The Telephone Consumer Protection Act (TCPA) is a US federal law that restricts certain calls and text messages and gives consumers rights against unwanted telemarketing and automated communications. For marketers, the practical TCPA rulebook is not one sentence. It is the statute together with FCC regulations, FCC orders, court decisions, and a body of fact-specific interpretation.
TCPA- TCPA
- The TCPA is a framework, not a universal “marketing text law” slogan
- The 2023 “one-to-one” restriction was vacated
- Revocation rules changed, but not all at once
- The 2026 waiver matters
- Quiet hours and do-not-call concepts
- TCPA, CTIA and carrier policy are different things
- What a messaging platform should actually do
- Preserve consent evidence
- Preserve revocation evidence
- Separate candidate audience from send eligibility
- Recheck before dispatch
- Keep policy sources explicit
- Telemarketing, informational purpose and technology should not be flattened
- Do-not-call and consent are related but not identical
- What the 2025 court decision did not do
- Build a rule-source registry
- Product controls should expose facts, not pretend to issue legal conclusions
- Complaint reconstruction is a first-class operational capability
- Maintenance rule for a volatile page
- What does this page teach beyond a generic glossary definition?
- Worked example
- What TCPA requires
- A practical TCPA rollout
- What passes and what does not
TCPA
The most important editorial discipline is to avoid turning every SMS best practice into “the TCPA requires this.” Some requirements come from FCC rules implementing the TCPA. Others come from state law, CTIA guidance, carriers or messaging providers.
The TCPA is a framework, not a universal “marketing text law” slogan
Modern SMS programs can implicate several TCPA concepts:
- consent for certain automated or prerecorded/artificial-voice communications
- a higher prior express written consent standard for covered advertising or telemarketing communications
- company-specific do-not-call obligations
- time-of-day restrictions for telephone solicitations
- rules for honoring revocation of consent
- identification and opt-out mechanisms in specified contexts
Whether a particular message violates the TCPA depends on facts such as the communication’s purpose, the technology used, the number contacted and the applicable regulatory provision. A glossary should teach the structure, not pretend one checkbox is a universal legal safe harbor.
The 2023 “one-to-one” restriction was vacated
This is the most important stale-advice trap for 2026. In December 2023, the FCC adopted an additional consent restriction designed to require one seller at a time and a logical/topical relationship between the consent and the interaction that generated it. Many compliance articles written in 2024 treated that rule as the coming baseline.
On January 24, 2025, the Eleventh Circuit vacated that portion of the FCC order in Insurance Marketing Coalition Ltd. v. FCC. The FCC had postponed its effective date pending the case, and later made conforming changes after the court decision. As of September 2026, the vacated one-to-one restriction should not be presented as a current FCC requirement.
The underlying prior-express-written-consent definition remains. The court decision also does not invalidate separate state law, consumer-protection rules, contractual restrictions, carrier standards or provider lead-generation policies.
The vacated rule and the current gates are two different things
- Dec 2023FCC adopts one-to-one restrictionAn additional consent restriction
- Jan 24 2025Eleventh Circuit vacates itInsurance Marketing Coalition v. FCC
- Apr 11 20252024 revocation amendments applicableReasonable-method revocation, 10 business days
- 2026Waiver extendedDelayed cross-category revocation rule: a separate issue
- Jan 31 2027Current waiver end date
What a send system checks today, independent of that history:
- 1Message purpose + technology
- 2Consent evidence
- 3Revocation / suppression current
- 4Timing / do-not-call
- 5Provider / carrier eligibleNot TCPA law, but still a gate
- OutcomeSEND
Revocation rules changed, but not all at once
The FCC separately strengthened its consent-revocation rules in 2024. The core current model includes these ideas:
- a consumer can revoke covered consent by any reasonable method that clearly expresses a desire to stop
- specified reply words such as STOP, QUIT, END, REVOKE, OPT OUT, CANCEL and UNSUBSCRIBE are recognized as standard methods for text replies
- a caller/texter cannot force consumers to use only one designated revocation channel when another method is reasonable
- covered revocation and company-specific do-not-call requests must be honored within a reasonable time, no more than 10 business days
- a one-time confirmation text can be sent within the rule’s constraints
Compliance with specified portions of those amended rules became required on April 11, 2025.
