TCPA guidelines 2026

TL;DR

  • The FCC pushed its “revoke-all” consent rule to January 31, 2027, giving businesses extra runway to close compliance gaps before it takes effect.
  • The McLaughlin v. McKesson ruling means courts can now interpret the TCPA independently of FCC guidance, so compliance requirements increasingly vary by state and jurisdiction.
  • Bot-generated leads are a growing risk: fake or scraped phone numbers can enter your outreach lists with no real consumer consent behind them, creating TCPA exposure you never intended.
  • Key action: Treat 2026 as a readiness year by centralizing consent records, documenting capture across every channel, and using tools like TrustedForm to verify and store proof of consent before the revoke-all deadline arrives.

Overview

If your business has just started thinking about TCPA compliance, you’re not alone—and you’re right to take it seriously. The Telephone Consumer Protection Act (TCPA) is one of the most important US laws governing how businesses communicate with consumers. Whether you’re making sales calls or launching SMS marketing campaigns, understanding TCPA guidelines is essential to avoid hefty fines and protect your brand.

In this post, we’ll break down TCPA guidelines in 2026, including key updates from the Federal Communications Commission (FCC), and what they mean for SMS and telemarketing. We’ll also explain what it takes to be compliant and how tools like TrustedForm can help simplify and document your compliance efforts.

What is the TCPA?

The TCPA was enacted by the FCC in 1991 to regulate telemarketing and protect consumers from unwanted communications. It covers a wide range of practices, including:

  • Auto-dialed phone calls
  • Prerecorded voice messages
  • SMS and MMS text messages
  • Fax advertisements (yes, those still count)
  • Do-Not-Call (DNC) lists

Non-compliance can result in statutory damages ranging from $500 to $1,500 per violation—and if you’re sending messages or calling thousands of consumers, those numbers add up quickly.

TCPA guidelines for 2026: What’s new this year?

The regulatory landscape around TCPA consent shifted more than it settled in 2026. Most of the year’s “updates” were delays and open rulemakings rather than finished rules, which means compliance teams are planning around moving targets. Here’s where things stand:

1. FCC TCPA guidelines: The 2026 update

The FCC spent 2026 reconsidering several TCPA provisions rather than finalizing them. Key developments:

  • The “revoke-all” rule was pushed to 2027. The rule requiring businesses to treat any consent revocation as applying to all future calls and texts from that caller, regardless of topic, was set to take effect April 11, 2026. The FCC extended that deadline to January 31, 2027, while it decides whether to modify or scrap the rule.
  • The FCC is rethinking the revoke-all rule itself. Through a pending rulemaking, the FCC is weighing whether businesses can designate specific opt-out methods (like “STOP”) instead of having to honor “any reasonable means” a consumer uses to revoke consent. 
  • Courts are no longer bound by FCC interpretations. The Supreme Court’s McLaughlin v. McKesson ruling means judges can now decide independently whether to follow FCC guidance on the TCPA, creating a more fragmented, court-by-court compliance landscape. Convoso’s compliance breakdown has a good rundown of what this means practically, including the rise of state “mini-TCPAs” that add stricter rules on top of federal ones.
  • Robocall Mitigation Database requirements got stricter. Providers must now recertify their filings annually by March 1, update records within 10 business days of any change, and face higher penalties for false or inaccurate filings.

2. TCPA customer consent management guidelines

With this much still in flux and courts now free to diverge from FCC guidance state by state, the businesses staying compliant are the ones treating consent management as infrastructure:

  • Centralize consent records in one system instead of scattering them across forms, spreadsheets, and vendor platforms.
  • Document how, when, and where consent was captured for every channel: voice, SMS, and any automated outreach  since pending rule changes and state-level splits could affect each differently.
  • Monitor opt-out propagation across channels, so a revocation on one doesn’t get missed on another while the revoke-all rule’s future gets sorted out.
  • Use the extended deadline to close gaps now instead of scrambling before January 2027.

3. TCPA guidelines for SMS in 2026

Text messaging remains one of the most effective marketing communication channels, but it still demands purposeful compliance attention to avoid regulatory or legal action.

TCPA requirements around SMS messages emphasize:

  • Prior express written consent is required for all marketing messages sent via SMS.
  • Clear opt-out instructions must be included in every message. Consumers should be able to respond with “STOP” or similar phrases to opt out.
  • Quiet hours restrictions apply. At the federal level, you can’t send marketing messages before 8:00 a.m. or after 9:00 p.m. in the recipient’s time zone. Many states enforce their own TCPA calling hours that differ from federal ones.
  • Documented proof of consent is essential. A list of phone numbers isn’t enough: you need to show how, when, and where consent was obtained.

How to stay compliant with TCPA guidelines

Staying compliant doesn’t have to be overwhelming. Whether you’re managing business communications or balancing multiple academic tasks, attention to detail is what makes the difference, something every college paper writer understands well. Here are the key steps every marketer should follow. Here are the key steps every marketer should follow:

1. Secure clear, documented consent

The first and most important step is to gather prior express written consent from anyone you plan to contact via SMS or auto-dialed calls. This means:

  • Displaying a clear, conspicuous notice before a consumer provides their information.
  • Including language that specifies they agree to receive marketing messages.
  • Making it clear that consent is not a condition of purchase.

If you’re using web forms, make sure they include compliant consent language and capture timestamped records.

2. Honor opt-out requests promptly

The start of every SMS communication campaign must include an opt-out mechanism, and you’re expected to process opt-out requests within 10 business days. Avoid sending any promotional follow-ups after someone has opted out.

