Telephone Consumer Protection Act (TCPA)

Telephone Consumer Protection Act (TCPA)

Telephone Consumer Protection Act (TCPA)

TL;DR

TL;DR

The Telephone Consumer Protection Act (TCPA) is a 1991 US federal law that restricts autodialed calls, prerecorded voice messages, and text messages sent to consumers without prior consent.

The Telephone Consumer Protection Act (TCPA) is a 1991 US federal law that restricts autodialed calls, prerecorded voice messages, and text messages sent to consumers without prior consent.

What is the Telephone Consumer Protection Act?

The Telephone Consumer Protection Act is a United States federal law that restricts how businesses may contact consumers by phone. It governs autodialed calls, prerecorded and artificial voice messages, text messages, and unsolicited faxes, and it makes prior consent the condition on which most automated outreach depends.

Congress passed the law in 1991 to curb intrusive telemarketing, and its reach has widened with every new channel: a statute written for answering machines and fax machines now governs SMS marketing, voice broadcasting, and synthetic-voice calling systems that did nothing at all when it was drafted.

How the Telephone Consumer Protection Act works

Compliance turns on four questions, asked in order: which number you are contacting, what technology places the contact, what consent you hold for that number, and when the contact goes out.

The number comes first, because restrictions are tightest on wireless lines, where an automated call or text arrives at a device the consumer carries and often pays for. Technology comes second: whether an automatic telephone dialing system, a prerecorded message, or an artificial voice is involved determines which restrictions attach at all. Consent comes third, and it is graded, with the strictest form reserved for marketing and a narrower permission covering purely informational or transactional contact. Timing comes fourth, covering calling hours and revocation, since an opt-out ends the permission whatever was signed earlier.

Whether outreach leaves through a call center dialer, a short message service (SMS) gateway, or an outbound voice AI platform, those four questions decide legality before a single number is dialed.

What the Telephone Consumer Protection Act covers

  • Autodialed calls: Calls placed by equipment dialing from a stored or generated list without a human pressing the keys, the core target of the statute.

  • Prerecorded and artificial voice: Any call that plays a recorded message or synthesized speech to the consumer, whether or not a dialer was involved.

  • Text messages: SMS and MMS to wireless numbers are treated as calls for consent purposes, so marketing text programs carry the exposure voice campaigns carry.

  • App-based messaging: WhatsApp Business API traffic travels over the internet while carrier SMS moves through the phone network, a distinction that changes the analysis without erasing consent obligations.

  • Do-not-call obligations: Scrubbing against the national registry and maintaining an internal, company-specific suppression list recording every consumer who has asked you to stop.

TCPA vs CAN-SPAM vs the Do Not Call Registry vs state mini-TCPA laws

Teams building an outbound program meet these four rules in the same week and cannot tell which one is biting. CAN-SPAM governs commercial email, setting rules for header accuracy, sender identification, and unsubscribe handling. The National Do Not Call Registry governs telemarketing to numbers consumers have listed, and it operates through periodic list scrubbing. State mini-TCPA statutes govern the same calls and texts under separate state law, frequently with their own consent definitions and their own private right of action. The TCPA sits underneath all of it as the federal baseline for automated calls and texts to US phone numbers.


Who it binds

What it requires

How it is evidenced

Telephone Consumer Protection Act (TCPA)

Anyone placing automated calls or texts to US phone numbers

Prior consent, honored revocations, restricted calling hours

Retained consent records and dated suppression logs

CAN-SPAM Act

Senders of commercial email

Accurate headers, working unsubscribe, physical postal address

Message archives and unsubscribe processing records

National Do Not Call Registry

Telemarketers dialing listed residential and wireless numbers

Regular registry scrubbing before each campaign

Dated scrub files matched against the dialed list

State mini-TCPA statutes

Callers contacting residents of that particular state

State-specific consent language and disclosure terms

Per-state consent capture and campaign audit trail

If you send commercial email, CAN-SPAM is your rule. If you dial or text US phone numbers with any automated system, the TCPA is the floor, registry scrubbing is one obligation inside it, and the state statutes stack on top wherever your recipients live.

Why the Telephone Consumer Protection Act matters for customer experience

Consent rules are usually framed as legal exposure, and the exposure is real: statutory damages are assessed per contact, so one misconfigured campaign multiplies across a list of hundreds of thousands of numbers, and private class actions are the usual enforcement route.