The 2026 waiver matters
One portion of the FCC’s revocation framework concerns the extent to which a revocation for one category of robocalls/robotexts must be treated as revoking consent for all categories from that caller. The FCC has extended a waiver of the delayed requirement through January 31, 2027. This is separate from the vacated 2023 one-to-one consent restriction. A current page should therefore distinguish:
- consent formation: what permission is needed before the communication
- the vacated one-to-one rule: a 2023 additional restriction that is not current law
- revocation mechanics: how consumers withdraw covered consent
- the current waiver: a delayed part of the cross-category revocation implementation
Quiet hours and do-not-call concepts
The FCC’s rules include a federal restriction against telephone solicitation to a residential subscriber before 8:00 a.m. or after 9:00 p.m. local time at the called party’s location, alongside company-specific do-not-call procedures.
Do not interpret that federal window as a complete nationwide marketing-SMS schedule. State laws can impose additional or different telemarketing restrictions. Provider and carrier rules may be stricter. A messaging platform should be able to apply recipient-local policy rather than hard-code a single global schedule.
TCPA, CTIA and carrier policy are different things
A useful compliance document labels its source. A merchant can comply with one layer and still fail another.
| Option | Source | What it is | Example consequence |
|---|---|---|---|
| TCPA statute | TCPA statute | Federal law enacted by Congress | Statutory/private-enforcement exposure in covered circumstances |
| FCC rules/orders | FCC rules/orders | Federal regulation and agency interpretation | Regulatory obligations implementing the TCPA |
| Court decisions | Court decisions | Judicial interpretation/review | Can uphold, narrow or vacate agency rules |
| State law | State law | Separate state statutes/regulations | Additional or different obligations |
| CTIA guidance | CTIA guidance | Industry principles/best practices | Ecosystem expectations; not itself federal statute |
| Carrier/provider policy | Carrier/provider policy | Network/account terms | Registration rejection, blocking, filtering or account enforcement |
What a messaging platform should actually do
A durable system needs more than a consented column.
Preserve consent evidence
Store the permission event, disclosure version, source, timestamp, brand, number and scope.
Preserve revocation evidence
Keep the inbound request or preference event, its normalized interpretation, effective scope and time.
Separate candidate audience from send eligibility
Segmentation answers “who is relevant?” Permission, suppression, quiet hours and route eligibility answer “who can receive this message now?”
Recheck before dispatch
A customer can revoke consent after a campaign is queued. The worker should re-evaluate current suppression close to provider submission.
Keep policy sources explicit
If a rule is a provider requirement, call it a provider requirement. If it comes from a state mini-TCPA, do not cite CTIA. This makes future updates far easier.
Telemarketing, informational purpose and technology should not be flattened
The TCPA and FCC rules apply different standards depending on the communication and technology. A marketing platform should classify at least the purpose of the message and the mechanism used to deliver it instead of applying one undifferentiated “TCPA yes/no” label to every outbound contact. For product design, this means keeping structured metadata such as:
- promotional/telemarketing versus non-promotional informational purpose
- channel and sender technology
- recipient number/type where relevant
- consent basis and evidence
- do-not-call/suppression state
- local-time policy
- provider/carrier route
This does not automate legal conclusions by itself. It preserves the facts a policy engine or legal rule needs.
What the 2025 court decision did not do
The one-to-one vacatur is frequently over-read. It did not:
- repeal the TCPA
- abolish the FCC’s existing prior-express-written-consent definition
- eliminate seller identification from that definition
- cancel the 2024 consent-revocation order
- preempt state telemarketing laws
- force carriers/providers to accept any lead-generation practice
It vacated the challenged Part III.D restrictions of the 2023 order. Keep the holding that narrow in product copy.
Build a rule-source registry
For a messaging SaaS, a practical way to avoid misinformation is to attach every compliance control to a source class and last-reviewed date. Example:
| Option | Control | Authority type | Maintainer |
|---|---|---|---|
| Prior express written consent disclosure | Prior express written consent disclosure | FCC regulation | legal/compliance |
| Reasonable opt-out parser | Reasonable opt-out parser | FCC rule + internal implementation | compliance/engineering |
| Toll-free verification evidence | Toll-free verification evidence | provider/ecosystem policy | messaging operations |
| Merchant-defined 9 a.m.-8 p.m. window | Merchant-defined 9 a.m.-8 p.m. window | merchant policy | merchant |
| State-specific restricted hours | State-specific restricted hours | state law | legal/compliance |
When a provider changes onboarding, you update the provider policy without pretending federal law changed. When a court vacates an FCC rule, you know exactly which controls and help text depend on that authority.
