TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros

Is someone constantly texting you harassment?

Unsolicited marketing texts can cost $500–$1,500 each under TCPA rules. Learn consent, DNC scrubbing, and opt-out requirements to keep your outreach com...

Flat illustration of a smartphone overwhelmed by incoming message bubbles with a lime-green highlighted text, illustrating the legal cost of unsolicited marketing texts.

Key Facts

  • Legitimate domestic businesses—not scammers—are the primary targets of TCPA litigation
  • TCPA statutory damages range from $500 to $1,500 per violating text message
  • TCPA filings jumped 46.7% after the FCC's July 2015 Declaratory Ruling
  • Nearly 100,000 phone numbers are reassigned daily, making consent number-dependent
  • Consumers can revoke consent 'in any reasonable manner' effective April 11, 2025
  • Businesses must honor opt-out requests within 10 business days starting April 11, 2025
  • Landmark TCPA outcomes include a $925 million jury verdict in Wakefield v. ViSalus

Why Frequent Texting Can Trigger TCPA Liability

That barrage of texts from a business isn't just annoying — under federal law, each unsolicited message can carry a price tag of up to $1,500. The Telephone Consumer Protection Act (TCPA) turns what feels like everyday marketing spam into strict-liability territory, and the penalties compound fast.

The TCPA requires prior express written consent for autodialed marketing texts to cell phones. Consent must be seller-specific and "logically and topically" related to where it was obtained — as Cooley's telecom attorneys note, a consumer consenting on a car loan comparison site hasn't agreed to texts about loan consolidation. A vague, one-size-fits-all consent form doesn't protect the sender.

The stakes per message are substantial:

  • $500 in statutory damages per violating text as the standard baseline
  • Up to $1,500 per violation when the conduct is willful or knowing
  • Landmark outcomes include a $925 million jury verdict in Wakefield v. ViSalus and a $280 million Dish Network fine

Because the TCPA imposes strict liability, intent doesn't matter — a business that believed it had valid consent still pays if the documentation falls short, as compliance analyses consistently emphasize.

Here's the counterintuitive part: it's not scammers getting hammered in TCPA courtrooms. Research from the Institute for Legal Reform found that legitimate domestic companies — not unscrupulous telemarketers — are the primary targets of TCPA litigation. Scammers are hard to find and collect from; registered businesses with assets are not.

The numbers confirm the trend. Following the FCC's July 2015 Declaratory Ruling, TCPA filings jumped 46.7% — from 2,127 to 3,121 cases across comparable 17-month windows. The Institute describes well-intentioned companies facing "staggering, and potentially annihilating" statutory damages tied to technologies that didn't exist when the TCPA was enacted in 1991.

Once sued, businesses typically settle rather than risk an unpredictable jury, and many insurers exclude TCPA claims entirely, leaving companies to absorb defense costs themselves.

This is why documentation-heavy lead operations exist. GrowthPros, for example, attaches a consent record to every lead it delivers — disclosure text, timestamp, IP address, and the named contacting party — so buyers can verify consent provenance before the first text goes out. In a litigation landscape where legitimate businesses are the targets, that paper trail isn't bureaucracy. It's the difference between a compliant outreach program and a class action.

How GrowthPros Builds TCPA-Compliant Lead Follow-Up

Most TCPA lawsuits don't target scam operations — they target legitimate businesses whose follow-up systems cut corners. A study by the Institute for Legal Reform found that well-intentioned domestic companies, not fraudsters, are the primary defendants, facing statutory damages of $500 to $1,500 per violating text. That reality shapes how GrowthPros structures every part of its lead follow-up pipeline.

Consent is captured at the source, per seller. The FCC's January 2024 order requires "one-to-one consent" — a single checkbox can no longer authorize texts from a bundle of unknown sellers, and consent must be "logically and topically" related to the interaction where it was given, as Cooley's telecom team explains. Every lead delivered by GrowthPros therefore carries a consent record containing the disclosure text, timestamp, IP address, and the named contacting party — not a vague aggregator reference. That trail travels with the lead into the client's CRM and is retained to align with the TCPA's four-year statute of limitations.

Lists are scrubbed before every outreach wave. DNC Registry protections now extend to marketing texts, and with roughly 100,000 numbers reassigned daily, consent attaches to the person, not the number. DNC scrubbing runs before any outbound contact — including reactivation campaigns targeting pre-existing, opted-in relationships, never cold lists.

The compliance framework rests on four pillars:

  • Seller-specific consent capture with timestamp, IP, and disclosure records attached to each lead
  • DNC scrubbing before every campaign, including dead-lead reactivation sequences
  • Multi-channel opt-out ingestion — SMS, voice, email, and web — with suppression propagated across all channels
  • Separate marketing and informational message flows, so revocations trigger the correct scope of suppression

The April 11, 2025 Opt-Out Rule raises the bar further. Consumers can now revoke consent "in any reasonable manner" — a voicemail, an email, even a comment to a cashier — and businesses must honor it within 10 business days. Because revoking from a marketing message stops marketing only, while revoking from an informational message stops everything, message-type tagging isn't optional. GrowthPros' AI follow-up sequences tag every voice, SMS, and email touch accordingly, and opt-outs are honored immediately and permanently rather than at the regulatory deadline.

