
TCPA and Telemarketing Rules · September 28, 2026 · GrowthPros
What is a TCPA violation?
Learn what counts as a TCPA violation, the $500–$1,500 per-call penalties, and how lead buyers can stay compliant with consent records and DNC scrubbing.

Key Facts
- TCPA statutory damages range from $500 to $1,500 per unauthorized call or text
- 200 non-compliant calls can expose a business to $100,000–$300,000 in damages from a single plaintiff
- 10,000 non-compliant texts could trigger up to $15 million in exposure if deemed willful
- 2,788 TCPA class action filings were recorded in 2024—a 67% surge from the previous year
- Average TCPA settlements now exceed $6.6 million
- FCC extended DNC Registry protections to marketing text messages in December 2023
- Businesses must honor opt-outs within 10 business days under the FCC's consent revocation rule effective April 11, 2025
Why TCPA Violations Are a Lead Buyer's Biggest Hidden Liability
TCPA violations are no longer just a regulatory footnote—they're a financial landmine for lead buyers. With statutory damages ranging from $500 to $1,500 per unauthorized call or text, even modest compliance gaps can snowball into massive liability. For example, 200 non-compliant calls expose a business to $100,000–$300,000 in damages from a single plaintiff, while 10,000 non-compliant texts could trigger up to $15 million in exposure if deemed willful. These figures aren't theoretical: in 2024 alone, 2,788 TCPA class action filings were recorded—a 67% surge from the previous year—with average settlements now exceeding $6.6 million. The core issue isn't the technology used to dial or text, but whether proper consent was obtained and honored at every step. For a lead buyer like GrowthPros, whose model hinges on delivering qualified, consent-recorded leads with AI-powered follow-up inside five minutes, this distinction is critical. Every lead must carry a verifiable consent trail—not just to meet compliance standards, but to prevent the kind of costly, reputation-damaging violations that are increasingly targeting businesses that purchase and act on lead data. Recent litigation trends show that failure to maintain granular consent records, scrub against the DNC registry, or honor opt-out requests within the required 10-business-day window are among the most common—and expensive—missteps. As regulatory scrutiny intensifies and plaintiffs' attorneys sharpen their focus on consent scope and validity, lead buyers who treat TCPA as a dialing issue rather than a consent problem are setting themselves up for avoidable, severe financial risk. The next section breaks down exactly what constitutes a TCPA violation—and how to build a compliance framework that protects your business while maintaining lead velocity. Understanding the nuances of consent requirements is the first step toward turning compliance from a liability into a competitive advantage.
The Six Actions That Constitute a TCPA Violation
Most TCPA violations don't come from rogue robocall operations — they come from ordinary businesses making calls and texts with consent paperwork that doesn't hold up. Michele Shuster of M&S Law Group notes that TCPA litigation typically turns on two questions: whether the consumer consented at all, and whether the call exceeded the scope of that consent. Here are the six actions that most commonly constitute a violation.
1. Calling or texting wireless numbers without prior express written consent. Under the TCPA, marketing calls or texts made to wireless numbers using an autodialer, artificial (AI) voice, or prerecorded voice are illegal without prior express written consent, as Honigman LLP explains. Since February 2024, AI-driven calls are classified in the same category as traditional robocalls, requiring consent before the call per Phonexa's analysis.
2. Prerecorded calls to landlines without consent. The same standard applies to landlines: any prerecorded-voice call without the required consent is a violation, according to M&S Law Group.
3. Calling numbers on the National DNC Registry. The FCC extended DNC Registry protections to marketing text messages in December 2023, per Cooley's analysis. Marketers can still contact DNC-listed consumers, but only with the consumer's prior express invitation or permission. The stakes are steep: the cost of not scrubbing can reach up to $43,792 per call, per one compliance guide.
4. Exceeding the scope of consent. The FCC requires that robocalls and robotexts be logically and topically related to the website where consent was obtained — consent given on a car loan comparison site doesn't authorize robotexts about loan consolidation, as Cooley highlights.
5. Failing to honor opt-outs within 10 business days. Under the FCC's consent revocation rule effective April 11, 2025, businesses must honor opt-outs within 10 business days, accept any reasonable revocation method, and treat keywords like STOP as automatic opt-outs, per compliance reporting.
6. Using invalid consent mechanisms. The FCC prohibits consent to share information with vague "partner companies" or "marketing partners," including lists buried in small print or behind hyperlinks — Cooley notes the FCC's position that "sharing lead information with a daisy-chain of 'partners' is not permitted."
Each violation carries statutory damages of $500 to $1,500 per call or text, and 200 non-compliant calls can mean $100,000–$300,000 in exposure from a single plaintiff, per industry data. That's why GrowthPros attaches a full consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead delivered, and scrubs lists against the DNC Registry before any outbound contact.
Want leads that arrive with their consent trail already attached? Book a 15-minute qualification call and see what compliant, speed-to-lead delivery looks like.
