
TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros
What are the legal restrictions on texting customers?
Learn the legal restrictions on texting customers under TCPA rules, including consent requirements, opt-out compliance, and how to avoid $500–$1,500 per...

Key Facts
- A single unlawful marketing text can cost $500 — and $1,500 if the violation is knowing, according to BCLP legal analysis.
- The FCC's 2024 rule extended National Do-Not-Call Registry protections to text messages effective March 26, 2024, per the official Federal Register publication.
- Since April 11, 2025, businesses must honor opt-out requests within 10 business days and accept them in any reasonable manner, per new FCC rules.
- After an opt-out, only one clarification message is allowed — sent within five minutes, with zero marketing content, per BCLP.
- Courts have held sellers vicariously liable for texts sent by lead generators, even when the seller never sent the message, according to BCLP.
- SMS consent must be obtained separately from email opt-ins and can never be required as a condition of purchase, per Klaviyo's compliance guidance.
- Because the TCPA carries a four-year statute of limitations, experts advise retaining consent and opt-out records for at least four years, per BCLP.
Why Texting Customers Without TCPA Compliance Is a $1,500-Per-Text Risk
A single marketing text can cost your business $500 — and if a court decides you knew better, that number triples to $1,500 per message. Multiply that across a campaign of thousands, and texting without TCPA compliance becomes an existential financial risk, not a line item.
The regulatory stakes rose sharply in 2024. The FCC's rule targeting unlawful text messages, effective March 26, 2024, extended National Do-Not-Call Registry protections to SMS and closed long-standing lead generator loopholes, as detailed in the official Federal Register publication. The rule also requires comparison shopping websites to obtain consumer consent one seller at a time, directly targeting the practice of reselling consent beyond its original scope.
Here's the part most businesses miss: the expensive lawsuits rarely come from bad actors. According to compliance experts at ActiveProspect, the most expensive TCPA damages come from operational failures, not malicious intent. As they put it, "'Compliant' isn't a claim, it's a record."
The most common liability triggers include:
- Unclear disclosures — consent language that doesn't identify the seller or specify contact methods
- Missing documentation — no per-lead proof of what the consumer agreed to, and when
- Misaligned expectations between lead buyer and lead seller
- Operational gaps in how leads are generated, sold, and worked
The risk compounds through vicarious liability. Legal analysis from BCLP notes that courts have held sellers liable for texts sent by lead generators and downstream actors — even when the seller never placed the call or sent the message themselves. If your lead source can't show the actual web form a consumer filled out, you inherit their compliance failures.
That's why documentation standards matter more than good intentions. BCLP recommends retaining consent records and opt-out documentation for at least four years, aligned with the TCPA statute of limitations. Every lead should carry a consent trail: the disclosure text, timestamp, IP address, and named contacting party.
This is exactly why GrowthPros attaches a consent record to every lead it delivers — because when a plaintiff's attorney comes asking, "trust us" is not a defense. Businesses that buy leads should demand the same from every source: traffic transparency, seller identity disclosure, and per-lead proof of consent. The alternative is betting your balance sheet on someone else's paperwork.
The Consent Rules That Decide Whether Your Texts Are Legal
Every marketing text you send lives or dies on one question: can you prove the customer said yes — in writing — before you hit send? Under the TCPA, that proof is the difference between a compliant campaign and statutory damages of $500 per violation, or $1,500 for knowing violations, according to legal analysis from BCLP.
Marketing texts require prior express written consent — not a checkbox buried in terms and conditions, but a clear, documented agreement. Consent language must identify the seller, specify the contact methods (calls, texts, prerecorded or AI voice), and answer exactly what the consumer agreed to and when, as ActiveProspect's compliance framework explains.
Two rules trip up even careful marketers. First, SMS consent must be obtained separately from email opt-ins — a customer who agreed to emails has not agreed to texts. Second, per Klaviyo's compliance guidance, SMS consent can never be required as a condition of purchase or account creation. It must always be optional.
The FCC's 2024 rule requires comparison shopping websites to obtain consumer consent one seller at a time, closing the lead generator loophole that allowed consent to be resold far beyond its original scope, per the Federal Register publication. However, the 11th Circuit vacated the rule in January 2025, leaving its status contested and the landscape unsettled, as BCLP notes.
