Answer

What is TCPA (Telephone Consumer Protection Act)?

TCPA sits at the intersection of consumer-privacy law and sales operations. Every outbound call, text, and automated voicemail your team sends is covered, which is why consent capture and suppression are first-class features in a modern CRM, not a bolt-on.

Short answer

The TCPA is a 1991 United States federal law that regulates telemarketing calls, auto-dialed calls, prerecorded voice messages, text messages, and unsolicited faxes. It requires prior express consent for most autodialed or texted marketing, prior express written consent for prerecorded marketing, and compliance with the National Do Not Call Registry. Violations carry statutory damages per message and significant class-action exposure.

Key points

What matters most.

The six ideas every sales, marketing, and RevOps leader should understand before running an outbound phone or SMS program, and the one that drives most of the class-action risk.

The law

A 1991 federal statute, actively updated.

Congress passed the TCPA in 1991 to curb unsolicited telemarketing. The Federal Communications Commission writes the implementing rules and continues to update them, including meaningful 2024 rulings on consent definitions and the right to revoke. The statute itself is old; the enforcement environment is not.

What it covers

Calls, texts, prerecorded voice, and faxes.

TCPA governs voice calls placed with an autodialer, prerecorded or artificial-voice messages, SMS and MMS marketing, and unsolicited fax advertisements. Business-to-business, business-to-consumer, and nonprofit outreach are each handled a little differently, but the core consent framework applies across all four channels.

Consent

Prior express, with a higher bar for recorded.

Autodialed or texted marketing generally requires prior express consent. Prerecorded marketing to residential and wireless numbers generally requires prior express WRITTEN consent, including a clear disclosure and an affirmative signature or e-signature. Informational, transactional, and emergency messages often sit outside the written-consent requirement, but the facts matter.

Do Not Call

The National DNC Registry plus state lists.

The Federal Trade Commission maintains the National Do Not Call Registry. Sellers must scrub marketing calls against it and honor internal do-not-call requests. Many states (including Florida, Texas, Oklahoma, and others) run their own DNC registries with stricter rules, so a complete suppression program checks federal and state lists on every send.

Damages

Statutory damages per violation, times every message.

The TCPA provides statutory damages on a per-violation basis, with elevated damages available when a court finds a willful or knowing violation. One sloppy campaign to a few thousand numbers can multiply into exposure that threatens a company, which is why TCPA is the single biggest driver of consumer class actions against B2C marketers.

Private right of action

Consumers can sue; plaintiffs firms do.

The TCPA grants a private right of action, meaning any recipient can file suit without waiting for a regulator. Specialized plaintiffs firms monitor outbound dialing and texting at scale and file class actions aggressively. Settlements routinely reach the millions, and defense costs begin accruing the moment a complaint lands.

How TCPA works

The six pieces every outbound program must handle.

TCPA compliance is not one feature. It is a chain of six operational practices that have to work on every call and every text, every time. If any link breaks, the whole program is exposed, because the statute creates per-violation liability and a plaintiffs bar is already measuring. Below are the pieces of that chain and what each one actually means in day-to-day sales operations.

Consent capture

Prove the recipient opted in.

Every number on an outbound marketing list needs a documented opt-in: a web form submission, a checkbox on a lead-gen landing page, or a signed agreement. The record of consent (timestamp, source URL, exact disclosure text, IP address) is what a defendant produces in court. If you cannot show it, you did not have it.

Scope of consent

Match the ask to the message.

Consent is channel-specific and purpose-specific. A customer who agreed to appointment reminders did not agree to promotional texts. A B2C website visitor who ticked a sales-contact box did not agree to prerecorded voicemail drops. The message you send must stay inside the scope the recipient actually agreed to.

DNC scrubbing

Check federal and state lists on every send.

Before a marketing call or text goes out, the destination number should be checked against the National DNC Registry, state DNC registries that apply, and your internal company-specific do-not-call list. Scrub timing matters: a stale scrub from thirty days ago does not prove compliance for today.

Revocation

Honor opt-outs across every channel.