The One-to-One Consent Rollercoaster: What Changed in 2025
If you thought TCPA compliance would settle into a predictable rhythm in 2025, the courts and the FCC had other plans. In the span of a few weeks, a major consent rule was adopted, scheduled, and then struck down — three days before it ever took effect.
Here's the sequence. In December 2023, the FCC adopted a one-to-one consent rule requiring consumers to grant separate consent to each identified seller, closing what regulators called the "lead generator loophole." The rule was set to take effect after a 12-month transition period. Then, on January 24, 2025, the Eleventh Circuit vacated the rule entirely, finding the FCC had exceeded its statutory authority — just three days before its effective date, according to compliance industry reporting.
The vacatur restored the prior standard, meaning consumers can still grant consent to multiple sellers as long as the disclosure is clear. But don't mistake that for a compliance free-for-all. Several requirements from the 2023 rulemaking survive regardless of the court's decision:
- Logical and topical relatedness still applies. Consent obtained on a car loan comparison site doesn't authorize robotexts about loan consolidation — communications must match the context where consent was given.
- No daisy-chain disclosures. The FCC prohibits asking for consent to share information with vague "partner companies" or "marketing partners," whether buried in small print or hidden behind a hyperlink.
- DNC protections now cover marketing texts. Since December 2023, National Do-Not-Call Registry protections extend from voice calls to text messages, though marketers can still text DNC-listed consumers with prior express invitation or permission.
- AI-driven calls are robocalls. Since February 2024, calls made with AI-generated voices fall into the same category as traditional robocalls, requiring one-to-one consent before the call.
There's one more wrinkle that catches lead buyers off guard: even where the FCC rule was vacated, wireless carriers still enforce one-to-one opt-in for SMS campaigns. A business can follow the letter of the vacated rule and still find its text messaging blocked at the carrier level, as industry guidance notes.
The stakes of getting any of this wrong haven't softened. Statutory damages run $500 to $1,500 per call or text, and TCPA class action filings hit 2,788 in 2024 — a 67% increase over 2023 — with 507 more filed in Q1 2025 alone, per litigation tracking data.
This regulatory whiplash is exactly why GrowthPros builds every lead with a full consent record — disclosure text, timestamp, IP address, and the named contacting party attached before delivery. When the rules shift, the paper trail is what protects you.
How to Prevent TCPA Violations Before You Dial or Text
Preventing TCPA violations starts long before the first dial or text—it begins with how you capture and manage consent. Every lead must carry a documented consent record that includes the disclosure text, timestamp, IP address, and the named contacting party, creating an auditable trail that proves prior express written consent was obtained. This level of documentation is not just best practice—it’s a legal necessity given that statutory damages for unauthorized contact can reach $500 to $1,500 per call or text, with willful violations maxing out at the higher end of that range. For businesses buying or selling leads, skipping this step invites exposure that can quickly escalate into six- or seven-figure liability, especially when considering that 2,788 TCPA class action filings were recorded in 2024 alone, a 67% increase from the previous year.
Equally critical is scrubbing every number against the National Do-Not-Call Registry before any outbound contact. The cost of compliance is minimal—just $75 per area code, capped at $20,868 annually for full list access—yet the penalty for skipping this step can be catastrophic: up to $43,792 per unauthorized call. This stark contrast makes DNC scrubbing one of the highest-ROI investments in telemarketing compliance. GrowthPros builds this safeguard into its process by ensuring all leads—whether freshly sourced or reactivated from dormant lists—are DNC-scrubbed and consent-recorded before delivery, eliminating guesswork for clients who purchase leads as a product.
Honoring opt-outs must be immediate and permanent across all channels. Under the FCC’s consent revocation rule effective April 11, 2025, businesses have just 10 business days to process opt-out requests, and standardized keywords like STOP or QUIT must be treated as automatic opt-outs regardless of how they’re delivered. Finally, every communication must remain logically and topically tied to the original consent context—meaning a lead who opted in for auto insurance quotes cannot legally receive robotexts about mortgage refinancing. By embedding these practices into its lead delivery and AI follow-up system—where every lead receives voice, SMS, and email contact within five minutes—GrowthPros helps clients stay compliant while maximizing speed-to-lead advantages.
- Document consent for every lead: disclosure text, timestamp, IP, and named contacting party
- Scrub against the National DNC Registry before any outbound contact
- Honor opt-outs immediately and treat STOP/QUIT as automatic
- Keep all communications topically tied to the consent context
- Use AI follow-up within five minutes to maintain speed without sacrificing compliance
Buy Leads With the Paper Trail Attached — or Don't Buy Them
Here is the uncomfortable truth about cheap leads: the seller's TCPA problem becomes yours the moment you dial. When a lead arrives with no consent record attached, you have no proof the consumer ever agreed to be contacted — and under the TCPA, the caller bears the liability. Statutory damages run $500 to $1,500 per call or text, and TCPA class action filings hit 2,788 in 2024, a 67% jump over the prior year.
The math gets brutal fast. Per compliance analysis of lead-buyer exposure, 200 non-compliant calls from a single plaintiff can mean $100,000–$300,000 in statutory damages, and 10,000 non-compliant texts can create $5 million in base exposure — $15 million if willful. A "bargain" shared lead list without documentation is the most expensive purchase you'll ever make.
