Every automated marketing text you send without the right consent is a separate violation with a statutory price tag on it. The rules are strict, but they’re also short — here is all of it, in one page.
The Telephone Consumer Protection Act governs automated texts, robocalls, and autodialed calls. If your messages go out through software — a CRM, a marketing platform, a follow-up tool like FollowUp — they’re covered.
The trap that catches sales teams: TCPA applies to B2B too. “I’m texting businesses, not consumers” doesn’t help when the number is a cell phone — and nearly every business contact’s number is. The solar rep texting homeowners, the property manager texting residents, the supplier texting contractors’ cells: all covered, all held to the same consent standard.
For automated marketing texts, consent must be written, documented, and specific (47 CFR 64.1200(f)(9)). Valid forms: a signed agreement, an online form with clear disclosure, a text-to-join keyword, or an unchecked-by-default checkbox at signup. Not valid: a number scraped from a website, an existing customer relationship, a business card, or “they never said not to.”
Compliant consent language looks like this:
“I agree to receive marketing text messages from [Company] at the number provided. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe at any time, HELP for help. View our Privacy Policy and Terms.”
In practice, consent lives where your paperwork already lives: a checkbox on the roofing estimate form, a line in the pest-control service agreement, a step in the solar proposal’s e-sign flow, a clause at lease signing for property managers. Add it once at the point where the customer is already saying yes, and the whole relationship is covered.
Record the timestamp, the form version, and exactly what the person saw. In a dispute, that record is the whole defense. One 2025 change worth knowing: the FCC’s one-to-one consent rule was struck down in January 2025 (Insurance Marketing Coalition v. FCC), but state laws can be stricter — per-seller consent remains the safe practice.
Under the FCC’s revocation rules (FCC 24-24, effective 2025), a person may revoke consent by any reasonable means — STOP, CANCEL, QUIT, and similar keywords count automatically — and you must honor it within 10 business days across all channels. Best practice is instant, automated suppression: keyword detected, contact flagged, one final confirmation sent.
Maintain your own do-not-contact list, apply it before every send, share it across the whole company, and keep it at least five years. For calling, also scrub against the national registry at donotcall.gov.
The first message to a new subscriber carries the full disclosure set; every message after identifies your business and leaves the exit open:
The window is based on the recipient’s time zone, applies every day of the week, and has no urgency exception — the roofer blasting storm leads at 7 AM while the hail is still on the lawn is the textbook violation. Schedule with a buffer — 9 AM to 8 PM — so an area-code edge case never becomes one either.
Aged solar leads and storm-chaser roofing lists are the classic source. The vendor’s consent doesn’t transfer to you — every automated marketing text to that list is a separate statutory violation.
Consent must be an affirmative act. A box the user has to uncheck is not consent.
Email opt-in and SMS opt-in are separate. “They subscribed to our newsletter” doesn’t authorize a single text.
AT&T, T-Mobile, and Verizon enforce their own layer: unregistered traffic gets filtered or blocked regardless of consent. Register for A2P 10DLC.
An opt-out that keeps receiving messages is the classic class-action fact pattern. Detect keywords automatically and suppress on the spot.
If any box is unchecked, don’t send until it is.
TCPA has a private right of action: recipients can sue directly, at $500 per violating text in statutory damages and up to $1,500 when the violation is willful — no proof of harm required, and each message counts separately. Do the arithmetic on an ordinary list: 5,000 contacts texted twice without valid consent is 10,000 violations — $5 million in statutory exposure before willfulness triples it. That multiplication is why these cases arrive as class actions.
The headline settlements are not hypothetical: Papa John’s paid roughly $16 million over unconsented franchise text blasts, and Capital One’s TCPA class settlement ran $75.5 million. On top of the legal exposure, carriers block offending numbers — quietly ending the channel for your legitimate messages too.
TCPA is the floor, not the ceiling. Florida’s FTSA adds its own consent and timing rules, Texas and Oklahoma have their own telemarketing statutes, and California layers privacy rights on the data itself. The safe pattern is to follow the strictest law that touches your audience — the state-by-state texting rules map them, and the compliance glossary decodes PEWC, DNC, and 10DLC. If you use voicemail drops, check where ringless voicemail is legal before sending.
Compliance done right is invisible: prospects just experience a company that asks first, shows up at reasonable hours, and stops when asked — which is exactly the company they buy from. FollowUp ships with this built in: consent tracking, automatic opt-out handling, quiet-hours enforcement, and an audit trail for every message.