Prudent businesses treat one-to-one consent as the operating standard regardless of the litigation outcome. That's why GrowthPros builds the FCC's one-to-one direction into every lead from day one rather than waiting for the courts to settle it.
As ActiveProspect puts it, "compliant" isn't a claim — it's a record. The most expensive TCPA damages come from unclear disclosures, missing documentation, and operational gaps, not malicious intent. When you buy leads, demand per-lead proof rather than "trust us" assurances. Every lead should carry:
- The exact disclosure text the consumer saw
- A timestamp showing when consent was given
- The IP address captured at the point of consent
- The named contacting party the consumer agreed to hear from
Courts have held that sellers can be vicariously liable for the actions of downstream actors even when the seller never sent the text themselves, per BCLP's lead generation analysis. Retain all consent documentation for at least four years to align with the TCPA statute of limitations. Your consent trail isn't paperwork — it's your defense.
Want leads that arrive with their consent trail already attached and followed up inside five minutes? Book your free 15-minute qualification call — honest about fit, no commitment required.
Opt-Out Compliance After April 11, 2025: The New Rules Most Businesses Miss
Most businesses think opt-out compliance means a customer texts "STOP" and the messages stop. Since April 11, 2025, that assumption can cost you $500 per violation — or $1,500 if the violation is knowing, according to legal analysis from BCLP.
The FCC's new Opt-Out Rule fundamentally changes how consent revocation works. Consumers can now opt out "in any reasonable manner" — not just by texting a keyword like STOP. If a customer replies "please don't text me anymore," types "unsubscribe," or even tells a rep on a call, that counts. Businesses must honor the request within 10 business days of receipt.
There's one narrow exception. You may send a single clarification message, but only within five minutes of the revocation request, and it must contain zero marketing content. Anything promotional in that message — or a second follow-up — converts a routine opt-out into a statutory damages claim of $500 to $1,500 per violation, per class member.
For teams running lead follow-up, this creates real operational risk. A sales rep who doesn't recognize a soft opt-out ("take me off your list, thanks") can trigger liability the business never sees coming. BCLP recommends inventorying all communication channels and training staff across departments to spot revocation requests wherever they arrive.
The second rule most businesses miss: documentation retention. Because the TCPA carries a four-year statute of limitations, experts advise retaining opt-out records and consent documentation for at least four years. As ActiveProspect puts it, "compliant" isn't a claim, it's a record — and the most expensive TCPA damages come from missing documentation, not malicious intent.
To stay on the right side of the April 11, 2025 rules:
- Accept opt-outs in any reasonable manner — never require a specific keyword or channel.
- Process every revocation within 10 business days, ideally immediately and permanently.
- Limit post-revocation contact to one clarification message, within five minutes, with no marketing content.
- Retain all consent and opt-out records for at least four years to match the TCPA statute of limitations.
At GrowthPros, every lead we deliver carries a full consent trail — disclosure text, timestamp, IP address, and the named contacting party — and opt-outs are honored immediately and permanently across SMS, voice, and email. That documentation discipline isn't a nice-to-have; it's what stands between a routine text campaign and a class action.
Exclusive, consent-recorded leads — followed up within minutes, opt-outs honored the moment they arrive. See how it works.
How to Audit Your Lead Sources and Build a Defensible Texting Program
How to Audit Your Lead Sources and Build a Defensible Texting Program
Protecting your business from TCPA liability starts long before you hit send on a text message—it begins with how you acquire and validate your leads. With statutory damages reaching $500 per violation and up to $1,500 for knowing infractions, every unsolicited text poses a serious financial risk, especially when scaled across campaigns. The foundation of a defensible texting program lies in rigorous lead source auditing and ironclad consent documentation that can withstand regulatory scrutiny.