The FCC has also made clear that consent buried in fine print or behind vague "marketing partner" language doesn't count. Cooley's analysis of the FCC's lead generation rules notes the agency prohibits sharing lead information with a "daisy-chain of 'partners,'" and consent must be logically and topically related to where it was given.
So how do you vet a lead vendor? Ask for the consent trail on every single lead — and walk away if they can't produce it:
- The exact disclosure text the consumer saw before consenting
- A timestamp and IP address proving when and where consent occurred
- The named party authorized to contact them
- Proof the list was scrubbed against the National DNC Registry before delivery
The same logic applies to reactivation campaigns. Reviving dormant leads only works on pre-existing, opted-in relationships — never cold lists. As M&S Law Group's Michele Shuster explains, TCPA litigation often turns on whether the consumer consented at all and whether the contact exceeded the scope of that consent. A list you bought last year is not a relationship; a list of customers who opted in and went quiet is.
That's why GrowthPros attaches a consent record — disclosure text, timestamp, IP, and named contacting party — to every lead delivered, and runs reactivation only on opted-in databases clients already own, DNC-scrubbed before any outbound contact. Compliance isn't a feature of a good lead. It's the definition of one.
If you're buying leads by niche or sitting on a dormant opted-in list worth reviving, book the 15-minute qualification call. It's free, it commits you to nothing, and we'll be straight about whether our exclusive and capped-shared leads fit your niche and budget.
Exclusive leads by niche, followed up in minutes — including the leads you already paid for.
Frequently Asked Questions
What counts as a TCPA violation?
The most common TCPA violations are calling or texting wireless numbers without prior express written consent, making prerecorded calls to landlines without consent, contacting numbers on the National DNC Registry, exceeding the scope of consent, failing to honor opt-outs within 10 business days, and using invalid consent mechanisms like vague "marketing partner" disclosures. According to Michele Shuster of M&S Law Group, most litigation turns on two questions: whether the consumer consented at all, and whether the call exceeded the scope of that consent.
How much can a TCPA violation actually cost my business?
Statutory damages run $500 to $1,500 per call or text, with willful violations at the higher end. That means 200 non-compliant calls can mean $100,000–$300,000 in exposure from a single plaintiff, and 10,000 non-compliant texts could trigger up to $15 million if deemed willful. Average TCPA class action settlements now exceed $6.6 million.
Did the FCC's one-to-one consent rule get thrown out?
Yes — on January 24, 2025, the Eleventh Circuit vacated the FCC's one-to-one consent rule just three days before its effective date, finding the FCC exceeded its statutory authority. Consumers can still consent to multiple sellers if the disclosure is clear, but requirements like logical/topical relatedness, the DNC text protections, and the ban on daisy-chain "partner" disclosures all still apply — and wireless carriers still enforce one-to-one opt-in for SMS campaigns.
If I buy leads from a vendor, am I the one who gets sued for TCPA violations?
Yes — the caller bears the liability. When a lead arrives with no consent record attached, you have no proof the consumer agreed to be contacted, and the seller's TCPA problem becomes yours the moment you dial. That's why every GrowthPros lead ships with the disclosure text, timestamp, IP address, and named contacting party attached, plus proof of DNC Registry scrubbing before delivery.
Do I have to stop texting someone on the Do-Not-Call Registry?
Since December 2023, DNC Registry protections extend to marketing text messages, not just voice calls. You can still contact DNC-listed consumers, but only with their prior express invitation or permission. Scrubbing costs just $75 per area code (capped at $20,868/year for full access) versus penalties of up to $43,792 per unauthorized call.
How fast do I have to honor an opt-out or STOP request?
Under the FCC's consent revocation rule effective April 11, 2025, you must honor opt-outs within 10 business days, accept any reasonable revocation method, and treat keywords like STOP or QUIT as automatic opt-outs. GrowthPros honors opt-outs immediately and permanently across SMS, voice, and email — well inside the 10-business-day window.
Compliance Isn't a Feature of a Good Lead — It's the Definition of One
TCPA violations aren't about the technology you use to dial or text — they're about whether you can prove consent, every single time. As we've covered, the six most common violations (missing written consent, DNC registry contacts, exceeding consent scope, ignoring opt-outs, and vague partner disclosures) all trace back to one root cause: leads without a paper trail. With statutory damages of $500 to $1,500 per call or text and 2,788 TCPA class action filings in 2024 alone, a cheap lead list without documentation is the most expensive purchase a business can make. Your next step is simple: audit your current lead sources and demand four things — disclosure text, timestamp, IP address, and the named contacting party. If a vendor can't produce them, walk away. GrowthPros attaches a full consent record to every lead delivered, DNC-scrubbed before any outbound contact, with AI follow-up inside five minutes. Compliance and speed-to-lead aren't competing priorities — they're the same product done right. Book the 15-minute qualification call, and we'll be straight about whether our leads fit your niche and budget.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.