podium logo

The TCPA Compliance Checklist to Help Your Business Succeed

Brad GrangerManaging Director, Podium Australia

Telephone Consumer Protect Act compliance is a must, but it doesn’t have to limit your marketing. Keep your customers informed without violating FCC guideline
clock0 min. read

If you’ve ever considered a telemarketing or SMS marketing strategy for your business, you probably know you can’t send messages to anyone at any time—and it’s not just a matter of ethics. TCPA compliance is required by law.

The Telephone Consumer Protection Act (TCPA) was created in 1991 to prevent intrusive telemarketing calls—including those that are auto-dialed or have pre-recorded voice messages—from reaching private phone lines. Since then, the Federal Communications Commission (FCC) has extended the law to regulate communication channels like text messages, too.

For marketers, the TCPA puts a spotlight on one overarching fact: Phone numbers are personal information that shouldn’t be taken lightly. To give your leads and customers the best experience possible, you need to be strategic while following TCPA guidelines.

To ensure you understand the rules, we’ll break down the most important elements of TCPA compliance and offer a checklist that makes it easy to follow.

What is TCPA compliance?

TCPA compliance simply means to abide by TCPA regulations on telemarketing calls, as well as faxes and text messages with a commercial purpose.

Telemarketing calls are perhaps the most strictly regulated form of communication under the TCPA. The law requires you to receive prior written express consent—usually in the form of a signed agreement—before you can make either of the following types of calls:

  • Pre-recorded messages: These include messages recorded by humans, as well as the artificial voice messages you often hear on robocalls.
  • Autodialer calls: These include any calls made on an automatic telephone dialing system (ATDS), in which numbers are stored and dialed without any human action.

Your telemarketing calls cannot hide your caller ID information, nor can they be made to users on the National Do Not Call Registry (DNC Registry).

Still, not all phone calls are considered telemarketing calls. Your business can take advantage of manual phone calls. For example, targeted cold calling is TCPA compliant, as long as it abides by rules and regulations included in the checklist below.

TCPA compliance for text messages

Due to the many limits placed on telephone solicitations, as well as the fact that consumers are shifting toward greater text message use, many companies are now turning toward SMS messaging first.

TCPA compliance is much easier when it comes to texts. Instead of requiring written consent, the FCC only requires your business to acquire basic prior express consent before sending SMS messages—and this consent is easy to obtain. Under the TCPA, your leads simply need to knowingly offer their number to your company, perhaps by filling in a form at a doctor’s office or by entering their number on a web chat tool.

Of course, consumers must be able to revoke their consent at any time (often by texting back “STOP”), in the same way that shoppers always have the option to unsubscribe from promotional emails.

TCPA compliance for SMS messages also requires that you send only messages related to what the consumer consented to. For example, if a consumer opts into hair appointment reminders at a salon, they shouldn’t be receiving promotional texts about discounts or new services.

The word “consent” gets used loosely in TCPA discussions, but the Act actually recognises a few different tiers, and mixing them up is one of the easiest ways to end up non compliant without realising it.

Express written consent is the strictest standard, required specifically for autodialed or prerecorded telemarketing calls and for most marketing text messages. It has to be in writing (a signed form, a checked box, a confirmed opt in text all count), clearly disclose what the customer is agreeing to, and can’t be buried in unrelated terms and conditions. A gym asking new members to tick a box agreeing to receive promotional texts about class schedules is a straightforward example.

Prior express consent is a slightly lower bar, and it applies to informational or transactional messages such as appointment reminders, delivery updates, or account alerts. This can be inferred from the existing relationship, such as a patient providing their number when booking an appointment.

The distinction between transactional and promotional messaging matters just as much as the consent type itself. A transactional message serves the existing relationship, think order confirmations, appointment reminders, or password resets, and generally needs a lighter touch on consent. A promotional message, anything selling a product, service, or discount, needs the higher bar of express written consent. Sending a promotional offer to a list that only consented to appointment reminders is a common and costly mistake.

Why TCPA compliance matters

TCPA compliance is an ethical must for every business. Contacting consumers through their mobile phones is a relatively personal form of communication, which means using telephone numbers with no regard for a customer’s privacy can feel intrusive over time.

When you want to build and maintain customer satisfaction, you must give your leads and current buyers the respect they deserve. Sending only the most relevant messages to willing consumers can even help you increase customer loyalty over time. 

It’s also costly to ignore the Telephone Consumer Protection Act. For every violation, you may be charged as much as $16,000. Plus, each of the individual people who you contact can claim up to $500 for every violating call, text, fax, or voice message. If the federal courts believe your violation was done on purpose, this claim can rise to $1,500 per message.

By fully understanding TCPA compliance, you can develop excellent text messaging or calling campaigns that won’t put your company at risk for fines or other penalties.

The TCPA compliance risks businesses often overlook

Most TCPA violations aren’t the result of businesses deliberately ignoring the rules. They come from a handful of easy to miss traps that catch out otherwise careful marketing teams.

Purchased lists are the most obvious risk. Buying a list of phone numbers, even one marketed as opted in, almost never meets the TCPA’s consent standard, because the consent was given to a different company for a different purpose. If you can’t trace consent back to your own business and your own message type, treat the number as unconsented.

Reassigned phone numbers cause a surprising number of complaints. Mobile numbers get recycled constantly, so a number that gave valid consent two years ago may now belong to someone who never agreed to hear from you at all. The FCC has previously allowed a small buffer for a single message to a reassigned number, but repeated messaging after that is a real liability, which is why periodically cleaning your contact list matters.