When purchasing leads, demand full transparency: insist on traffic source visibility, verified seller identity, and per-lead proof of consent rather than accepting vague assurances. As compliance experts emphasize, lead generators must be able to demonstrate consent quality because that’s what regulators and plaintiffs examine when issues arise. Avoid vendors who cannot show the actual web form disclosures or provide consistent, auditable consent records for each lead—this lack of documentation is a primary source of TCPA exposure. Strengthen your contracts with TCPA warranties, indemnity provisions, and explicit audit rights to shift risk appropriately and ensure accountability down the chain.
Implement periodic lead audits to verify ongoing compliance, train your team to recognize opt-out requests in any reasonable manner—not just “STOP” keywords—and maintain a clear inventory of all communication channels used for outreach. Under the FCC’s new Opt-Out Rule effective April 11, 2025, businesses must honor revocation requests within 10 business days and may send only one clarification message within five minutes of receiving an opt-out. GrowthPros supports this process by delivering DNC-scrubbed, consent-recorded leads with full audit trails attached—including disclosure text, timestamp, IP address, and the named contacting party—so every lead carries its compliance pedigree from origin to outreach. This approach transforms consent from a claim into a defensible record, reducing vulnerability to costly litigation.
Frequently Asked Questions
How much can a single illegal text message cost my business?
Under the TCPA, each unlawful text can cost $500 in statutory damages, and that jumps to $1,500 per message if the court finds the violation was knowing, according to legal analysis from BCLP. Multiply that across a campaign of thousands of texts and a compliance mistake becomes an existential financial risk.
What kind of consent do I need before sending marketing texts?
Marketing texts require prior express written consent — not a checkbox buried in your terms and conditions. The consent language must identify the seller, specify contact methods like calls, texts, or AI voice, and document exactly what the consumer agreed to and when, per ActiveProspect's compliance framework. Also note that SMS consent must be obtained separately from email opt-ins and can never be required as a condition of purchase.
Does the Do-Not-Call Registry apply to text messages now?
Yes. The FCC's rule effective March 26, 2024 extended National Do-Not-Call Registry protections to SMS and closed long-standing lead generator loopholes, as detailed in the official Federal Register publication. The rule also requires comparison shopping websites to obtain consumer consent one seller at a time, though the 11th Circuit vacated that provision in January 2025, leaving its status contested.
Can I get sued for texts sent by a lead generator I bought leads from?
Yes — courts have held sellers vicariously liable for texts sent by lead generators and downstream actors even when the seller never sent the message themselves, according to BCLP's lead generation analysis. If your lead source can't show the actual web form a consumer filled out, you inherit their compliance failures.
Do customers have to text 'STOP' for an opt-out to count?
No. Since the FCC's Opt-Out Rule took effect April 11, 2025, consumers can opt out in any reasonable manner — a reply like 'please don't text me anymore,' typing 'unsubscribe,' or even telling a rep on a call all count, and you must honor the request within 10 business days, per BCLP's analysis. You may send only one clarification message within five minutes of the request, and it must contain zero marketing content.
How long do I need to keep consent records for text marketing?
Legal experts recommend retaining consent and opt-out documentation for at least four years to align with the TCPA statute of limitations. Each lead should carry a consent trail — the exact disclosure text, timestamp, IP address, and named contacting party — because as ActiveProspect puts it, 'compliant' isn't a claim, it's a record. That's why GrowthPros attaches a full consent record to every lead it delivers.
Text Legally, Text Profitably: Your Next Move
The rules for texting customers come down to one principle: proof beats promises. With statutory damages of $500 per violation — up to $1,500 for knowing violations, per BCLP's legal analysis — the businesses that stay safe are the ones that can show what the consumer agreed to, when, and on what form. That means prior express written consent for every marketing text, opt-outs honored in any reasonable manner within 10 business days under the April 11, 2025 rules, and consent records retained for at least four years. Your next steps: audit your lead sources for per-lead consent documentation, train your team to recognize soft opt-outs, and inventory every channel you use for outreach. If a vendor can't show you the actual disclosure a consumer saw, walk away. GrowthPros delivers every lead with its consent trail already attached — disclosure text, timestamp, IP address, and named contacting party — so compliance travels with the lead from origin to outreach. Want leads that arrive defensible and get followed up inside five minutes? Book your free 15-minute qualification call — honest about fit, no commitment required.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.