The customer-experience failure sits earlier than the lawsuit. A program with weak consent hygiene sends renewal reminders to people who churned, delivery updates to numbers reassigned months ago, and promotions to customers who opted out through a channel the marketing stack never reads. Each of those lands as evidence that the company has lost track of who its customer is.

The tradeoff is genuine. Tight consent gating also suppresses contacts customers would have welcomed, including outage notices and fraud warnings, so the most defensible program is frequently the least useful one.

How is TCPA compliance measured?

TCPA compliance is measured against thresholds written into the implementing rule, which makes the targets identical for every company and unrelated to industry averages. The federal delivery restrictions, set out in the eCFR text of 47 CFR 64.1200, fix the outer telemarketing window at 8 a.m. to 9 p.m. in the called party's local time and cap the period for honoring a do-not-call request at 30 days.

Around those fixed points, outbound teams track four internal measures: consent coverage, the share of dialable numbers with a retrievable consent record; suppression latency, how long a stop request takes to reach every system that can dial; scrub currency, how recently the list was checked against the national registry; and complaint rate per thousand attempts. Complaint rate is the leading indicator, since it moves well before a demand letter arrives.

How AI agents change TCPA compliance

The mechanism is scale plus synthesis. An AI voice agent composes speech at call time, so every call is a fresh generation, yet it is delivered by an artificial voice under program control, which is the shape of contact the statute was written around. Voice cloning sharpens the question further, because a synthetic voice modeled on a named person raises identification and disclosure issues stacked on top of the consent question.

Volume is the second shift. A team that once placed a few thousand calls a day can now place many multiples of that, and the same consent defect that used to produce a handful of complaints now produces a class-sized list. Guidance on how AI voice agents handle customer calls treats consent verification and opt-out capture as call-flow steps, so the agent recognizes "stop calling me", writes it to suppression, and closes the call.

Implementing TCPA compliance in an outbound program

Coverage is the first axis: every number your systems can dial needs a retrievable consent record naming the channel, the date, the capture surface, and the exact language shown to the consumer. Integration surface is the second, because an opt-out captured by a chat agent has to reach the dialer, the messaging platform, and the CRM within minutes, and most incidents are propagation failures.

Governance decides who owns the suppression list and who may launch a campaign, the same control set an EU AI Act compliance checklist asks support teams to document. Regulated buyers also ask how consent evidence is stored and produced, so SOC 2 Type II reports get requested from whichever vendor holds those records.

The binding constraint is retention. Claims arrive long after a campaign ends, and a consent record you cannot produce years later functions as no consent at all.

The Telephone Consumer Protection Act and AI compliance

Consent management is where telephone law meets AI compliance generally: both ask an organization to prove that an automated system acted inside a permission it can produce on demand. The artifacts overlap almost entirely, since a consent ledger, an audit trail, and a documented escalation path serve either review.

AI personalization raises the stakes, because a model choosing which customers to contact and when can quietly widen a campaign past the segment consent was collected for, and the targeting logic then becomes part of the compliance record.

What does the TCPA mean in plain terms?

TCPA stands for the Telephone Consumer Protection Act, and the full form describes the job: it protects consumers from their own telephone. Think of it as a permission slip attached to every phone number. A business may use automated dialing or messaging on that number only while it holds a valid slip, and the person who signed it can tear it up at any moment.

Without that structure the economics run one way. Sending a million texts costs a business almost nothing per message, so any response rate above roughly zero pays for itself, and every handset in the country becomes a billboard. The law works by attaching a real cost to each unwanted message.

The tradeoff people actually feel is delay. A company that must verify a permission slip before dialing will be slower to reach you with something you wanted, such as a fraud alert, and that latency is the price of the protection.

Common Telephone Consumer Protection Act mistakes

Treating consent as an account-level property is the first pattern. Consent is captured on a specific number, for a specific purpose, through a specific surface, and a single CRM field named "marketing opt-in" collapses all three, so permission gathered for shipping alerts gets read as permission to run a promotion.

Fragmented suppression is the second. When each channel keeps its own stop list, an opt-out sent by text stops texts while the voice dialer keeps running, and the customer experiences the gap as being ignored on purpose.

Number reassignment is the third mechanism. Consent belongs to the person who gave it, carriers recycle disconnected numbers continuously, and a list that was clean the day it was built decays without anyone touching it.

