” consent action requirements. This is a written agreement, acknowledged by the consumer, to receive a phone call or text message from your company; this agreement includes a clear and obvious disclosure that permits your business to send marketing communications. Save a record of this consent to contact for a period of 2 to 5 years in case there is an inquiry or legal action.
Prior express written consent can also supersede the national DNC list, but scrubbing against it, as well as the RND (which reduces the risk of calling an old mobile number with a new owner), is still recommended. The biggest benefit? Contacting people who want to be contacted, which ultimately improves your conversion rates.
Some litigators hope you’re not going to have compliant, documented written consent, and if they bring a lawsuit and you may consider a settlement as a less expensive alternative. If you want to avoid paying hefty settlements or lawsuit expenses, you need to properly present and collect consent, document consent transactions, and be able to quickly access the documentation for proactive compliance or legal defense.
TrustedForm is a lead certification product that documents the consent for each individual webform lead or social lead ad. When our Web SDK (also known as a web script) is placed on a web form, ActiveProspect is able to independently document where and when consumers provided their information and consent to contact using a web form by capturing the events and providing an instant session replay showing the consumers’ exact actions.
With TrustedForm, you can verify, document, and archive the consent transaction for compliance with data regulations like TCPA; verify you are receiving authentic leads from interested consumers; and verify your brand is being properly represented on approved sites.
Our TrustedForm certificates provide unbiased third-party documentation of consent. This proof of consent can protect you in the event of litigation while giving you new confidence that your leads have actually asked you to contact them.
At its core, TCPA compliance means getting prior express written consent before contacting someone by call or text using an autodialer or prerecorded voice, and being able to prove that consent later if challenged. That includes clear, conspicuous disclosure language at the point of opt-in, a working opt-out mechanism, scrubbing your lists against the national DNC and RND databases, and honoring calling-hour restrictions. On top of the federal baseline, a growing number of states have their own requirements layered on top, so what counts as “compliant” can shift depending on where your leads live.
TCPA text messaging compliance covers the same core obligations as phone calls, prior express written consent, a clear and easy opt-out, and documented proof of both, but applied specifically to SMS and MMS. Texting adds a few wrinkles of its own: carrier registration through 10DLC, message frequency and timing limits, and a quirk where a single long text can technically count as multiple messages for violation purposes depending on how it’s transmitted. Because texts are treated the same as calls under current case law and FCC guidance, cutting corners on SMS carries the same legal exposure as an unauthorized robocall.
Final thoughts
The businesses that stay out of the headlines are the ones treating consent as infrastructure and not mere paperwork. That means documenting every opt-in, retaining proof in a format that holds up under legal scrutiny, and staying current as both state legislatures and the FCC keep moving the goalposts.
TrustedForm gives you that foundation. Every lead gets an independent, timestamped certificate of consent, capturing exactly when, where, and how a consumer opted in, so you’re not scrambling to reconstruct a defense after a demand letter arrives. Get started with TrustedForm today.
DISCLAIMER: This page and all related links are provided for general informational and educational purposes only and are not legal advice. ActiveProspect does not warrant or guarantee this information will provide you with legal protection or compliance. Please consult with your legal counsel for legal and compliance advice. You are responsible for using any ActiveProspect Services in a legally compliant manner pursuant to ActiveProspect’s Terms of Service. Any quotes contained herein belong to the person(s) quoted and do not necessarily represent the views and/or opinions of ActiveProspect.