Opt in mismatch across channels is another quiet risk. A customer who signs up for email marketing on your website hasn’t automatically consented to SMS, and vice versa. Each channel needs its own clear consent trail, even if the customer is the same person.

Finally, silent consent assumptions, treating a lack of complaint as ongoing permission, aren’t a defence. Consent needs to be actively given and it needs to be revocable at any time, regardless of how long someone has been on your list without objecting.

TCPA compliance checklist

Actively committing to TCPA compliance is the best way to create a great customer experience while avoiding expensive fines and class action TCPA lawsuits. However, the TCPA can be hard to follow, even if you have good intentions.

Below are some essential actions you must take to remain compliant with the Telephone Consumer Protection Act.

  1. Only contact consumers during approved times. Businesses cannot contact shoppers on their cell phones or landlines for commercial purposes between 9 p.m. and 8 a.m. (local time).
  2. Avoid consumers on the DNC Registry. For telemarketers, it’s required to check their current call lists against the national DNC list every 31 days.
  3. Get consent. Have proof of prior express consent, or get express written consent in the case of automated telephone calls or pre-recorded telemarketing messages.
  4. Allow consumers to opt out. Even if a consumer has given prior consent, they must have an opt-out option. Telemarketers are actually required to keep a company-specific “do not call” list that’s up-to-date.
  5. Abide by maximum character counts. The content of your text messages must include no more than 160 characters, including spaces and punctuation. This character count may go down to 70 when texting in character-based languages, such as Chinese or Japanese.
  6. Train your team. While this isn’t a requirement from the FCC, it’s highly recommended to keep your team members up-to-date on regulations, so they never unintentionally cause a violation.

As you can see, every step is designed to keep unsolicited advertisements to a minimum. These steps will also encourage you to send your leads and customers the most relevant information at the right times.

Understanding carrier rules and 10DLC registration

Following the TCPA is only half the compliance picture for businesses sending SMS at scale in the US market. Carriers have their own registration system, known as 10DLC (ten digit long code), that sits alongside legal compliance and directly affects whether your messages actually arrive.

10DLC brand registration involves registering your business and each messaging campaign with a central registry that the major US carriers use to verify who’s sending traffic and why. Unregistered numbers are increasingly treated with suspicion by carrier filtering systems, which scan for spam patterns, unusual sending volume, and low quality content before a message ever reaches a handset.

This is why unregistered SMS gets blocked or heavily throttled: carriers can’t distinguish a legitimate unregistered business from a spammer using the same workaround, so the safer option from their side is to filter aggressively. Businesses that skip registration often see delivery rates drop without any obvious explanation, which can be mistaken for a platform issue when it’s actually a carrier trust issue.

Message reputation scoring compounds this over time. Each registered brand and campaign builds a reputation score based on complaint rates, opt out behaviour, and content quality. A poor score leads to more filtering, while a clean sending history earns better deliverability. Working with a platform like Podium that handles 10DLC registration and monitors sending reputation on your behalf takes this off your plate entirely, but it’s worth understanding why the process exists in the first place.

SMS payments under the TCPA

While the TCPA may regulate commercial activities, it by no means exists to prevent you from adapting to the modern business landscape. As your competitors and consumers shift toward smartphone-based strategies—including text message payments—there’s no reason you can’t do so, too.

Plenty of businesses are starting to implement SMS payments into their checkout process, allowing buyers to pay via text—and it’s easy to do so without breaking TCPA regulations. 

By following the TCPA compliance checklist above, as you would for any text messages, you can offer your customers a convenient user experience that inspires them to complete the buyer’s journey.

How to build up your TCPA-safe SMS workflow

Understanding the rules is one thing. Building a repeatable process that keeps you compliant without slowing down your marketing is another. A solid TCPA safe workflow generally follows five steps.

  • Capture consent at the point of signup, whether that’s a website form, an in-store tablet, or a checkbox during checkout. Record the exact wording the customer agreed to, along with the date and method, since this becomes your evidence if consent is ever questioned.
  • Store consent centrally rather than in scattered spreadsheets or individual staff phones. A shared system means every team member sending messages is working from the same up to date record of who has agreed to what.
  • Segment users by consent type and message category. Someone who opted into appointment reminders shouldn’t be lumped into the same list as someone who opted into promotional offers, even if they’re the same customer.
  • Send compliant campaigns by matching the message to the consent on file, including your business name so recipients know who’s texting them, and respecting the 9pm to 8am contact window for anything with a commercial angle.
  • Manage opt outs automatically rather than manually. A customer texting “STOP” should be removed from future messaging immediately and across all relevant lists, not just the campaign they replied to. Manual opt out handling is where a lot of businesses fall behind, simply because it relies on someone remembering to act on every reply.

Platforms like Podium build most of this workflow in as standard, which is worth knowing if you’re currently managing consent and opt outs by hand.

Build customer satisfaction with Podium

The Telephone Consumer Protection Act regulates how you implement telemarketing, SMS messaging, and more phone-based communications into your strategy. However, it isn’t necessarily a limitation. 

Staying TCPA compliant can help you give your consumers the experience they want. When they only receive the most relevant messages at convenient times, they’re more likely to respond and become loyal patrons.

Nothing is stopping you from continually innovating under the TCPA, either. You can brainstorm and implement creative messages, as well as processes like SMS payments, that make the customer experience even better. 

With Podium Payments, an SMS payment solution, you can start closing deals and building relationships without worrying about breaking your TCPA compliance.