The fourth is assuming a conversational AI voice escapes the rules because it improvises its wording. The dialing is automated and the voice is synthetic, which is what the statute examines.

Frequently Asked Questions

What does TCPA stand for?

TCPA stands for the Telephone Consumer Protection Act, a United States federal law enacted in 1991. It restricts automated calls, prerecorded and artificial voice messages, text messages, and unsolicited faxes sent to consumers without prior consent, and it is the reason outbound programs store a permission record for every number they dial.

Does the TCPA apply to text messages?

The TCPA applies to text messages sent to wireless numbers, which are generally treated the same way calls are treated for consent purposes. A marketing SMS campaign therefore needs the permission a marketing voice campaign needs, and a stop request received by text has to suppress future messages across every system able to send them.

What is the difference between the TCPA and CAN-SPAM?

The TCPA and CAN-SPAM cover different channels. The TCPA governs calls and texts to phone numbers and is built around permission obtained before contact. CAN-SPAM governs commercial email and is built around accurate sender identification and a working unsubscribe after contact, which is why email programs may send first and process opt-outs afterward.

Is the Do Not Call Registry the same thing as the TCPA?

The Do Not Call Registry is one mechanism operating inside the broader telemarketing framework the TCPA established. The registry is a national list of numbers consumers have asked telemarketers to avoid, and scrubbing against it is a single obligation. Consent, calling hours, dialing technology, and internal suppression lists sit outside the registry entirely.

Do AI voice agents fall under the TCPA?

AI voice agents generally fall under the same rules that cover other automated outreach, because the statute examines automated dialing and artificial or prerecorded voice delivery. A conversational agent improvising its wording still speaks with a synthesized voice under program control, so outbound campaigns need consent, clear disclosure, and immediate opt-out handling on the call.

What counts as prior express written consent?

Prior express written consent is the strictest permission tier, applied to automated marketing calls and texts. In practice it means a signed or electronically recorded agreement in which the consumer identifies the number, names the business permitted to contact them, and acknowledges the disclosures presented at the moment of capture. Programs retain that record for years.

Learn More

Learn More

Knowledge base

K

Average handling time (AHT)

A

Telephony

T

Customer acquisition cost (CAC)

C

Business process outsourcing (BPO)

B

AI tokens

A

Human in the loop (HITL)

H

AI grounding vs retrieval-augmented generation (RAG)

A

Short message service (SMS)

S

Call center

C

Data annotation

D

Ticket routing

T

Customer service quality assurance (QA)

C

Live chat

L

Speech Synthesis Markup Language (SSML)

S

Batch inference

B

Barge-in

B

SLA compliance rate

S

Queue management

Q

Prompt versioning

P

Emotion detection

E

Retrieval-augmented generation (RAG)

R

Natural language understanding (NLU)

N

Text classification

T

Call routing

C

Customer churn rate

C

Speech-to-speech

S

Intent recognition

I

Voice of the employee (VoE)

V

Confidence score

C

Resolution-based pricing

R

AI personalization

A

Voice cloning

V

Asynchronous messaging

A

Hallucination

H

ReAct agent pattern

R

Long-term memory

L

Forecast accuracy

F

Customer feedback loop

C

Structured output

S

Outbound voice AI

O

AI guardrails

A

Direct preference optimization (DPO)

D

Prompt chaining

P

SIP transfer

S

Fallback intent

F

Conversation summarization

C

Auto-tagging

A

Cost per contact

C

VoIP jitter

V

Model card

M

Ticket prioritization

T

Sentiment analysis

S

Agent utilization rate

A

Speech-to-intent

S

Prompt engineering

P

Knowledge atlas

K

SOC 2 AI support

S

Prosody

P

Chatbot containment rate

C

Speech synthesis

S

Intelligent virtual agent (IVA)

I

Fine-tuning

F

ISO 42001

I

Intent-based search

I

After-call work (ACW)

A

Chatbot

C

AI agent

A

Prior authorization automation

P

AI customer service

A

Ticket deflection

T

AIUC-1

A

Workforce management (WFM)

W

Skill-based routing

S

Interactive voice response (IVR)

I

Contact center as a service (CCaaS)

C

Warm transfer

W

Customer segmentation

C

Reinforcement learning

R

Voice activity detection (VAD)

V