The 2024 FCC rulings clarified that consumers can revoke consent through any reasonable method (reply STOP, voicemail, email, web request) and the revocation applies broadly across the sender. Once a recipient opts out, every subsequent outbound marketing message to that number is a violation, so suppression has to be instantaneous and system-wide.

Time and manner rules

Calling windows, identification, and content.

TCPA and related FTC rules restrict marketing calls to allowed hours in the recipient's local time zone, require the caller to identify the seller and provide a callback number, and prohibit misleading caller ID. Text messages carry their own requirements for sender identification and opt-out instructions. These are not optional even when consent exists.

Recordkeeping

Keep the paper trail that proves it.

Consent records, scrubbed-list snapshots, suppression events, campaign logs, and complaint response history should all be retained for the full statute-of-limitations window. In TCPA litigation, the defendant with the better records usually settles faster and cheaper, and the one without them loses.

The common question

Does TCPA apply to B2B cold calling?

This is the question every outbound sales leader asks, and the honest answer is: more than you probably think. The TCPA's rules are not purely business-to-consumer. Wireless numbers (which cover most mobile phones and increasingly most business lines) sit squarely under the statute, and SMS to a mobile number is governed regardless of whether the recipient uses it for work or personal use.

Wireless numbers

Mobile is mobile, business or not.

TCPA restrictions on autodialed and prerecorded calls to wireless numbers apply even when the number is used for business purposes. A rep dialing from a power dialer into an executive's mobile line is on the same statutory footing as a B2C telemarketer calling the same device for a consumer product.

Autodialer definition

The equipment test matters.

TCPA restrictions on autodialing hinge on whether the system qualifies as an automatic telephone dialing system under current FCC and court interpretation. The definition has narrowed and widened over time (notably the 2021 Facebook v. Duguid Supreme Court decision), which is why compliant programs lean on documented consent instead of hoping the dialer fits an exception.

Manual dialing

A real human, one call at a time.

A rep hand-dialing a specific number from a researched account list is treated differently than a system firing calls from an uploaded list. Many compliant B2B programs lean on manual dialing for the first touch, add human-initiated flows for follow-up, and reserve automated sequences for recipients with explicit opt-in.

SMS to business numbers

Texting is where B2B gets caught.

Mass-texting a prospect list of mobile numbers scraped from LinkedIn or a lead-gen file is one of the fastest paths to a TCPA complaint, because consent almost never exists. The rules apply regardless of whether the recipient is a decision-maker, a buyer, or a target account. Sending without opt-in is the risk.

Prerecorded voicemail

Ringless voicemail is not a loophole.

The FCC has signaled that ringless voicemail drops are covered by the TCPA, meaning prerecorded voicemail delivered without ringing the phone is still subject to the written-consent requirement for marketing. The product category markets around this; the law does not care about the marketing.

The practical takeaway

Treat every outbound channel as regulated.

The sturdiest B2B outbound programs treat phone and SMS the same way marketing teams treat email: as a channel with real consent rules, real suppression discipline, and real recordkeeping. The programs that assume B2B means a free pass are the ones showing up in the plaintiffs-firm filings.

Operations

How a CRM makes TCPA compliance survivable.

TCPA is not a legal problem that can be solved by legal review alone. It is a systems problem, because the obligations attach to every single outbound message. A CRM that treats consent, suppression, and recordkeeping as first-class features turns compliance from a hopeful policy into a repeatable workflow. These are the operational pieces that have to exist somewhere, and the right place for them is next to the contact record itself.

Consent fields

Opt-in state lives on the contact.

Every contact record should carry structured consent fields: whether marketing calls are allowed, whether SMS is allowed, whether prerecorded voice is allowed, when consent was captured, where it came from, and the exact language the recipient saw. The CRM, not a spreadsheet, is the system of record for consent.

DNC checks

Scrub at send time, not at list time.

A compliant workflow scrubs the destination number against DNC lists at the moment of send, not when the list was uploaded a week earlier. A good CRM wires this into the outbound action itself, so a rep clicking call or send gets a block the moment the number should not be contacted.

Suppression propagation

One opt-out, every channel, immediately.

When a recipient replies STOP, uses a web unsubscribe, or asks a rep to be removed, that revocation needs to flow across every outbound channel inside the CRM in real time. Email suppression lists, SMS stop lists, and voice do-not-call lists should share state, not sit in separate silos that can be forgotten.