Product controls should expose facts, not pretend to issue legal conclusions
A SaaS platform can enforce clear product rules such as “this profile is suppressed” or “this route is not verified.” It should be much more careful with labels such as “TCPA compliant.” TCPA applicability can depend on facts outside the platform, including communication purpose, technology, how consent was collected, the relationship between the parties and other legal context. A better product exposes the inputs and the rule being applied: > Promotional SMS. Prior-express-written-consent record selected. No current opt-out. Recipient-local timing policy passed. Toll-free route verified. That is auditable and useful without turning a software status into a legal opinion.
Complaint reconstruction is a first-class operational capability
When a recipient disputes a message, the business should be able to reconstruct the chain without querying 5 disconnected systems. A useful complaint packet can link:
- the recipient/profile and normalized number
- the consent event and disclosure version relied on
- any later revocation or do-not-call event
- the campaign/workflow and message purpose
- the send-decision trace and local time
- the provider message identifier and sender route
- subsequent inbound replies, including opt-out handling
This record does not prove that every legal requirement was satisfied, but it preserves the evidence needed to investigate the actual facts. It also reveals systemic defects such as a queue that ignored a newer suppression event.
Maintenance rule for a volatile page
Treat this glossary entry as a dated legal-operations map, not evergreen copy. Re-review it whenever the FCC changes §64.1200, a controlling court materially changes the relevant interpretation, the current revocation waiver expires or is replaced, or OnVoard adds a new calling/texting mechanism that changes the factual analysis. The durable lesson is the separation of concepts. The exact regulatory edges still require freshness.
What does this page teach beyond a generic glossary definition?
It gives the reader the current legal timeline and a source-of-authority map. In particular, it prevents 2 common 2026 errors: treating the vacated 2023 one-to-one rule as current law, and conflating that vacatur with the separate FCC revocation rules and their current waiver.
> This educational page is not legal advice. Businesses should obtain current advice for their specific technologies, message purposes, jurisdictions and consent flows.
Worked example
A shopper enters a mobile number during checkout but does not join marketing texts. The store later wants to send an automated cart reminder.
- The fact that the message is “behavioral” does not answer the TCPA consent question. The system must know whether the store has the permission required for that marketing communication and whether the recipient has since opted out. It must also apply timing and provider-route rules
If the shopper later replies “please stop texting me,” the system should recognize the revocation intent even if the text is not exactly STOP, update suppression, and prevent a previously queued reminder from escaping after the revocation.
What TCPA requires
The FCC’s current rule defines prior express written consent as a written agreement, signed by the called party, that clearly authorizes a specified seller to deliver or cause delivery of advertisements or telemarketing messages using covered technology to the specified telephone number.
The disclosure must be clear and conspicuous and must explain that the person is not required to sign as a condition of purchasing property, goods or services. Electronic and digital forms of signature can qualify under the rule.
Operationally, this means a business should be able to reconstruct the agreement: who acted, which seller was named, which number was supplied, what disclosure was shown, what affirmative act/signature occurred, and when/where the event happened.
A practical TCPA rollout
One step.
- 01Send-decision evidenceFor high-risk automated channels, recording why a message was eligible can be as important as the audience definition. A compact decision trace might capture: > candidate because Started Checkout; promotional purpose; required consent record found; no current revocation; local time permitted; toll-free route approved; sent at 14:08. Or: > candidate because Started Checkout; recipient revoked SMS permission at 13:57; skipped at 14:08. This event-level trace makes compliance, support and engineering debugging converge on the same facts instead of recreating eligibility from today’s database state.
What passes and what does not
- It does not provide a 50-state telemarketing survey, decide whether a particular dialer is an ATDS, or give legal advice about a specific campaign. Those questions can depend on detailed facts and changing law
- It also does not substitute CTIA or provider policy for the legal analysis. Those layers are operationally important but should be named accurately
Every app on every plan. Connect your store and switch on the flows in an evening.