What is the TCPA?
short answer
The TCPA is a US federal law restricting telemarketing calls, autodialed calls, prerecorded messages and text messages to consumers. Its teeth come from statutory damages: $500 per violation, trebled to $1,500 for wilful violations, with a private right of action. Because damages are per message, a single campaign to a modest list can produce enormous exposure — which is why proof of consent, not the mere assertion of it, is the operative issue.
Why the TCPA drives behavior more than most privacy laws
Most privacy statutes are enforced by regulators with limited capacity. The TCPA has a private right of action and statutory damages, which means any recipient can sue without proving actual harm, and damages are calculated per message.
- $500 per negligent violation
- $1,500 per wilful or knowing violation
- Multiplied by every call or text
A campaign of 10,000 messages with a consent defect is not a compliance annoyance. It is a mathematically serious event, and it is why lead buyers increasingly audit consent before they will pay for a lead at all.
What level of consent applies
The requirement depends on what you are sending and how:
| Situation | Consent needed |
|---|---|
| Marketing call or text using an autodialer or prerecorded voice | Prior express written consent |
| Informational, non-marketing call to a mobile using an autodialer | Prior express consent |
| Manually dialled, non-marketing call | Generally none under the TCPA |
Express written consent is the standard that matters commercially, and it has specific content requirements — a clear disclosure, identification of the seller, and a signature.
The one-to-one rule was vacated — get this right
In December 2023 the FCC adopted a rule that would have required consent to be given to one identified seller at a time, closing the practice of a single checkbox consenting to hundreds of “marketing partners.”
That rule was vacated by the Eleventh Circuit in January 2025 and is not in force. Anyone still selling compliance with the one-to-one rule as a current federal obligation is either out of date or hoping you are.
Two things remain true regardless:
- CMS’s separate requirement stands. Medicare marketing rules require each recipient to be identified. That is a CMS rule, unaffected by the FCC vacatur.
- Buyers ask anyway. Naming recipients has become a commercial expectation in lead purchasing, independent of any federal mandate. The rule went away; the market preference did not.
Where organizations actually get caught
Rarely on whether consent was obtained. Usually on whether it can be demonstrated afterwards:
- The consent record exists but the disclosure text has since changed, and nobody kept what was on the page that day
- The record shows a timestamp and an IP but not what the person actually agreed to
- The recipient list has grown since consent was given
- A revocation was received and not honored within a reasonable time
- The lead was bought, and the seller’s consent evidence cannot be produced
See proving consent for what a defensible record contains.
Revocation
Consumers may revoke consent through any reasonable means. You cannot require a specific method, and you cannot ignore revocation delivered through a channel you did not designate. Honor it promptly, and — critically — record that you honored it and when. Silence after a revocation is only evidence if you can show the revocation was received and acted on.
This is general information, not legal advice. TCPA case law moves; consult counsel for your specific situation.
people also ask this as
- What does the TCPA require?
- What are TCPA damages per violation?
- Do I need written consent to text customers?
- Is the one-to-one consent rule still in effect?
keep reading
Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.