Cadence governance

Sequences respect consent, not just logic.

Sales cadences and sequences in the CRM should refuse to send to contacts without the right consent flag for the step's channel. A sequence that includes a prerecorded voicemail step should be unable to execute that step against a contact who has not provided written consent for prerecorded marketing.

Audit trail

Every send is a logged event.

Every outbound call, text, and voicemail should write a timestamped activity record showing who initiated the message, what number it went to, which consent evidence authorized it, and whether the DNC scrub passed. In litigation, this is the evidence that decides whether a program was compliant or merely optimistic.

Admin controls

Templates, approvals, and policy enforcement.

A CRM admin should be able to block risky patterns at the template level: no prerecorded step without a written-consent flag, no SMS to a contact without an SMS opt-in, no outbound call outside the recipient's allowed hours. Guardrails at the platform level beat training reps to remember rules under quota pressure.

Run outbound with consent and suppression wired in.

Strkr treats consent, DNC checks, and suppression as first-class features on the contact record, so sales cadences respect opt-ins instead of hoping reps remember the rules. See how the sales cadences, SMS, and dialer features ship today.

People also ask

Related questions.

What does TCPA stand for?

TCPA stands for the Telephone Consumer Protection Act. It is a United States federal statute passed in 1991 and codified at 47 U.S.C. 227, with implementing regulations written and periodically updated by the Federal Communications Commission. The law regulates telemarketing calls, autodialed and prerecorded calls, text messages, and unsolicited faxes.

Does the TCPA cover text messages?

Yes. The FCC has long treated SMS and MMS messages sent to wireless numbers as calls under the TCPA. Marketing texts generally require prior express consent, and in most cases prior express written consent is the safer baseline. Transactional and informational texts that fit specific exceptions carry a lower bar, but the exceptions are narrow and fact-specific.

What is the National Do Not Call Registry?

The National Do Not Call Registry is a federal list of phone numbers that have asked not to receive telemarketing calls. It is operated by the Federal Trade Commission. Sellers making marketing calls must scrub against the registry on a recurring basis and honor requests to be added to internal company-specific do-not-call lists. Several states run additional DNC registries with their own rules.

What are the TCPA penalties for violations?

The TCPA provides statutory damages on a per-violation basis, with elevated damages available for willful or knowing violations. Because every unlawful call, text, or voicemail is a separate violation, exposure scales with volume. The combination of per-message damages, a private right of action, and class-action availability is what drives the large settlements that TCPA cases are known for.

What changed with the 2024 FCC TCPA rulings?

The FCC in 2023 and 2024 issued rulings that tightened consent definitions and clarified the right to revoke. Consent must be specific to the seller rather than funneled through lead-generation marketplaces, and consumers can revoke consent through any reasonable method with the revocation applying broadly across the sender. Programs that relied on broad lead-gen consent or narrow opt-out channels have had to redesign.

Does TCPA apply to B2B sales calls?

In important respects, yes. TCPA restrictions on autodialed and prerecorded calls and on texts to wireless numbers apply even when the recipient is a business user. B2B programs that rely on cold SMS, prerecorded voicemail drops, or power-dialed outreach to mobile numbers face the same statutory risk as consumer-facing programs. Manual, human-initiated outreach to researched numbers carries materially different risk than automated blasts.

How is TCPA different from the CAN-SPAM Act?

CAN-SPAM governs commercial email: it requires accurate headers, a clear opt-out mechanism, and a valid physical address, but it does not require opt-in consent before sending. TCPA governs phone, text, prerecorded voice, and fax, and does require prior express consent (and in many cases written consent) before marketing. The two laws are often confused but have different scope and very different consent rules.

Is this page legal advice?

No. This page is a general educational explanation of how the TCPA works and how CRM operations typically address it. It is not legal advice, does not create an attorney-client relationship, and does not substitute for counsel familiar with your program, your consent flows, your dialing architecture, and the current state of FCC guidance and case law in your jurisdiction. Before launching an outbound phone or SMS program at scale, review the plan with qualified counsel.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.