Best practices include:

  • Monitoring for freeform opt-outs (e.g., “stop messaging me”, “unsubscribe”, “remove me”).
  • Sending a final confirmation message, without any marketing content.

3. Scrub lists regularly

Compliance doesn’t end once you’ve captured consent. Your list must be kept up to date to avoid:

  • Messaging numbers on the National Do-Not-Call (DNC) Registry.
  • Contacting numbers in state-specific DNC lists (where applicable).
  • Reaching out to reassigned or recycled numbers by checking the Reassigned Number Database (RND) service.

4. Respect time-of-day restrictions

The TCPA prohibits calls or texts outside of 8 a.m. to 9 p.m. local time for the recipient. Many states enforce even stricter “quiet time” rules, so make sure your systems can account for time zones and state-level variations.

5. Keep detailed records

If you face a TCPA complaint, your best defense is documentation. That means:

  • Timestamped proof of consent.
  • Screenshots or copies of the consent language presented.
  • Records of opt-in and opt-out actions.
  • A log of messages sent and responses received.

6. Watch for bot-generated leads
A newer compliance risk: leads that were never submitted by a real consumer at all. 

Bot-generated form submissions can slip fake or scraped phone numbers into your outreach lists, meaning you have no valid consent to rely on if that number gets contacted, and no real consumer behind it to have given any. That’s a TCPA violation waiting to happen, even though the business never intended to contact anyone without consent.

TrustedForm Bot Detection flags bot-generated and fraudulent leads before they ever reach your CRM, so you’re not building outreach campaigns on top of fake, non-compliant  data. You can see how this plays out in practice in this breakdown of lead fraud and bot detection.

How TrustedForm helps simplify TCPA compliance

One of the best ways to reduce risk and help guarantee compliance is by using a trusted tool to capture and store proof of consent. That’s where TrustedForm by ActiveProspect comes in.

TrustedForm is a consent verification solution that helps businesses collect, verify, and store independent proof of a lead’s opt-in. Here’s how it supports your TCPA compliance:

Independent proof of consent

TrustedForm certifies where, when, and how consent was obtained, capturing:

  • A session replay of the exact moment the user submitted their information
  • A timestamp and session metadata
  • The lead’s IP address and location

This data can be used to defend your business in the event of a TCPA claim or audit.

Real-time verification

TrustedForm works in real time with your lead capture forms and lead vendors, allowing you to reject leads that lack valid consent language and webform presentation before they hit your CRM. Check out this guide to see how to set up TrustedForm.

Secure storage and audit trails

Every TrustedForm Certificate can be stored securely and accessed on demand for up to five years, giving your compliance team a complete, auditable record of consent for every lead.

FAQs

1. What are the basic TCPA guidelines businesses must follow?

Businesses need prior express written consent before sending marketing calls or texts, a working opt-out mechanism in every campaign, and compliance with the 8 a.m.–9 p.m. calling window in the recipient’s time zone. You also have to scrub contact lists against the National DNC Registry and any state-specific lists, and keep documented proof of consent on hand in case a complaint comes in.

2. What are the 2026 TCPA guideline updates I need to know about?

The biggest one: the FCC pushed its “revoke-all” consent rule deadline from April 2026 to January 31, 2027, while it decides whether to modify or eliminate it. Courts are also now free to interpret the TCPA independently of FCC guidance following the McLaughlin v. McKesson ruling, which means compliance requirements can vary more by state and jurisdiction than before. On top of that, Robocall Mitigation Database filings now require annual recertification, with steeper penalties for inaccurate records.

3. How long do I need to keep TCPA consent records?

At minimum, keep consent records for as long as the TCPA’s statute of limitations runs ( up to four years for most claims). In practice, most compliance teams retain records for five to six years to account for related state laws and to have a strong defense ready if a dispute surfaces well after the fact. TrustedForm certificates can be stored for up to five years, giving you an audit-ready record without manual tracking.

4. What’s the difference between TCPA guidelines for SMS vs. phone calls?

Both require prior express written consent and honor the same 8 a.m.–9 p.m. calling window, but the mechanics differ. SMS compliance centers on opt-out keywords like “STOP” built into every message and monitoring for freeform opt-out phrases, while phone call compliance focuses on autodialer and prerecorded-message rules, DNC scrubbing, and — as of the FCC’s AI guidance, treating AI-generated voice calls the same as traditional robocalls. TCPA guidelines for text messages go into more detail on the SMS-specific requirements.

Final thoughts

In today’s regulatory environment, compliance is not optional—it’s a business necessity. The TCPA guidelines 2025 are more detailed and enforced than ever before, particularly when it comes to SMS marketing and AI-powered outreach. By following FCC TCPA guidelines, documenting consent, and using tools like TrustedForm, your business can stay compliant and build consumer trust.

Getting started with TCPA compliance may feel daunting, but a few thoughtful steps can protect your brand from lawsuits, fines, and reputational damage. And in the process, you’ll create a better experience for your customers—one based on consent, transparency, and trust.

DISCLAIMER: This page and all related links are provided for general informational and educational purposes only and are not legal advice. ActiveProspect does not warrant or guarantee this information will provide you with legal protection or compliance. Please consult with your legal counsel for legal and compliance advice. You are responsible for using any ActiveProspect Services in a legally compliant manner pursuant to ActiveProspect’s Terms of Service. Any quotes contained herein belong to the person(s) quoted and do not necessarily represent the views and/or opinions of ActiveProspect.

Stay in the loop! Subscribe to the recAP email list to get our latest updates and insights.