← All Articles

TCPA Compliance Guide: How to Avoid $500–$1,500 SMS Marketing Fines

Every automated marketing text you send without the right consent is a separate violation with a statutory price tag on it. The rules are strict, but they’re also short — here is all of it, in one page.

$500
statutory damages per violating text
$1,500
per text when the violation is willful
8–9
sending window: 8 AM–9 PM, recipient’s time
5 yr
minimum retention for consent and DNC records
Bottom line up front
  • Get prior express written consent before automated marketing texts — no bought lists, no pre-checked boxes.
  • Honor STOP instantly, keep your own do-not-contact list, retain records five years.
  • Send only 8 AM–9 PM recipient time, and register your numbers for 10DLC.

What TCPA covers — including your B2B texts

The Telephone Consumer Protection Act governs automated texts, robocalls, and autodialed calls. If your messages go out through software — a CRM, a marketing platform, a follow-up tool like FollowUp — they’re covered.

The trap that catches sales teams: TCPA applies to B2B too. “I’m texting businesses, not consumers” doesn’t help when the number is a cell phone — and nearly every business contact’s number is. The solar rep texting homeowners, the property manager texting residents, the supplier texting contractors’ cells: all covered, all held to the same consent standard.

For automated marketing texts, consent must be written, documented, and specific (47 CFR 64.1200(f)(9)). Valid forms: a signed agreement, an online form with clear disclosure, a text-to-join keyword, or an unchecked-by-default checkbox at signup. Not valid: a number scraped from a website, an existing customer relationship, a business card, or “they never said not to.”

Compliant consent language looks like this:

“I agree to receive marketing text messages from [Company] at the number provided. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe at any time, HELP for help. View our Privacy Policy and Terms.”

In practice, consent lives where your paperwork already lives: a checkbox on the roofing estimate form, a line in the pest-control service agreement, a step in the solar proposal’s e-sign flow, a clause at lease signing for property managers. Add it once at the point where the customer is already saying yes, and the whole relationship is covered.

Record the timestamp, the form version, and exactly what the person saw. In a dispute, that record is the whole defense. One 2025 change worth knowing: the FCC’s one-to-one consent rule was struck down in January 2025 (Insurance Marketing Coalition v. FCC), but state laws can be stricter — per-seller consent remains the safe practice.

Opt-outs: STOP works by any reasonable means now

Under the FCC’s revocation rules (FCC 24-24, effective 2025), a person may revoke consent by any reasonable means — STOP, CANCEL, QUIT, and similar keywords count automatically — and you must honor it within 10 business days across all channels. Best practice is instant, automated suppression: keyword detected, contact flagged, one final confirmation sent.

Maintain your own do-not-contact list, apply it before every send, share it across the whole company, and keep it at least five years. For calling, also scrub against the national registry at donotcall.gov.

Disclosures: every message says who you are and how to leave

The first message to a new subscriber carries the full disclosure set; every message after identifies your business and leaves the exit open:

What compliant messages look like
Welcome to [Company]! You’ll get occasional updates and offers (up to 4/month). Msg&data rates may apply. Reply HELP for help, STOP to cancel.
✓ First message — identity, frequency, rates, HELP, STOP: all present
[Company]: You’re unsubscribed and won’t receive further messages. Reply START to rejoin anytime.
✓ One final opt-out confirmation is allowed — then silence
What gets you sued
Don’t send thisFINAL NOTICE: Your discount expires TONIGHT! Act now → bit.ly/xxxx
✗ No identity, no opt-out, pressure language, link shortener — a violation that also trips every carrier filter

Quiet hours: 8 AM–9 PM on the recipient’s clock

RECIPIENT’S LOCAL TIME 12 AM 8 AM — sending opens 9 PM — sending closes Weekends included. No urgency exception. A time-zone bug costs the statutory rate per message.

The window is based on the recipient’s time zone, applies every day of the week, and has no urgency exception — the roofer blasting storm leads at 7 AM while the hail is still on the lawn is the textbook violation. Schedule with a buffer — 9 AM to 8 PM — so an area-code edge case never becomes one either.

The five violations that actually happen

Texting a purchased list

Aged solar leads and storm-chaser roofing lists are the classic source. The vendor’s consent doesn’t transfer to you — every automated marketing text to that list is a separate statutory violation.

Pre-checked consent boxes

Consent must be an affirmative act. A box the user has to uncheck is not consent.

Borrowing email consent

Email opt-in and SMS opt-in are separate. “They subscribed to our newsletter” doesn’t authorize a single text.

Ignoring carrier rules

AT&T, T-Mobile, and Verizon enforce their own layer: unregistered traffic gets filtered or blocked regardless of consent. Register for A2P 10DLC.

Missing STOP replies

An opt-out that keeps receiving messages is the classic class-action fact pattern. Detect keywords automatically and suppress on the spot.

The pre-send checklist

  1. Consent documented? Written, specific, timestamped.
  2. Language compliant? Clear, separate from other terms, frequency and rates disclosed.
  3. DNC scrubbed? Every opt-out suppressed before this send.
  4. Disclosures in? Company name, STOP instructions.
  5. Quiet hours enforced? 8 AM–9 PM, recipient’s clock, buffer applied.
  6. Numbers registered? 10DLC campaign live before volume goes out.

If any box is unchecked, don’t send until it is.

What violations actually cost

TCPA has a private right of action: recipients can sue directly, at $500 per violating text in statutory damages and up to $1,500 when the violation is willful — no proof of harm required, and each message counts separately. Do the arithmetic on an ordinary list: 5,000 contacts texted twice without valid consent is 10,000 violations — $5 million in statutory exposure before willfulness triples it. That multiplication is why these cases arrive as class actions.

The headline settlements are not hypothetical: Papa John’s paid roughly $16 million over unconsented franchise text blasts, and Capital One’s TCPA class settlement ran $75.5 million. On top of the legal exposure, carriers block offending numbers — quietly ending the channel for your legitimate messages too.

State laws stack on top

TCPA is the floor, not the ceiling. Florida’s FTSA adds its own consent and timing rules, Texas and Oklahoma have their own telemarketing statutes, and California layers privacy rights on the data itself. The safe pattern is to follow the strictest law that touches your audience — the state-by-state texting rules map them, and the compliance glossary decodes PEWC, DNC, and 10DLC. If you use voicemail drops, check where ringless voicemail is legal before sending.

Getting compliant this week

  1. Pause automated sends until you can show consent for every contact on the list.
  2. Fix collection — unchecked boxes, full disclosure language, consent records stored with timestamps.
  3. Automate opt-outs — keyword detection, instant suppression, one confirmation message.
  4. Enforce the window — time-zone lookup on every number, sends held to 9 AM–8 PM.
  5. Register 10DLC — brand and campaign, before volume ramps.

Compliance done right is invisible: prospects just experience a company that asks first, shows up at reasonable hours, and stops when asked — which is exactly the company they buy from. FollowUp ships with this built in: consent tracking, automatic opt-out handling, quiet-hours enforcement, and an audit trail for every message.