The result is speed without exposure: five-minute, multi-channel follow-up on leads whose consent trail stands up to scrutiny — because as compliance practitioners put it, avoiding TCPA liability comes down to one principle: document and respect consumer consent.

Practical Steps to Audit and Protect Your Texting Practices

Practical Steps to Audit and Protect Your Texting Practices

Regularly auditing your texting practices is essential to avoid costly TCPA violations that can reach $500–$1,500 per violating text. Start by verifying that every lead in your system includes a complete consent record with disclosure text, timestamp, IP address, and the named contacting party, as required for seller-specific consent under FCC rules. These records must be retained for at least four years to align with the TCPA statute of limitations, ensuring you can defend against claims long after initial contact.

Next, confirm that your DNC scrubbing process runs before every outbound campaign, including reactivation efforts, since nearly 100,000 numbers are reassigned daily and consent attaches to the person, not the number. Test your opt-out honoring mechanism across SMS, voice, and email channels to ensure revocations are processed within 10 business days, regardless of how the consumer communicates their request—whether via "STOP," email, voicemail, or in-person communication. Finally, distinguish between marketing and informational messages in your workflows, as opting out of informational content requires stopping all messages, while opting out of marketing only halts promotional outreach. GrowthPros builds these safeguards into every lead delivery, ensuring compliance is embedded in the process rather than added as an afterthought. To see how these protections work in practice, book a qualification call or submit the get-started funnel to review your current setup.

Frequently Asked Questions

How many texts before it legally counts as harassment?
There's no specific frequency threshold — what matters under the TCPA is whether the sender had your prior express written consent for autodialed marketing texts to your cell phone. Without valid consent, each unsolicited text can carry statutory damages of $500, or up to $1,500 if the violation was willful or knowing.
How much can a business be fined for texting without permission?
The TCPA imposes $500 per violating text as a baseline and up to $1,500 per violation for willful or knowing conduct — and because it's strict liability, intent doesn't matter. Landmark outcomes include a $925 million jury verdict in Wakefield v. ViSalus and a $280 million Dish Network fine.
Can I stop marketing texts by replying 'STOP' or just telling the company?
Yes. Under the FCC's Opt-Out Rule effective April 11, 2025, consumers can revoke consent 'in any reasonable manner' — a voicemail, email, or even a comment to a cashier — and businesses must honor it within 10 business days, so they can't force you to use a single opt-out method.
Who actually gets sued under the TCPA — scammers or real companies?
Legitimate businesses, not scammers. Research from the Institute for Legal Reform found that well-intentioned domestic companies are the primary targets of TCPA litigation, facing 'staggering, and potentially annihilating' statutory damages — scammers are simply hard to find and collect from.
I gave consent on one website — can other companies text me about different things?
No. The FCC's one-to-one consent rules require consent to be seller-specific and 'logically and topically' related to where it was obtained — a consumer consenting on a car loan comparison site hasn't agreed to texts about loan consolidation. A vague, one-size-fits-all consent form doesn't protect the sender.
How does a lead generation company stay TCPA-compliant when texting leads?
By building compliance into the pipeline: GrowthPros attaches a consent record to every lead — disclosure text, timestamp, IP address, and named contacting party — DNC-scrubs lists before every campaign, and honors opt-outs immediately across SMS, voice, and email. Since roughly 100,000 numbers are reassigned daily, consent must be verified against the person, not just the number.

The Paper Trail Is the Profit Trail

The uncomfortable truth about TCPA liability is that it rarely catches the villains — it catches legitimate businesses whose consent records couldn't withstand scrutiny. With statutory damages of $500 to $1,500 per text and litigation filings up 46.7% after the FCC's 2015 ruling, the gap between "we thought we had consent" and "we can prove it" is where companies get destroyed. Your audit checklist is straightforward: seller-specific consent documentation with timestamps and IP addresses, DNC scrubbing before every campaign wave, opt-out honoring across every channel within 10 business days, and marketing-versus-informational message tagging. GrowthPros builds these safeguards into every lead it delivers — consent trail attached, DNC-scrubbed, followed up inside five minutes — so compliance isn't a project your team tackles after the fact. If you'd like a second set of eyes on your current texting practices, book a 15-minute qualification call or submit the get-started funnel. It's free, honest about fit, and commits you to nothing.

This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.

Start

More booked calls. Not more form fills.

Tell us your niche and your goal. We will show you realistic volume, exclusivity options, and what follow-up looks like on a live call — no pressure, no 40-page deck.